Conversation
The CachekitIO server parses a key starting `ns:` or `nsapi:` as namespace-prefixed, so an interop key in either namespace was rejected (400) or scoped to a namespace named after the operation. interop/v1 fixture 1.1.0 reserves both as namespaces (exact match; operations are unaffected). BREAKING CHANGE: interop_key and #[cachekit(namespace = "ns" | "nsapi")] now reject those namespaces (runtime InvalidKey / compile error). Such keys were already rejected or misrouted by CachekitIO, but worked on Redis, Memcached and file backends.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-rs/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe change reserves the exact namespace values ChangesReserved namespace validation
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The reserved-namespace behavior is reflected consistently in the supplied runtime, macro, test, and documentation summaries. No actionable issue remains before merge. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The restriction prevents keys with reserved prefixes from being generated, but it is a breaking change for deployments that use those namespaces. Renaming them causes cache misses, and the impact of mixed-version deployment or rollback is not established. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
Summary
Reserves
nsandnsapias interop namespaces in both the runtime key builder and the#[cachekit]proc macro. The CachekitIO server parses keys that begin withns:ornsapi:as namespace-prefixed, so interop keys with these namespaces could not be used safely against it.Modified Public APIs
cachekit::interop::interop_keynow returnsCachekitError::InvalidKeywhennamespaceis exactlynsornsapi. Its# Errorsdoc section documents this.#[cachekit(namespace = ...)]now fails at compile time for the same two values, and the error is spanned to the string literal. The attribute docs describe the reservation.The
operationargument and theinterop = ...attribute are unchanged.Behavioral Details
validate_segmentandparse_segment. A malformed segment still produces the existing grammar error, and the reservation error only appears for well-formed input.NSnever reach the reservation check, because the grammar only allows lowercase.nsx,nsapi2,nsfw,nandns-api.namespace "<value>" is reserved: the CachekitIO server parses a key starting "<value>:" as namespace-prefixed. The runtime message is prefixed withinterop.if/elseexpression. Grammar behavior is unchanged.Maintenance Notes
interop.rsandcachekit-macrosnow coverparse_segmentas well assegment_is_valid. Any future change to the reservation has to be made in both crates.ef3e6d4d(sha256a1f24b61…226df) to protocol 1.1.0 (sha2569b185585…e7bc).Tests
syn::parse_str::<MacroArgs>on a full attribute string. It checks that the error names the reservation and that the reserved names are still accepted as operations.namespace_rejects_reserved_ns_and_nsapireservation_is_exact_match_and_namespace_only