Skip to content

dir-sim: the history log in Lance; group grants read from the authority's policy - #1485

Merged
AdaWorldAPI merged 1 commit into
mainfrom
ccr-0455e606-wmtsor
Oct 11, 2026
Merged

AdaWorldAPI merged 1 commit into
mainfrom
ccr-0455e606-wmtsor

Conversation

@AdaWorldAPI

@AdaWorldAPI AdaWorldAPI commented Oct 11, 2026 •

Copy link
Copy Markdown
Owner

What

D-DSP-2b, the last piece of decision 3(b): the dir-sim history log stored in Lance.

lance-graph-dir-sim-lance is a new crate, excluded from the workspace with its own root, like lance-graph-dir-sim. dir-sim itself stays free of lance, arrow and datafusion. The crate stores the records lance_graph_dir_sim::log builds and reads them back. It decides nothing about their content.

  • LanceLog::append: stores one batch as one Lance commit (Create for the first, then Append), and only then advances the LogState.
    • Stale writer: the writer holds the dataset version it last saw. If the dataset has moved, nothing is written (StaleWriter). Without this check Lance would rebase the append onto the newer version and interleave two writers' batches.
    • Race: a commit that does not land as the next version is reported as Race.
  • LanceLog::restore: reads every record in one scan and hands them to replay, which refuses the whole log at the first damaged batch. A missing dataset is an empty log.
  • Two clocks: the logical versions stay in the records. The Lance version is only the physical commit counter.

Tests (tests/lance_log.rs, plus 2 unit tests)

  • Restore: two saves restore to the same reads, and to the same log state as the writer's.
  • Missing dataset: an empty log.
  • Stale writer: writes nothing, both on create (the dataset exists) and on append (the dataset moved on).
  • Torn batch: a batch stored with a record missing is refused at restore (ReplayError::RecordCount).
  • Out of order: a batch out of order is refused before anything is written.

Disable runs:

  • Removing the stale-writer check fails a_stale_writer_writes_nothing.
  • Not advancing the log state after the commit fails three tests.

Not covered: the Race path has no test. It needs a second writer to commit between the check and the write, which can't be forced deterministically here.

CI and board

Locally: cargo +1.99.0 fmt --check, clippy --all-targets -D warnings and cargo test (7 passed) pass, with debug info off.

Also in this PR: group grants read from the authority's policy (HubSPO wishlist #2)

GroupRoles::from_policy builds ViewActors' grants from one version of OGAR's ogar_rbac::GroupRolePolicy (decision 4(b)). The grants now have one home: the directory supplies membership, and the authority's versioned policy supplies which roles a group confers.

  • Unread vs. empty (decision 5(a)): a group the policy never named stays unread and is named by unread_groups. A group whose grants were all revoked is read with no roles.
  • Policy versions: an earlier policy version gives the roles that stood then.
  • Dependencies: dir-sim's rbac feature now pulls in ogar-rbac. The crate's own [patch] points lance-graph-contract and lance-graph-rbac at this checkout, so there is one RoleId. No consumer enables rbac, and Spear still resolves.
  • Tests: roles_come_from_one_version_of_the_group_role_policy. It fails to compile without from_policy. As a disable run, dropping groups with no standing roles fails it.
  • Board: row D-DSP-3b.

🤖 Generated with Claude Code

https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg


Generated by Claude Code


Generated by Claude Code

D-DSP-2b. A new workspace-excluded crate, lance-graph-dir-sim-lance, so
lance-graph-dir-sim itself stays free of lance, arrow and datafusion.
It stores the records lance_graph_dir_sim::log builds and reads them
back; it decides nothing about their content.

- LanceLog::append stores one batch as one Lance commit (Create for the
  first, then Append) and only then advances the LogState. The writer
  holds the dataset version it last saw: if the dataset is elsewhere,
  nothing is written (StaleWriter), because Lance would rebase an append
  onto a newer version and interleave two writers' batches. A commit that
  does not land as the next version is reported as Race.
- LanceLog::restore reads every record in one scan and hands them to
  replay; a missing dataset is an empty log.
- The logical versions stay in the records; the Lance version is only
  the physical commit counter.

Tests: two saves restore to the same reads and the same log state; a
missing dataset is an empty log; a stale writer writes nothing, on create
and on append; a batch stored with a record missing is refused at
restore; a batch out of order is refused before anything is written.

CI: .github/workflows/dir-sim-persist.yml builds and tests the crate
(protoc and the protobuf includes installed, which lance's build needs).
Board: D-DSP-2a shipped (#1482), D-DSP-4 shipped (#1481), D-DSP-2 in PR.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
@AdaWorldAPI
AdaWorldAPI marked this pull request as ready for review October 11, 2026 11:16
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

Next included review available in 20 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 64 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: e12e9f68-6f8b-4804-84b5-f5c5bdd9e7cb

📥 Commits

Reviewing files that changed from the base of the PR and between ac3c8fb and 293737c.


📒 Files selected for processing (6)
  • .claude/board/STATUS_BOARD.md
  • .claude/plans/dir-sim-persist-v1.md
  • .github/workflows/dir-sim-persist.yml
  • crates/lance-graph-dir-sim-lance/Cargo.toml
  • crates/lance-graph-dir-sim-lance/src/lib.rs
  • crates/lance-graph-dir-sim-lance/tests/lance_log.rs

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Comment @coderabbitai help to get the list of available commands.

@AdaWorldAPI
AdaWorldAPI merged commit 4c3e813 into main Oct 11, 2026
11 checks passed
@AdaWorldAPI AdaWorldAPI changed the title dir-sim-lance: the history log stored in Lance, one batch per append dir-sim: the history log in Lance; group grants read from the authority's policy Oct 11, 2026
AdaWorldAPI pushed a commit that referenced this pull request Oct 11, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants