fix(interop)!: reject reserved namespaces ns and nsapi (LAB-5876) - #350
Conversation
The segment grammar accepted ns and nsapi as an interop namespace, but the CachekitIO server parses a key starting ns: or nsapi: as namespace-prefixed: it rejects the key when the operation contains '.', and otherwise scopes it to a namespace named after the operation. interop-mode 1.1.0 reserves both names (exact match, namespace only); re-vendor its test vectors. BREAKING CHANGE: @cache(interop=..., namespace="ns"|"nsapi") now raises ConfigurationError (chained from InteropError) at decoration, and generate_interop_key raises InteropError. Such keys were already rejected or misrouted by CachekitIO, but worked on Redis, Memcached and File backends.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-py/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughInterop validation now rejects ChangesInterop namespace reservations
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~12 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to No actionable merge-blocking issue is identified; the change appears ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The new validation prevents keys that the server can misinterpret, but applications using the newly reserved names need a coordinated transition. Renaming a namespace makes its existing entries unreachable through normal new-version cache operations; older workers may still use them until retired or the entries are removed. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 34.29% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 35 functions across 5 files. (3 skipped: 3 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
This change reserves the namespaces
nsandnsapiin interop mode (interop/v1). The CachekitIO server parses any key starting withns:ornsapi:as namespace-prefixed. Interop keys use the format{namespace}:{operation}:{args_hash}, so either namespace produced keys that the server rejected (if the operation contains.) or routed to a namespace named after the operation. These configurations now fail when the function is decorated, not at request time.Public API changes
cachekit.interop.RESERVED_NAMESPACESis afrozenset({"ns", "nsapi"})and is added to__all__.validate_segment(name, segment): whenname == "namespace", it now raisesInteropErrorfor a reserved value. This check runs after the existingSEGMENT_REpattern check, and the error message contains "reserved".validate_interop_config(operation, namespace)andgenerate_interop_key(namespace, operation, args)both callvalidate_segment, so both now raiseInteropErrorfor a reserved namespace.@cache(interop=..., namespace="ns"|"nsapi")andcreate_cache_wrappernow raiseConfigurationErrorat decoration time.Scope of the reservation. It matches exact values and applies only to the namespace:
SEGMENT_REis unchanged.nsandnsapiare still valid operation names.nsx,nsfw,nsapi2andnsapix, are still accepted.Breaking impact
Existing deployments that use
nsornsapias an interop namespace on Redis, Memcached or File backends worked before this change and must now rename the namespace. Renaming means a full cache miss for that namespace.Conformance fixture
interop-mode.jsonis re-vendored at protocol version 1.1.0 from fix(interop)!: reserve ns and nsapi as interop namespaces (LAB-5876) protocol#78, sha2569b1855851d888c479e37a8fff9e9bbe5738737a9a408e749d9126c7678b9e7bc. That PR must merge first.reject_reserved_namespace_nsreject_reserved_namespace_nsapireservation_scope(namespacensapix, operationnsapi)pragma: allowlist secret, and its.secrets.baselineentry is removed. The fixture's line entries in the baseline are refreshed to match the new file.Tests
test_interop_model.py: the newTestReservedNamespacesclass checks that:nsandnsapiare accepted;nsx,nsfwandnsapi2are accepted.test_interop_decorator.pyhas two new tests:reservation_scopevector decorates successfully and writes its byte-pinned key.namespace="ns"as a placeholder and now use"users".Docs
docs/features/interop-mode.md:src/cachekit/__init__.pynow usesnamespace="users".