Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
95 commits
Select commit Hold shift + click to select a range
d177545
build(chtypes): build, package and release against the chtypes SDK
EricAndrechek Oct 1, 2026
e58d17f
docs: describe the chtypes type layer on the multi-tenant text
EricAndrechek Oct 1, 2026
b4779b2
Merge docs for the chtypes migration into chtypes-v2
EricAndrechek Oct 1, 2026
e071158
feat(policy): resolved row-filter predicates and a typed WHERE renderer
EricAndrechek Oct 1, 2026
6e1fce2
feat(discovery): refresh hooks before loaded, and the server zone
EricAndrechek Oct 1, 2026
3f27439
feat(typelayer): tenant-keyed chtypes engine with lazy handle pools
EricAndrechek Oct 1, 2026
443b19a
Merge the Go foundation for the chtypes migration into chtypes-v2
EricAndrechek Oct 1, 2026
4995331
feat(api)!: serve /v1/query and pipes through ClickHouse's HTTP inter…
EricAndrechek Oct 1, 2026
e000751
Merge branch 'chtypes-v2' into v2-w3
EricAndrechek Oct 1, 2026
6dd65fb
feat(typelayer): parse a row under the INSERT column list it was publ…
EricAndrechek Oct 1, 2026
35a008e
feat(query): bind integer policy claims through the strict cast
EricAndrechek Oct 1, 2026
2aa6f7d
feat(config,ingest): chtypes registry key and typelayer insert settings
EricAndrechek Oct 1, 2026
e87c9ce
Merge the HTTP read path for the chtypes migration into chtypes-v2
EricAndrechek Oct 1, 2026
b02bdd2
Merge branch 'chtypes-v2' into v2-w5
EricAndrechek Oct 1, 2026
852d5f8
feat(stream): judge row-level security with the type layer, per tenant
EricAndrechek Oct 1, 2026
91e86dc
Merge the chtypes-backed stream filter into chtypes-v2
EricAndrechek Oct 1, 2026
0537e89
feat(ingest)!: judge every body with ClickHouse's own parser
EricAndrechek Oct 1, 2026
3ba7c6e
Merge branch 'chtypes-v2' into v2-w5
EricAndrechek Oct 1, 2026
6fec76e
Merge branch 'chtypes-v2' into v2-w2
EricAndrechek Oct 1, 2026
1ceb21d
test(e2e)!: pin ClickHouse's own ingest verdicts and exception_code
EricAndrechek Oct 1, 2026
0499111
Merge the chtypes-judged ingest path into chtypes-v2
EricAndrechek Oct 1, 2026
8dcb496
Merge branch 'chtypes-v2' into v2-w5
EricAndrechek Oct 1, 2026
a776b2c
feat(app): open the type layer in API processes and bind it per tenant
EricAndrechek Oct 1, 2026
df6f93d
build(chtypes): move to SDK go/v0.5.1 and the ClickHouse 26.8 line
EricAndrechek Oct 1, 2026
3694f5e
fix(typelayer): set each library's zone through the SDK default
EricAndrechek Oct 1, 2026
cd1ddd7
fix(typelayer): compile with ClickHouse's type gates
EricAndrechek Oct 1, 2026
e1e3404
Merge branch 'chtypes-v2' into v2-w1c
EricAndrechek Oct 1, 2026
92c6c6e
test(integration): chtypes on the app harness, with policies and tokens
EricAndrechek Oct 1, 2026
9f78c0b
Merge SDK go/v0.5.1 and the ClickHouse 26.8 line into chtypes-v2
EricAndrechek Oct 1, 2026
2f230f8
Merge branch 'chtypes-v2' into v2-w5
EricAndrechek Oct 1, 2026
eb5ba5b
test(ingest): feed DateTime64 the way ClickHouse 26.8 reads a number
EricAndrechek Oct 1, 2026
be20317
Merge app wiring, config and the integration suite into chtypes-v2
EricAndrechek Oct 1, 2026
99a4529
refactor: delete the Go-side canonicalizer, row evaluator and compact…
EricAndrechek Oct 1, 2026
eb36644
Merge the old-API sweep into chtypes-v2
EricAndrechek Oct 1, 2026
6a72536
docs: reconcile docs with the chtypes type layer as landed
EricAndrechek Oct 1, 2026
4c9786d
Merge the docs reconcile pass into chtypes-v2
EricAndrechek Oct 1, 2026
c6b0128
fix(query): parse timestamp filters in ClickHouse, send in lists as t…
EricAndrechek Oct 1, 2026
3858fb7
docs(query): timestamp filters parse in ClickHouse; in lists are unca…
EricAndrechek Oct 1, 2026
9a044a0
Merge branch 'chtypes-v2' into v2-w3b
EricAndrechek Oct 1, 2026
39d3528
docs(api): give the timestamp-filter rule its own paragraph
EricAndrechek Oct 1, 2026
f32dd7a
Merge ClickHouse-parsed timestamp filters and external-data in-lists …
EricAndrechek Oct 1, 2026
943a828
docs(access-control): timestamp claims take the zone-less form
EricAndrechek Oct 1, 2026
9513fdb
test(integration): fit the suite back under its timeout
EricAndrechek Oct 1, 2026
e2e057e
Merge branch 'chtypes-v2' into v2-integ
EricAndrechek Oct 1, 2026
6915489
test(integration): run internal/api's live filter test in the target
EricAndrechek Oct 1, 2026
67e2b5d
build(chtypes): move to SDK go/v0.5.2
EricAndrechek Oct 1, 2026
d0ba5de
fix(discovery): publish refreshes in the order they started
EricAndrechek Oct 1, 2026
2dd4de7
test(integration): clear gosec's G703 on the settings cleanup
EricAndrechek Oct 1, 2026
d02cb78
docs: fix review-round findings across the chtypes docs
EricAndrechek Oct 1, 2026
5aa1b81
test(typelayer): move the test engine helpers into typelayertest
EricAndrechek Oct 1, 2026
db21526
fix(api): cap query-path connections per pool, not per server
EricAndrechek Oct 1, 2026
3c6d674
perf(typelayer): grow a role shape's handle pool under contention
EricAndrechek Oct 1, 2026
60862a8
chore(api): note that the 64 MiB response cap covers every query path
EricAndrechek Oct 1, 2026
8464208
fix(api): render DateTime as RFC 3339 UTC on every read and stream su…
EricAndrechek Oct 1, 2026
a888661
fix(sdk): compare timestamps as instants in stream filters and liveQuery
EricAndrechek Oct 1, 2026
3662865
Merge per-tenant read cap and RFC 3339 UTC rendering
EricAndrechek Oct 1, 2026
b708c1f
Merge round-1 docs review fixes
EricAndrechek Oct 1, 2026
4aa01e3
fix(ingest): role shapes keep denied columns, stamp _eq columns, take…
EricAndrechek Oct 1, 2026
b6035d3
fix(ingest): refuse content after a JSON array body
EricAndrechek Oct 1, 2026
3c8542a
test(integration): stored rows for denied, stamped and ephemeral columns
EricAndrechek Oct 1, 2026
c88603a
Merge round-1 code review fixes (insert column policy, EPHEMERAL, rol…
EricAndrechek Oct 1, 2026
330fd09
test(typelayer): use the in-package engine helper
EricAndrechek Oct 1, 2026
3674b79
docs: match the role-shape, EPHEMERAL, timestamp and read-cap fixes
EricAndrechek Oct 1, 2026
9dde7ed
docs: fix round-2 review findings (RFC 3339 examples, wire columns, r…
EricAndrechek Oct 1, 2026
6221019
docs: tighten EPHEMERAL, timestamp rendering and check-literal claims
EricAndrechek Oct 1, 2026
dc9ee8f
chore: label and coverage-exclude the typelayer package
EricAndrechek Oct 1, 2026
eab6e3d
chore: correct comments the type-layer migration left stale
EricAndrechek Oct 1, 2026
9da80ec
docs: fix round-3 findings (Nullable nulls, dedupe example, stale mec…
EricAndrechek Oct 1, 2026
0343354
fix(ingest): blank layout newlines after a JSON array's closing bracket
EricAndrechek Oct 1, 2026
56ba58f
chore: correct comments contradicted by measurement on 26.8
EricAndrechek Oct 1, 2026
4d35acf
docs: correct ingest codes, timestamp claims and stale mechanisms
EricAndrechek Oct 1, 2026
4950a59
ci: the fetch script takes no --frozen flag; it always fetches frozen
EricAndrechek Oct 1, 2026
289d55a
docs: make dev OTel endpoint, operator-key scope, ClickHouse statuses
EricAndrechek Oct 1, 2026
e7215e8
perf(typelayer): compile role shapes outside the role cache lock
EricAndrechek Oct 1, 2026
f367511
perf(typelayer): give every handle the whole filter cache budget
EricAndrechek Oct 1, 2026
6cb72bd
chore: reflow comments left over-long by the last round
EricAndrechek Oct 1, 2026
e8ad99a
docs: name roweval.go in the stream package and who sets the e2e OTLP…
EricAndrechek Oct 1, 2026
f09d96f
docs: show ClickHouse's escaped slashes in raw stream and pipe output
EricAndrechek Oct 1, 2026
417d7b0
fix(api): leave / unescaped wherever ClickHouse renders JSON
EricAndrechek Oct 1, 2026
e219066
test(stream): pin that an unreadable row is declined, not an error
EricAndrechek Oct 1, 2026
7ad1be8
docs: who labels each withheld row, and what the type layer holds in …
EricAndrechek Oct 1, 2026
871c86c
docs: the envelope re-encodes the writer's row without changing any v…
EricAndrechek Oct 1, 2026
241f869
docs: finish the exact-bytes correction; say what the error reason means
EricAndrechek Oct 1, 2026
da0c0aa
docs: the last two copies of the exact-bytes claim; untangle the erro…
EricAndrechek Oct 1, 2026
e3c3f14
docs: a table whose schema cannot compile is unavailable on its own
EricAndrechek Oct 1, 2026
9d8f95a
docs: every copy of the unavailable claim names all four causes
EricAndrechek Oct 1, 2026
e07e0ce
fix(policy): resolve row-filter predicates in column order
EricAndrechek Oct 1, 2026
53d874e
refactor(api): inject the ClickHouse HTTP reader instead of a package…
EricAndrechek Oct 1, 2026
63d7f45
test(app): run the package's tests in parallel where they share no gl…
EricAndrechek Oct 1, 2026
741f086
Merge the internal/app test-time fix into chtypes-v2
EricAndrechek Oct 1, 2026
755c108
Merge origin/main (#711) into chtypes-v2
EricAndrechek Oct 1, 2026
2601574
fix(ingest): decline a body chtypes answers short, never report it short
EricAndrechek Oct 1, 2026
f0213ee
docs: correct the type layer's unavailable causes, NaN rendering and …
EricAndrechek Oct 1, 2026
90860b6
Merge branch 'chtypes-v2' into v2-uuid
EricAndrechek Oct 1, 2026
a318830
fix(ingest): read BOM- and form-feed-led bodies the way ClickHouse does
EricAndrechek Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,14 @@
# scope". Suppress only that exact message — a genuine scope typo (e.g.
# `contents` → `conten`) still produces a different message and fails. Drop
# this once actionlint ships the scope.
#
# nektos/act has the same gap and no equivalent escape hatch: `act` (0.2.89)
# refuses ci.yml outright with `Unknown Property code-quality` from its own
# schema validator, before running anything. That is the tool, not the
# workflow — GitHub accepts the scope. To dry-run or run ci.yml under act,
# copy the workflows to a scratch dir and strip the one `code-quality: write`
# line there. (act's default image also ships no Go, so `setup-env`'s
# `go version` step exits 127 under act regardless.)
paths:
"**/*.yml":
ignore:
Expand Down
52 changes: 52 additions & 0 deletions .github/actions/setup-env/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,15 @@
# lockfile + astro.config.mjs. Speeds up warm `astro check` /
# `astro build` — unchanged content skips the parse + transform
# pipeline. See #132.
# 7. chtypes artifact cache (~/.cache/chtypes/artifacts/abi6) keyed on
# chtypes.lock — the pinned ClickHouse-version .so/.dylib the SDK
# dlopens. Measured for the 26.6 line (linux-amd64), pinned before 26.8:
# 316 MiB of libchtypes.so on disk, ~65 MiB as a stored archive, and
# 85 MiB over the wire on a MISS (the upstream .tar.gz). Fetched via
# scripts/fetch-chtypes.sh (--frozen: refuses anything the lock
# doesn't name), which the CLI makes idempotent even on a cache hit
# (a lightweight manifest check, not a re-download). Go test jobs
# that dial chtypes need this; see .github/workflows/README.md.
name: Setup CI environment
description: Caches (restore + automatic post-job save) and toolchains for WaveHouse CI

Expand All @@ -66,6 +75,9 @@ inputs:
astro:
description: "Cache the Astro content collections (docs check/build)"
default: "false"
chtypes:
description: "Fetch + cache the chtypes artifact(s) pinned in chtypes.lock (Go test jobs that dial chtypes only)"
default: "false"

# Exact-key cache-hit flags, for consumers that want to skip work on a
# warm cache (e.g. docs-build's pnpm-store prune). Saves are NOT gated on
Expand Down Expand Up @@ -178,6 +190,36 @@ runs:
restore-keys: |
golangci-${{ runner.os }}-

# chtypes artifact cache — keyed on chtypes.lock (not go.mod/go.sum):
# the pinned file+sha256 per platform/line is the only thing that
# changes its contents. runner.arch is in the key on principle (all CI
# runners are ubuntu-latest amd64 today; a future arm64 runner must not
# restore amd64 .so files into its search path).
#
# The SDK's default fetch dir is revision-scoped:
# ~/.cache/chtypes/artifacts/abi<R>/<os>-<arch>. The path and the key
# prefix both name the ABI revision (6 at SDK v0.5.2), so a cache saved
# by an older SDK is never restored into the search path. When the SDK's
# ABI revision changes, bump `abi6` in both places and re-lock (see
# docs/development.md).
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
if: ${{ inputs.chtypes == 'true' }}
id: chtypes-cache
with:
path: ~/.cache/chtypes/artifacts/abi6
key: chtypes-abi6-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('chtypes.lock') }}
restore-keys: |
chtypes-abi6-${{ runner.os }}-${{ runner.arch }}-

# Runs on both cache hit and miss: scripts/fetch-chtypes.sh always fetches
# frozen against chtypes.lock, is cheap on a hit (a manifest check, not a
# re-download — see the script), and is what turns a restored-but-
# unverified cache entry back into a hash-checked one every run.
- name: Fetch pinned chtypes artifact
if: ${{ inputs.chtypes == 'true' }}
shell: bash
run: scripts/fetch-chtypes.sh

# No actions/setup-go: it spends ~9s/job downloading + extracting a
# toolchain the runner can already provide. The image's preinstalled
# `go` + GOTOOLCHAIN=auto (the Go ≥1.21 default) resolve go.mod's
Expand All @@ -189,6 +231,16 @@ runs:
# this step makes that cost visible and the post-job save captures it.
# Trade-off: setup-go's inline problem matchers (PR-file annotations
# on compile errors) are gone; the log output is unchanged.
#
# On a chtypes job the cold cost is paid TWICE, and the second fetch is
# invisible because it happens inside the step above: `go run <pkg>@ver`
# resolves its toolchain from the pinned CLI module, not from this
# repo's go.mod, so it can land on a different patch than the one this
# step materialises (measured on an ambient go1.24.13: go1.27.1 for the
# CLI, go1.27.0 for `go 1.27` here). Both are ~80 MB and both live in
# ~/go/pkg/mod/golang.org/toolchain, so gomod-v1 absorbs both after the
# first save. A `toolchain` line in go.mod naming the same patch the CLI
# resolves would collapse it to one — not worth pinning for ~7s.
- name: Verify Go resolves go.mod's toolchain
if: ${{ inputs.go == 'true' }}
shell: bash
Expand Down
7 changes: 7 additions & 0 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,13 @@
- any-glob-to-any-file:
- "internal/pipes/**"

"area/typelayer":
- changed-files:
- any-glob-to-any-file:
- "internal/typelayer/**"
- "chtypes.lock"
- "scripts/fetch-chtypes.sh"

"area/sdk":
- changed-files:
- any-glob-to-any-file:
Expand Down
Loading
Loading