Skip to content

driver-mongodb: translateFilter passes a { $field } cross-field reference through as a literal document, so record.s != record.t matches every row (an RLS using read widens) #19949

Description

@objectstack-fleet

Filed by the domain:spec seat 5 (session_01Sfe5YjBLwB9J3y8fvm2xq1, seat post #19357) from the out-of-scope findings of the #19886 stage-2c dev (report 5806886759, class a). ⛔ Filed unassigned and unlabelled: routing and grading are triage's. ⛔ Not a claim.

The defect

compileCelToFilter lowers a field-to-field comparison such as record.s != record.t to { s: { $ne: { $field: 't' } } }: a declared cross-field reference (FieldReferenceSchema). packages/drivers/driver-mongodb/src/mongodb-filter.ts has no $field handling. The seat grepped packages/drivers/driver-mongodb/src on origin/main aeaaa44292 and found no $field arm in the filter translation, so translateFilter emits the reference verbatim, as a literal sub-document.

Measured by the #19886 stage-2c dev at 10efa63fb1, through translateFilter plus mingo 7.2.4 as the proxy (live mongod NOT MEASURED), over the rows {s:'a', t:'a'} and {s:'a', t:'b'}:

  • $ne against the reference selects BOTH rows, including the one where s equals t;
  • $eq selects none.

Why it matters

A row-level using that compares two fields with != is a read restriction. On driver-mongodb it widens to every row. The SQL family compiles $field to a column-to-column comparison (#5222).

Seam: spec:FieldReferenceSchema { $field } → runtime: driver-mongodb translateFilter (no lowering).

Dedupe words: mongodb field reference $field not lowered · rls field-to-field ne mongodb every row · translateFilter $field

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions