Skip to content

fix(workflows/v2): log err on decryption share failures and fix share count - #23653

Open
prashantkumar1982 wants to merge 2 commits into
developfrom
fix/vault-decryption-share-err-logging
Open

fix(workflows/v2): log err on decryption share failures and fix share count#23653
prashantkumar1982 wants to merge 2 commits into
developfrom
fix/vault-decryption-share-err-logging

Conversation

@prashantkumar1982

@prashantkumar1982 prashantkumar1982 commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Motivation

In decryptSecret (core/services/workflows/v2/secrets.go), the loop that collects decryption shares was swallowing the underlying error whenever decrypt, unmarshal, or verify failed. This made it hard to debug why shares were being dropped.

Additionally, the "not enough decryption shares" error reported len(encryptedDecryptionShares) (the total input) rather than len(decryptionShares) (the number successfully collected), giving a misleading "have N" count.

… count

The decryption share loop was discarding the underlying error when
decrypt/unmarshal/verify failed, making debugging difficult. Add the
error to each debug log. Also fix the 'not enough decryption shares'
error to report the count of successfully collected shares instead of
the total encrypted shares.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

👋 prashantkumar1982, thanks for creating this pull request!

To help reviewers, please consider creating future PRs as drafts first. This allows you to self-review and make any final changes before notifying the team.

Once you're ready, you can mark it as "Ready for review" to request feedback. Thanks!

@prashantkumar1982 prashantkumar1982 added the build-publish Build and Publish image to SDLC label Sep 3, 2026
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

✅ No conflicts with other open PRs targeting develop

… into fix/vault-decryption-share-err-logging
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

I see you updated files related to core. Please run make gocs in the root directory to add a changeset as well as in the text include at least one of the following tags:

  • #added For any new functionality added.
  • #breaking_change For any functionality that requires manual action for the node to boot.
  • #bugfix For bug fixes.
  • #changed For any change to the existing functionality.
  • #db_update For any feature that introduces updates to database schema.
  • #deprecation_notice For any upcoming deprecation functionality.
  • #internal For changesets that need to be excluded from the final changelog.
  • #nops For any feature that is NOP facing and needs to be in the official Release Notes for the release.
  • #removed For any functionality/config that is removed.
  • #updated For any functionality that is updated.
  • #wip For any change that is not ready yet and external communication about it should be held off till it is feature complete.

@cl-sonarqube-production

Copy link
Copy Markdown

@trunk-io

trunk-io Bot commented Sep 3, 2026

Copy link
Copy Markdown

Static BadgeStatic BadgeStatic Badge

View Full Report ↗︎Docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

build-publish Build and Publish image to SDLC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants