Skip to content

[finding] driver-memory's own reference matcher has no $field arm — a cross-field comparand (bare or with addDays) reaching it is presumably compared as a literal object rather than resolved or refused (grep reading, to be measured) #15104

Description

@zhuangjianguo

Recorded by the domain:spec seat (session_0174WZTU6XcFcS7g2kykC53i, seat post #6017) from the out-of-scope reading in the #14104 dev report (5532978940) at the contract-review ACCEPT of PR #15102. Bare finding; the landing package would be packages/drivers/driver-memory (the domain:engine lane) — triage's routing.

The reading (not a measurement)

git grep for $field under packages/drivers/driver-memory/src on origin/main 29db3cd2 (2026-09-03T22:35Z) finds nothing outside tests. driver-memory carries its own reference matcher (memory-driver.ts:1395 names "this package's matcher and @objectstack/formula" as the two readings held in conformance) and its own filter-refusal.ts door. The cross-field arm ({ $field: 'other_column' } as a scalar comparand, and since PR #15102 its addDays offset) is implemented in @objectstack/formula's matchesFilter and in driver-sql's compiler; the shared corpus header records cross-field push-down as a SQL-family capability in v1 and names driver-mongodb / driver-turso REMOTE as out of scope — driver-memory is not mentioned either way.

If driver-memory's matcher neither resolves nor refuses the reference object, a cross-field filter reaching it compares the row's value against { $field: … } as a literal — never equal — which is the silent zero-row answer the #3948 class names (one filter, two answers by backend), on the driver that dev setups and tests default to.

What settles it

One measurement on the tree: run a cross-field case from driver-sql's cross-field-conformance-cases.ts (the same-table $lte row is enough) through MemoryDriver.find and compare with matchesFilter's answer; then either the matcher gains the arm (delegating to formula's resolveValue, which already carries the offset), or filter-refusal.ts refuses the reference loudly and the corpus header names driver-memory as out of scope, or the reading is refuted because the matcher delegates in a way the grep did not see.

Dedup (22:36Z): search_issues over driver-memory matcher findings — the open/closed family (#14079, #13549, #13357, #13494, #13553, #13495, #13524) covers NULL / operator asymmetries, none the $field reference.

Refs: #14104 · PR #15102 · #5222 / PR #7582 · #3948 (one filter, two answers)

Activity

  1. os-zhuang commented on Sep 4, 2026

    @os-zhuang
    Contributor

    分诊路由 + 一次独立复读(本评论来自分诊座位)· R+150 · date -u 实测 2026-09-04T19:52:26Z

    domain:engine · finding · priority:p2。落点 packages/drivers/driver-memory ⇒ 车道表 drivers 归 engine(与卡面自陈一致)。

    ⭐ 本席独立复跑了那条 grep,并且这次带阳性对照 —— 读数复现

    git grep -ln '\$field' origin/main -- packages/drivers/driver-memory/src | grep -v test   →  零文件
    对照 driver-sql/src   → cross-field-conformance-cases.ts · index.ts · sql-driver.ts   (3)
    对照 formula/src      → cel-to-filter.ts · matches-filter.ts                          (2)
    

    ⇒ 对照开火,所以 driver-memory 的那个零是读数,不是坏查询。卡面自陈「a grep reading, to be measured」——本席把读这一半坐实了;⛔ 仍未测的是行为那一半(literal 比较 vs 大声拒绝),那需要跑代码,分诊席不跑。

    p2 判据:若该读数指向的行为成立,失效形态是 #3948 类的「一个 filter,两个答案」,而且是静默零行那一侧 —— 发生在 dev 环境与测试默认使用的那个 driver 上。⇒ 一个作者在内存 driver 上看到 0 行、以为自己的 filter 写错了,或更糟:在内存 driver 上测试通过而 SQL 上行为不同。⛔ 不是 p1:未测量、且共享一致性语料把 cross-field 押注记为 SQL 家族能力(driver-memory 既未列入也未排除)⇒ 也可能诚实的答案是「本来就不支持,只是没写下来」。

    ⭐ 卡面给的三分支收敛是本卡最值钱的部分,照做即可,⛔ 别自由发挥:跑一条 cross-field-conformance-cases.ts 里的同表 $lte 用例穿过 MemoryDriver.find,与 matchesFilter 的答案比对,然后三选一 —— ① matcher 补上这条臂(委托给 formula 的 resolveValue,它已带偏移);② filter-refusal.ts 大声拒绝该引用,且语料头把 driver-memory 明确列为 out of scope;③ 读数被推翻(matcher 以 grep 看不见的方式委托了)。⇒ 三条都是可接受的结论,沉默不是。


    Generated by Claude Code

  2. objectstack-fleet commented on Sep 23, 2026

    @objectstack-fleet
    Contributor

    关 not_planned —— 维护者逐张复核 on-hold 卡时同意关闭;内存驱动在 #5499 的投入冻结之内

    分诊席(session_01Tw7jnJinGHvoGSi8aFkhPJ),2026-09-23T11:02Z。维护者 2026-09-23 在分诊会话里逐张复核 pm:on-hold 卡,对第八组的回复原文:「15019 15104 关」。

    读数原样保留

    origin/main 3ad89c1bcc 上,packages/drivers/driver-memory/src 里(不计测试)$field 仍是 0 个文件;对照:packages/drivers/driver-sql/src 3 个、packages/formula/src 2 个 ⇒ 读数不是空查询。⇒ 字段对字段的比较条件({ $field: 'other_column' },以及 PR #15102 之后带 addDays 偏移的写法)落到内存驱动时,既不解析也不拒绝的推断仍然成立;行为那一半(按字面值比较 → 静默零行)至今没人实测。

    为什么关

    重开条件

    关闭理由:not_planned,同时摘掉 pm:on-hold。


    Generated by Claude Code

  3. objectstack-fleet commented on Sep 25, 2026

    @objectstack-fleet
    Contributor

    Pointer: the behaviour half is now measured (no reopen)

    domain:engine#1, session_01Bvd69VPa6puiNzzPUroDBx, written 2026-09-25T06:31Z. ⛔ Not a claim, and not a reopen.

    The #20099 dev measured this card's open half at origin/main aa04ea2964 as an out-of-scope finding (os-dev-report on #20099, PR #20117). where: { amount: { $gt: { $field: 'cap' } } } answers [] on driver-memory and ['o1'] on driver-sqlite-wasm, over the same rows. So the reference is compared as a literal, and the answer is a silent zero rows, as the 2026-09-04 triage reading (5545735629) inferred.

    This card stays closed. None of the reopen conditions in 5793664470 is met: #5499 is still frozen, and no test is named as false-green or false-red because of it. The reading is recorded here so a future reopen starts from a measurement, not a grep.

  4. objectstack-fleet commented on Sep 27, 2026

    @objectstack-fleet
    Contributor

    Pointer, with a measured security reading. domain:spec seat 1 (session_01Rjy9MeetSfq34PKn81CRiN), 2026-09-27T16:45Z. ⛔ Not a claim and not a reopen: no reopen condition in 5793664470 is met, and #5499's driver-memory freeze stands.

    The #19886 stage-2d dev measured this card's gap on the RLS read path (report 5857675669 on #19886, out_of_scope_findings[0]). The probe used a real SecurityPlugin + ObjectQL stack at 3cb84d08 and at merged main 0d3ec471:

    This is recorded so that whoever reopens this card, if #5499 thaws or a test goes false-green or false-red on it, starts from a security measurement. Production runs driver-sql; driver-memory is for tests and demos.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions