Skip to content

Add opt-in host-managed timestamps for repository entities - #109

Merged
Dastari merged 1 commit into
mainfrom
feat/repository-host-timestamps-20261002
Oct 3, 2026
Merged

Dastari merged 1 commit into
mainfrom
feat/repository-host-timestamps-20261002

Conversation

@Dastari

@Dastari Dastari commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

Add the approved per-field #[graphql_orm(timestamp = "host")] opt-in for RepositoryEntity i64/Option timestamps. Writable annotated fields use ordinary typed create/update inputs and retain exact caller values across direct/pinned insert, update, CAS, bounded updates, upsert and insert-if-absent. Rust names and physical aliases are covered by one shared timestamp decision; unannotated fields retain legacy behavior and GraphQL SDL.

Non-null writable creates require a value, even with a default. Nullable updates preserve omission/value/SQL NULL. Host-managed created_at is ordinarily writable, including upsert conflict updates; use existing restrictions/policies for immutability. Defaults and physical metadata are unchanged. Unsupported derives/types/field combinations produce compile diagnostics. Caller UUID/auto_generated=false behavior is preserved.

Executable conformance uncovered two small prerequisites included here: repository upsert field checks now call the framework-neutral repository authorizer, and the exact PostgreSQL deparsed form of the ORM's epoch-second default compares equivalent for no-op planning. The latter preserves the expression and storage units; regenerate unapplied guarded migration plans. No runtime A–D interfaces or DateTime interpretation changes.

Accepted implementation head: efa2cd97fc7c58ca148528eacabba61d485ee5f9. Rebased onto current reviewed main 3bff96b90ce19efa2bfc9cc71d3c95f45cad8c39 (published workspace-2026.10.03.1, ORM/macros 0.38.0) at 64d5c5f356b8db926e1c598786fa9daaa0b26a3f. This is a single linear commit; its complete source tree is identical to the prior reviewed reconciliation 75361295392d090d8de65192f2be27fc1905ad0f. Aligned ORM/macros 0.39.0, all root/fixture locks and generated inventory are retained. PR A #97 and its worktree remain untouched at e41866d582c36fd920044f6461cb15c6bd446f17. No A code is incorporated. No release identity is assigned and no timestamp release is published.

#108 is resolved through the normal documentation review in merged #110, merge 2f5dd8418f73a34995e9a1f16168cd4a6be533eb. Four reviewed documents have valid lifecycle dates. No checker suppression or accepted ADR edits. Documentation validation passes after incorporating main.

Verification

All local verification below was rerun and passed on rebased head 64d5c5f356b8db926e1c598786fa9daaa0b26a3f. Fresh exact-head CI completed successfully: all 12 PR checks passed, including every workspace-integrity step without skips. CI and release explicitly execute the existing owned PostgreSQL timestamp tests and standalone consumer; cancellation guarantees are unchanged.

All builds used an isolated worktree, disk-backed TMPDIR, CARGO_BUILD_JOBS=2 and sequential backend lanes. No application databases or sibling repositories used.

  • SQLite core selected regression targets: 84 passed, including six host timestamp scenarios and compile-fail inputs. Macro units: 9 passed. Minimal external consumer: 2 passed, plus actual standalone example execution.
  • PostgreSQL: all 6 ignored-by-default timestamp tests explicitly executed against verified disposable postgres:17-alpine containers; 1 standalone-consumer host example executed similarly. Core unit/planner 43 passed, macro units 9 passed. Normal consumer compile pass reports three owned tests ignored; all three owned tests (host timestamps, portable groups, plain aggregates/field denial) were explicitly executed on disposable databases.
  • MSSQL: 48 unit/rendering/UI tests and 9 macro units passed; external-writable example compiles. No live MSSQL timestamp execution.
  • SQLite all-targets Clippy; PostgreSQL lib/tests Clippy; MSSQL selected supported-target Clippy; Rustdoc all three backends: warnings denied, passed. Explicit SQLite+MSSQL coexistence fixture passed.
  • Formatting, dependency trees/directions, inventory/release-state, package-release-policy, SemVer (1 changed library lane), and deterministic release-manifest tests passed.
  • Combined main-feature regressions: SQLite portable/complete groups, ordinary aggregates and projections 21 passed; owned PostgreSQL portable-group parity 8 passed, standalone portable consumer 1 passed.
  • Workspace-integrity is green with no skipped steps. Locally storage 44, backup 56, operation-catalog/tool-profiles 52 tests passed, all zero failures/ignored. Documentation 191 documents validated; router-notice 13 and release-manifest 6 tests passed.
  • Fresh exact-head CI: run. all 11 CI jobs passed, plus the independent Samba check. Full ORM, owned PostgreSQL timestamp/consumer, aggregate/projection, companions, SemVer and release-policy checks are green.
  • Framework-neutral aggregate compatibility: the minimal external consumer compiles both backend lanes with direct normal dependencies only graphql-orm + serde. Plain aggregate enums assert they implement neither GraphQL input nor output traits. SQLite aggregate/field denial and PostgreSQL owned aggregate/field denial execute successfully (1 each).
  • Exact core acceptance commands: cargo test -p graphql-orm --locked --no-default-features --features sqlite --test host_timestamps --test host_timestamp_ui; cargo test -p graphql-orm --locked --no-default-features --features postgres --test host_timestamps -- --ignored --test-threads=1.
  • Runnable external example: cargo run --manifest-path crates/graphql-orm/tests/fixtures/repository-aggregate-consumer/Cargo.toml --locked --no-default-features --features sqlite --example host_timestamps. Consumer has no direct async-graphql dependency. Its PostgreSQL owned test runs with --features postgres --test host_timestamps -- --ignored --test-threads=1.

Acceptance covers signed extrema/nonaligned milliseconds/zero/negative/fake clocks, nullable keys/inputs, mixed host/legacy fields, explicit and implicit default no-op replanning, CAS success/conflict, denied writes before mutation hooks, change metadata, propagated hook/journal rollback and whole-transaction cancellation while work/hooks are pending.

Limitations: catching an inner mutation timeout and then returning Ok does not guarantee rollback; no unfinished-operation poisoning is introduced. Lost commit acknowledgements remain ambiguous. MSSQL gates remain unchanged and live execution is unverified. Broader backend target-gating failures are tracked separately in #89. The historical documentation failure is resolved by reviewed #110; current documentation checks pass. All workspace-integrity steps passed on this exact reconciliation, including storage, backup, operation-catalog and AI-tool-profile tests skipped by the old failed job.

Documentation impact

  • Documentation updated
  • No documentation impact

Canonical repository reference, macro/runtime READMEs, changelog, migration guide and generated package inventory document the opt-in, legacy/default behavior, limitations and compiled example. Owned backend release lanes now include the timestamp regressions and consumer example. This PR is independent of A–D and does not modify Digibase, GEMA, agql-auth, license policy or release/deployment state.

@Dastari

Dastari commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Initial CI: package-release-policy and SemVer passed. workspace-integrity failed only on the four unchanged expired review_by dates already reproduced locally/on baseline and tracked in #108. Confirmed via completed job logs: https://github.com/Dastari/graphql-orm/actions/runs/36977350551/job/110743945011. Other jobs remain running; this is not an all-green CI claim. All isolated local timestamp/backend verification reported in the PR passed.

@Dastari

Dastari commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Independent portable aggregate PR #111 is open at 09915d1, currently stacked only on documentation review-date repair #110. It proposes aligned ORM/macros 0.38.0, leaving this timestamp branch/version untouched. If #111 merges before #109, rebase/reconcile the timestamp version above current main and rerun combined owned backend lanes before publication. If merge order differs, align versions/inventory/locks then; there is no forced dependency on A–D.

Both PostgreSQL complete event enumeration and ordinary complete-SQL-visibility aggregates now have actual disposable-backend evidence. Publication is requested for #111 through the required human protected-environment workflow; no release is published yet. Its release should not be described as implementing timestamp opt-in or PR A unless those independently reviewed predecessors actually merge into the chosen source.

@Dastari

Dastari commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Independent portable aggregate #111 merged at 3bff96b90ce19efa2bfc9cc71d3c95f45cad8c39, ORM/macros 0.38.0, tested head c7d564ffab8105e67c6f1932cc99a572c347313a with all 12 checks green. This timestamp branch remains untouched. Rebase/reconcile its 0.37.0 reservation above actual main before merge, retaining its reviewed timestamp contract and rerunning combined owned SQLite/PostgreSQL lanes.

The source-only workspace-2026.10.03.1 release is validating the aggregate merge: https://github.com/Dastari/graphql-orm/actions/runs/37080240446 . It does not include this unmerged timestamp capability or runtime A. No release has been published yet.

@Dastari

Dastari commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Published immutable workspace-2026.10.03.1, ORM/macros 0.38.0, exact source 3bff96b90ce19efa2bfc9cc71d3c95f45cad8c39 (merged #111; tested head c7d564ffab8105e67c6f1932cc99a572c347313a). All 12 PR checks and all 20 release jobs passed.

Release: https://github.com/Dastari/graphql-orm/releases/tag/workspace-2026.10.03.1
Manifest: https://github.com/Dastari/graphql-orm/releases/download/workspace-2026.10.03.1/workspace-2026.10.03.1.json

Workspace/core/macro tags resolve to the exact merge source. Published manifest/notes match the deterministic preview; checksums, package trees and lockfile hash verified. Complete SQLite/PostgreSQL text-group enumeration and SQL-visible ordinary COUNT/SUM are now published. Remaining joined/computed queries, MSSQL summaries/pages and private generated views stay open in #91. Runtime A–D and host timestamps are not included; pending branch versions must advance above actual main before merge. No downstream files or application databases were changed.

@Dastari
Dastari force-pushed the feat/repository-host-timestamps-20261002 branch from 7536129 to 64d5c5f Compare October 3, 2026 01:57
@Dastari
Dastari merged commit df474c7 into main Oct 3, 2026
12 checks passed
@Dastari

Dastari commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Merged #109 at df474c761c4057cb643e27a6582dd0376f56e31f and published immutable workspace-2026.10.03.2, with ORM/macros 0.39.0. All 20 release jobs passed. Annotated workspace/package tags peel to the merged source; downloaded checksums, deterministic manifest and exact-source/workflow provenance verification passed. The merged tree equals accepted head 64d5c5f356b8db926e1c598786fa9daaa0b26a3f.

The cancellation limitation remains: catching an inner mutation timeout then returning Ok does not guarantee rollback; no unfinished-operation poisoning. MSSQL coverage remains compilation/rendering, with no live timestamp execution claimed. PR A remains separate/unmodified; Digibase and sibling repositories are unchanged. Downstream adoption is a separate reviewed pin/integration change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant