Repository navigation
dir-sim: the history log in Lance; group grants read from the authority's policy - #1485
Conversation
D-DSP-2b. A new workspace-excluded crate, lance-graph-dir-sim-lance, so lance-graph-dir-sim itself stays free of lance, arrow and datafusion. It stores the records lance_graph_dir_sim::log builds and reads them back; it decides nothing about their content. - LanceLog::append stores one batch as one Lance commit (Create for the first, then Append) and only then advances the LogState. The writer holds the dataset version it last saw: if the dataset is elsewhere, nothing is written (StaleWriter), because Lance would rebase an append onto a newer version and interleave two writers' batches. A commit that does not land as the next version is reported as Race. - LanceLog::restore reads every record in one scan and hands them to replay; a missing dataset is an empty log. - The logical versions stay in the records; the Lance version is only the physical commit counter. Tests: two saves restore to the same reads and the same log state; a missing dataset is an empty log; a stale writer writes nothing, on create and on append; a batch stored with a record missing is refused at restore; a batch out of order is refused before anything is written. CI: .github/workflows/dir-sim-persist.yml builds and tests the crate (protoc and the protobuf includes installed, which lance's build needs). Board: D-DSP-2a shipped (#1482), D-DSP-4 shipped (#1481), D-DSP-2 in PR. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reachedYour organization has reached its usage spending cap. Adjust your spending cap in the billing tab. Next included review available in 20 minutes. View limit details
Warning Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption. Comment |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
What
D-DSP-2b, the last piece of decision 3(b): the dir-sim history log stored in Lance.
lance-graph-dir-sim-lanceis a new crate, excluded from the workspace with its own root, likelance-graph-dir-sim. dir-sim itself stays free of lance, arrow and datafusion. The crate stores the recordslance_graph_dir_sim::logbuilds and reads them back. It decides nothing about their content.LanceLog::append: stores one batch as one Lance commit (Createfor the first, thenAppend), and only then advances theLogState.StaleWriter). Without this check Lance would rebase the append onto the newer version and interleave two writers' batches.Race.LanceLog::restore: reads every record in one scan and hands them toreplay, which refuses the whole log at the first damaged batch. A missing dataset is an empty log.Tests (
tests/lance_log.rs, plus 2 unit tests)ReplayError::RecordCount).Disable runs:
a_stale_writer_writes_nothing.Not covered: the
Racepath has no test. It needs a second writer to commit between the check and the write, which can't be forced deterministically here.CI and board
.github/workflows/dir-sim-persist.ymlruns clippy (-D warnings) and the tests for this crate. It installsprotobuf-compilerandlibprotobuf-dev, which lance's build needs. No other job builds the crate.Locally:
cargo +1.99.0 fmt --check,clippy --all-targets -D warningsandcargo test(7 passed) pass, with debug info off.Also in this PR: group grants read from the authority's policy (HubSPO wishlist #2)
GroupRoles::from_policybuildsViewActors' grants from one version of OGAR'sogar_rbac::GroupRolePolicy(decision 4(b)). The grants now have one home: the directory supplies membership, and the authority's versioned policy supplies which roles a group confers.unread_groups. A group whose grants were all revoked is read with no roles.rbacfeature now pulls inogar-rbac. The crate's own[patch]pointslance-graph-contractandlance-graph-rbacat this checkout, so there is oneRoleId. No consumer enablesrbac, and Spear still resolves.roles_come_from_one_version_of_the_group_role_policy. It fails to compile withoutfrom_policy. As a disable run, dropping groups with no standing roles fails it.🤖 Generated with Claude Code
https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
Generated by Claude Code
Generated by Claude Code