test(encryption): ignore the wall-clock key-timing test on shared runners (LAB-6714) - #95
Conversation
…ners (LAB-6714) A wall-clock ratio on a shared CI runner cannot measure constant-time behaviour, and on native targets the timed operation is ring's AES-256-GCM, not this crate's code. The threshold was already raised 20% -> 150% -> 200% and macos-latest still hit 209%. Ignore it by default with the on-demand command in a comment.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe timing test is now ignored by default. Comments explain the limits of its measurements on shared runners and show how to run it on demand. The test logic and timing assertions are unchanged. ChangesTiming test execution
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to The timing test remains available on demand while routine runs skip unreliable wall-clock measurements. No substantive issue prevents merging. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
This PR marks
security_tests::test_timing_independent_of_key_patternintests/encryption_tests.rswith#[ignore], so it no longer runs by default incargo testor in CI. The test body, itsdiff < 2.0threshold, and all code undersrc/are unchanged. No public APIs are affected.Changes
#[ignore = "wall-clock timing ratio on shared CI runners cannot measure constant-time behaviour"]to the test. The reason appears in the test runner output, so the exclusion is visible rather than silent.ring's AES-256-GCM, so the test cannot detect a leak in cachekit-core's own code.cargo test --all-features --test encryption_tests -- --ignored test_timing_independent_of_key_patternImpact
--ignoredunder controlled conditions, with the original assertion strictness.security_testsare unaffected. That includes the preceding timing test, which still runs by default.