fix: implement rust-skills audit remediation - #107
Merged
Conversation
Bound the flush loop to snapshot_seq so the prepared path no longer falls through to an empty RocksDB read_range on every tick, and split hyperbytedb_flush_wal_read_seconds by path for clearer observability. Co-authored-by: Cursor <cursoragent@cursor.com>
Land all 29 fix items from the 2026-07-30 audit: data safety, cluster correctness, security/ops hardening, TSQL/query fixes, and performance polish across hyperbytedb, proxy, and CLI. Cluster & data safety: durable Raft fsync, monotonic mutation acks, replication lock, fail-closed drain, WAL key guards, ordered flush shutdown, hinted-handoff backpressure, learner catch-up, persisted mutation dedup, retention leader-gating with series deletes, and fail-closed ingest metadata. Security & ops: HTTP timeouts and credential redaction, opt-in query-param auth, proxy admin listener split from public traffic, TSQL identifier hardening, configurable Raft RPC timeouts, proxy streaming retries, and CLI timeout/error-chain improvements. Parser & platform: negative duration rejection (including `now() - -1h`), SHOW/TSQL compat fixes, columnar prepared WAL ingest, metadata spawn_blocking, chDB hot-path optimizations, config deny_unknown_fields, ChainedError source chains, bump arrow 54→59 to match chdb-rust, and clippy/test cleanups.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Land all 29 fix items from the 2026-07-30 audit: data safety, cluster
correctness, security/ops hardening, TSQL/query fixes, and performance
polish across hyperbytedb, proxy, and CLI.
Cluster & data safety: durable Raft fsync, monotonic mutation acks,
replication lock, fail-closed drain, WAL key guards, ordered flush
shutdown, hinted-handoff backpressure, learner catch-up, persisted
mutation dedup, retention leader-gating with series deletes, and
fail-closed ingest metadata.
Security & ops: HTTP timeouts and credential redaction, opt-in query-param
auth, proxy admin listener split from public traffic, TSQL identifier
hardening, configurable Raft RPC timeouts, proxy streaming retries, and
CLI timeout/error-chain improvements.
Parser & platform: negative duration rejection (including
now() - -1h),SHOW/TSQL compat fixes, columnar prepared WAL ingest, metadata
spawn_blocking, chDB hot-path optimizations, config deny_unknown_fields,
ChainedError source chains, bump arrow 54→59 to match chdb-rust, and
clippy/test cleanups.