Skip to content

fix(exec): preserve authenticated owners in Cypher property mutations - #1245

Merged
DecisionNerd merged 7 commits into
mainfrom
fix/1224-cypher-property-ownership
Sep 11, 2026
Merged

DecisionNerd merged 7 commits into
mainfrom
fix/1224-cypher-property-ownership

Conversation

@DecisionNerd

@DecisionNerd DecisionNerd commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Ordinary Cypher SET/REMOVE could publish a second property owner for edges created through public construction, causing the immediate query to refuse corruption. Resolve committed edge owners through the same authenticated, bounded resolver used by composite publishing; keep pending creates on their own route and batch replacement-map key reads.

Staging uses current workspace rows and live counts, with pinned semantic declarations for a qualified route's first property write. This preserves mixed MERGE effects without mixing generation authorities. Empty accumulators add no property-admission scan. Typed scans retain the resolved storage route needed for mutations.

Validation:

  • Public construction, scalar/map SET and REMOVE, exact queries, active snapshots, reopen, export/full verification/clean import and subsequent mutation pass for exploratory and qualified fixtures.
  • The 8,193-edge multi-batch fixture checks cumulative owner/key-read work and explicit deterministic ceilings. Direct qualified relationship values and WITH aliases preserve public type names.
  • 27 write-driver regressions, workspace clippy, formatting, gate-registry checks and make pre-push-fast pass. Independent source review found no actionable findings.
  • Full validation passed 739 API unit tests and all 3,897 TCK scenarios. Corrected lowerer assertions pass 244 tests and reviewed plan goldens pass 15 tests. Full local pre-push stops at the existing test(storage): respect native TMPDIR in socket inventory regression #1192 hardcoded /tmp filesystem-admission fixture; it is not claimed green.

Frozen-release evidence in docs/development/evidence/cypher-property-ownership-1224.json records nine passing uninstrumented lifecycle processes plus six separate sampling/tracing processes. CPU ranges are 4.20–4.21 / 1.57–1.60 / 1.07–1.16 seconds across the three fixtures, with process RSS, filesystem counters, syscall bytes and inode-deduplicated sampled disk peaks recorded separately. Logical reader budgets are not native-memory bounds; disk sampling excludes unlinked open files. The original baseline refuses corruption, so its incomplete lifecycle is not a valid latency baseline. Failed staging prototypes and supplementary collectors are retained honestly.

Initial CI passed 99/101 Bazel targets and all independent binding/platform/quality lanes. Its two failing targets contained old expectations for the intentional route projection; those assertions and two snapshots are corrected here. Final exact-head CI remains the merge gate.

Closes #1224

@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: b505b8df-377f-4b15-a95c-c660d4cb298c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added planner Changes to query planner executor Changes to query executor core Core source code changes testing Test coverage and testing infrastructure documentation Improvements or additions to documentation labels Sep 11, 2026
@blacksmith-sh

This comment has been minimized.

@DecisionNerd
DecisionNerd marked this pull request as ready for review September 11, 2026 02:25
@DecisionNerd
DecisionNerd merged commit b896e4d into main Sep 11, 2026
23 checks passed
@DecisionNerd
DecisionNerd deleted the fix/1224-cypher-property-ownership branch September 11, 2026 02:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core Core source code changes documentation Improvements or additions to documentation executor Changes to query executor planner Changes to query planner testing Test coverage and testing infrastructure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(api): preserve property ownership in composite publishing routes

1 participant