Skip to content

fix #5: tests, docs, CI, and Docker CVEs - #6

Merged
JoshuaChi merged 5 commits into
mainfrom
fix/5-post-merge
Jul 29, 2026
Merged

JoshuaChi merged 5 commits into
mainfrom
fix/5-post-merge

Conversation

@JoshuaChi

@JoshuaChi JoshuaChi commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

What Does This PR Do?

Hardens the Docker image (zero-CVEs, zero-config startup) and overhauls developer docs and CI for the d-lmdb v0.1 release follow-up.

Type:


Why Is This Needed?

Closes #5 review follow-ups. The shipped Docker image had 118 CVEs (5 Critical), the entrypoint required manual config, CI rebuilt an untested image, and the README was unclear for first-time developers.


Changes

Area Files What
Entrypoint docker-entrypoint.sh Auto-generate single-node config, auto-inject --config, skip chown when ownership matches; gosu → setpriv
Docker Dockerfile setpriv over gosu (68 Go CVEs gone), purge perl-base + tar, --force-remove-essential, apt-get upgrade at build
Docs d-lmdb-server/README.md Zero-config single-node, 3-node with git clone + verification + leader failover demo, ?level=linearizable for consistent reads, remove cross-repo refs
CI Makefile docker-verify-* targets, docker-cve-check with graceful skip when Docker unavailable
Config deny.toml rand@0.8.6 → rand@0.8 (stale patch version)
Source error.rs, error_test.rs Remove d-engine-product-design references

Checklist

  • make check passes
  • make test passes
  • Added tests for new code
  • Updated relevant docs

Testing

  • Unit tests: kv_test — handler integration via real DLmdb in temp dir; error_test — full error-to-JSON mapping
  • Manual: single-node docker run zero-config; 3-node docker compose + HAProxy + leader kill failover (smoke-test.sh)

Security Impact

Before After
Critical 5 0
High 31 0
Medium 40 0
Total 118 ~28 (LOW baseline)

Reviewer Notes

  • docker-entrypoint.sh: the auto-config + --config injection is the critical logic — review that first
  • setpriv replaces gosu — both in Dockerfile and entrypoint; setpriv is from util-linux, pre-installed
  • --force-remove-essential --force-depends is narrower than --force-all

Estimated review complexity: Medium (~180 lines net new)

Summary by CodeRabbit

  • New Features

    • Docker images now start with a default single-node configuration when no configuration file is mounted.
    • Added Docker image verification, smoke tests, and vulnerability checks.
  • Bug Fixes

    • Improved container startup permissions handling and privilege dropping.
    • Reduced unnecessary runtime packages for a smaller image.
  • Documentation

    • Updated setup, Docker, high-availability, API, error, and configuration guidance with clearer examples and verification steps.
  • Tests

    • Docker vulnerability checks now run as part of the standard test workflow.

- kv_test: add handler integration tests (PUT/GET/DELETE via real DLmdb)
- Makefile: add docker-verify-local/remote/cve-check targets with Docker guard
- README: fix API example, reference published image, adjust sleep timing

- Dockerfile: gosu → setpriv (eliminates 68 Go stdlib CVEs),
  force-purge perl-base + tar (CVE-2026-12087, CVE-2025-45582),
  --force-remove-essential --force-depends over --force-all
- docker-entrypoint.sh: setpriv, skip chown when ownership matches

- CI: push tested image (no rebuild), fix shell injection, CVE scan gate
- smoke-test: teardown compose on failure
- deny.toml: rand@0.8.6 → rand@0.8 (stale patch version)
@coderabbitai

coderabbitai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@JoshuaChi, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 8 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 5f06d0e0-9d0c-4412-b8a9-e200c3b1e194

📥 Commits

Reviewing files that changed from the base of the PR and between 99445ca and 6dd50fa.

📒 Files selected for processing (7)
  • .github/workflows/ci.yml
  • .github/workflows/dependency-audit.yml
  • .github/workflows/docker-ci.yml
  • .github/workflows/docker-release.yml
  • Makefile
  • d-lmdb-server/README.md
  • docker-entrypoint.sh
📝 Walkthrough

Walkthrough

The Docker runtime now uses setpriv, supplies a default configuration, and conditionally adjusts data ownership. Makefile targets build or pull images, run smoke tests, and enforce Docker Scout CVE checks. README, HTTP comments, and cargo-deny configuration were also updated.

Changes

Container Runtime and Verification

Layer / File(s) Summary
Runtime packages and startup behavior
Dockerfile, docker-entrypoint.sh
Replaces gosu with setpriv, removes unnecessary runtime packages, creates default configuration when absent, injects --config, and conditionally changes /data ownership before privilege dropping.
Docker build, smoke test, and CVE gate
Makefile
Adds local and remote Docker verification flows, PUT/GET smoke tests, Docker Scout Medium-plus vulnerability checks, and the CVE gate to make test.
Documentation and validation annotations
d-lmdb-server/README.md, d-lmdb-server/src/http/error.rs, d-lmdb-server/src/http/error_test.rs, deny.toml
Updates Docker, HA, API, error, and configuration documentation, clarifies HTTP mapping comments, removes a stale header reference, and broadens the skipped rand version range.

Estimated code review effort: 3 (Moderate) | ~30 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Makefile
  participant Docker
  participant dlmdb
  participant curl
  participant DockerScout
  Makefile->>Docker: Build or pull image
  Docker->>dlmdb: Run container with mounted config and data
  Makefile->>curl: PUT and GET /kv/hello
  curl->>dlmdb: Send smoke-test requests
  Makefile->>DockerScout: Scan local image
  DockerScout-->>Makefile: Return vulnerability counts
Loading

Possibly related PRs

  • deventlab/d-lmdb#4: Updates the same container runtime and entrypoint privilege-handling areas.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is concise and accurately reflects the PR's main focus on tests, docs, CI, and Docker CVE hardening.
Linked Issues check ✅ Passed The documented changes address the issue's Docker hardening, CI verification, shell-safety, smoke-test cleanup, and README quick-start requirements.
Out of Scope Changes check ✅ Passed No clearly unrelated code changes stand out beyond minor cleanup and dependency-rule updates that fit the follow-up scope.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/5-post-merge

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docker-entrypoint.sh`:
- Around line 24-28: Update the argument check in the docker entrypoint’s
config-injection case to recognize both separate-value and equals-form flags
(`--config` and `--config=...`). Append the default CONFIG_FILE only when
neither form was supplied, preserving the caller’s explicit configuration.

In `@Makefile`:
- Around line 259-270: The smoke-test recipes at Makefile lines 259-270 and
275-286 must preserve failures instead of masking them: add fail-fast handling
with cleanup via trap, remove any || true from build or cleanup commands, wait
for service readiness, and make both curl requests fail on HTTP errors while
asserting the GET response body is “world”. Apply the identical changes to both
the local-image and pulled-image flows.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c28c64a4-0348-45a5-b7f8-966a0c8465bf

📥 Commits

Reviewing files that changed from the base of the PR and between f0b5753 and 99445ca.

📒 Files selected for processing (7)
  • Dockerfile
  • Makefile
  • d-lmdb-server/README.md
  • d-lmdb-server/src/http/error.rs
  • d-lmdb-server/src/http/error_test.rs
  • deny.toml
  • docker-entrypoint.sh
💤 Files with no reviewable changes (1)
  • d-lmdb-server/src/http/error.rs

Comment thread docker-entrypoint.sh
Comment thread Makefile Outdated
@JoshuaChi
JoshuaChi merged commit 2d6e501 into main Jul 29, 2026
6 checks passed
@JoshuaChi
JoshuaChi deleted the fix/5-post-merge branch July 29, 2026 10:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: tests, docs, CI, and Docker CVEs — post-merge follow-ups

2 participants