You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(scripts): durability gate — declare the seeder wrappers tryInsert/tryUpdate (#15458)
The #12981 programme's last step. Batches 1-9 repaired the
`catch { return null; }` seeder family; this declares the family's own helper
names in `DURABILITY_CRITICAL_CALLEES`, which is the handover
`scripts/measure-durability-swallow-family.mjs` reserved for the end of the
programme — and it lands with zero findings, which is what keeps
`durability-degradation.baseline.json` at its designed empty steady state.
The raw ObjectQL verbs stay out, and the map header now records the measurement
rather than the assertion: bare `insert` reports 36 quiet degradations in 30
files on this tree, the two wrappers report none.
Claude-Session: https://claude.ai/code/session_012zGPuVVX3deAx9LdjK8jCk
Co-authored-by: Claude <noreply@anthropic.com>
* Each entry names WHY it is durability-critical — the note is printed in the
265
265
* violation message, so the author reads the consequence rather than a rule id.
266
+
*
267
+
* ## The raw ObjectQL verbs are still NOT here — measured, not assumed (#12981)
268
+
*
269
+
* `insert` / `update` sit in the same excluded class as the read rule's
270
+
* `find` / `findOne` / `count`: names too generic to declare repo-wide. #12981
271
+
* closed by declaring the SEEDER WRAPPERS instead — `tryInsert` / `tryUpdate`
272
+
* are the `catch { return null; }` helpers that whole family is made of, so
273
+
* naming them puts the family in the vocabulary without dragging every write in
274
+
* the monorepo in with it. That order was deliberate: the wrappers could only be
275
+
* declared once the family had been REPAIRED, which is what the census
276
+
* (`scripts/measure-durability-swallow-family.mjs`) exists to prove, and it is
277
+
* what keeps `durability-degradation.baseline.json` at its designed empty
278
+
* steady state rather than filling it with transitional debt.
279
+
*
280
+
* Both halves measured on `origin/main@f01adfa5c` while landing the wrappers,
281
+
* so the next author reads a number rather than re-deriving one:
282
+
*
283
+
* - the two wrappers → 0 findings (this file, unchanged verdict)
284
+
* - bare `insert` → 36 quiet degradations in 30 files
285
+
*
286
+
* ⇒ The second is a repair programme wearing the costume of a vocabulary edit,
287
+
* and it is the thing #12981 was filed to NOT do by accident. If a future card
288
+
* needs one specific `ql.insert(...)` seam visible — `keys.ts::handleKeysRequest`
289
+
* is the standing example, whose catch answers the caller a 500 envelope on
290
+
* every path and is waiting to say so in `FAILURE_PROPAGATION_SITES` — the
291
+
* choice is between paying for those 36 and giving this map a per-site scope
292
+
* the way `FAILURE_PROPAGATION_SITES` already scopes the other vocabulary. That
293
+
* is a design call, and it is deliberately not taken here.
266
294
*/
267
295
constDURABILITY_CRITICAL_CALLEES=newMap([
296
+
[
297
+
'tryInsert',
298
+
"A seeder's insert was refused and the helper answered `null` — the row is simply absent while the seeding pass moves on and its per-boot summary still reads clean. This is the shape #12981 was filed over: the RBAC catalog seeders swallowed refused writes in `catch { return null; }`, and a boot logged \"RBAC catalog seeded\" at `info` over zero landed rows, on a deployed plane, for weeks (#12923). The helper answers its CALLER, which reports the refusal through the #12923 accumulator; what this entry holds is that no caller may re-swallow that answer in a quiet `catch`.",
299
+
],
300
+
[
301
+
'tryUpdate',
302
+
"A seeder's update was refused and the helper answered `false` — the row keeps its pre-seed contents while the pass counts it as reconciled, so a catalog that never converged reports the same bytes as one that had nothing to do (#12923, #12970). The helper answers its CALLER, which reports the refusal through the #12923 accumulator; what this entry holds is that no caller may re-swallow that answer in a quiet `catch`.",
303
+
],
268
304
[
269
305
'syncSchema',
270
306
'DDL for the object never ran — the table/columns do not exist, yet the object stays registered and served.',
0 commit comments