Repository navigation
Conversation
The governance cache keyed resolved policies, shapes, rules and schema by (kind, model ledger, graph, t), relying on new commits to produce new keys. `t` is not a model ledger's identity: one dropped and created again under its name restarts at t 1, so after the same number of commits it landed on a key the dropped ledger had filled, and every data ledger it governs was served the dropped ledger's artifacts until the server restarted. A model whose new policies deny what the old ones allowed kept allowing it. The key now carries the model's head commit id beside its t. The per-request pin (`ResolveCtx::resolved_heads`, carried across `wrap_policy` and `query` on the view) holds the two together, so a later stage that opens the model at the pinned t keys under the same commit rather than a newer one. The compiled-SHACL cache on the data ledger had the same blind spot: it is keyed by the shapes wire's origin and checked before translation, so a recreated model at the same t reused the shapes compiled from the dropped one. `WireOrigin` (both the API and policy crates' copies) now carries the commit id, and the compile cache keys on it.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A model ledger dropped and created again under its name kept enforcing its predecessor's policies and shapes on every data ledger it governs, until the server restarted. No error: a new model whose policies deny what the old ones allowed kept allowing it.
The governance cache keys resolved artifacts by
(kind, model ledger, graph, t). A recreated ledger restarts att1, so after the same number of commits it lands on a key the dropped ledger already filled. Dropping a ledger already clears its cached ledger state; the governance cache was the only stale layer.The compiled-SHACL cache on the data ledger has the same blind spot. It is keyed by the shapes wire's origin
(model, graph, t)and checked before translation, so even with a fresh wire, a recreated model at the sametreused the shapes compiled from the dropped one.Change
ModelHead { t, commit_id }replaces the baretin the resolution key. The commit id comes from the nameservice record the resolver already reads, so there is no extra I/O.ResolveCtx::resolved_heads(andGraphDb::cross_ledger_resolved_heads, carried fromwrap_policytoquery) pinstand commit together, so a later stage opening the model at the pinnedtkeys under the same commit rather than a newer one.WireOrigincarries the commit id (the API and policy crates' copies), and the compiled-SHACL cache keys on it.(kind, ledger, graph, t); its public type is unchanged.Cost is negligible: a
ContentIdis 96 bytes inline, no allocation; one extra hash per resolution, and the 4,096-entry cache grows by at most ~384 KB. Hit rate is unchanged in steady state, sincetand head commit move together on every commit.Tests
recreated_model_ledger_policies_replace_the_dropped_ones(it_policy_cross_ledger): end to end throughdb_with_policy. M denies users; M is dropped and recreated allowing them at the samet; the query must return them.recreated_model_ledger_is_not_served_the_dropped_ones_artifact(it_cross_ledger_resolver): the resolver returns a fresh artifact, not the dropped M's cachedArc.recreated_model_ledger_shapes_replace_the_cached_compile(it_shapes_cross_ledger): a write rejected by M's shape (compiled and cached), then M recreated at the sametwith the shape deactivated; the same write must pass.Mutation checks:
Related
Partially addresses #1962 (caches keyed by ledger id and
tthat collide on drop/recreate). This one was not on its list.#1980 keys the same cache by the model ledger's instance. When it lands, the commit id here makes the instance in the key redundant, and its recreate test still applies.
Also keys correctly a branch whose head returns to an earlier
twith other commits, as aSkiprebase can produce. That case isn't pinned here: today such a rebase never moves the branch's durable head, becausepublish_commitignores a head that doesn't advancet. That is a separate bug, to be filed on its own.