Repository navigation
fix: prevent lost and partial revocations in the status list - #1112
Merged
paullatzelsperger merged 2 commits intoOct 6, 2026
Conversation
…atus The status list credential is now read with CredentialStore#queryForUpdate when a credential's status is changed, so it stays locked until the revocation has written it back. Concurrent revocations no longer overwrite each other's bits, and a revocation no longer writes back a stale index. Closes eclipse-edc#1105 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A revocation writes the status list credential and the revoked credential. If one of them cannot be written, the transaction is now rolled back, so that the status list and the issuer's records cannot disagree. A failure to read the current status is now reported as such, instead of as a successful revocation. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
jimmarino
approved these changes
Oct 6, 2026
wolf4ood
approved these changes
Oct 6, 2026
wolf4ood
approved these changes
Oct 6, 2026
paullatzelsperger
deleted the
fix/1105_statuslist_revocation_lost_update
branch
October 6, 2026 15:44
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR changes/adds
BitstringStatusListFactorynow reads the status list credential withCredentialStore#queryForUpdate, introduced infix: prevent duplicate status list indices on concurrent issuance #1104. The status list credential therefore stays locked until the surrounding transaction completes.
StatusListInfoFactoryjavadoc documents that a status change must be made within that transaction.CredentialStatusServiceImpl#revokeCredentialrolls back its transaction when the status list credential or therevoked credential cannot be written. It still returns the original failure as a
ServiceResult.CredentialStatusServiceImpl#revokeCredentialnow returns a failure when the credential's current status cannot beread from the status list.
Why it does that
entire row. Without a lock, two concurrent revocations on the same status list could overwrite each other. The
credential's record would say
REVOKED, but the published status list would not.currentIndex, so indices handed out in the meantimewere handed out again.
LocalTransactionContextonly rolls back on exceptions.If the second write failed, the first one was still committed, and the status list and the issuer's records disagreed.
mapFailure()of a successfulresult. That is a successful result, so the revocation reported success without changing anything.
Linked Issue(s)
Closes #1105
🤖 Generated with Claude Code