Skip to content

feat: standalone checksum-only integrity API (#13) - #50

Merged
27Bslash6 merged 10 commits into
mainfrom
feat/checksum-only-api
Jul 15, 2026
Merged

27Bslash6 merged 10 commits into
mainfrom
feat/checksum-only-api

Conversation

@27Bslash6

@27Bslash6 27Bslash6 commented Jun 16, 2026 •

Copy link
Copy Markdown
Contributor

Closes the cachekit-core half of #13. (PyO3 bindings + py-vs-FFI benchmark land in a follow-up cachekit-py PR once 0.3.0 publishes.)

What

Exposes xxHash3-64 integrity as a standalone primitive, decoupled from compression — two free functions gated on feature = "checksum" alone:

  • checksum(data: &[u8]) -> [u8; 8]
  • verify_checksum(data: &[u8], expected: &[u8; 8]) -> bool

Usable with default-features = false, features = ["checksum"] (no LZ4/messagepack). This unblocks callers (e.g. Python Arrow/JSON serializers) that want the fast 8-byte xxHash3 checksum where LZ4 compression is ineffective, without reaching for Blake3.

DRY

StorageEnvelope::{new,extract} now consume the new primitive — one canonical xxHash3-64 definition. The inline xxh3_64 is gone from byte_storage.rs. No wire-format change: the stored checksum bytes are byte-identical (big-endian), test-locked by envelope_embeds_canonical_checksum.

Design notes (deliberate — please don't "fix")

  • checksum() is intentionally unbounded (no size cap): a pure O(n) hash over already-materialized bytes; the MAX_UNCOMPRESSED_SIZE cap is StorageEnvelope's decompression-bomb concern, not applicable here.
  • verify_checksum is plain (non-constant-time) equality: correct for a non-cryptographic corruption check. Tamper-resistance is AES-256-GCM's job.

Tests

  • Determinism, empty-input (value-pinned), match/reject, single-bit-flip rejection.
  • Known-answer test locking algorithm + big-endian order (checksum(b"cachekit-kat")), reproduced independently against Python xxhash.
  • DRY-guard (write path) + tightened fail-open guard (extract returns the ChecksumMismatch variant on corruption).

Verification

cargo fmt --check · cargo clippy --all-features -- -D warnings · cargo test --all-features (198 pass) · cargo test --no-default-features --features checksum --lib (feature-gating) — all green.

Release

feat: → release-please cuts 0.3.0, co-tenant with #48 (perf: borrow input…). Both are already on this branch's base.

Summary by CodeRabbit

Release Notes

  • New Features

    • Added a standalone xxHash3-64 checksum module (feature-gated) for data integrity verification.
  • Improvements

    • Centralised checksum generation and verification for consistent integrity checking.
    • Strengthened integrity validation with more precise checksum-mismatch handling.
    • Updated documentation and architecture diagram to reflect the new checksum module.

@coderabbitai

coderabbitai Bot commented Jun 16, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Important

Review skipped

No new commits to review since the last review.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: b2fb8034-026e-4c71-9605-1d60127ecbef

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Walkthrough

A new src/checksum.rs module provides standalone xxHash3-64 checksum and verification primitives. They are exported from src/lib.rs under the checksum feature. src/byte_storage.rs delegates checksum generation and verification to the module, with README architecture documentation updated.

Changes

Standalone checksum extraction and storage integration

Layer / File(s) Summary
Checksum primitive and crate wiring
src/checksum.rs, src/lib.rs, README.md
Adds checksum and verification APIs with big-endian xxHash3-64 output, unit tests, feature-gated crate-root exports, standalone-use documentation, and an Architecture diagram entry.
Storage envelope checksum delegation
src/byte_storage.rs
Routes checksum creation and decompressed-data verification through crate::checksum, and tests canonical digests and specific ByteStorageError::ChecksumMismatch results.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related issues

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarises the new standalone checksum-only integrity API introduced by the PR.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/checksum-only-api

Comment @coderabbitai help to get the list of available commands.

Extracts xxHash3-64 checksum and verify_checksum as a standalone public
primitive in src/checksum.rs, gated on the 'checksum' feature alone.
Usable without compression or messagepack. Includes 6 unit tests: 5
behavioral + 1 known-answer regression locking algorithm and big-endian
byte order. Wire value is identical to StorageEnvelope's embedded checksum.
DRY: replace inline xxh3_64(data).to_be_bytes() with crate::checksum::checksum(data).
The DRY-guard test (envelope_embeds_canonical_checksum) confirms byte-identical
wire output before and after the refactor. xxh3_64 import retained — extract()
still uses it.
DRY: replace inline xxh3_64(&decompressed).to_be_bytes() + manual compare
with crate::checksum::verify_checksum(). ChecksumMismatch error variant is
preserved on false return. Removes the now-dead xxhash_rust import from
byte_storage.rs — single canonical xxHash3-64 definition lives in checksum.rs.
Updates the xxHash3-64 security property bullet to call out standalone
availability via checksum/verify_checksum without requiring compression.
@27Bslash6
27Bslash6 force-pushed the feat/checksum-only-api branch from 4003b0e to aec9510 Compare July 14, 2026 13:21

@coderabbitai coderabbitai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@README.md`:
- Line 259: Update the README source-tree entry for checksum.rs to annotate that
it is available only when feature = "checksum" is enabled, matching the
feature-gating documented in src/lib.rs and the annotations for related modules.
🪄 Autofix (Beta)

✅ Autofix completed


ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 2b5214cc-1f6b-4c0d-9940-2a9f5cef4940

📥 Commits

Reviewing files that changed from the base of the PR and between 4003b0e and aec9510.

📒 Files selected for processing (4)
  • README.md
  • src/byte_storage.rs
  • src/checksum.rs
  • src/lib.rs

Comment thread README.md Outdated
@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor

Note

Autofix is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it.

Fixes Applied Successfully

Fixed 1 file(s) based on 1 unresolved review comment.

Files modified:

  • README.md

Commit: 900aa86c94fcff03ee16e133d244199e6aad491f

The changes have been pushed to the feat/checksum-only-api branch.

Time taken: 7m 13s

coderabbitai Bot and others added 2 commits July 14, 2026 14:18
Fixed 1 file(s) based on 1 unresolved review comment.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Transitive dev-dependency (criterion -> rayon -> rayon-core ->
crossbeam-deque -> crossbeam-epoch) flagged by cargo audit and
cargo deny for an invalid pointer dereference in the fmt::Pointer
impl for Atomic/Shared. Lockfile-only bump; cargo audit, cargo deny
check, and cargo test --all-features verified green locally.

Co-authored-by: multica-agent <github@multica.ai>
@27Bslash6

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@27Bslash6
27Bslash6 enabled auto-merge (squash) July 15, 2026 14:24
@27Bslash6
27Bslash6 merged commit afced1a into main Jul 15, 2026
30 checks passed
@27Bslash6
27Bslash6 deleted the feat/checksum-only-api branch July 15, 2026 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant