What happens
GetWorkGroup synthesizes the primary workgroup when no record exists
(emulator/athena_plugin.go:401-429, comment: "'primary' always exists as the default workgroup"),
and StartQueryExecution attributes a query to primary when the request names no workgroup
(:162-165). But ListWorkGroups reads only the workgroup_names: index (:486-488), which is
appended to by CreateWorkGroup alone — so primary is never in it.
The result is three answers that cannot all be true of one account:
GetWorkGroup{"WorkGroup":"primary"} -> 200, WorkGroup primary, State ENABLED
ListWorkGroups{} -> 200, WorkGroups: [] <- primary absent
ListQueryExecutions{"WorkGroup":"primary"} -> 200, every query started without a workgroup
A caller that discovers workgroups by listing them cannot find the one every unqualified query is
attributed to, and a caller that lists queries in primary is reading a workgroup the listing says
does not exist.
What AWS publishes
API_ListWorkGroups returns "A list of WorkGroupSummary objects that include the names,
descriptions, creation times, and states for each workgroup" with Array Members minimum 0, so the
page does not itself say primary is present. The claim that it is comes from Athena's own user
guide, which says every account gets a primary workgroup and that it cannot be deleted — and from
substrate's own GetWorkGroup, which already asserts it. Verify the user-guide wording against the
page before writing the fix, per CLAUDE.md's rule that the AWS documentation is the source of
truth; do not take this body's summary for it.
Acceptance criteria
Provenance of the finding
Found while reading athena_plugin.go for #1086's pagination conversion; unrelated to the token
refusal, so it was left out of that PR rather than folded in.
What happens
GetWorkGroupsynthesizes theprimaryworkgroup when no record exists(
emulator/athena_plugin.go:401-429, comment: "'primary' always exists as the default workgroup"),and
StartQueryExecutionattributes a query toprimarywhen the request names no workgroup(
:162-165). ButListWorkGroupsreads only theworkgroup_names:index (:486-488), which isappended to by
CreateWorkGroupalone — soprimaryis never in it.The result is three answers that cannot all be true of one account:
A caller that discovers workgroups by listing them cannot find the one every unqualified query is
attributed to, and a caller that lists queries in
primaryis reading a workgroup the listing saysdoes not exist.
What AWS publishes
API_ListWorkGroupsreturns "A list ofWorkGroupSummaryobjects that include the names,descriptions, creation times, and states for each workgroup" with Array Members minimum 0, so the
page does not itself say
primaryis present. The claim that it is comes from Athena's own userguide, which says every account gets a
primaryworkgroup and that it cannot be deleted — and fromsubstrate's own
GetWorkGroup, which already asserts it. Verify the user-guide wording against thepage before writing the fix, per
CLAUDE.md's rule that the AWS documentation is the source oftruth; do not take this body's summary for it.
Acceptance criteria
ListWorkGroupsincludesprimaryfor an account that has created no workgroup, with the sameName/StatethatGetWorkGroupsynthesizes — one producer for the synthesized record, not twocopies of the literal.
ListWorkGroupsreports forprimary,GetWorkGroupreports the same, andDeleteWorkGroupon it behaves consistently with whateverAWS publishes about deleting it (check: the user guide says it cannot be deleted, and substrate
currently answers
InvalidRequestException/400 "not found", which is wrong under either reading).in the order the offset indexes into, so it must be prepended or appended deterministically and
the choice recorded.
CreateWorkGroup/ListWorkGroups/GetWorkGroupcalls ratherthan by seeding the index (cfn: the aws:cloudformation:* stamp covers EC2 only, so the rest of a stack is unstamped #765).
docs/services.md's Athena section records what is synthesized and on whose authority.Provenance of the finding
Found while reading
athena_plugin.gofor #1086's pagination conversion; unrelated to the tokenrefusal, so it was left out of that PR rather than folded in.