feat: standalone checksum-only integrity API (#13) - #50
Conversation
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
WalkthroughA new ChangesStandalone checksum extraction and storage integration
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related issues
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Extracts xxHash3-64 checksum and verify_checksum as a standalone public primitive in src/checksum.rs, gated on the 'checksum' feature alone. Usable without compression or messagepack. Includes 6 unit tests: 5 behavioral + 1 known-answer regression locking algorithm and big-endian byte order. Wire value is identical to StorageEnvelope's embedded checksum.
DRY: replace inline xxh3_64(data).to_be_bytes() with crate::checksum::checksum(data). The DRY-guard test (envelope_embeds_canonical_checksum) confirms byte-identical wire output before and after the refactor. xxh3_64 import retained — extract() still uses it.
DRY: replace inline xxh3_64(&decompressed).to_be_bytes() + manual compare with crate::checksum::verify_checksum(). ChecksumMismatch error variant is preserved on false return. Removes the now-dead xxhash_rust import from byte_storage.rs — single canonical xxHash3-64 definition lives in checksum.rs.
Updates the xxHash3-64 security property bullet to call out standalone availability via checksum/verify_checksum without requiring compression.
4003b0e to
aec9510
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 259: Update the README source-tree entry for checksum.rs to annotate that
it is available only when feature = "checksum" is enabled, matching the
feature-gating documented in src/lib.rs and the annotations for related modules.
🪄 Autofix (Beta)
✅ Autofix completed
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 2b5214cc-1f6b-4c0d-9940-2a9f5cef4940
📒 Files selected for processing (4)
README.mdsrc/byte_storage.rssrc/checksum.rssrc/lib.rs
|
Note Autofix is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it. Fixes Applied SuccessfullyFixed 1 file(s) based on 1 unresolved review comment. Files modified:
Commit: The changes have been pushed to the Time taken: |
Fixed 1 file(s) based on 1 unresolved review comment. Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Transitive dev-dependency (criterion -> rayon -> rayon-core -> crossbeam-deque -> crossbeam-epoch) flagged by cargo audit and cargo deny for an invalid pointer dereference in the fmt::Pointer impl for Atomic/Shared. Lockfile-only bump; cargo audit, cargo deny check, and cargo test --all-features verified green locally. Co-authored-by: multica-agent <github@multica.ai>
|
@coderabbitai review |
✅ Action performedReview finished.
|
Closes the cachekit-core half of #13. (PyO3 bindings + py-vs-FFI benchmark land in a follow-up cachekit-py PR once 0.3.0 publishes.)
What
Exposes xxHash3-64 integrity as a standalone primitive, decoupled from compression — two free functions gated on
feature = "checksum"alone:checksum(data: &[u8]) -> [u8; 8]verify_checksum(data: &[u8], expected: &[u8; 8]) -> boolUsable with
default-features = false, features = ["checksum"](no LZ4/messagepack). This unblocks callers (e.g. Python Arrow/JSON serializers) that want the fast 8-byte xxHash3 checksum where LZ4 compression is ineffective, without reaching for Blake3.DRY
StorageEnvelope::{new,extract}now consume the new primitive — one canonical xxHash3-64 definition. The inlinexxh3_64is gone frombyte_storage.rs. No wire-format change: the stored checksum bytes are byte-identical (big-endian), test-locked byenvelope_embeds_canonical_checksum.Design notes (deliberate — please don't "fix")
checksum()is intentionally unbounded (no size cap): a pure O(n) hash over already-materialized bytes; theMAX_UNCOMPRESSED_SIZEcap isStorageEnvelope's decompression-bomb concern, not applicable here.verify_checksumis plain (non-constant-time) equality: correct for a non-cryptographic corruption check. Tamper-resistance is AES-256-GCM's job.Tests
checksum(b"cachekit-kat")), reproduced independently against Pythonxxhash.extractreturns theChecksumMismatchvariant on corruption).Verification
cargo fmt --check·cargo clippy --all-features -- -D warnings·cargo test --all-features(198 pass) ·cargo test --no-default-features --features checksum --lib(feature-gating) — all green.Release
feat:→ release-please cuts 0.3.0, co-tenant with #48 (perf: borrow input…). Both are already on this branch's base.Summary by CodeRabbit
Release Notes
New Features
Improvements