Skip to content

Commit 845d767

Browse files
claude[bot]claude
andauthored
fix(scripts): durability gate — declare the seeder wrappers tryInsert/tryUpdate (#15458)
The #12981 programme's last step. Batches 1-9 repaired the `catch { return null; }` seeder family; this declares the family's own helper names in `DURABILITY_CRITICAL_CALLEES`, which is the handover `scripts/measure-durability-swallow-family.mjs` reserved for the end of the programme — and it lands with zero findings, which is what keeps `durability-degradation.baseline.json` at its designed empty steady state. The raw ObjectQL verbs stay out, and the map header now records the measurement rather than the assertion: bare `insert` reports 36 quiet degradations in 30 files on this tree, the two wrappers report none. Claude-Session: https://claude.ai/code/session_012zGPuVVX3deAx9LdjK8jCk Co-authored-by: Claude <noreply@anthropic.com>
1 parent e8c7956 commit 845d767

1 file changed

Lines changed: 36 additions & 0 deletions

File tree

‎scripts/check-durability-degradation-log-level.mjs‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -263,8 +263,44 @@ const READ_INVENTION_BASELINE_PATH = join(
263263
*
264264
* Each entry names WHY it is durability-critical — the note is printed in the
265265
* violation message, so the author reads the consequence rather than a rule id.
266+
*
267+
* ## The raw ObjectQL verbs are still NOT here — measured, not assumed (#12981)
268+
*
269+
* `insert` / `update` sit in the same excluded class as the read rule's
270+
* `find` / `findOne` / `count`: names too generic to declare repo-wide. #12981
271+
* closed by declaring the SEEDER WRAPPERS instead — `tryInsert` / `tryUpdate`
272+
* are the `catch { return null; }` helpers that whole family is made of, so
273+
* naming them puts the family in the vocabulary without dragging every write in
274+
* the monorepo in with it. That order was deliberate: the wrappers could only be
275+
* declared once the family had been REPAIRED, which is what the census
276+
* (`scripts/measure-durability-swallow-family.mjs`) exists to prove, and it is
277+
* what keeps `durability-degradation.baseline.json` at its designed empty
278+
* steady state rather than filling it with transitional debt.
279+
*
280+
* Both halves measured on `origin/main@f01adfa5c` while landing the wrappers,
281+
* so the next author reads a number rather than re-deriving one:
282+
*
283+
* - the two wrappers → 0 findings (this file, unchanged verdict)
284+
* - bare `insert` → 36 quiet degradations in 30 files
285+
*
286+
* ⇒ The second is a repair programme wearing the costume of a vocabulary edit,
287+
* and it is the thing #12981 was filed to NOT do by accident. If a future card
288+
* needs one specific `ql.insert(...)` seam visible — `keys.ts::handleKeysRequest`
289+
* is the standing example, whose catch answers the caller a 500 envelope on
290+
* every path and is waiting to say so in `FAILURE_PROPAGATION_SITES` — the
291+
* choice is between paying for those 36 and giving this map a per-site scope
292+
* the way `FAILURE_PROPAGATION_SITES` already scopes the other vocabulary. That
293+
* is a design call, and it is deliberately not taken here.
266294
*/
267295
const DURABILITY_CRITICAL_CALLEES = new Map([
296+
[
297+
'tryInsert',
298+
"A seeder's insert was refused and the helper answered `null` — the row is simply absent while the seeding pass moves on and its per-boot summary still reads clean. This is the shape #12981 was filed over: the RBAC catalog seeders swallowed refused writes in `catch { return null; }`, and a boot logged \"RBAC catalog seeded\" at `info` over zero landed rows, on a deployed plane, for weeks (#12923). The helper answers its CALLER, which reports the refusal through the #12923 accumulator; what this entry holds is that no caller may re-swallow that answer in a quiet `catch`.",
299+
],
300+
[
301+
'tryUpdate',
302+
"A seeder's update was refused and the helper answered `false` — the row keeps its pre-seed contents while the pass counts it as reconciled, so a catalog that never converged reports the same bytes as one that had nothing to do (#12923, #12970). The helper answers its CALLER, which reports the refusal through the #12923 accumulator; what this entry holds is that no caller may re-swallow that answer in a quiet `catch`.",
303+
],
268304
[
269305
'syncSchema',
270306
'DDL for the object never ran — the table/columns do not exist, yet the object stays registered and served.',

0 commit comments

Comments
 (0)