You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit f3a9675
Browse filesBrowse the repository at this point in the historyBrowse files
fix(objectql): a `find` / `findOne` whose `fields` names a formula field returns that projection, not every stored column
6
+
7
+
Clause-②: no
8
+
9
+
To evaluate a formula field, the engine widens the projection it hands the driver to every stored column of the object (CEL's `record.<field>` reads whatever the formula needs off the full row). The rows were never cut back, so a projection that named a formula field returned every column: the tenant, owner, owning unit and audit columns, and every field the caller did not name. A flow's `get_record`, whose `config.fields` is declared as "only these fields are read", passed all of them on to its later nodes.
10
+
11
+
Each row is now cut back to the caller's projection once the read is done: the columns the caller named, plus the formula's computed value. `id` is returned only when it is named. `driver-memory` and `driver-mongodb` add `id` to every projection at the driver layer, so on those two drivers a projection that names a formula field but not `id` no longer carries `id`, while the same projection without the formula still does: name `id` when you need it. The formula still sees the full row, and so do the `afterFind` hooks and the middlewares, as before. A key an `afterFind` hook derives is kept.
12
+
13
+
Unchanged: a projection that names no formula field, and a read with no projection (every declared column, with the formulas computed). Field-level security is unchanged as well: a field the caller may not read was already masked off the widened row, and still is.
fix(service-storage): chunks sent in parallel to one chunked upload each record their part
6
+
7
+
Clause-②: no
8
+
9
+
`PUT /storage/upload/chunked/:uploadId/chunk/:chunkIndex` merges its chunk into the upload session's record of the chunks it holds (`parts`, `uploaded_chunks`, `uploaded_size` on `sys_upload_session`). It read that record, merged in memory and wrote the whole record back, so two chunk PUTs to one upload at the same time both answered `200` while the record kept only one of them: `GET …/progress` undercounted, and the completion was refused `409 RESOURCE_CONFLICT` naming the chunk the record had lost until the client sent it again.
10
+
11
+
The record is now written with a compare-and-set: the write lands only while the row still holds the progress the chunk door read, and when another chunk's write landed first the door reads the record again and merges again. On a wired data engine this is the engine's own conditional update, evaluated in the same statement that writes, so it holds across server processes. Every chunk sent in parallel is recorded, and a parallel upload completes on its first completion. A sequential upload is unchanged.
12
+
13
+
A chunk whose record write loses to another write on 16 attempts in a row is refused `409 RESOURCE_CONFLICT`, with `error.details``{ chunkIndex, attempts }`: its bytes are stored, but the upload does not hold it. Send that chunk again.
Copy file name to clipboardExpand all lines: content/docs/permissions/tenant-audit-census.mdx
+23-23Lines changed: 23 additions & 23 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -83,7 +83,7 @@ what moved this page's population from 225 to 227; nothing about the two sites
83
83
changed, only whether this instrument could see them.
84
84
85
85
**The expensive failure direction is a keyword.** Sites whose receiver the author
86
-
typed `any` have no type to read, and there are 50 of them — just over a fifth
86
+
typed `any` have no type to read, and there are 51 of them — just over a fifth
87
87
of the population, concentrated in exactly the seed and bootstrap paths this
88
88
control exists for. Scoring an unreadable receiver as "not an engine" would have
89
89
dropped every one of them silently, with a clean exit and a smaller number that
@@ -122,7 +122,7 @@ are reported as `undecidable` rather than assumed either way.
122
122
123
123
The same holds twice over for the context. An options argument spelled as a
124
124
literal can be read; one spelled `options`, `{ ...opts }`, or handed through a
125
-
forwarding shim cannot, and **52 of the 236 sites are spelled that way**. A
125
+
forwarding shim cannot, and **53 of the 237 sites are spelled that way**. A
126
126
context resolved from an inline literal or a local `const` can be tested for
127
127
`isSystem`; one arriving from a helper call cannot.
128
128
@@ -150,8 +150,8 @@ now **0**: nothing on this surface threads a context that provably lacks the fla
150
150
151
151
**"No tenant context" counted sites it had not read.** An options argument the
152
152
walker could not parse was folded into the same bucket as one it had read and
153
-
found empty. That published **60 sites "carrying no tenant context at all"**
154
-
when 8 said so and 52 were simply unread — an over-claim in the *alarming*
153
+
found empty. That published **61 sites "carrying no tenant context at all"**
154
+
when 8 said so and 53 were simply unread — an over-claim in the *alarming*
155
155
direction, on the very figure this page tells other cards to cite. `carries` is
156
156
now three-valued, and an unreadable argument can never contribute to the
157
157
provable count.
@@ -187,10 +187,10 @@ reproduce them. Where it disagrees, it disagrees on the page:
187
187
188
188
| carried figure | where it survives | this census |
189
189
| :--- | :--- | ---: |
190
-
| 175 write call sites | quoted in the merged changeset |**236**|
191
-
| 24 carrying no tenant context | quoted in the merged changeset |**2** provable and tenancy-enabled; **31** more whose options argument is unreadable |
192
-
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card |**156 of 236** decidable, **80** undecidable |
193
-
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration**|**not reproduced**: 125 decidably elevated, 0 decidably not, 103 undecidable |
190
+
| 175 write call sites | quoted in the merged changeset |**237**|
191
+
| 24 carrying no tenant context | quoted in the merged changeset |**2** provable and tenancy-enabled; **32** more whose options argument is unreadable |
192
+
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card |**157 of 237** decidable, **80** undecidable |
193
+
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration**|**not reproduced**: 125 decidably elevated, 0 decidably not, 104 undecidable |
194
194
| 141 and 132, two independent re-derivations | the card that filed this work | — |
195
195
196
196
**The differences are not reconciled, and deliberately so.** The old census's
@@ -200,21 +200,21 @@ be stated is what this instrument counts, which is written above and re-runnable
200
200
at any commit.
201
201
202
202
Two structural facts do plausibly widen this reading against any hand or regex
203
-
one, and both are counted in the generated tables below: the 50 sites reached
203
+
one, and both are counted in the generated tables below: the 51 sites reached
204
204
through an erased (`any`) receiver, and the 50 that name their object through a
205
205
`const` rather than inline. An instrument that read either the way a person does
206
206
would report a smaller number and would not say so.
207
207
208
208
The fourth row is the one worth flagging to anyone citing it. **The 135 / 77%
209
209
figure has no surviving corroboration anywhere in the tree.** This census reads
210
-
125 of 236 (53%) as decidably elevated, with 103 more whose elevation is a
210
+
125 of 237 (53%) as decidably elevated, with 104 more whose elevation is a
211
211
run-time fact — so the claim is neither confirmed nor refuted, and the honest
212
212
answer is that a static reading cannot settle it.
213
213
214
-
⇒ **Cite `2 / 236`, and say what it is**: the sites whose options argument was
214
+
⇒ **Cite `2 / 237`, and say what it is**: the sites whose options argument was
215
215
READ and holds no tenant context, against a decidably tenancy-enabled object.
216
216
That is the control's provable yield surface. ⛔ Do not cite it as "the sites
217
-
without tenant context" — **31 further sites** have an options argument this
217
+
without tenant context" — **32 further sites** have an options argument this
218
218
cannot read, and they are neither in nor out.
219
219
220
220
{/* BEGIN GENERATED: tenant-audit-census (scripts/tenant-audit-census.mjs) — DO NOT EDIT */}
@@ -223,28 +223,28 @@ cannot read, and they are neither in nor out.
223
223
224
224
| what | count |
225
225
| :--- | ---: |
226
-
| write call sites on the application surface |**236**|
227
-
| …whose object name is statically decidable |156|
226
+
| write call sites on the application surface |**237**|
227
+
| …whose object name is statically decidable |157|
228
228
| …whose object name is chosen at run time | 80 |
229
-
| …against an object with tenancy ENABLED |155|
229
+
| …against an object with tenancy ENABLED |156|
230
230
| …against an object that declares tenancy off | 1 |
231
231
| threading a tenant context | 176 |
232
232
| PROVABLY carrying none (options read, no context key) |**8**|
233
233
| …of those, against a decidably tenancy-enabled object |**2**|
234
-
| options argument UNREADABLE — may or may not carry one |52|
235
-
| …of those, against a decidably tenancy-enabled object |31|
234
+
| options argument UNREADABLE — may or may not carry one |53|
235
+
| …of those, against a decidably tenancy-enabled object |32|
236
236
| threading a decidably ELEVATED (`isSystem`) context | 125 |
237
237
| threading a context that is decidably NOT elevated | 0 |
238
-
| threading a context whose elevation is a run-time fact |103|
238
+
| threading a context whose elevation is a run-time fact |104|
239
239
240
240
| how the instrument reached the site | count |
241
241
| :--- | ---: |
242
242
| receiver carried a readable engine type | 186 |
243
-
| receiver erased, placed by the object NAME |30|
243
+
| receiver erased, placed by the object NAME |31|
244
244
| receiver erased, placed by an `object: string` PARAMETER | 15 |
245
245
| receiver erased, placed by an `UNTYPED_RECEIVERS` row | 5 |
246
246
247
-
| object name spelled inline |106|
247
+
| object name spelled inline |107|
248
248
| object name spelled through a `const`| 50 |
249
249
| object name is an `object: string` parameter | 19 |
250
250
| object name is some other run-time expression | 61 |
@@ -297,13 +297,13 @@ holds still. They are required to be HERE and to say WHEN they were true;
297
297
their values are not compared. The reasoning, and the measurement behind it,
0 commit comments