Repository navigation
fix #5: tests, docs, CI, and Docker CVEs - #6
Conversation
- kv_test: add handler integration tests (PUT/GET/DELETE via real DLmdb) - Makefile: add docker-verify-local/remote/cve-check targets with Docker guard - README: fix API example, reference published image, adjust sleep timing - Dockerfile: gosu → setpriv (eliminates 68 Go stdlib CVEs), force-purge perl-base + tar (CVE-2026-12087, CVE-2025-45582), --force-remove-essential --force-depends over --force-all - docker-entrypoint.sh: setpriv, skip chown when ownership matches - CI: push tested image (no rebuild), fix shell injection, CVE scan gate - smoke-test: teardown compose on failure - deny.toml: rand@0.8.6 → rand@0.8 (stale patch version)
|
Warning Review limit reached
Next review available in: 8 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (7)
📝 WalkthroughWalkthroughThe Docker runtime now uses ChangesContainer Runtime and Verification
Estimated code review effort: 3 (Moderate) | ~30 minutes Sequence Diagram(s)sequenceDiagram
participant Makefile
participant Docker
participant dlmdb
participant curl
participant DockerScout
Makefile->>Docker: Build or pull image
Docker->>dlmdb: Run container with mounted config and data
Makefile->>curl: PUT and GET /kv/hello
curl->>dlmdb: Send smoke-test requests
Makefile->>DockerScout: Scan local image
DockerScout-->>Makefile: Return vulnerability counts
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docker-entrypoint.sh`:
- Around line 24-28: Update the argument check in the docker entrypoint’s
config-injection case to recognize both separate-value and equals-form flags
(`--config` and `--config=...`). Append the default CONFIG_FILE only when
neither form was supplied, preserving the caller’s explicit configuration.
In `@Makefile`:
- Around line 259-270: The smoke-test recipes at Makefile lines 259-270 and
275-286 must preserve failures instead of masking them: add fail-fast handling
with cleanup via trap, remove any || true from build or cleanup commands, wait
for service readiness, and make both curl requests fail on HTTP errors while
asserting the GET response body is “world”. Apply the identical changes to both
the local-image and pulled-image flows.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: c28c64a4-0348-45a5-b7f8-966a0c8465bf
📒 Files selected for processing (7)
DockerfileMakefiled-lmdb-server/README.mdd-lmdb-server/src/http/error.rsd-lmdb-server/src/http/error_test.rsdeny.tomldocker-entrypoint.sh
💤 Files with no reviewable changes (1)
- d-lmdb-server/src/http/error.rs
What Does This PR Do?
Hardens the Docker image (zero-CVEs, zero-config startup) and overhauls developer docs and CI for the d-lmdb v0.1 release follow-up.
Type:
Why Is This Needed?
Closes #5 review follow-ups. The shipped Docker image had 118 CVEs (5 Critical), the entrypoint required manual config, CI rebuilt an untested image, and the README was unclear for first-time developers.
Changes
docker-entrypoint.sh--config, skip chown when ownership matches;gosu→setprivDockerfilesetprivovergosu(68 Go CVEs gone), purgeperl-base+tar,--force-remove-essential,apt-get upgradeat buildd-lmdb-server/README.mdgit clone+ verification + leader failover demo,?level=linearizablefor consistent reads, remove cross-repo refsMakefiledocker-verify-*targets,docker-cve-checkwith graceful skip when Docker unavailabledeny.tomlrand@0.8.6→rand@0.8(stale patch version)error.rs,error_test.rsd-engine-product-designreferencesChecklist
make checkpassesmake testpassesTesting
kv_test— handler integration via real DLmdb in temp dir;error_test— full error-to-JSON mappingdocker runzero-config; 3-nodedocker compose+ HAProxy + leader kill failover (smoke-test.sh)Security Impact
Reviewer Notes
docker-entrypoint.sh: the auto-config +--configinjection is the critical logic — review that firstsetprivreplacesgosu— both in Dockerfile and entrypoint;setprivis fromutil-linux, pre-installed--force-remove-essential --force-dependsis narrower than--force-allEstimated review complexity: Medium (~180 lines net new)
Summary by CodeRabbit
New Features
Bug Fixes
Documentation
Tests