fix(objectql)!: having takes the temporal-comparand door where and the per-aggregation filter take (#20263) - #20307
Conversation
…e per-aggregation filter take (#20263) A having comparand its aggregated column's storage rule cannot read is refused INVALID_FILTER / 400 before any driver read, by the same walk and the same core predicate as where; the kind comes from the column class #20127 derives. Text operators are stepped over (#15661's door owns them). Claude-Session: https://claude.ai/code/session_01Bvd69VPa6puiNzzPUroDBx Co-authored-by: Claude <noreply@anthropic.com>
… paths (#20263) Claude-Session: https://claude.ai/code/session_01Bvd69VPa6puiNzzPUroDBx Co-authored-by: Claude <noreply@anthropic.com>
…door over SqlDriver (#20263) Claude-Session: https://claude.ai/code/session_01Bvd69VPa6puiNzzPUroDBx Co-authored-by: Claude <noreply@anthropic.com>
…rect the two pending notes it makes false (#20263) Claude-Session: https://claude.ai/code/session_01Bvd69VPa6puiNzzPUroDBx Co-authored-by: Claude <noreply@anthropic.com>
…ving-temporal-door
…d of erasing them (#20263) Claude-Session: https://claude.ai/code/session_01Bvd69VPa6puiNzzPUroDBx Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 1 package(s): 5 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
What this run could not see
Coarse fallback — 17 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin eb49dfd60c99af6fff6b489a23a50e5b823471cd && git checkout eb49dfd60c99af6fff6b489a23a50e5b823471cd
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 6a6a17b62e8b58d0ee31cbfabf5fc7322032ba94 a2ff967202602a677d8d4e5ac6d4b99cbc4bf0a4 && git checkout -B drift-repro 6a6a17b62e8b58d0ee31cbfabf5fc7322032ba94 && git merge --no-ff a2ff967202602a677d8d4e5ac6d4b99cbc4bf0a4
node scripts/docs-audit/affected-docs.mjs --json 6a6a17b62e8b58d0ee31cbfabf5fc7322032ba94
|
Contract reviewServed-tier: Scope: PR #20307 (card #20263, ① Derived judgments
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS |
…er, and the per-aggregation filter refusals name aggregations[i].filter (objectstack-ai#20334) (objectstack-ai#20368) Fixes objectstack-ai#20334 Clause-②: no (narrowing) ## What this does Two `where` behaviours the other filter positions of `engine.aggregate` lacked, per triage 5861202636's three execution notes, and a third change the seat's answer 5863946181 ordered as a patch round on this PR (open question 1 = B). 1. **`having` resolves `{placeholder}` tokens through the resolver `where` uses.** `ObjectQL.resolveWhereTokens` now takes the AST slot as a parameter (`'where'` by default, `'having'` from `aggregate`), and `aggregate` calls it once for `having`, after the per-aggregation filters resolve and before the middleware chain. ⛔ No second resolver: the call is the same method, through the same stage function (`resolveWhereFilterTokens` → `@objectstack/core`'s `resolveFilterTokens`) that `where` and the judge use. An unknown token is `FILTER_TOKEN_UNKNOWN` / 400 and a context token with no value is `FILTER_TOKEN_UNRESOLVED` / 400, in `where`'s words, before any driver read. A known token compares as the value it names. 2. **The per-aggregation `filter`'s refusals name their position.** `assertTemporalComparandsInterpretable` and `assertTextOperatorTargetsAreStringCapable` take an optional `path` (default `'where'`), and the per-aggregation loop passes `` `aggregations[${i}].filter` ``, the root its list-shape and comparand-type doors already pass. 3. **The `having` temporal refusal's remedy is `where`'s** (patch round). `assertHavingTemporalComparandsInterpretable` now ends its refusal in `REMEDY[hit.kind]`, the table the `where` and per-aggregation refusals read, and the parallel `HAVING_REMEDY` table and its docblock are deleted (net 1 line added, 16 removed). A string a `date` or `datetime` column cannot read now gets the remedy naming the relative-date placeholder (`"{30_days_ago}" / "{current_month_start}"`), which `having` resolves from item 1 on. `DATE_YEAR_REMEDY` is untouched, and the `time` kind's words are the same string as before (`HAVING_REMEDY.time` was `REMEDY.time`). `REMEDY`'s own docblock names no reader, so it does not misstate one and is not edited. Files: `packages/objectql/src/engine.ts` (`resolveWhereTokens`, `aggregate`), `temporal-comparand-door.ts` and `text-operator-declared-type-door.ts` (the `path` parameter; in the first, also the `having` remedy of item 3), two new pins (`objectql/src/engine-aggregate-positions.test.ts`, `rest/src/rest-aggregate-positions.test.ts`), one updated pin (`objectql/src/engine-aggregate-having-temporal-door.test.ts`: the unknown-token row replaced, the remedy case flipped), `.changeset/20334-aggregate-positions.md` (new: `minor`, BREAKING narrowing, ADR-0087 `not-required (no-migration-prescription)`), and a DELIBERATE CORRECTION to `.changeset/20263-having-temporal-comparand-door.md` (two sentences; each rewrite is listed under Deviations). Both door functions are package-internal: only `engine.ts` imports them, and neither `src/index.ts` nor `src/core.ts` re-exports them. ## How `having` reaches the one resolver (H2) - At base, `resolveWhereTokens(ast, execCtx)` read `ast.where` alone: `if (!ast || ast.where == null) return; ast.where = resolveWhereFilterTokens(ast.where, execCtx);`. The per-aggregation `filter` resolved through its own call to core's `resolveFilterTokens`, and `having` reached no resolver at all. - **The resolver needs no field type.** Core's walk replaces values and never reads keys (`for (const [k, v] of Object.entries(node)) out[k] = walk(v)`), and a token resolves from the request context alone (`now`, `timezone`, `userId`, `orgId`). So a `having` keyed by aggregate aliases resolves exactly as a `where` keyed by fields does. The one field-type-aware step, reading a resolved day by a column's storage rule, is `applyHaving`'s, as it already is for a literal day. - **Order against the temporal door.** On `where` the door runs inside `lowerWhereFilterArray`, before `resolveWhereTokens`, and steps around any `classifyFilterToken` hit (core's `isUninterpretableTemporalComparand`). `having`'s door (objectstack-ai#20263) runs in the same position relative to the new call: every `having` door first, then resolution. So `{ last_placed: { $lt: 'not-a-date' }, first_opened: { $gte: '{not_a_token}' } }` is the temporal door's `INVALID_FILTER`, and an earlier door's refusal (`totl`, objectstack-ai#20123) keeps its words. Both are pinned. As on `where`, a resolved value is not judged again by the door. - Both `applyHaving` doors (native `driver.aggregate()` and the rows fallback) read `ast.having`, so one call covers both paths, before `executeWithMiddleware` and any driver read. The caller's `having` object is not written back: the resolver is copy-on-write, and the AST is the engine's own object (pinned). ## The path (H3) - At base the per-aggregation loop called `assertTemporalComparandsInterpretable(object, 'aggregate', schema, aggFilter)` with no path, and the walk rooted at its default `'where'`. - The doors that already name their position there, quoted from the base: the list-shape door, "Received string ("2026-01-10") at aggregations[1].filter.placed_on.$in"; the comparand-type door, "Filter comparand at aggregations[1].filter.amount.$eq is a plain object". The walker's refusals name `` `aggregations[1].filter` ``, and the materializable door names no path at all. - **Partly falsified: a second door had the same defect.** The text-operator declared-type door (objectstack-ai#15661) was also called with no path: `$contains` on a number field in `aggregations[1].filter` said `at where.amount.$contains` at base, on all three drivers and both doors. It is fixed here the same way, as a bounded in-place fix (see Deviations). Head: `at aggregations[1].filter.placed_on.$gt`, `at aggregations[1].filter.$or[1].placed_on.$lt`, `at aggregations[1].filter.amount.$contains`, and `at aggregations[2].filter.…` when the filter sits on the third aggregation. ## Measured: base `26daf0b036` and head, three drivers, both doors, both `having` paths InMemoryDriver, SqlDriver on SQLite and SqlDriver on PostgreSQL 16.13 (a private role and database on the system cluster, database timezone `Asia/Shanghai`, process `TZ=America/New_York`), through `engine.aggregate` and `POST /api/v1/data/:object/query` (JSON round-tripped), four groups c1–c4 (`max(placed_on)` 2026-01-10 / 03-01 / 01-15 / 02-01, `sum(amount)` 500 / 1200 / 50 / 20). 432 cells per tree; driver reads counted. The head runtime is the objectql source at `f78b1e0c9d`. The later commits of the first round change tests, changesets and one doc comment, and `engine.ts` is byte-identical (blob `1c4f6d0a41c2`) at `a1a42d4c4a` and at the patch round's head `8b950b8e`. The patch round changes one runtime string, the `having` remedy, measured in its own section below. The three drivers and both doors agree on every row below unless the row says otherwise. | position · input | base | head | `where` twin | |:--|:--|:--|:--| | `having` `{ last_placed: { $gt: '{current_year_start}' } }` | 200, no group | 200, c1–c4 (the literal `'2026-01-01'` twin: c1–c4) | 200, c1–c4 | | `having` `{ last_placed: { $gte: '{not_a_token}' } }` | 200, no group, 1 read | `FILTER_TOKEN_UNKNOWN` / 400, 0 reads | `FILTER_TOKEN_UNKNOWN` / 400 | | `having` `'{TODAY}'` (near miss), an unknown token on `count`, under `$and` or `$or` | 200 (no group; `$or` kept c2) | `FILTER_TOKEN_UNKNOWN` / 400, 0 reads | — | | `having` `{today}` `$lte` / `{30_days_ago}` `$gt` / `{current_month_start}` `$lt` | c1–c4 / none / c1–c4 (text order) | c1–c4 / none / c1–c4 (resolved; the same groups by this data) | resolved | | `having` `{7_months_ago}` `$gt`, `$between` `['{current_year_start}', '2026-02-01']`, `{current_year_start}` `$gte` on `min(opened_at)`, `$not` of a token | none, none, none, c1–c4 | c2; c1, c3, c4; c1–c4; none | — | | `having` `$or: [{ total: { $gt: 1000 } }, { last_placed: { $gt: '{current_year_start}' } }]` | c2 | c1–c4 | — | | `having` `{ customer_id: '{current_user_id}' }`, user c2 | none | c2 | c2 | | `having` the same with no user · `{current_org_id}` with no org (engine) · `{record_id}` | none | `FILTER_TOKEN_UNRESOLVED` / 400, 0 reads (REST with no user: 401 before and after) | `FILTER_TOKEN_UNRESOLVED` / 400 | | `having` `{current_org_id}`, user c2, no org, both doors | none | `FILTER_TOKEN_UNRESOLVED` / 400 | — | | `having` `{ total: { $gt: '{today}' } }` on `sum` | none | none, except PostgreSQL native: c1, c3 | — | | `aggregations[1].filter` `{ placed_on: { $gt: 'not-a-date' } }` | 400 `INVALID_FILTER` `at where.placed_on.$gt` | 400 `INVALID_FILTER` `at aggregations[1].filter.placed_on.$gt` | 400 `at where.placed_on.$gt` | | `aggregations[1].filter` the same under `$or`, and the number for 10000-01-01 | `at where.…` | `at aggregations[1].filter.…` | `at where.…` | | `aggregations[1].filter` `{ amount: { $contains: '5' } }`, `{ placed_on: { $startsWith: '2026' } }`, and under `$or` | `at where.amount.$contains` … | `at aggregations[1].filter.amount.$contains` … | `at where.amount.$contains` | The PostgreSQL native `sum` cell is not a new divergence. Its literal twin `{ total: { $gt: 'TODAY-AS-A-DAY' } }` keeps c1, c3 there on the base too (PostgreSQL's native aggregate returns `sum` as a string, objectstack-ai#20307's out-of-scope finding 3, the region objectstack-ai#20335 holds). The resolved token compares exactly as that literal does. ## Collateral (H4) - **`where`: 48 of 48 cells byte-identical** base → head (status, code, message, groups, reads): tokens resolved and refused, the temporal and text-operator refusals, `{current_user_id}` with and without a user. - **`having` without a token: 96 of 96 cells byte-identical** at `a1a42d4c4a`, including the temporal refusals in their words (the patch round then moves one thing among them, the `date` / `datetime` temporal refusal's remedy, measured in its section below), a nested `$or` refusal, `a{b}c` (braces inside a string, not a placeholder), a `{ $field }` reference and the literal twins. - **Per-aggregation `filter`, every other door: 36 of 36 byte-identical** (list-shape, comparand-type, `$median`, `$field`, the unknown-token refusal and a resolved token's counts). - **The per-aggregation temporal and text-operator refusals: code, status and reads unchanged**, and at the engine the message differs in the `at where.` → `at aggregations[1].filter.` root alone (18 of 18 cells). Over REST the message is the engine's under the existing 500-character bound (`truncateClientMessage`), on every cell of both trees. The two `'not-a-date'` refusals (489 and 496 characters at base) now cross the bound and lose the end of their remedy (`"{current_month_s…`). The year-class and text-operator refusals were already cut at base. The changeset says so. - **A known token now compares as its resolved value, not as text**: pinned as "the token keeps exactly the groups the value written out keeps" on both paths, for ten shapes (a comparand, `$in`, both `$between` endpoints, a bare day on `min(datetime)`, `$and` / `$or` / `$not`) and `{current_user_id}`. ## Declaration and who is reached (H5) - The claim's `Clause-②: no (narrowing)` holds. An unknown token and an unresolvable context token on `having` answered 200 and now answer 400, which narrows the accept set. A known token that compared as text now resolves, which is a changed answer rather than a narrowed accept set. `node scripts/check-changeset-no-major.mjs --base origin/main`: "✓ This diff introduces no `major` bump." `node scripts/check-adr-0087-registration.mjs --base origin/main`: "✓ … 1 declared-breaking changeset(s), each carrying an ADR-0087 disposition", `.changeset/20334-aggregate-positions.md [BREAKING+bang+clause-②-narrowing] not-required (no-migration-prescription)`. - **Shipped authors of a `{…}` string on `having`: none.** There are five `having` clauses in `content/docs` and `skills/`: `queries.mdx` twice, `query-syntax.mdx` and `skills/objectstack-query/rules/aggregation.md` twice. Each compares `order_count` / `total_spent` / `total` with a number. Outside the engine and the spec that declare it, no runtime code, example app or `apps/` file composes a `having`. The control grep, a `where` / `filter` carrying a token in `examples/`, hits 16. ## Patch round: the `having` remedy (seat answer 5863946181), measured Before is `c599f758` (the merge of `main` at `c577e66635` into `a1a42d4c4a`, `HAVING_REMEDY` still read). After is `8b950b8e`, whose `temporal-comparand-door.ts` is the `db334ac4` blob `3ee7abf0c722`. - **Where the words are built (H1): one site, as hypothesised.** It is `assertHavingTemporalComparandsInterpretable` in `packages/objectql/src/temporal-comparand-door.ts`, the only line carrying "The `having` was NOT applied.", and it read `HAVING_REMEDY[hit.kind]` once. It now reads `REMEDY[hit.kind]`, and `git grep HAVING_REMEDY` answers 0 at `8b950b8e`. The year-class branch still reads `DATE_YEAR_REMEDY`. - **The pin sweep (H2), partly falsified.** Terms swept across this repository (every tracked file) and `../objectui`: `HAVING_REMEDY`, "The `having` was NOT applied", "a 200 indistinguishable from a real answer", "keep no group or every group", the two old remedy strings, "names no placeholder", "literal forms only", "remedy names none", `assertHavingTemporalComparandsInterpretable`, and `{30_days_ago}` / `current_month_s` in test files. Only one pin read the old remedy: `engine-aggregate-having-temporal-door.test.ts`, whose remedy case asserted `not.toContain('{30_days_ago}')`. It is flipped (Deviations). `packages/rest/src/data-query-having-temporal-door.test.ts` asserts only the column clause of the REST `error` (`toContain(column)`), which sits before the remedy, and no remedy words, so it has nothing to flip. The other having message-equality pins (`engine-aggregate-positions.test.ts`, `rest-aggregate-positions.test.ts`, `engine-aggregate-having-comparand-shape.test.ts`) compare token or walker refusals, not this door's. No doc, skill or `objectui` text quotes the having remedy. Every rejection assertion for a genuinely illegal shape is unchanged. - **What moved, at the engine.** 16 `having` cells (object `ledger_having`, SqlDriver on SQLite, both `having` paths) plus the two `where` twins were each read at both commits. 26 of the 26 moved cell-paths differ from before in the remedy alone: substituting the new remedy for the old one in the before message gives the after message byte for byte. The 8 unmoved cell-paths are the `time` column, the year class and the `where` twins. Both paths give one message in every cell. The `having` remedy equals the `where` twin's remedy byte for byte, on a `date` and on a `datetime` column. - **Over REST, the 500-character bound (H3), confirmed.** The bound (`CLIENT_MESSAGE_MAX`, a message of 500 or more characters is cut to 499 plus `…`) is unchanged. A `date` column's fixed words plus its new remedy take 409 characters, which leaves 90 for the object name, the column, what it aggregates, the quoted comparand and the path. A `datetime` column's take 502, so every such refusal is cut. "Whole" below means the REST `error` equals the engine message byte for byte. | `having` cell (`date` unless stated) | engine characters, before → after | REST, before → after | |:--|:--|:--| | `'not-a-date'` `$lt` on `max(placed_on)` | 382 → 481 | whole → whole | | `'+010000-01-01T00:00:00.000Z'` `$gt` on `max(placed_on)` | 399 → 498 | whole → whole (the longest measured) | | an `$in` member, a `$between` endpoint, the implicit-equality slot, under `$or`, under `$not` | 385, 390, 378, 389, 387 → 99 more each | whole → whole | | a `placed_on` groupBy key, a `day` bucket of `opened_at` | 391, 375 → 490, 474 | whole → whole | | `'not-a-date'` `$lt` on `min(opened_at)` (`datetime`) | 480 → 576 | whole → cut: `…epoch milliseconds, or a relative-date pl…` | | `'not-a-date'` on an `opened_at` groupBy key (`datetime`) | 487 → 583 | whole → cut: `…milliseconds, or a relative-…` | | `'last_30_days'` on `max(placed_on)` / `min(opened_at)` | 385 / 483 → 484 / 579 | `VALIDATION_FAILED` / 400 from the query schema, before and after: REST never reaches the engine with a preset name | | control: `'not-a-date'` / `'noon'` on `max(slot)` (`time`) | 412 / 406, unchanged | whole | | control: the number for 10000-01-01 on `max(placed_on)` (year class) | 555, unchanged | cut, before and after | | control, `where`: `'not-a-date'` on `placed_on` / `opened_at` | 485 / 578, unchanged | whole / cut at `…or a relative-date …`, before and after | The changeset states this: every measured `date` refusal arrives whole, and a `datetime` refusal is cut inside the remedy, as `where`'s already was. - **Ablation of the flipped pin, at `8b950b8e`.** It ran through `scripts/ablation-replace.mjs` (WRAP) under one verify lock. The anchor `` The \`having\` was NOT applied. ${REMEDY[hit.kind]} `` was replaced by the old literal-only remedy table, inlined behind the marker `ABLATION-20334-LITERAL-ONLY`. The tool read the anchor x1 → x0, the replacement x0 → x1, and the blob `3ee7abf0c722` → `bfe6275fe997`. Result: `engine-aggregate-having-temporal-door.test.ts` had 1 failed / 50 passed, the failure being the flipped case: `AssertionError: expected 'Write a "YYYY-MM-DD" calendar day.' to contain '"{30_days_ago}"'`. The direction is red, as predicted. The restore was proven: blob == HEAD `3ee7abf0c722`, `git diff HEAD` empty, tree clean. The test imports `./engine.js`, the source, so the leg needed no build. The built `dist/` (from `db334ac4`, the same `objectql` source) carries 0 hits of the marker. The whole `objectql` suite ran green again after the restore (below). ## Tests and evidence, patch round (head `8b950b8e`, after merging `main` at `c577e66635`) `main` at `c577e66635` brought no change to `objectql`, `core` or the drivers. It changed `packages/rest/src` (the draft-read builder gate), `packages/core/src/qa` and `spec`. The merge is `c599f758`, a true merge commit with parents `a1a42d4c4a` and `c577e66635`, through `scripts/pm/os-regen-merge.sh`: no generated artefact was pending, and main's side was taken for every `os-regen` path. The rest closure was rebuilt from it (`turbo run build --filter='@objectstack/rest^...'`, 24 tasks, exit 0), and `objectql` was rebuilt after the fix (dist carries the new remedy strings and 0 of the old). - `pnpm --filter @objectstack/objectql exec vitest run --project local --project repo --maxWorkers=2`: 324 files, 5890 tests passed. - `pnpm --filter @objectstack/rest exec vitest run --project local --project repo --maxWorkers=2`: 213 files, 3845 passed, 2 skipped (main added two files). - `engine-aggregate-having-temporal-door.test.ts` alone: 51 passed. The flipped remedy case is one of them, and it goes red under the ablation above. - `pnpm --filter @objectstack/objectql run typecheck`: exit 0, with the test layer: "40 file(s) / 234 error(s) / 65 pinned signature(s) held", unchanged. `tsc -p tsconfig.test.json --listFiles` lists `engine-aggregate-having-temporal-door.test.ts` (1 hit). `pnpm --filter @objectstack/rest run typecheck`: exit 0. - ESLint, narrowed and proven, at `8b950b8e`: `eslint --no-inline-config --format json` over the 6 `.ts` files this PR changes against the merge base counts 6 files in the JSON, 0 errors and 0 warnings. The population is read from `eslint.config.mjs` (`packages/**/*.{ts,tsx,mts,cts}`). Invariance: the config "never enables type-aware linting (no `parserOptions.project`, no typed `@typescript-eslint` rules)" (its own note), so this diff cannot move a verdict on an untouched file. - The REST measurement above ran as a scratch test file placed in `packages/rest/src` for one run at each commit and deleted after it. It was never committed, and the tree was clean after each run. ## Tests and evidence, first round (head `a1a42d4c4a`, after merging `main` at `29720975b6`, which touched none of these packages) - `pnpm --filter @objectstack/objectql exec vitest run --project local --project repo --maxWorkers=2`: 324 files, 5890 tests passed. - `pnpm --filter @objectstack/rest exec vitest run --project local --project repo --maxWorkers=2`: 211 files, 3819 passed, 2 skipped. - `pnpm --filter @objectstack/driver-memory exec vitest run --maxWorkers=2`: 57 files, 1374 passed. - `driver-sql`'s nine aggregate test files (`src/*aggregat*`), with `OS_TEST_POSTGRES_URL` on the private PostgreSQL 16 database and `TZ=America/New_York`: 9 files, 174 passed, 4 skipped. The suite's own summary: `live postgres RAN`, `live mysql NOT RUN` (no MySQL here; CI's Temporal Conformance job runs it). - New pins: `engine-aggregate-positions.test.ts` 28 passed, `rest-aggregate-positions.test.ts` 6 passed. The updated `engine-aggregate-having-temporal-door.test.ts` passes 51 and `data-query-having-temporal-door.test.ts` passes 11. - `pnpm --filter @objectstack/objectql run typecheck` and `pnpm --filter @objectstack/rest run typecheck`: exit 0, test layers included (objectql debt held at 40 files / 234 errors, unchanged; rest 0). `tsc --listFiles` on each `tsconfig.test.json` lists the new and updated test files (objectql 2, rest 1). - ESLint, narrowed and proven: `eslint --no-inline-config --format json` over the 6 changed `.ts` files counts 6 files in the JSON, 0 errors and 0 warnings. The population is read from `eslint.config.mjs` (`packages/**/*.{ts,tsx,mts,cts}`). Invariance: that config enables no type-aware linting (its own note), so this diff cannot move a verdict on an untouched file. **Ablations, at `93170f5468`, through `scripts/ablation-replace.mjs` (WRAP) under one verify lock each, with the restore proven.** Each leg ran mutate → `objectql` rebuilt → `ablation-dist-preflight` marker present in 4 built files → pins. Its restore leg ran blob == HEAD `1c4f6d0a41c2` → `git diff HEAD` empty → rebuilt → preflight `--absent` over all 14 built files → tree clean → pins green again (79/79 objectql, 17/17 REST). My first attempt at leg 1 never ran: its lock call timed out (exit 99) before the build, and the tool restored the file. Only the landing runs are reported. | leg (anchor replaced by a marker) | objectql (2 files) | REST (2 files) | what went red | |:--|:--|:--|:--| | the `having` resolution call | 19 failed / 60 passed | 4 failed / 13 passed | every resolved and every refused `having` cell, plus the objectstack-ai#20263 file's unknown-token row; the door-order, braces, caller-copy and per-aggregation cells stayed green | | the temporal door's `path` argument | 4 failed / 75 passed | 1 failed / 16 passed | the three temporal rows and the `aggregations[2]` index | | the text-operator door's `path` argument | 2 failed / 77 passed | 1 failed / 16 passed | the two text-operator rows | ## Gates, patch round (head `8b950b8e`) `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` at `8b950b8e` derives the same 65 commands, against the same 8 paths versus merge base `c577e66635`. All 65 ran at `8b950b8e`, each exit code written to a file before any pipe. `--ran` reconciliation: "✓ dispatch-gates --ran: 65 derived famil(ies) accounted for — 63 run, 2 NOT-MEASURED (2 DERIVED from a recorded exit 3)." 0 were unrun, and 62 exited 0. - Red by design: `node scripts/check-empty-changeset.mjs --base origin/main` exits 1 on the DELIBERATE CORRECTION of `.changeset/20263-having-temporal-comparand-door.md`. Its lines: "✓ No empty-frontmatter changeset introduced by this diff (2 declaring changeset(s) added)." and "… DELIBERATE CORRECTION -- your change may have made this PENDING release note false, and you rewrote it in the same stroke. Remedy: do NOT restore it -- say so on the PR and get it confirmed …". This PR says so under Deviations. - NOT MEASURED: `pnpm check:dual-build-cjs-loads` and `pnpm check:type-check-debt`, reason: PREREQUISITE NOT MET (exit 3). They need the whole workspace's built `dist`, which this worktree does not hold ("Run `pnpm build` first"; "7 workspace dependenc(ies) of the ledgered packages have no built type entry point on disk"). CI builds it. - Two gates refused on this clone's shallow history (`check-engine-split-ratio.mjs --days 90`, exit 2; `check-plugin-teardown-shape.mjs --self-test`, exit 3, "cannot read the positive control at 621a487"). The clone was deepened as they prescribe (`git fetch --unshallow origin main`), and both were re-run at `8b950b8e`: exit 0 each ("48 cases pass" for the self-test). The reconciliation records those re-runs. - `check-changeset-no-major.mjs --base origin/main`: "✓ This diff introduces no `major` bump." `check-adr-0087-registration.mjs --base origin/main`: "✓ check-adr-0087-registration: 1 declared-breaking changeset(s), each carrying an ADR-0087 disposition." `check-issue-citations.mjs`: "✅ … every citation this change adds resolves". `check:nul-bytes`: "OK (… no raw ASCII control bytes)". `check:doc-authoring`: all clean. - `origin/main` moved on during the round, to `db74b169d` (4 commits, among them objectstack-ai#20370 in `objectql/src/validation/record-validator.ts`). None of them touches a file this PR changes, and the branch is not merged again. The gates read three-dot from the merge base `c577e66635`, so the moving pointer did not enter their change set. ## Gates, first round `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` at `a1a42d4c4a` derives 65 commands, the same 65 as the dispatch's list. All ran at `a1a42d4c4a`. The `--ran` reconciliation found 65 derived, 63 run, 2 NOT-MEASURED and 0 unrun. - NOT MEASURED: `pnpm check:dual-build-cjs-loads` and `pnpm check:type-check-debt`, reason: PREREQUISITE NOT MET (exit 3). Both read whole-workspace built artefacts this worktree does not hold, and CI builds them. - Red by design: `node scripts/check-empty-changeset.mjs --base origin/main` exits 1 on the one DELIBERATE CORRECTION below. In its own words, the fix is to "say so on the PR … and get it confirmed … this gate stays red either way". Its other line: "✓ No empty-frontmatter changeset introduced by this diff (2 declaring changeset(s) added)". - `node scripts/check-issue-citations.mjs --base 2972097`: exit 0, "✅ … every citation this change adds resolves", 8 citations. - Also run, as the derivation flagged their rosters under this diff's directories: `node scripts/check-changeset-fixed.mjs`, `check:authz-resolver`, `check:error-code-casing`, `check:filter-alias-parity`, all exit 0. ## Deviations - **DELIBERATE CORRECTION, `.changeset/20263-having-temporal-comparand-door.md`**: two sentences, numstat 2/2 against `main`. `Check Changeset` stays red by design. Every rewrite, in order: 1. First round, the `What is judged` clause. Before (on `main`): "`having` does not resolve placeholders, and did not before, so the refusal's remedy names none." After (`a1a42d4c4a`): "`having` resolves placeholders from the same release (objectstack-ai#20334), after this door, and the refusal's remedy names none." 2. Patch round, the same clause again, because its last half is false at `8b950b8e`. Before: the `a1a42d4c4a` text above. After: "`having` resolves placeholders from the same release (objectstack-ai#20334), after this door, so the refusal's remedy on a `date` or `datetime` column is the `where` refusal's and names them, e.g. `{30_days_ago}` / `{current_month_start}`." 3. Patch round, the note's own **Fix.** line gains the placeholder form. Before: "**Fix.** Compare a `date` column with a `YYYY-MM-DD` day, a `datetime` column with an ISO-8601 instant, a bare day or epoch milliseconds, and a `time` column with an `HH:MM` or `HH:MM:SS` wall clock." After: "**Fix.** Compare a `date` column with a `YYYY-MM-DD` day, a `datetime` column with an ISO-8601 instant, a bare day or epoch milliseconds, either one with a relative-date placeholder the resolver knows (`{30_days_ago}`, `{current_month_start}`; `having` resolves them from the same release, objectstack-ai#20334), and a `time` column with an `HH:MM` or `HH:MM:SS` wall clock." Its "Unchanged" list ("`{today}`-style placeholders, known or not" and "every existing `having` refusal, in its words") is a before-and-after statement about objectstack-ai#20263's own door, so it stays TRUE and is not touched. The sentence "The refusal follows the `where` door's words" is truer now and is not touched either. - **This PR's own `.changeset/20334-aggregate-positions.md`, patch round** (not a correction: the file is new in this PR). Added: the paragraph "**The `having` temporal refusal's remedy is `where`'s.** …", which states the change and the REST bound reading in the patch-round section above. Rewritten: "…keeps that refusal and its words." became "…keeps that refusal, in that door's words.", and the Unchanged clause "every `having` that carries no placeholder, its refusals in their words;" became "every `having` that carries no placeholder, and its refusals in their words other than the `date` / `datetime` temporal refusal's remedy above;". Both old sentences read as "the words did not move", which is false at `8b950b8e`. - **Bounded in-place fix beyond the claimed surface: `packages/objectql/src/text-operator-declared-type-door.ts`**, its `path` parameter and the `path` field's doc line only. All four conditions hold. ① It is ruling 2's defect class exactly: a per-aggregation refusal naming `where`. ② The fix is mechanical and its shape is pinned by the temporal door's. ③ No open PR touches the file (a census of the 13 open PRs' file lists, including objectstack-ai#20309's branch; objectstack-ai#20335's branch has no commits). ④ The same pins and gate families cover it. The first round's claim did not list this file; the takeover claim 5863879760 now does (open question 2 = A). - **`temporal-comparand-door.ts` beyond "its path parameter only"**: in the first round the `HAVING_REMEDY` doc comment was corrected with no runtime byte moved, and whether the remedy should name a placeholder was put to the seat. The seat answered B (5863946181), so the patch round deletes `HAVING_REMEDY` and its doc comment and the `having` refusal reads `REMEDY`. This is item 1 of that answer, not a surface breach. - **The objectstack-ai#20263 pin that held the defect is replaced, not re-spelled.** Its row `'an unknown {placeholder} too'` asserted 200 with no group for `{not_a_token}` on `having`, which is the branch this change removes. It is now a case asserting `FILTER_TOKEN_UNKNOWN` / 400 with zero reads, not the door's `INVALID_FILTER`. In the first round the remedy case's title "having resolves none" was retitled with its assertion unchanged. In the patch round the case is flipped and retitled "the remedy names the placeholder the resolver knows, in the where twin's words". For a `date` and a `datetime` column it asserts the envelope (`INVALID_FILTER` / 400 through `expectHavingRefusal`, both paths, empty or populated, no read), the message's first sentence, `"{30_days_ago}"` in the remedy, and the remedy byte-equal to the `where` twin's. The ablation below turns it red. - **"Pin on the three drivers"** (ruling 3) is executed as objectstack-ai#20307 executed it. No driver reads `having` and every refusal precedes the driver, so the engine is pinned on both path shapes with counting drivers (objectql), and the engine and REST doors over a real SqlDriver on SQLite (rest), with the `where` twin as the control everywhere. InMemoryDriver and PostgreSQL were measured (432 cells per tree, above), not pinned. No package in the claim's surface holds the engine together with those drivers: objectql has neither, and rest has `driver-sql` but no `driver-memory` and no CI job hands it a PostgreSQL URL. Adding either is outside the surface. ## Acceptance notes (observations, not filed) - The first round's note that `HAVING_REMEDY` named only literal forms is resolved by the patch round (open question 1 = B). - Over REST, the 500-character bound now cuts a `datetime` column's `having` refusal inside the remedy, before the placeholder it names (`…epoch milliseconds, or a relative-date pl…`). The `where` refusal for a `datetime` field was already cut at the same place on `main` (578 characters, in the patch-round table above). The engine message is whole, and the order kept the bound as it is. So the placeholder half of the remedy reaches an in-process caller, and a REST caller only on a `date` column. Noted, not filed. - The per-aggregation `filter` still resolves tokens through a direct call to core's `resolveFilterTokens` with `filterTokenContextFrom`, which is the same resolver in a second spelling of the stage function `resolveWhereFilterTokens`. It is behaviour-identical and not changed here. - The per-aggregation temporal refusal keeps `where`'s consequence sentence ("reach the driver as written … return 200 with an empty result"). For a per-aggregation filter the consequence is a wrong count for that one aggregation. Ruling 2 moved only the path, so the wording is left as it was. - `.changeset/20148-aggregation-filter-where-doors.md` says the per-aggregation filter is "refused by the temporal-comparand door `where` takes, run unchanged on this position, in its words". I judge it TRUE as scoped to objectstack-ai#20148: the same door and sentence, now with this position's location clause. It is not corrected, and the seat may re-judge. ## Open questions (answered by the seat) - **Q1, the `having` remedy's words: B, in this PR** (seat answer 5863946181). `having`'s temporal refusal reads `REMEDY` and `HAVING_REMEDY` retires, done in this patch round (item 3 above). - **Q2, the claim's file surface: A** (seat answer 5863946181). The takeover claim 5863879760 amends its `File surface:` to list `text-operator-declared-type-door.ts`, its path parameter and one doc line. ## Out-of-scope findings None filed or proposed. The only divergence seen, PostgreSQL's native `sum` returned as a string, is objectstack-ai#20307's finding 3, which objectstack-ai#20335 holds. Authored in two rounds. The first was an os-dev run under `session_01Bvd69VPa6puiNzzPUroDBx` (report 5862763145). The patch round was an os-dev run under the seat session `session_01N8TPEsoJxPsdSdNKGnNGEN` (takeover claim 5863879760; this round's report is on objectstack-ai#20334). --------- Co-authored-by: Claude <noreply@anthropic.com>
Fixes #20263
Clause-②: no (narrowing)
What this does
engine.aggregateevaluateshavingitself, so no driver reads it, and none of the doors in front of it judged a temporal comparand. A comparand the aggregated column's storage rule cannot read was compared as written:having { last_placed: { $lt: "not-a-date" } }onmax(placed_on)kept every group with a 200, while itswheretwin answered 400.havingnow takes the temporal-comparand door thatwhere(#8690) and the per-aggregationfilter(#20148) take: the same walk and the same@objectstack/corepredicate (isUninterpretableTemporalComparand). When #20264 moves the year range in that predicate,havingfollows with no second edit (pinned: see "one predicate" below).packages/objectql/src/temporal-comparand-door.ts: the walk is factored into onewalkConditionwith a per-position scope (the kind of the column a key names, and which operators are judged).findUninterpretableTemporalComparand(thewhereentry) keeps its signature and behaviour. NewassertHavingTemporalComparandsInterpretable(object, having, classes, query).packages/objectql/src/engine.ts,ObjectQL.aggregate: one call, afterassertHavingIsEvaluableand beforegetDriver, so it covers bothapplyHavingdoors (nativedriver.aggregate()and the rows fallback) with zero driver reads on a refusal.packages/objectql/src/having-filter.ts:temporalKindOfis exported (one keyword and a doc line), so the door and the storage rule read one kind.objectqlandrest, and.changeset/20263-having-temporal-comparand-door.md(minor, BREAKING narrowing, ADR-0087not-required (no-migration-prescription)).How the kind is read (H3)
From the class #20127 already derives,
aggregatedRowColumnClasses, whichengine.aggregatecomputes once and now hands to this door too; nothing is derived again.min/maxof adate/datetime/timefield keeps that kind, a groupBy projection of such a field takes its kind, adaybucket is adate.count/count_distinct/sum/avg, aweek/month/quarter/yearbucket, and every other column are not judged. An alias that names no column is still refused by #20123's words, first.Two deliberate differences from
where, each measuredhavingdoors. On a clause anotherhavingdoor refuses (an unknown operator, a key naming no column, a comparand of no comparable type, anaddDayspair, an array in the equality slot), that door answers in its own words. So every cell refused at the base keeps its words byte for byte (H4), and only cells that answered 200 move.wherea text operator on a temporal field never reaches this door: [Decision] refuse a text operator ($containsfamily) over a field whose DECLARED type is not textual —INVALID_FILTER400 at the engine's field-aware door (option C of #14079); the textual-type vocabulary is the question #15661's declared-type door refuses it one step earlier, because "not a date value" is the wrong sentence for an operator no comparand could make runnable. That door does not fronthaving, and [Decision] refuse a text operator ($containsfamily) over a field whose DECLARED type is not textual —INVALID_FILTER400 at the engine's field-aware door (option C of #14079); the textual-type vocabulary is the question #15661's ruling keeps the row beneath it answered there (pinned inengine-text-operator-declared-type-door.test.ts). Judging them here would revive the retired wording, so$contains: "2026"and$startsWith: "not-a-date"onmax(placed_on)answer exactly as before.It judges the caller's own clause before the bigint narrowing, which is what
where's object form judges (see Acceptance notes for the bigint consequence).Measured: base
89f87f2344and head, three drivers, both doors, both pathsInMemoryDriver, SqlDriver on SQLite, SqlDriver on PostgreSQL 16 (private cluster). Through
engine.aggregateandPOST /api/v1/data/:object/query, native path and rows path,groupBycustomer over four groups. 1650 cells per run; 162 moved, all of themhavingcells that went from 200 with one read to 400INVALID_FILTERwith zero reads. Within each row below the three drivers, both doors and both paths agree.havingcolumn · comparand$gtbase → head$ltbase → headwheretwinmax(date)· "not-a-date"max(date)· "+010000-01-01T00:00:00.000Z"max(date)· the number (REST and engine) orDate(engine) for 10000-01-01max(date)· "2026-02-01" (control)min(datetime)· "not-a-date"min(datetime)· the extended-year ISO, number orDatedatetimerule reads it; PostgreSQL answers 500, #20264's range)min(datetime)· 2026 instant (control)max(time)· "not-a-date"max(time)· extended-year ISO, number,Datemax(time)· "12:00" (control)count/sum/avg· a stringH3 cells: "not-a-date" on a
placed_onoropened_atgroupBy key, "noon" on aslotkey, "not-a-date" and the number for 10000-01-01 on adaybucket: 200 → 400 on all three drivers and both doors. Amonthbucket and a text key: unchanged.H2, paths. The call sits before
getDriver, the middleware chain and bothapplyHavingdoors. Driver reads of the object on a refusal: 0 on every refused cell (was 1), on both paths, on an empty and a populated object.H4, collateral. Byte-identical base → head on all three drivers, both paths, both doors: every
whereand per-aggregationfiltercell (11 shapes, each at both doors), and 41havingshapes: a day, an ISO instant, an epoch-ms number or string, in-rangeDate, zone-naive instant, wall clock, extended-year instant ondatetime,{today}/{30_days_ago}/{not_a_token}, the empty and whitespace string,null,$exists,$in/$nin/$between,$not/$or/$and,{ $field },$contains/$startsWith, a string onsum, and the ten existing refusals (#20099 x3, #20123 x3, #20127, #19974, the type door,$icontains), in their words.H5, the words. Envelope
INVALID_FILTER/ 400, thewheredoor's wording class, naming thehavingpath, the column, what it aggregates and its kind:The year class (a number or
Dateoutside 0..9999 on adatecolumn) keeps #20240's sentence. Disclosure: likewhere, the column's declared kind, and otherwise only what the query carries (alias, function, field, comparand, path). The remedy names no{placeholder}, unlikewhere's:havingresolves none, so naming one would send the author to a literal.Tests and evidence (head
a2ff967202)pnpm --filter @objectstack/objectql exec vitest run --project local --project repo --maxWorkers=2: 321 files, 5828 tests passed, at438014d26c, before mergingmain(the merge touched no objectql file; the objectql source is byte-identical at head, and the one objectql test file changed since was re-run at head).pnpm --filter @objectstack/rest exec vitest run --project local --project repo --maxWorkers=2, at49d218bf7a(after mergingmain, closure rebuilt): 204 files, 3681 passed, 1 skipped.pnpm --filter @objectstack/driver-sql exec vitest run --maxWorkers=2, at438014d26c, withOS_TEST_POSTGRES_URL(serverAsia/Shanghai, processTZ=America/New_York): 199 files passed, 3 skipped; 3888 tests passed, 88 skipped. The suite's own summary:live postgres RAN,live mysql NOT RUN(no MySQL here; CI's Temporal Conformance job runs it).pnpm --filter @objectstack/driver-memory exec vitest run --maxWorkers=2, at49d218bf7a: 57 files, 1374 tests passed.engine-aggregate-having-temporal-door.test.ts51 passed;data-query-having-temporal-door.test.ts11 passed (re-run at head).pnpm --filter @objectstack/objectql run typecheckandpnpm --filter @objectstack/rest run typecheck: exit 0, test layers included (objectql debt held at 40 files / 234 errors, unchanged; rest 0).eslint --no-inline-config --format jsonover the 6 changed.tsfiles, 6 files counted in the JSON, 0 errors, 0 warnings. Population read fromeslint.config.mjs(packages/**/*.{ts,tsx,mts,cts}); invariance: that config enables no type-aware linting (its own note), so this diff cannot move a verdict on an untouched file.Ablation 1 (the door call), at
438014d26c, throughscripts/ablation-replace.mjswith restore proven. The call inengine.tswas replaced by a marker; objectql rebuilt (exit 0);ablation-dist-preflightfound the marker in 4 built files. objectql test: 20 failed / 31 passed (every refused, one-predicate and H3 case red; every unchanged and earlier-door case green). REST test: 6 failed / 5 passed. Restore leg: blob equals HEAD, rebuilt, marker absent from all 14 built files, tree clean, 51/51 and 11/11 green.Ablation 2 (the text-operator skip).
judgesOperatorforced to judge every operator: exactly the two text-operator cells went red (2 failed / 49 passed); restored byte-identical.Gates
node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstackat head: 64 commands. All run ata2ff967202;--ranreconciliation: 64 derived, 62 run, 2 NOT MEASURED, 0 unrun.check:dual-build-cjs-loadsandcheck:type-check-debt, reason: PREREQUISITE NOT MET (exit 3), both read a whole-workspacedist/this worktree does not hold. CI builds it.node scripts/check-empty-changeset.mjs --base origin/mainexits 1 on the two DELIBERATE CORRECTIONS below. Its own text: say so on the PR and get it confirmed; it stays red either way.check:query-options-erasurewent red on the first run (test surface 236 → 238, twoas anyoption bags in the new tests); the options are typed now and it holds at 236.node scripts/check-issue-citations.mjs --base 2dccb7d494: exit 0, 16 citations resolve.packages/:check:authz-resolver,check:error-code-casing,check:filter-alias-parity, all exit 0.Deviations
.changeset/20240-date-year-four-digits.md, one clause. It said "havingdoes not reach the temporal-comparand door for any comparand, so a number orDateoutside 0..9999 there is still compared as written." Now: "havingreaches the same door in the same release (objectqlhaving: a comparand on an aggregateddatecolumn never meets the temporal-comparand door — over RESThaving { last_placed: { $lt: "not-a-date" } }onmax(placed_on)keeps every group (200) while itswheretwin answers 400 #20263), so a number orDateoutside 0..9999 is refused there too.".changeset/19974-having-comparand-shape-face.md, one clause. It said neither the type door nor the declared-type gates "are run onhaving; this change adds the comparand-shape face only". Now it scopes that to "by this change" and adds that the comparand-TYPE door (objectqlhavingdoes not take the rest ofwhere's filter doors: a$fieldreference is never resolved, the comparand-TYPE door does not run, FilterArray sugar answers no group, and its own refusals fire only on a non-empty grouped set #20099) and the temporal-comparand door (objectqlhaving: a comparand on an aggregateddatecolumn never meets the temporal-comparand door — over RESThaving { last_placed: { $lt: "not-a-date" } }onmax(placed_on)keeps every group (200) while itswheretwin answers 400 #20263) reachhavingin the same release. The type-door half was already false since objectqlhavingdoes not take the rest ofwhere's filter doors: a$fieldreference is never resolved, the comparand-TYPE door does not run, FilterArray sugar answers no group, and its own refusals fire only on a non-empty grouped set #20099; this corrects both halves in one clause.packages/rest/src/data-query-date-year-range.test.tssaidhavingdoes not reach the door; corrected to point at the new pin.havingpaths with counting drivers (objectql) and the REST door over a real SqlDriver on SQLite (rest). InMemoryDriver and PostgreSQL were measured (the table above), not pinned: no package in the claim's surface has both the engine and those drivers (rest has nodriver-memorydependency, and no CI job hands the REST suite a PostgreSQL URL). Adding either is outside the claimed file surface.Acceptance notes (observations, not filed)
havingnorwhere's object form (the door runs before the type door narrows it);where's array form narrows first and refuses it. In-process only, as JSON carries no bigint. Reported to the seat below.wherewith a non-numeric string on anumberfield answers 500DATABASE_ERRORwhere memory and SQLite answer 200. Outside the temporal family; noted, not measured further.Out-of-scope findings for the seat (not filed by this PR)
havingresolves no{placeholder}:{ lp: { $gt: "{current_year_start}" } }onmax(placed_on)keeps no group (both groups are after 2026-01-01), and{not_a_token}answers 200 wherewhereanswersFILTER_TOKEN_UNKNOWN/ 400.resolveWhereTokensreadsast.whereonly.filter's temporal refusal names the wrong position: a bad date inaggregations[1].filteris reported "at where.placed_on.$gt".count/sum/avgas strings ("n":"1","total":"20.000000000000000000000000000000", also over REST), sohaving { n: { $in: [2] } }keeps no group there while memory and SQLite keep c1, c2, and a string comparand on those columns answers differently on the native and the rows path.Generated by Claude Code