Skip to content

Fix repository transaction counts under SQL row visibility - #103

Merged
first-assist merged 2 commits into
mainfrom
fix/repository-count-visibility-20261001
Oct 1, 2026
Merged

first-assist merged 2 commits into
mainfrom
fix/repository-count-visibility-20261001

Conversation

@first-assist

@first-assist first-assist commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

An installed row policy currently causes transaction-bound repository count() and exists() to reject every call, including explicitly unrestricted trusted repository reads. This blocks populated application startup when maintenance counts retained records. Resolve current row visibility, intersect complete SQL predicates with caller filters, and count on the existing pinned transaction. Preserve entity authorization and rejection of callback-only/prefilter policies, invalid entity bindings and residual filters under an installed policy.

Advance runtime/macros together to 0.35.2; macros alignment only. No public API, GraphQL SDL or stored-data change. This PR does not change the immutable AI-only workspace-2026.10.01.2; the external ORM owner coordinates the subsequent release identity.

Verification

  • Regression before fix: unrestricted and complete-policy counts failed; callback rejection and no-policy baseline passed.
  • Eight new SQLite regressions pass, including current visibility, entity denial, wrong entity, caller-filter intersection, same-transaction writes and rollback.
  • Nineteen existing transaction, hook-read, entity-policy, projection and repository tests pass.
  • Formatting, documentation, generated inventory, package release policy and diff checks pass.
  • Scoped warnings-denied SQLite Clippy and core/macros Rustdoc passed. PostgreSQL and MSSQL warnings-denied library Clippy compile lanes passed. No live database used.
  • Hosted CI skipped during the authorized fast iteration path; final release validation remains separate.

Documentation impact

  • Documentation updated
  • No documentation impact

Explanation: repository count visibility contract, changelog, migration guidance, aligned installation versions and generated workspace inventory.

@first-assist
first-assist marked this pull request as ready for review October 1, 2026 08:49
@first-assist
first-assist merged commit 4540dcf into main Oct 1, 2026
@Dastari

Dastari commented Oct 1, 2026

Copy link
Copy Markdown
Owner

ORM release coordination: #103 is already merged at 4540dcf and can be included in workspace-2026.10.01.3 with the cross-crate, target-authorization, complete-group and projection fixes (#96/#98/#99/#102). The immutable AI-only .2 remains unchanged.

The earlier .3 run at 73ef09d failed its current-main guard after this merge; it published nothing: https://github.com/Dastari/graphql-orm/actions/runs/36833471126. The .3 identity remains available. I am preparing a focused follow-up to synchronize the external fixture lockfiles to 0.35.2 (their --locked builds currently fail), and executing these count regressions against disposable owned PostgreSQL as well as SQLite. The new .3 source will be the exact reviewed main commit after that follow-up, with its full SHA and new release run recorded here. No runtime migration A or B–D implementation is included.

@Dastari

Dastari commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Update: the ORM release fixture/count follow-up is #104, with SQLite/PostgreSQL regressions passing. Its CI uncovered an unrelated current-Rust router deprecation that blocks the mandatory warnings-denied workspace gate; separate #105 preserves the Rust 1.90 MSRV with equivalent atomic metrics semantics (router 0.5.4). Planned release remains workspace-2026.10.01.3, ORM/macros 0.35.2, source-only, at exact reviewed main after these two follow-ups. No .3 tag/publication exists; .2 stays unchanged. New source SHA and release run will be recorded after validation/merge.

@Dastari

Dastari commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Release coordination checkpoint: #104 merged as 35431c5 (count/exists policy tests pass SQLite and owned PostgreSQL; fixture locks repaired). Source-only .3 remains planned with ORM/macros 0.35.2. #105 independently fixes the router atomic deprecation (0.5.4); #106 makes CI and release use the reviewed Rust 1.97.1 compiler, keeping every warning/provider/backend and native human gate. Full pinned CI run: https://github.com/Dastari/graphql-orm/actions/runs/36929742200. Rust 1.99 async-trait companion Clippy remains explicitly open in #107. #105/#106 will merge only after combined validation; exact final main SHA/replacement release run will follow. .2 remains unchanged and .3 has not been published.

@Dastari

Dastari commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Release owner handoff: #103 is included in the replacement workspace-2026.10.01.3 run at exact merged source 809d894:
https://github.com/Dastari/graphql-orm/actions/runs/36934024517

ORM/macros are both 0.35.2; router is 0.5.4; AI remains 0.106.1 and the immutable AI-only .2 is unchanged. This is source-only, with no router binary or registry publication.

All twelve combined CI checks passed at 6a8a177 (run 36929742200), and the merged source has an identical tree. Exact-source release manifest preview, existing immutable package-tag checks and local documentation/inventory/dependency/format gates pass. #104 repaired external fixture locks and executed eight count regressions each on SQLite and owned PostgreSQL; #105 preserved atomic router metrics/MSRV; #106 pins the reviewed Rust 1.97.1 compiler without removing any warnings/provider/backend/human gate. Rust 1.99 companion Clippy remains tracked separately in #107.

#103 merge: 4540dcf
#104 merge: 35431c5
#105 merge: 6e478d2
#106 merge: 809d894

The new run is awaiting Dastari's native protected release-environment review. No .3 tag/release has been published yet, so it is not an adoptable GEMA release. Please keep main at this source until the approved run passes its current-main guard. A remains open in #97; B–D remain gated, and the remaining GEMA joins/computed queries/MSSQL summaries/pages/private generated views stay open in #91.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants