Skip to content

fix(analytics): the native-SQL strategy applies the engine's aggregate policies — double accumulation, the PostgreSQL boolean cast and the empty-sum fold, hoisted into core (#21042) - #21209

Merged
objectstack-fleet[bot] merged 8 commits into
mainfrom
claude/issue-21042-native-aggregate-policies
Oct 1, 2026
Merged

objectstack-fleet[bot] merged 8 commits into
mainfrom
claude/issue-21042-native-aggregate-policies

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #21042
Clause-②: yes (widening)

What this changes

The analytics native-SQL strategy (NativeSQLStrategy, the default on a SQL driver) skipped three aggregate policies that SqlDriver.aggregate() applies. So one route answered different numbers, or a 500, depending on which strategy served it. This PR follows the route ruling on #21042 (comment 5925613967): the operand policies are hoisted into @objectstack/core, beside AGGREGATE_ANSWER_KIND, and both faces read them from there.

  • packages/core/src/utils/aggregate-answer.ts (@objectstack/core, minor). It takes:
  • packages/drivers/driver-sql/src/sql-driver.ts (patch), in the ruled regions only. The AGGREGATE_ACCUMULATION table becomes a pointer plus an import. isFractionalNumericType is deleted. The two registry fills fill fractionalNumericFields through the predicate. accumulatesInDouble / doubleAccumulationOperand are replaced by aggregandColumnClassOf, which maps the driver's registries onto the predicate's classes. In aggregate(), the private boolean-cast condition and the accumulation call become one aggregandOperandSql(funcName, class, this.dialectName, '??').
  • packages/services/service-analytics/src/strategies/native-sql-strategy.ts (patch), in two places.
    • resolveMeasureSql wraps the column it hands AGGREGATE_SQL / CONDITIONAL_AGGREGATE_SQL in aggregandOperandSql. The column class comes from the declaration the host already relays (declaredValueShape), on the object the column lives on (columnObjectOf, the one hop resolver). The dialect comes from sqlDialect, which the strategy already reads.
    • The execute shaping point that PR fix(core,driver-sql,service-analytics): the analytics native-SQL path answers measures declared number as numbers (#20889) #21040 added now folds a null measure answer to emptyGroupValueFor(measure.type) (@objectstack/spec). It does this for every measure, measure-scoped ones included, before the number presenter, in driver-sql's order. The dataset door's DatasetExecutor fill stays, and it is idempotent on a folded row.
    • The one line outside those two regions is the generateSql call site, which now passes ctx to resolveMeasureSql.
  • No native copy of any policy, and no runtime hook asks the driver: the rejected (C) route was not taken. canHandle, buildFieldMeta, the hop-object sites, the filter / text-match rendering, analytics-service.ts and field-read-admission.ts are untouched.

The card's table, before and after

Measured through AnalyticsService.query (the cube door, which POST /api/v1/analytics/query relays verbatim) and AnalyticsService.queryDataset (the dataset door), on AnalyticsServicePlugin over a real ObjectQL engine and SqlDriver. Native is the plugin's own composition (NativeSQLStrategy answered, with one raw statement and no engine aggregate). ObjectQL is the same composition narrowed to engine.aggregate. "Before" is the strategy file at the base d34aa58a2a; "after" is this branch at 61aab5013a. Neither merge since then touches the aggregate code paths, and the pins below are green at ef1f9d8484.

Fixture:

  • group f: frac (a number column) holds 0.1 and 0.2, and flag holds true and false;
  • group i: stars (a rating column) holds seven 1s and two 2s, and flag holds 7 trues and 2 falses;
  • group n: every aggregand is NULL in all three rows.

The measure-scoped measures filter on tag = x, which only group f holds.

PostgreSQL 16.13 (a private local server; the ObjectQL column is the same before and after):

measure group door native before native after ObjectQL
sum(frac) f cube, dataset 0.3 0.30000000000000004 0.30000000000000004
avg(frac) f cube, dataset 0.15 0.15000000000000002 0.15000000000000002
avg(stars), an integer column i cube, dataset 1.222222222222222 1.2222222222222223 1.2222222222222223
sum(flag) i cube, dataset 500 DATABASE_ERROR 7 7
avg(flag) i cube, dataset 500 DATABASE_ERROR 0.7777777777777778 0.7777777777777778
min(flag) / max(flag) i cube, dataset 500 DATABASE_ERROR 0 / 1 0 / 1
sum(frac), all-NULL group n cube null 0 0
sum(frac), all-NULL group n dataset 0 (executor fill) 0 0
sum(flag), all-NULL group n cube 500 DATABASE_ERROR 0 0
avg(frac), all-NULL group n cube, dataset null null null
measure-scoped sum(frac), no admitted row i cube null 0 0
measure-scoped sum(frac), no admitted row i dataset 0 (executor fill) 0 0
measure-scoped avg(frac), no admitted row i cube null null null
count control n cube, dataset 3 3 3
measure-scoped count control i cube, dataset 0 0 0

SQLite (better-sqlite3): accumulation and the boolean answers already agreed on every face (0.30000000000000004, 0.15000000000000002, 1.2222222222222223, 7, 0.7777777777777778, 0 / 1). The fold is the policy that diverged there:

measure group door native before native after ObjectQL
sum(frac) / sum(stars) / sum(flag), all-NULL group n cube null 0 0
sum(frac) / sum(stars) / sum(flag), all-NULL group n dataset 0 (executor fill) 0 0
measure-scoped sum(frac), no admitted row i, n cube null 0 0
measure-scoped sum(frac), no admitted row i, n dataset 0 (executor fill) 0 0

After the fix, the native and ObjectQL faces differ in 0 of 144 cells (2 drivers × 2 doors × 12 measures × 3 groups).

MySQL is NOT MEASURED: there is no MySQL server in this container. The MySQL operand text is pinned offline: by core's aggregate-answer.test.ts, and by the driver-sql move proof for the driver's own statements.

The move proof

driver-sql's aggregate statements were dumped at the base, before any consumer changed. The dump covered SqlDriver.aggregate() for every function (count, count_distinct, sum, avg, min, max, and count(*)), aliased and unaliased, over 23 columns: every fractional, integral and boolean type, the float / integer / int aliases, multi-valued and untyped columns, and text / date / lookup / formula. It ran on SQLite, PostgreSQL and MySQL, through both registration paths (registerObjectMetadata and registerExternalObject), offline (knex toSQL()).

The policies were then hoisted, driver-sql was switched to the imports, and the same dump was run again:

  • base dump: 1668 entries, 0 errors, md5 8eee668372a28a7568f3eb1cc5a2bc9b;
  • after dump (at bc8aa0cc2f): 1668 entries, md5 8eee668372a28a7568f3eb1cc5a2bc9b. cmp printed nothing: the two dumps are byte-identical.

sql-driver.ts and aggregate-answer.ts are unchanged between bc8aa0cc2f and 61aab5013a.

The committed move-proof pin, packages/drivers/driver-sql/src/sql-driver-21042-aggregate-policy-move.test.ts, holds the captured expressions for one column of each class, on each dialect and through each registration path. It passed at the base (192fc0010b: 54 / 54) and passes after (54 / 54).

Pins (committed red first, then the fix)

file at the pins commit (192fc0010b, base code) after
core aggregate-answer.test.ts 16 red (the exports did not exist) 22 / 22
service-analytics native-sql-aggregate-policies.test.ts (each measure on both faces at both doors, against the engine's arithmetic; SQLite and live PostgreSQL cells) SQLite: the cube-door folds red. PostgreSQL: accumulation, boolean 500, folds red 49 / 49
service-analytics cube-measure-field-type-door.test.ts, the lifted skip PostgreSQL native max(boolean) red (500) 23 / 23
rest analytics-dataset-aggregate-policies-door.test.ts (the route, both strategies) PostgreSQL: 7 red (accumulation and booleans). SQLite green (that door already folded) 19 / 19
driver-sql move proof 54 / 54 54 / 54

The lifted skip: it.skipIf(cell.id === 'pg' && face === 'native') in cube-measure-field-type-door.test.ts (from PR #21128) is gone. Its comment now says why the cell runs on every cell and face. The PostgreSQL native max_flag cell answers 1.

native-sql-measure-number-presentation.test.ts gets a comment-only edit: its header said the native statement does not carry #20387's accumulation, and it now points at the new pin.

Ablations

There was one ablation per policy, each predicted in writing before it ran. Each mutation was planted through scripts/ablation-replace.mjs, which checks that the anchor hit and that the blob changed. Each mutation was confirmed in the built dist/ (ablation-dist-preflight.mjs: marker present). Each restore ran by absolute path (git checkout HEAD), and the file's blob was proven equal to its HEAD blob with git diff HEAD empty. After each restore the package was rebuilt, and the marker was proven absent from dist/ with the tree clean. Every prediction held exactly.

ablation mutation predicted red observed red
A1 accumulation core accumulatesInDouble's dialect gate never admits PostgreSQL or MySQL core 3; driver-sql move proof 24 (pg and mysql × both fills × the six numeric / boolean columns); service-analytics 10, PostgreSQL only (both doors × sum / avg(frac), avg(stars), measure-scoped sum / avg); rest 3, PostgreSQL only the same 3 / 24 / 10 / 3; SQLite cells green; avg(flag) green as predicted
A2 boolean cast core aggregandOperandSql never casts core 1; move proof 4 (pg × both fills × boolean / toggle); service-analytics 8, PostgreSQL only; the lifted cell, PostgreSQL native and ObjectQL, 2; rest 4, PostgreSQL only the same 1 / 4 / 8 / 2 / 4
A3 fold the native shaping point never folds service-analytics 8, cube door only (SQLite and PostgreSQL × the three all-NULL sums and the measure-scoped sum); everything else green, the rest dataset-door route included, because the executor fill folds there the same 8; rest 19 / 19 green

A1 and A2 show one policy reaching both faces. Each one turned driver-sql's own statements red. Under A2 the ObjectQL face's max(boolean) cell failed too, with the driver's refusal. Under A1 the ObjectQL face answered the same exact decimal as the native face for the plain measures: the failing assertion was the engine's number, while native and ObjectQL still agreed.

A reverse type check also ran. Passing a dialect the new type rejects ('oracle') to aggregandOperandSql turned service-analytics' typecheck red (TS2345 ... not assignable to parameter of type 'AggregandSqlDialect'), which shows the rebuilt core .d.ts was read. The file was restored byte-identical.

Verification (at ef1f9d8484, after merging origin/main at cb45469e67, which carries PR #21170 and PR #21173)

Everything below ran as one locked script, at ef1f9d8484, with each exit code captured before any pipe. The live PostgreSQL 16.13 server ran at timezone = Asia/Shanghai, and the driver-sql suite ran under TZ=America/New_York, which are its own non-vacuity preconditions.

  • Refresh after the merge: pnpm turbo run build --filter='!@objectstack/docs' --concurrency=1 exit 0, and pnpm --filter @objectstack/spec check:generated exit 0.
  • Gates: node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack derived 67 commands from the real diff (10 paths). All 67 exited 0. Reconciliation with --ran and the recorded exit codes printed: Run reconciliation — 67 derived, 67 run, 0 NOT-MEASURED, 0 UNRUN.
  • Typecheck: pnpm --filter … typecheck exit 0 for @objectstack/core, @objectstack/driver-sql, @objectstack/service-analytics and @objectstack/rest.
  • Tests, every vitest project of every touched package (vitest run --maxWorkers=2, with OS_TEST_POSTGRES_URL set so the live cells ran):
package / project files tests
core local 74 passed 2120 passed
core repo 3 passed 48 passed
driver-sql 216 passed, 3 skipped 4300 passed, 96 skipped
service-analytics 161 passed 3765 passed
rest local 256 passed 5027 passed, 127 skipped
rest repo 5 passed 179 passed, 1 skipped

Acceptance notes

  • MySQL is NOT MEASURED (no server in this container). The MySQL operand text is pinned offline in core and in the driver-sql move proof.
  • The live PostgreSQL cells are not run in CI. No CI step sets OS_TEST_POSTGRES_URL for service-analytics or rest. The cells above ran against a private PostgreSQL 16.13 started for this run and removed afterwards. In CI the SQLite cells run, and so do the offline core / move-proof pins.
  • Phase 0's note on the dataset door, which is no divergence: a measure-scoped avg is absent from a row its supplementary query reported no row for. That is x_avg_frac for groups i and n, on both strategies and before and after. It is not null. The new service pin holds this cell only to "both faces agree", not to a value. Relatedly, a dataset-door selection made only of measure-scoped measures reports only the groups their filter admits, so the pin asks each one beside the base count.
  • Residual, as stated in the ruling: a host that relays no field declarations (declaredValueShape), or names no SQL dialect, gets no column class or no policy. It keeps the native arithmetic it had, and a PostgreSQL boolean sum there still answers 500. The plugin's own composition wires both.
  • How driver-sql reads the class: it reads its own registries rather than calling the predicate per column. fractionalNumericFields is filled by the predicate. booleanFields and numericFields are filled by the driver's coercion rules, whose populations equal the predicate's 'boolean' and 'fractional' ∪ 'integral' classes. The move proof pins that equality per column class. Asking the predicate per column through the driver's valueShapeFields would retire fractionalNumericFields, but its declaration and shard-alias regions are outside the ruled surface, so this PR does not do it.
  • The scan-order residual is unchanged. On PostgreSQL and MySQL the double sums are added without compensation (AGGREGATE_ACCUMULATION's docblock), so three or more fractions can still differ in the last place from SQLite and the rows path. The pins use two addends.
  • analytics: a config cube min / max whose sql is a relationship path is neither judged by the aggregate field-type table nor presented by its declared type on the native face (#21044's family, the dotted half) #21129 (the presenter for a relationship-path min / max) is not addressed here.

Generated by Claude Code

claude added 8 commits October 1, 2026 13:28
…L face (red), and the driver-sql statement the move must keep

The pins this card's fix turns green, committed first:

- core aggregate-answer.test.ts: the operand policies the hoist exports
  (red: the exports do not exist yet);
- service-analytics native-sql-aggregate-policies.test.ts: each measure on
  both faces at the cube and dataset doors, held to the engine's number
  (red on SQLite: the all-NULL and measure-scoped sum fold at the cube door;
  red on PostgreSQL: double accumulation, the boolean cast, the fold);
- cube-measure-field-type-door.test.ts: the PostgreSQL native boolean cell
  runs (red on PostgreSQL: max(boolean) does not exist);
- rest analytics-dataset-aggregate-policies-door.test.ts: the dataset route
  on both strategies (red on PostgreSQL);
- driver-sql sql-driver-21042-aggregate-policy-move.test.ts: the move proof,
  captured from the driver at the base, green before and after the move.

Claude-Session: https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H
Co-authored-by: Claude <noreply@anthropic.com>
…s with the base count, so every group is reported

A selection of measure-scoped measures alone reports only the groups their
filter admits, which is the executor's row set and not this card's question.

Claude-Session: https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H
Co-authored-by: Claude <noreply@anthropic.com>
…ompile and shaping point apply them

Claude-Session: https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H
Co-authored-by: Claude <noreply@anthropic.com>
…r-sql and service-analytics patch

Claude-Session: https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 3 package(s): @objectstack/core, @objectstack/driver-sql, @objectstack/service-analytics, touching 17 documentable anchor(s).

13 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/ai/natural-language-queries.mdx (via count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST))
  • content/docs/data-modeling/drivers.mdx (via SqlDriver (symbol, a top-level class))
  • content/docs/data-modeling/index.mdx (via SqlDriver (symbol, a top-level class))
  • content/docs/data-modeling/queries.mdx (via SqlDriver (symbol, a top-level class), count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST))
  • content/docs/deployment/validating-metadata.mdx (via count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST))
  • content/docs/kernel/contracts/data-engine.mdx (via count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST))
  • content/docs/permissions/tenant-audit-census.mdx (via SqlDriver (symbol, a top-level class))
  • content/docs/plugins/packages.mdx (via SqlDriver (symbol, a top-level class))
  • content/docs/protocol/kernel/index.mdx (via SqlDriver (symbol, a top-level class))
  • content/docs/protocol/kernel/lifecycle.mdx (via SqlDriver (symbol, a top-level class))
  • content/docs/protocol/objectql/query-syntax.mdx (via SqlDriver (symbol, a top-level class), count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST))
  • content/docs/protocol/objectql/types.mdx (via SqlDriver (symbol, a top-level class))
  • content/docs/ui/dashboards.mdx (via count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST))

⛔ 5 release-owned page(s) also name something this change touched. These are read-only:

  • content/docs/releases/v14.mdx (via generateSql (symbol, a method of class NativeSQLStrategy))
  • content/docs/releases/v15.mdx (via count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST))
  • content/docs/releases/v17/17-0.mdx (via SqlDriver (symbol, a top-level class), count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST))
  • content/docs/releases/v17/17-3.mdx (via AggregationFunction (symbol, a top-level type))
  • content/docs/releases/v17/17-5.mdx (via SqlDriver (symbol, a top-level class), count_distinct (symbol, a field of const object POSTGRES_BOOLEAN_AGGREGAND_CAST), generateSql (symbol, a method of class NativeSQLStrategy))

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

What this run could not see
  • 6 name(s) were too generic to anchor anything (single lowercase words)
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 36 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5e5ce48cef6d1a05714a9fda7eeaed6df5c072b8 → packageMentionDocs.

Which tree this was computed on

This run read content/docs from c96a80761eb220dbd4eefd0c3dff224950794d46 — the merge of head ef1f9d84846c5c30d7753d727a4c8a3d65ff8b59 into base 5e5ce48cef6d1a05714a9fda7eeaed6df5c072b8, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin c96a80761eb220dbd4eefd0c3dff224950794d46 && git checkout c96a80761eb220dbd4eefd0c3dff224950794d46
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5e5ce48cef6d1a05714a9fda7eeaed6df5c072b8 ef1f9d84846c5c30d7753d727a4c8a3d65ff8b59 && git checkout -B drift-repro 5e5ce48cef6d1a05714a9fda7eeaed6df5c072b8 && git merge --no-ff ef1f9d84846c5c30d7753d727a4c8a3d65ff8b59

node scripts/docs-audit/affected-docs.mjs --json 5e5ce48cef6d1a05714a9fda7eeaed6df5c072b8

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5e5ce48cef6d1a05714a9fda7eeaed6df5c072b8 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: ef1f9d84846c5c30d7753d727a4c8a3d65ff8b59
Local-runs: none

Inputs, and nothing else: card #21042 (its body and all eight comments: triage 5924484249, the unblock 5925017838, the claim 5925147145, phase 0 5925588922, the route ruling 5925613967, the build note 5932112476, the dev report 5936175525, the seat's acceptance 5936205915); PR #21209 (its body, its file list, and the net diff against main at the merge base cb45469e67: 10 files, +1309 / −139, 8 commits of which 4 are merges of main); the check-runs on the head. Everything was read by REST GET or by read-only git show of commits already in the checkout's object store. Nothing was built, run or re-run.

① Derived judgments

Public surface.

  • @objectstack/core root gains five value exports and two type exports through the existing export * (index.ts:62, no line added): AGGREGATE_ACCUMULATION, aggregandColumnClass, POSTGRES_BOOLEAN_AGGREGAND_CAST, doubleAccumulationOperand, aggregandOperandSql, and the types AggregandColumnClass, AggregandSqlDialect. accumulatesInDouble stays module-private. Right: one implementation read by both faces, the ruling's route A, and no native copy. No new package edge: driver-sql and service-analytics already depend on core and spec by workspace:*, and dataset-executor.ts already imports emptyGroupValueFor.
  • @objectstack/driver-sql: the module-private AGGREGATE_ACCUMULATION table and isFractionalNumericType are deleted; on the exported class SqlDriver, the protected members accumulatesInDouble(func, table, field) and doubleAccumulationOperand(operand) are replaced by protected aggregandColumnClassOf(table, field). That is the one movement in the driver's published .d.ts. Right, with a note: both helpers were aggregate sum / avg: PostgreSQL and MySQL native answer exact decimal (0.1 + 0.2 = 0.3) while SQLite and the engine rows path answer a double (0.30000000000000004), so having { s: { $eq: 0.3 } } keeps the group on PG / MySQL native only #20387's implementation of the very region the ruling ordered to become an import; nothing in the tree names them outside sql-driver.ts (whole-tree grep at the merge base; the subclasses SqliteWasmDriver and the LegacyStorageDriver testkit override neither); a protected implementation helper is not a declared contract face. Residual stated in ③ 9.
  • @objectstack/service-analytics and @objectstack/rest: no export moves. The route pin under rest is test-only.

Accept set. canHandle is untouched, so no request the native face served is now refused. The one request family that was answered with an error — a PostgreSQL sum / avg / min / max over a boolean, 500 on SQLSTATE 42883 — is now served with #11152's ruled numbers (7, 0.7777777777777778, 0 / 1). An error becoming an answer widens; it does not narrow. Right.

Served values that move, each to declared text.

  • PostgreSQL / MySQL sum over a fractional column and avg over every numeric or boolean class: exact decimal to double (0.3 to 0.30000000000000004, 1.222222222222222 to 1.2222222222222223). Declared by AGGREGATE_ACCUMULATION's docblock ("so one query answers one number on every face") and by AGGREGATE_ANSWER_KIND's precision policy ("one JS number, the loss declared"). Right.
  • Cube door, every dialect: an all-NULL group's sum, and a measure-scoped sum that admits no row, null to 0; avg / min / max stay null. Declared by emptyGroupValueFor's docblock (spec data/aggregation-policy.ts: "Counting no rows is 0 and summing them is 0: those are measured facts ... Averaging, minimising or maximising no rows is undefined ... and must stay null"). The dataset door already answered 0 through DatasetExecutor; its fill stays and is idempotent on a folded row. Right.
  • SQLite: only the fold moves. The operand policies answer the column as stored there, pinned in core's test for sqlite and unknown. Right.

The compile wraps only what the policies name. resolveMeasureSql leaves *, any measure.type that is not a key of AGGREGATE_ANSWER_KIND (the expression metric types), and any measure.sql that is not an identifier path (an expression) unwrapped. A column the host cannot describe gets no class, and a host naming no dialect gets 'unknown' from sqlDialectFor, so both aggregate as stored. The class is read on the object the column lives on (columnObjectOf, the last hop of a dotted path) through declaredValueShapeResolver; the three helpers pre-date this PR and are unchanged by it. Right.

The fold. At the execute shaping point PR #21040 added, emptyGroupValueFor(lookupMember(cube, member, 'measure')?.type) is read per selected measure (a measure-scoped one carries its aggregate in the same type); only null folds and undefined stays visible; it runs after executeRawSql and before the #20889 presenter, driver-sql's order. Right.

The move is a move. The AGGREGATE_ACCUMULATION docblock plus table (60 lines) in core differs from the merge-base driver text in exactly one line, const to export const (compared line by line). doubleAccumulationOperand's docblock is re-flowed around a @link tag and gains the dialect parameter: equivalent, not byte-identical, and the PR claims byte-identity for the table only. In aggregate(): the base accumulatesInDouble 'double' arm read numericFields or booleanFields, which is "class defined"; its 'double-over-fractional' arm read fractionalNumericFields, which is 'fractional'; the base castBooleanAggregand read isPostgres and lowering.sql !== 'count' and field not * and table not null and booleanFields, which is dialect === 'postgres' and class 'boolean' and POSTGRES_BOOLEAN_AGGREGAND_CAST[func] (the two counts are the only functions lowering to count; dialectName is derived from the same isPostgres / isMysql getters with isSqlite tested first). The composition order is unchanged (cast inside, double operand around) and the one ?? binding is kept. The two registry fills, aggregandColumnClass({ type, multiple: field?.multiple }) === 'fractional', equal isFractionalNumericType(type) && !isMultiValuedColumn(type, field): the same isMultiValueField({ type, multiple: multiple === true }) reading, and no boolean type has an exact numeric column kind. The committed move proof (sql-driver-21042-aggregate-policy-move.test.ts: 3 dialects, 2 registration paths, 6 functions, 9 column shapes, offline toSQL()) pins the statements, and the head's test check-runs carry it. Right.

Tests and the lifted skip. cube-measure-field-type-door.test.ts drops it.skipIf(cell.id === 'pg' && face === 'native') for max(boolean) and says why. The new service-analytics pin holds every measure on both faces at both doors to the engine's arithmetic and to each other, the one dataset-door x_avg_frac absence held to agreement only. The rest route pin holds POST /api/v1/analytics/dataset/query on both strategies. core's pin holds the two tables and the operand per dialect. The PostgreSQL cells are OS_TEST_POSTGRES_URL-gated named skips in CI, as each file's header states. native-sql-measure-number-presentation.test.ts changes a comment only. Right.

② Semver level

③ Boundary flags

  1. One line outside the ruled native regions: the generateSql measure loop passes ctx to resolveMeasureSql. Forced by the signature the ruled region needed; declared in the PR. Answered: accepted.
  2. fractionalNumericFields kept as a registry filled by the predicate, booleanFields / numericFields keeping their coercion fills. The class equality is shown in ① and pinned per class by the move proof; retiring the registry would touch its declaration and shard-alias regions outside the ruling. Answered: accepted; no follow-up card owed.
  3. main ahead of the merge base: five commits at this reading (build(turbo): build task hashes cover the root scripts each build runs (#21193) #21199 joined the four the dev named), 40 files, zero overlap with the PR's ten, zero under packages/core, packages/drivers/driver-sql, packages/services/service-analytics or the analytics rest tests. CI runs on the merge ref. Answered: accepted.
  4. MySQL NOT MEASURED (no server). The MySQL operand text is pinned offline in core's test and in the move proof's mysql2 cell; the live MySQL answer is unmeasured, which the PR and the changeset state. Answered: accepted as a stated residual.
  5. The live PostgreSQL cells are not run in CI: no CI step sets OS_TEST_POSTGRES_URL for service-analytics or rest. The PR carries its local PostgreSQL 16.13 run; the SQLite cells and the offline pins run in CI. Answered: accepted, stated in each file's header.
  6. Residual host shape: a host relaying no declaredValueShape, or naming no dialect, keeps the native arithmetic it had, and a PostgreSQL boolean sum there still answers 500. Stated in the changeset; the plugin's own composition wires both hooks. Answered: accepted.
  7. Dataset-door findings: a measure-scoped avg is absent, not null, from a group its supplementary query did not report, and a selection of only measure-scoped measures reports only the groups their filter admits; both on both strategies. No divergence between the faces; in the PR's Acceptance notes; carrier none. Answered: nothing owed on this PR.
  8. The scan-order residual (uncompensated double sums on PostgreSQL / MySQL for three or more fractions) is unchanged and stated in the moved docblock; the pins use two addends. Answered: unchanged by this PR.
  9. The protected helpers removed from SqlDriver (① above). An out-of-tree subclass that overrode accumulatesInDouble or doubleAccumulationOperand would silently lose its override; the CHANGELOG records one cross-repo subclass, TursoDriver. Not a declared contract face and not a narrowing of any served request; named so the owning seat can decide whether a CHANGELOG sentence is wanted. Not a condition of this verdict.
  10. analytics: a config cube min / max whose sql is a relationship path is neither judged by the aggregate field-type table nor presented by its declared type on the native face (#21044's family, the dotted half) #21129 (the presenter for a relationship-path min / max) is not addressed here; out of scope by the build note.
  11. Dev process notes, for the seat and not the diff: stray /gates.pid and /progress.log were written at the filesystem root and the dev could not remove them, so they want removing by hand; each full gate run held the shared lock about 29 to 36 minutes and flagged holder-side starvation. Neither touches the diff.
  12. Phase 0's two open questions (Q1 the route, Q2 the boolean cast) were ruled A and A and are built as ruled; the final dev report carries no open question.
  13. Check-runs on the head, read after the last one completed: 34 check-runs, 31 success and 3 skipped (Console Pin Gate, Build Docs, Packed-tarball smoke (opt-in): path-filtered or opt-in), none failed, none pending. Among the green: Check Changeset, Lint & Repo Gates (the changeset and ADR-0087 gates), Governed Surface Queue Guard, Build Core, Test Core 1/6 to 6/6, Type Check source / consumer / workspace / debt ledger, Temporal Conformance (live PG + MySQL), the three Dogfood Regression Gate shards and Dogfood Verify CLI. Their conclusions are the gate verdicts this record reads; nothing was re-run.

Implemented-by: claude/issue-21042-native-aggregate-policies
Reviewed-by: session_01XY5uCwTjZj7884yYtyur4H

VERDICT: PASS

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 1, 2026 17:12
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit 097ef80 Oct 1, 2026
36 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-21042-native-aggregate-policies branch October 1, 2026 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/xl tests tooling

Projects

None yet

2 participants