Skip to content

chore(xtest): Add nano plaintext policy coverage #327

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged

Conversation

dmihalcik-virtru
Copy link
Member

@dmihalcik-virtru dmihalcik-virtru commented Aug 1, 2025

Currently always skipped since not implemented

image

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary of Changes

Hello @dmihalcik-virtru, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request introduces comprehensive test coverage for the "plaintext policy mode" feature within the nano TDF container. It updates the testing framework to properly configure and execute encryption operations with this new policy mode across different SDKs (Go, Java, JavaScript) and adds a dedicated test case to validate its behavior.

Highlights

  • SDK Test Script Updates: Modified cli.sh scripts for Go, Java, and JavaScript SDKs to recognize and support the nano_policymode_plaintext feature. This includes adding the necessary command-line arguments (--policy-mode plaintext or --policy-type plaintext) when the plaintext policy is enabled for encryption.
  • Python Test Framework Integration: Updated xtest/tdfs.py to expose the policy_mode option in the encrypt helper function, allowing tests to explicitly request plaintext policy encryption by setting the XT_WITH_PLAINTEXT_POLICY environment variable.
  • New Test Case for Plaintext Policy: Introduced test_container_policy_mode in xtest/test_policytypes.py to specifically validate the functionality of plaintext policy mode for nano containers, including checks on the TDF header's policy type, asserting it remains EMBEDDED.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point in your pull request via creating an issue comment (i.e. comment on the pull request page) using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in issue comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments or fill out our survey to provide feedback.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

The pull request adds test coverage for the nano TDF plaintext policy mode. There's a bug in the Java SDK's test script that will prevent it from running, and the new Python test for the plaintext policy mode doesn't actually enable the feature it's meant to test. I've also pointed out a logic bug in how the new feature is enabled in the Python test framework and a minor code duplication issue.

Copy link

sonarqubecloud bot commented Aug 1, 2025

Quality Gate Failed Quality Gate failed

Failed conditions
27.4% Duplication on New Code (required ≤ 8%)

See analysis details on SonarQube Cloud

@dmihalcik-virtru dmihalcik-virtru marked this pull request as ready for review August 1, 2025 21:35
@dmihalcik-virtru dmihalcik-virtru requested review from a team as code owners August 1, 2025 21:35
"""
if container not in {"nano", "nano-with-ecdsa"}:
pytest.skip(f"Container {container} does not support plaintext policy mode")
if not encrypt_sdk.supports("nano_policymode_plaintext"):
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

does the decrypt sdk also need to support plaintext policy?

@dmihalcik-virtru dmihalcik-virtru merged commit c21862e into opentdf:main Aug 1, 2025
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants