Skip to content

feat: type changes for trailer hash - #82

Merged
alanshaw merged 4 commits into
mainfrom
ash/feat/trailer-hash
Oct 1, 2026
Merged

alanshaw merged 4 commits into
mainfrom
ash/feat/trailer-hash

Conversation

@alanshaw

@alanshaw alanshaw commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Union decoding can materialize unbounded input before variant limits are enforced, creating a critical memory-consumption risk.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds digest-aware blob types and propagates computed trailer hashes through HTTP PUT results.

Changes:

  • Adds blob specification and reject-argument unions.
  • Updates generated CBOR/DAG-JSON codecs and tests.
  • Extends PUT results with optional computed digests.
File Description
commands/​internal/​codec/​codec.go Shared union decoding helpers
commands/​http/​types.go PUT result types
commands/​http/​put.go Updated PUT result binding
commands/​http/​put_test.go PUT result tests
commands/​http/​json_gen.go Generated JSON codecs
commands/​http/​gen/​main.go HTTP model registration
commands/​http/​cbor_gen.go Generated CBOR codecs
commands/​blob/​types.go Blob and reject union types
commands/​blob/​spec_test.go Blob union tests
commands/​blob/​json_gen.go Generated JSON codecs
commands/​blob/​gen/​main.go Blob model registration
commands/​blob/​codec.go Blob union codecs
commands/​blob/​cbor_gen.go Generated CBOR codecs
commands/​blob/​accept.go Digest mismatch error
commands/​blob/​abort_test.go Reject argument tests
Files not reviewed (4)
  • commands/blob/cbor_gen.go: Generated file
  • commands/blob/json_gen.go: Generated file
  • commands/http/cbor_gen.go: Generated file
  • commands/http/json_gen.go: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread commands/internal/codec/codec.go Outdated
@alanshaw
alanshaw marked this pull request as ready for review September 30, 2026 15:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Blob decoding can accept an invalid empty digest when conflicting fields are supplied.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)
Files not reviewed (4)
  • commands/blob/cbor_gen.go: Generated file
  • commands/blob/json_gen.go: Generated file
  • commands/http/cbor_gen.go: Generated file
  • commands/http/json_gen.go: Generated file

Comment thread commands/blob/codec.go Outdated
Comment on lines +106 to +110
switch hasDigest := len(m.Digest) > 0; {
case hasDigest && m.DigestCode == nil:
s.blob = &Blob{Digest: m.Digest, Size: m.Size}
case !hasDigest && m.DigestCode != nil:
s.code = &BlobDigestCode{DigestCode: *m.DigestCode, Size: m.Size}

@alanshaw alanshaw Oct 1, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤷‍♂️ this is super edge case and IMO not worth the complexity to enforce. An empty digest is not a valid multihash so it cannot possibly be the variant that should be used.

@alanshaw
alanshaw merged commit 6a79424 into main Oct 1, 2026
8 checks passed
@alanshaw
alanshaw deleted the ash/feat/trailer-hash branch October 1, 2026 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants