test(tls): cover exact peer certificate limits - #336
seonghobae wants to merge 2 commits into
Conversation
Co-Authored-By: Claude Code <noreply@anthropic.com>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 43 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (5)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Admission repair for exact head This Ready PR still has a concrete merge blocker: terminal workflow: CodeQL PR 36662360843=failure. Converted to Draft/Proposed so review admission does not imply merge readiness while preserving the full branch delta. Acceptance: repair the cited exact-head failure/topology or complete the declared predecessor, re-run required checks, resolve substantive review state, then return the unchanged verified head to Ready. No commits are closed or discarded. |
| let root = root_der(); | ||
| let boundary_bundle = TrustRootBundle::new( | ||
| TrustBundleIdentifier::parse("boundary_roots:v1").expect("identifier"), | ||
| std::iter::repeat_n(root, MAX_TRUST_ROOT_COUNT).collect(), | ||
| ) | ||
| .expect("maximum trust root count is accepted before canonical deduplication"); | ||
| assert_eq!(boundary_bundle.root_count(), 1); |
There was a problem hiding this comment.
🔍 Trust-root limit lacks distinct-root coverage
The 256-root input contains copies of one certificate. TrustRootBundle::new deduplicates them, so root_count() reaches only one. This test does not exercise a bundle retaining 256 roots.
Was this helpful? React with 👍 or 👎 to provide feedback.
Scope
Verification
cargo fmt --all -- --checkcargo test --locked --workspace --all-targets --offlinecargo clippy --locked --workspace --all-targets --offline -- -D warningsRUSTDOCFLAGS="-D warnings" cargo doc --locked --workspace --no-deps --offlinepython3 -m unittest discover -s tests -p "test_*.py"(152 passed)No production behavior or TLS authority changes. Protected-main status remains unchanged until required exact-head checks and review pass.
🤖 Generated with Claude Code