Skip to content

ffi: succeed with false for revocation-code predicates on live keys - #2488

Open
ronaldtse wants to merge 1 commit into
mainfrom
fix-2467-revocation-predicates
Open

ronaldtse wants to merge 1 commit into
mainfrom
fix-2467-revocation-predicates

Conversation

@ronaldtse

Copy link
Copy Markdown
Contributor

Summary

  • rnp_key_is_compromised(), rnp_key_is_retired() and rnp_key_is_superseded() returned RNP_ERROR_BAD_PARAMETERS when the queried key was not revoked, although a key which is not revoked is a normal state rather than a failure. Callers therefore had to map the error code to false by hand and could not distinguish a healthy key from an actual problem, while the sibling predicates rnp_key_is_revoked() and rnp_key_is_valid() already succeed with a boolean for the same state, as reported in rnp_key_is_compromised/retired/superseded return RNP_ERROR_BAD_PARAMETERS for keys that are not revoked #2467.
  • The three predicates now succeed with false for a key which is not revoked at all, and RNP_ERROR_BAD_PARAMETERS remains reserved for an invalid key handle.
  • The change is a three-line adjustment in the shared rnp_key_is_revoked_with_code() helper, together with a regression test which exercises all three predicates on a non-revoked key inside test_ffi_revocations.

Test plan

  • rnp_tests.test_ffi_revocations passes with the new assertions on a non-revoked key
  • full CI matrix, which also re-runs the existing assertions for revoked keys on all three predicates

rnp_key_is_compromised(), rnp_key_is_retired() and rnp_key_is_superseded()
returned RNP_ERROR_BAD_PARAMETERS for a key which is not revoked at all,
which is a normal key state, so callers could not distinguish a healthy
key from an actual problem and had to map the error to false by hand. The
predicates now succeed with false for a non-revoked key, matching the
behaviour of the sibling predicates rnp_key_is_revoked() and
rnp_key_is_valid(). An invalid key handle continues to return
RNP_ERROR_BAD_PARAMETERS.

Fixes #2467.
@codecov

codecov Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.46%. Comparing base (26482f6) to head (0dd1359).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2488   +/-   ##
=======================================
  Coverage   85.45%   85.46%           
=======================================
  Files         125      125           
  Lines       23042    23043    +1     
=======================================
+ Hits        19691    19693    +2     
+ Misses       3351     3350    -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant