Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

CI speed up#3062

Merged
poovamraj merged 15 commits into
mainopenfga/openfga:mainfrom
fix-flaky-testsopenfga/openfga:fix-flaky-testsCopy head branch name to clipboard
Apr 21, 2026
Merged

CI speed up#3062
poovamraj merged 15 commits into
mainopenfga/openfga:mainfrom
fix-flaky-testsopenfga/openfga:fix-flaky-testsCopy head branch name to clipboard

Conversation

@poovamraj

@poovamraj poovamraj commented Apr 13, 2026

Copy link
Copy Markdown
Contributor

Description

What problem is being solved?

CI test runs are slow and flaky. The monolithic tests job runs all tests sequentially in a single runner, leading to long feedback cycles (~15+ minutes). Additionally, SQLite storage tests
experience intermittent database is locked failures due to an aggressive 100ms busy timeout, and the MPMC queue tests use unnecessarily large workloads that cause timeouts under race
detection.

How is it being solved?

  1. Parallelize CI test jobs — Split the single tests job into three parallel jobs (tests-unit, tests-storage, tests-matrix) that run concurrently on ubuntu-latest-4-cores runners, with an
    aggregate tests job to satisfy branch protection rules.
  2. Fix flaky SQLite tests — Increase busy_timeout from 100ms to 5000ms and add synchronous(NORMAL) pragma to reduce lock contention.
  3. Tune MPMC queue test workloads — Reduce test message count from 1000 to 200 and shrink the "large" test case capacity/cycles to prevent timeouts under -race.
  4. Add per-job Go build caching — Cache GOCACHE across jobs keyed on source file hashes for faster compilation.
  5. Conditionally skip expensive jobs — Gate goreleaser-dryrun and go-bench on path filters so they only run when relevant files change.

What changes are made to solve it?

  • .github/workflows/pull_request.yaml / .github/workflows/main.yaml — Split into tests-unit, tests-storage, tests-matrix parallel jobs with build caching; add path-filter gating for
    goreleaser-dryrun and go-bench; add aggregate tests job
  • Makefile — Add test-unit, test-storage, test-matrix targets with package-group variables (STORAGE_PACKAGES, MATRIX_PACKAGES)
  • internal/containers/mpmc/queue_test.go — Separate testMessageCount (200) from benchMessageCount (1000); reduce "large" test case capacity from 1<<20 to 1<<14 and cycles from 10 to 3
  • pkg/testfixtures/storage/sqlite.go — Increase SQLite busy_timeout to 5000ms and add synchronous(NORMAL) pragma
  • CI_SPEEDUP_REPORT.md / FLAKY_TESTS_REPORT.md — Analysis reports documenting findings and recommendations

Additionally, changes have been made to the PostgreSQL test container creation to remove a creation race that existed between test packages. Now each package will have its own PostgreSQL test container, with a unique name, that is cleaned up after each test package completes.

Here is the complete list of packages that run PostgreSQL test containers, tracing through the full call chain:

  Direct callers (call RunDatastoreTestContainer(t, "postgres") or RunPostgresTestContainer(t)):

  ┌──────────────────────┬──────────────────┬────────────────────────────────────────────────────────────────────────────────────┐
  │       Package        │       File       │                                        Call                                        │
  ├──────────────────────┼──────────────────┼────────────────────────────────────────────────────────────────────────────────────┤
  │ pkg/storage/postgres │ postgres_test.go │ RunDatastoreTestContainer(t, "postgres")                                           │
  ├──────────────────────┼──────────────────┼────────────────────────────────────────────────────────────────────────────────────┤
  │ pkg/server           │ server_test.go   │ RunDatastoreTestContainer(t, "postgres") and MustBootstrapDatastore(t, "postgres") │
  ├──────────────────────┼──────────────────┼────────────────────────────────────────────────────────────────────────────────────┤
  │ cmd/run              │ run_test.go      │ RunDatastoreTestContainer(t, engine) — parameterized, includes postgres            │
  └──────────────────────┴──────────────────┴────────────────────────────────────────────────────────────────────────────────────┘

  Indirect callers via tests.StartServer/StartServerWithContext (which calls RunDatastoreTestContainer(t, cfg.Datastore.Engine) with engine set to
  "postgres"):

  ┌───────────────────┬─────────────────────┐
  │      Package      │        File         │
  ├───────────────────┼─────────────────────┤
  │ tests/check       │ check_test.go       │
  ├───────────────────┼─────────────────────┤
  │ tests/listobjects │ listobjects_test.go │
  ├───────────────────┼─────────────────────┤
  │ tests/listusers   │ listusers_test.go   │
  └───────────────────┴─────────────────────┘

  Indirect callers via util.MustBootstrapDatastore (which calls RunDatastoreTestContainer(t, engine) with engine set to "postgres"):

  ┌─────────────────────┬─────────────────────────┐
  │       Package       │          File           │
  ├─────────────────────┼─────────────────────────┤
  │ pkg/storage/migrate │ migrate_test.go         │
  ├─────────────────────┼─────────────────────────┤
  │ cmd/validatemodels  │ validate_models_test.go │
  └─────────────────────┴─────────────────────────┘

References

Review Checklist

  • I have clicked on "allow edits by maintainers".
  • I have added documentation for new/changed functionality in this PR or in a PR to openfga.dev [Provide a link to any relevant PRs in the references section above]
  • The correct base branch is being used, if not main
  • I have added tests to validate that the change in functionality is working as expected

Summary by CodeRabbit

  • Chores

    • CI tests split into three parallel jobs with per-job timeouts, per-job coverage flags, shared Go build cache, and an aggregate status job that fails if any subjob fails.
    • Release and benchmark steps gated to relevant path/event changes.
  • Tests

    • Added scoped test targets, reduced test/benchmark workloads, and improved test container boot/cleanup coordination; relaxed one brittle assertion.
    • Added TestMain cleanup hooks across test packages.
  • Documentation

    • Added CI performance plan describing the speedup strategy.

Copilot AI review requested due to automatic review settings April 13, 2026 11:43
@poovamraj
poovamraj requested a review from a team as a code owner April 13, 2026 11:43
@coderabbitai

This comment was marked as outdated.

@poovamraj poovamraj added the Skip-Changelog Indicates that a PR does not need a changelog entry label Apr 13, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

POC aimed at reducing CI wall-clock time and flake impact by restructuring how Go tests run in GitHub Actions and by trimming a few known slow test knobs, alongside adding analysis reports for CI timing/flakiness.

Changes:

  • Split the monolithic make test CI job into tests-unit, tests-storage, and tests-matrix, and add Go build-cache caching to each.
  • Make GoReleaser dry-run and benchmark execution conditional based on changed paths (PR workflow).
  • Speed up/deflake some tests/config: tune SQLite test pragmas and reduce workload in the MPMC queue tests; add CI/flaky analysis reports.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
pkg/testfixtures/storage/sqlite.go Tweaks SQLite connection pragmas to reduce contention and improve CI stability/perf.
Makefile Adds split test targets and package groupings to enable parallel CI jobs.
internal/containers/mpmc/queue_test.go Reduces concurrency test workload to shorten CI runtime.
FLAKY_TESTS_REPORT.md Adds a report summarizing observed flaky-test families and recommendations.
CI_SPEEDUP_REPORT.md Adds a report analyzing CI timing and proposing speed-up strategies.
.github/workflows/pull_request.yaml Implements split test jobs, caching, and conditional goreleaser/bench steps for PRs.
.github/workflows/main.yaml Implements split test jobs and caching for main-branch workflow.

Comment thread Makefile Outdated
Comment thread .github/workflows/pull_request.yaml
Comment thread .github/workflows/main.yaml
coderabbitai[bot]

This comment was marked as outdated.

@codecov

codecov Bot commented Apr 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 80.60%. Comparing base (c9a0444) to head (dc844e9).
⚠️ Report is 2 commits behind head on main.

❌ Your project status has failed because the head coverage (80.60%) is below the target coverage (85.00%). You can increase the head coverage or adjust the target coverage.

❗ There is a different number of reports uploaded between BASE (c9a0444) and HEAD (dc844e9). Click for more details.

HEAD has 1 upload less than BASE
Flag BASE (c9a0444) HEAD (dc844e9)
1 0
Additional details and impacted files
@@             Coverage Diff             @@
##             main    #3062       +/-   ##
===========================================
- Coverage   90.88%   80.60%   -10.27%     
===========================================
  Files         194      194               
  Lines       21456    21491       +35     
===========================================
- Hits        19498    17321     -2177     
- Misses       1297     3421     +2124     
- Partials      661      749       +88     
Flag Coverage Δ
matrix 86.98% <ø> (?)
storage 86.28% <ø> (?)
unit 79.29% <100.00%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

coderabbitai[bot]

This comment was marked as outdated.

coderabbitai[bot]

This comment was marked as outdated.

Comment thread CI_SPEEDUP_REPORT.md Outdated
Comment thread FLAKY_TESTS_REPORT.md Outdated
@coderabbitai

This comment was marked as outdated.

@poovamraj
poovamraj marked this pull request as draft April 13, 2026 14:16
@poovamraj

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

This comment was marked as outdated.

coderabbitai[bot]

This comment was marked as outdated.

@poovamraj
poovamraj marked this pull request as ready for review April 20, 2026 17:58
@poovamraj poovamraj changed the title POC: Trial CI speed up CI speed up Apr 20, 2026
coderabbitai[bot]

This comment was marked as outdated.

coderabbitai[bot]

This comment was marked as outdated.

@senojj
senojj force-pushed the fix-flaky-tests branch 2 times, most recently from 31865c2 to 619cfd3 Compare April 20, 2026 22:00
coderabbitai[bot]

This comment was marked as outdated.

senojj
senojj previously approved these changes Apr 20, 2026
@poovamraj
poovamraj enabled auto-merge (squash) April 20, 2026 22:29
@senojj
senojj requested a review from a team as a code owner April 20, 2026 22:33
coderabbitai[bot]

This comment was marked as outdated.

senojj
senojj previously approved these changes Apr 20, 2026

@senojj senojj left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Now that the containers are unique per compiled package unit, and get cleaned up after all tests run, I think it is ready.

coderabbitai[bot]

This comment was marked as outdated.

Comment thread cmd/validatemodels/testmain_test.go
Comment thread .github/workflows/main.yaml Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.github/workflows/main.yaml (1)

11-120: Consider deduplicating the three near-identical test jobs via a reusable workflow or matrix.

tests-unit, tests-storage, and tests-matrix differ only in timeout-minutes, the make target, and the Codecov flags. The checkout, Go setup, GOCACHE discovery, cache step, and Codecov upload are byte-identical across all three and duplicated again in pull_request.yaml. A strategy.matrix job (or a workflow_call reusable workflow shared with pull_request.yaml) would collapse ~100 lines into one definition and keep the two workflows from drifting.

♻️ Sketch using a matrix
  tests:
    runs-on: ubuntu-latest-4-cores
    strategy:
      fail-fast: false
      matrix:
        include:
          - name: unit
            target: test-unit
            timeout: 10
          - name: storage
            target: test-storage
            timeout: 15
          - name: matrix
            target: test-matrix
            timeout: 15
    timeout-minutes: ${{ matrix.timeout }}
    steps:
      - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
      - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
        with:
          go-version-file: './go.mod'
          cache-dependency-path: './go.sum'
          check-latest: true
      - id: go-cache-paths
        run: echo "go-build=$(go env GOCACHE)" >> "$GITHUB_OUTPUT"
      - uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
        with:
          path: ${{ steps.go-cache-paths.outputs.go-build }}
          key: ${{ runner.os }}-go-build-${{ matrix.name }}-${{ hashFiles('**/*.go', 'go.sum') }}
          restore-keys: ${{ runner.os }}-go-build-${{ matrix.name }}-
      - run: make ${{ matrix.target }}
      - uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v6.0.0
        with:
          files: ./coverageunit.out
          flags: ${{ matrix.name }}
          verbose: true
          token: ${{ secrets.CODECOV_TOKEN }}
          fail_ci_if_error: true

Note that with a matrix job, branch protection can require tests (unit), tests (storage), tests (matrix) directly, removing the need for the aggregate job at lines 122-135.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/main.yaml around lines 11 - 120, The three nearly
identical jobs tests-unit, tests-storage, and tests-matrix should be collapsed
into a single job (e.g., tests) using strategy.matrix or extracted into a
reusable workflow; implement a matrix include with entries for
name/unit/storage/matrix, target (test-unit/test-storage/test-matrix) and
timeout, set job timeout-minutes to ${{ matrix.timeout }}, replace the
individual make runs with run: make ${{ matrix.target }}, and set the Codecov
flags to ${{ matrix.name }}; also update the cache key/restore-keys to
incorporate matrix.name so each matrix axis has its own cache while keeping the
shared checkout/setup/go-cache/Codecov steps centralized.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/main.yaml:
- Around line 28-34: The shared cache key used in the "Go build cache" step
(key: ${{ runner.os }}-go-build-${{ hashFiles('**/*.go', 'go.sum') }}) causes
cross-job cache contention; update the key to scope it per job by appending a
unique job identifier (for example the job name or matrix target) and adjust the
restore-keys prefix accordingly (e.g., include "-go-build-${{ matrix.target ||
job }}" pattern); apply the same change to the analogous cache steps that use
"-storage-" and "-matrix-" so each job writes/restores its own cache instead of
a shared key.

---

Nitpick comments:
In @.github/workflows/main.yaml:
- Around line 11-120: The three nearly identical jobs tests-unit, tests-storage,
and tests-matrix should be collapsed into a single job (e.g., tests) using
strategy.matrix or extracted into a reusable workflow; implement a matrix
include with entries for name/unit/storage/matrix, target
(test-unit/test-storage/test-matrix) and timeout, set job timeout-minutes to ${{
matrix.timeout }}, replace the individual make runs with run: make ${{
matrix.target }}, and set the Codecov flags to ${{ matrix.name }}; also update
the cache key/restore-keys to incorporate matrix.name so each matrix axis has
its own cache while keeping the shared checkout/setup/go-cache/Codecov steps
centralized.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 6dc29248-0cb8-4d7a-b923-9024bf465385

📥 Commits

Reviewing files that changed from the base of the PR and between 40de575 and f9f9eb4.

📒 Files selected for processing (3)
  • .github/workflows/main.yaml
  • .github/workflows/pull_request.yaml
  • plans/CI_SPEEDUP_PLAN.md
✅ Files skipped from review due to trivial changes (1)
  • plans/CI_SPEEDUP_PLAN.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/pull_request.yaml

Comment thread .github/workflows/main.yaml
@poovamraj
poovamraj requested review from justincoh and senojj April 21, 2026 14:43
@poovamraj
poovamraj merged commit 351813a into main Apr 21, 2026
25 of 26 checks passed
@poovamraj
poovamraj deleted the fix-flaky-tests branch April 21, 2026 14:56
senojj added a commit that referenced this pull request Apr 21, 2026
Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Co-authored-by: Joshua Jones <joshua.jones@okta.com>
senojj added a commit that referenced this pull request Apr 21, 2026
Author:    Poovamraj T T <poovamraj@gmail.com>
Date:      Tue Apr 21 16:56:45 2026 +0200

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Co-authored-by: Joshua Jones <joshua.jones@okta.com>
fredrikaverpil added a commit to fredrikaverpil/openfga that referenced this pull request Jul 12, 2026
Add support for exporting logs via OTLP, allowing integration with any
OpenTelemetry-compatible backend (Grafana Loki, Datadog, GCP Cloud
Logging, etc.).

When log.otlp.enabled is set, logs are exported via OTLP in addition to
stdout. The otelzap bridge attaches span context (trace ID, span ID) to
each log record, enabling log-trace correlation in backends that
support it.

Configuration mirrors the trace configuration shape: the standard OTel
env vars (OTEL_EXPORTER_OTLP_LOGS_ENDPOINT, OTEL_EXPORTER_OTLP_ENDPOINT)
only answer where logs are sent, while the explicit OpenFGA flag
(log.otlp.enabled / --log-otlp-enabled / OPENFGA_LOG_OTLP_ENABLED)
answers whether to export at all — so a cluster that injects the
generic endpoint variable for tracing does not silently start exporting
logs on upgrade.

zap's production sampling is applied outside the tee, so the keep/drop
decision is made once, before fan-out: stdout and OTLP receive the same
deterministically sampled stream and collector egress stays bounded
during log storms.

Changes:
- Add otelzap bridge core backed by an OTLP log provider
  (internal/telemetry/logging.go)
- Add WithOTELCore logger option that tees log entries to the bridge.
  The bridge core is capped to the configured log level, the stdout
  core strips the bridge-only context field via contextFilterCore, and
  the sampler wraps the tee (pkg/logger/logger.go)
- Attach the context field in the *WithContext logging methods only
  when an OTEL core is configured, and use those methods in the gRPC
  logging interceptor so the bridge can extract span context
  (pkg/middleware/logging/logging.go)
- Add config: log.otlp.enabled, log.otlp.endpoint, log.otlp.tls.enabled
  with OPENFGA_LOG_OTLP_* env vars and OTEL_EXPORTER_OTLP_* endpoint
  fallbacks (pkg/server/config/config.go, cmd/run/, .config-schema.json)

feat: add potential v2 breaking change logs for Expand and ListUsers (openfga#3182)
release: update changelog for release 1.18.1 (openfga#3188)
release: Update changelog to prep for 1.18.1 release (openfga#3186)
test: fix flaky TestV2CheckWithIteratorCache_HigherConsistencyBypassesCache (openfga#3061)

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Merge commit from fork

* test reproducing ListUsers report

* implement fix

* additional test with 3 operands
fix: match IPv4-mapped IPv6 addresses in the in_cidr condition (openfga#3181)

Signed-off-by: kanywst <niwatakuma@icloud.com>
fix: use deterministic proto marshaling for stored authorization models (openfga#3171)
chore: create draft release and publish after provenance succeeds for immutable tags/releases (openfga#3178)
docs: fix changelog entry (openfga#3177)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
feat: add v2Check logs for resolution breaking change (openfga#3149)
feat: BatchCheck uses v2Check when ExperimentalWeightedGraphCheck is enabled (openfga#3154)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
chore: update changelog to add CVE identifiers for recent fixes (openfga#3176)
chore: update todo comment string in migration guide (openfga#3175)
release: update changelog for release `v1.18.0` (openfga#3174)

Co-authored-by: adriantam <adrian.tam@okta.com>
Merge commit from fork

* fix(authn): require issuer and audience when OIDC authn is enabled

Enforce configuration authn.oidc.audience and authn.oidc.issuer when
`authn.method` is set to `oidc`.

* fixed based on code review feedback

* fix: adding comments + test case on empty space for audience

* update based on code review feedback

* Update CHANGELOG.md

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>

* update changelog

* Update CHANGELOG.md

---------

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Merge commit from fork

* fix(mysql): collate identifier columns as utf8mb4_bin

* fix: add operator note to changelog

* fix: move tests to shared storage

* fix: separate migrations for each table

* fix: add runbook for migrations

* fix: set lock_wait_timeout

* fix: add docker instructions

* fix: add docker instructions

* fix: combine the migrations back into one, fix documentation for this

* fix: include details about table copy and

* Update CHANGELOG.md

Co-authored-by: Adrian Tam <adrian.tam@okta.com>

---------

Co-authored-by: Adrian Tam <adrian.tam@okta.com>
fix: use constant-time comparison for preshared key authentication (openfga#3168)
chore(deps): bump the dependencies group with 2 updates (openfga#3166)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
chore(deps): bump the dependencies group with 2 updates (openfga#3167)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
release: update changelog for release `v1.17.1` (openfga#3165)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
chore: bump grpc-health-probe to v0.4.52 (openfga#3164)

Co-authored-by: Saad Hussain <saad.hussain@okta.com>
docs: update caching docs (openfga#3163)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix: continuation token deserializer - handle `|` in type names (openfga#3152)
chore(deps): bump the dependencies group across 1 directory with 13 updates (openfga#3162)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
chore(deps): bump the dependencies group across 1 directory with 10 updates (openfga#3156)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
fix: use query start time as iterator cache entry LastModified to prevent stale-read survival (openfga#3155)
chore(deps): bump grpc-ecosystem/grpc-health-probe from v0.4.50 to v0.4.51 in the dependencies group (openfga#3157)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
chore: Bump go toolchain to 1.26.4 (openfga#3159)
fix: prevent v2Check from falling back for throttling and validation (openfga#3150)
ci: make pr benchmark comparisons less fragile (openfga#3153)

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
release: update changelog for release `v1.17.0` (openfga#3151)

Co-authored-by: Vic-Dev <vmichellej@gmail.com>
refactor: redesign cache key generation, making it more secure and consistent (openfga#3148)
feat: add configurable trace sampler with ParentBased support (openfga#3072)
release: update changelog for release `v1.16.1` (openfga#3147)
chore: update grpc-health-probe to latest to addres std lib CVEs (openfga#3146)
fix: skip v2Check weight2 pruning if iterator is unordered (openfga#3145)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
chore: add concurrency-group to PR-related CI steps (openfga#3140)
docs: move OIDC JWKS refresh entry from v1.15.1 to v1.16.0 (openfga#3142)
fix: when v2Check is primary algorithm, fix fallback condition and emit metrics (openfga#3141)
release: update changelog for release `v1.16.0` (openfga#3139)
Merge commit from fork

* fix: Standardize cache key generation everywhere

* Revert "fix: Standardize cache key generation everywhere"

This reverts commit ce60c6f9ae48a310a4dea2b824b5993520c8ba1c.

* length-encoded approach

* Revert "length-encoded approach"

This reverts commit b94637c187c57a2d3f3904247267bbc8ad21a41a.

* implement Hexer() and use in some cache keys

* appendConditionsHash -> generateConditionsHash

* mv Hexer -> BuildKey

* BuildKey -> BuildCacheKey

refactor to BuildCacheKey on each individual prefix component to remove collision risk

* make v2 cacheKey functions the standard

* make cache key prefixes consistent

* generateConditionsHash -> generateConditionsString

* delimit condition name string

* remove extra empty check

* relocate and reuse existing userTypeRestrictions function

* replace hashing of conditions for brevity

* fix tests

* cleanup, add test file

* remove unused slice capacity

* make prefix treatments consistent

* add nil-byte separator in object ids

* hash user type restrictions for brevity

* update comment string, use nil-byte separator for future-proofing

* remove call to xxhash.new

* adjustments for performance, consistency, and interface ergonomics.

* make condition hash generation more efficient.

* add clarifying comments for size caluculations

* fix builder growth calculations to match original intentions

* update outdated comment

* don't hash potentially zero values

* Revert "don't hash potentially zero values"

This reverts commit 2ad6c5b796bc20a82c1414c5146c3c708330eefa.

* add condition key separator unconditionally

* patch test expectations for new key structure

* export V2IteratorCachePrefix, use in tests

---------

Co-authored-by: justin <justin.cohen@okta.com>
Co-authored-by: Joshua Jones <joshua.jones@okta.com>
fix: unintentional zeroing of slice values by setting slice to nil (openfga#3135)
increase the check v2 trace information fidelity (openfga#3134)
feat: add datastore ping and ping retry configurations (openfga#3113)
fix: prevent v2Check strategies returning spurious false on context cancellation (openfga#3128)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix(authn/oidc): refresh JWKS on unknown kid to handle key rotation (openfga#3101)
fix: v2Check falls back to v1 on errors (openfga#3126)
fix: don't cache false results from cancelled-context goroutines in v2Check (openfga#3125)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
make union cache key unique by including the node input's label (openfga#3117)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Saad Hussain <saad.hussain@okta.com>
fix: shadow v2check and check use the same trace (openfga#3118)
fix: bump go toolchain version to 1.26.3 (openfga#3115)
chore: add more spans/attributes to v1 and v2 Check (openfga#3116)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix: add matches attribute to shadowv2Check and Check spans (openfga#3114)
fix: use the same `request_id` for shadow traces in v2Check (openfga#3110)
release: update changelog for release `v1.15.1` (openfga#3112)
feat: reuse MySQL container across tests (openfga#3042)
fix: close all channels opened thus far, before return on error (openfga#3111)
chore: Add more spans/attributes to v2Check (openfga#3102)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix: ensure acquired limiter token is released on throttle context cancelation (openfga#3106)
fix: cancel context before waiting on worker pool in ResolveUnionEdges (openfga#3105)
fix: replace golang.org/x/exp/maps with stdlib maps to resolve govet inline errors (openfga#3104)
fix: v2Check EdgeCacheKey collisions (openfga#3097)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix: expose context errors when they can be the potential cause of an underlying datastore error (openfga#3096)
chore(deps): bump the dependencies group across 1 directory with 2 updates (openfga#3093)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: move subproblem cache lookup from ResolveUnionEdges into ResolveUnion (openfga#3095)
chore(deps): bump the dependencies group with 4 updates (openfga#3092)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: error handler panic (openfga#3091)
release: update changelog for release `v1.15.0` (openfga#3090)
chore(deps): bump the dependencies group across 1 directory with 4 updates (openfga#3087)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: v2Check correctly uses query cache even when cache controller is disabled (openfga#3086)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#3081)

Signed-off-by: dependabot[bot] <support@github.com>
chore(deps): bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2 (openfga#3085)

Signed-off-by: dependabot[bot] <support@github.com>
chore(deps): bump grpc-ecosystem/grpc-health-probe from v0.4.47 to v0.4.48 in the dependencies group across 1 directory (openfga#3065)

Signed-off-by: dependabot[bot] <support@github.com>
feat: try to use UDS internally between HTTP server and gRPC server (openfga#2937)
feat: add jitter to internal cache TTLs to prevent thundering herd effects (openfga#3033)

Signed-off-by: Asish Kumar <officialasishkumar@gmail.com>
list objects pipeline edge pruning (openfga#3075)
update toolchain go to 1.26.2 to address stdlib CVEs (openfga#3084)
chore: add store ID and datastore query/item count to shadowV2Check log (openfga#3073)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
CI speed up (openfga#3062)

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Co-authored-by: Joshua Jones <joshua.jones@okta.com>
Add tracing to v2 Check planner strategy selection (openfga#3077)
fix: v2Check honours `check-query-cache-enabled` flag (openfga#3070)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
feat: reuse PostgreSQL container across tests (openfga#3018)
chore: fix reporter links in changelog (openfga#3069)
release: update changelog for release `v1.14.2` (openfga#3068)
fix: add null byte delimiter in contextual tuple cache keys and validation in v2Check (openfga#3064)
release: update changelog for release `v1.14.1` (openfga#3060)
chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#3056)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
fix: use a baseURL for AuthZEN configuration endpoint (openfga#3057)
chore: replace docker with moby (openfga#3047)
Iterator Cache V2: Storage Wrapper Pattern with Lock-Free Design (openfga#3016)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
test: fix flaky condition test (openfga#3058)

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
chore(deps): bump the dependencies group across 1 directory with 6 updates (openfga#3045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.41.0 to 1.43.0 (openfga#3054)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
feat: add graceful shutdown timeout configuration (openfga#2976)
chore: update changelog to reflect playground off-by-default behavior (openfga#3053)
chore: decouple Error() and Unwrap() (openfga#3051)
perf: remove `fmt` from cache key generation (openfga#3006)
perf: enhancements for list objects (openfga#3043)
chore: remove stale notice file (openfga#3050)
docs: update 1.14.0 for CVE fix (openfga#3046)
feat: Add datastore throttling & concurrency limiting to v2Check (openfga#3035)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
release: update changelog for release `v1.14.0` (openfga#3040)
batch check cache (openfga#3025)
Merge commit from fork

Also prevent enabling playground when the server requires authentication
feat: add stats on tuple iterator query (openfga#3030)
fix: remove unnecessary non-deterministic test (openfga#3038)
remove unnecessary import (openfga#3032)
perf: improve the intersection algorithm, reducing latency and memory use (openfga#3031)
fix: ListObjects pipeline algorithm enhancements and fix for potential deadlock (openfga#3028)
chore: Also update openfga/helm-charts in release script (openfga#3010)
chore: update CICD to enforce GRPC healthprobe changes (openfga#2990)
fix: SQL `TupleOperation` serialization and `pgx.ErrNoRows` error handling (openfga#3014)
docs: update changelog for CVE-2026-33729 (openfga#3017)
chore: output the diff after running keep-a-changelog (openfga#3015)
chore(deps): bump the dependencies group across 1 directory with 11 updates (openfga#2998)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
chore(deps): bump the dependencies group across 1 directory with 10 updates (openfga#2999)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
release: update changelog for release `v1.13.1` (openfga#3002)
Merge commit from fork

* strip unicode control characters, encode context key length in cache key

* add cache_key tests to ensure we escape control characters and encode context key length

* run linter

* docs: update changelog

* Apply suggestion from @adriantam

Co-authored-by: Adrian Tam <adrian.tam@okta.com>

* Apply suggestion from @adriantam

Co-authored-by: Adrian Tam <adrian.tam@okta.com>

---------

Co-authored-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Saad Hussain <saad.h@outlook.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
release: update changelog for release `v1.13.0` (openfga#2997)
refactor: Separate caches for v1 and v2 Check (openfga#2968)

Co-authored-by: Justin Cohen <justincoh@gmail.com>
docs: fix typos in comments (openfga#2972)

Signed-off-by: Artem Muterko <artem@sopho.tech>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
observability: aggregate message statistics for each list-objects sender into a single span (openfga#2993)

Co-authored-by: Justin Cohen <justincoh@gmail.com>
fix: capture panics in pipeline's base resolver, and return as errors. (openfga#2994)
docs: fix typos in RELEASES.md and Makefile (openfga#2980)

Co-authored-by: Adrian Tam <adrian.tam@okta.com>
AuthZen v1.0 Implementation (openfga#2875)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Rokibul Hasan <mdrokibulhasan@appscode.com>
Signed-off-by: Vihang Mehta <vihang@gimletlabs.ai>
Co-authored-by: Karl Persson <kalle.persson92@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Maria Ines Parnisari <maria.inesparnisari@okta.com>
Co-authored-by: Rokibul Hasan <mdrokibulhasan18@gmail.com>
Co-authored-by: José Padilla <jose.padilla@okta.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
Co-authored-by: Vihang Mehta <vihang@gimletlabs.ai>
Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
release: update changelog for release `v1.12.1` (openfga#2992)
chore(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.3 (openfga#2988)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
chore: enforce minor version upgrade rule (openfga#2978)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
perf: tuple validation performance tweaks (openfga#2984)
fix: support URI schemes in OTLP endpoint configuration (openfga#2981)
refactor: remove custom pipes and replace with channels (openfga#2977)
chore(docs): added caching  docs (openfga#2664)

Co-authored-by: Saad Hussain <saad.hussain@okta.com>
release: update changelog for release `v1.12.0` (openfga#2974)
chore: update toolchain go to 1.26.1 (openfga#2975)
fix: update toolchain go to 1.25.8 to address stdlib CVEs (openfga#2971)
fix: correct swapped format args in DecodeParameterType error message (openfga#2961)

Signed-off-by: Artem Muterko <artem@sopho.tech>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
perf: small tweaks to tuple validation functions (openfga#2963)

Co-authored-by: Vic-Dev <vmichellej@gmail.com>
test: add tests for condition parameter type any with complex context structures (openfga#2959)

Signed-off-by: Artem Muterko <artem@sopho.tech>
test: add functional test for ReadAssertions API endpoint (openfga#2960)

Signed-off-by: Artem Muterko <artem@sopho.tech>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
make configurable the maximum received grpc message size (openfga#2952)

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
fix: set ExperimentalPipelineListObjects in experimentals by default (openfga#2957)

fix: `cache_item_count` metric overcounting (openfga#2950)

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#2953)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
refactor: Make shadowV2Check final log clearer (openfga#2946)

Move telemetry package to internal/telemetry (openfga#2938)

Signed-off-by: Oleksandr Shestopal <ar.shestopal-oshegithub@gmail.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
chore(deps): bump the dependencies group across 1 directory with 3 updates (openfga#2956)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: Resolve race condition in check reducers (openfga#2947)

Co-authored-by: Adrian Tam <adrian.tam@okta.com>
fix: gateway grpc client tls cert rotation (openfga#2951)

Signed-off-by: Shashank Goel <goelshashank13@gmail.com>
fix: disable LO pipeline if ff has it set for a store (openfga#2945)

chore(deps): bump the dependencies group across 1 directory with 4 updates (openfga#2949)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: various random fixes (openfga#2942)

refactor: check using weighted graph (openfga#2816)

Co-authored-by: Yissell Garma <yissell.garma@okta.com>
release: update changelog for release `v1.11.6` (openfga#2939)

feat: enable pipeline algorithm by default (openfga#2921)

add tests to exercise reported bug (openfga#2934)

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
refine AGENTS.md to make it more concise with higher value. (openfga#2936)

Co-authored-by: Justin Cohen <justincoh@gmail.com>
migrate grpc dial context to NewClient (openfga#2714)

Co-authored-by: Adrian Tam <adrian.tam@okta.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
chore(deps): bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (openfga#2935)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Skip-Changelog Indicates that a PR does not need a changelog entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.