redis - fix: clear() and iterator() match the namespace literally - #2185
Merged
Merged
Conversation
clear() and iterator() passed `<namespace><keyPrefixSeparator>*` to SCAN MATCH without escaping it, so `*`, `?`, `[`, `]` and `\` in the namespace or separator were read as glob syntax. clear() on namespace `tenant*` deleted namespace `tenant-prod`'s keys and iterator() returned them, while a namespace such as `t[12]` or `a\b` never matched its own keys. v5 built the same pattern. Both now build the pattern through getKeyPattern(), which escapes those characters in the namespace and separator, as @keyv/valkey does since #2147. filterScannedKeys() also checks each SCAN result against the literal prefix, so clear() can't delete another namespace's keys whatever glob syntax the server supports. Adds regression tests for clear(), iterator() and a separator with glob characters, documents the literal matching and the separator limitation in the README, and notes the change in the v5-to-v6 migration guide and the keyv-migrate skill references. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Wm1wtCGzQJEyYZdekgNVge
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2185 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 56 56
Lines 5790 5797 +7
Branches 996 987 -9
=========================================
+ Hits 5790 5797 +7 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Please check if the PR fulfills these requirements
What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)
Bug fix, with docs.
clear()anditerator()built theirSCAN MATCHpattern as<namespace><keyPrefixSeparator>*without escaping it, so*,?,[,]and\in the namespace or separator were read as glob syntax:clear()on namespacetenant*(likewiseuser?ort[12]) deleted another namespace's keys, anditerator()returned them.t[12]ora\bnever matched its own keys, soclear()left them behind.v5 (
@keyv/redis@5.1.6) built the same pattern.@keyv/valkeyfixed the same bug in jaredwray/keyv#2147.Changes
getKeyPattern()escapes those characters in the namespace and separator, as@keyv/valkeydoes.filterScannedKeys()also checks eachSCANresult against the literal prefix, soclear()can't delete another namespace's keys whatever glob syntax the server supports. It also holds the existing no-namespace filtering, whichclear()anditerator()now share.clear()anditerator()with glob characters in the namespace, and for a separator with glob characters. All three fail onmainand pass here.my-namespace::archiveundermy-namespace) is still covered by it, as the Valkey README does.keyv-migrateskill references: a@keyv/redissection and updated wording, since v5 behaved differently (per AGENTS.md).Verification
pnpm testinstorage/redisagainst local Redis (standalone, TLS, a 3-node cluster and sentinel): lint clean, 14 files and 257 tests pass, and every branch in the changed code is covered.pnpm --filter @keyv/website test(skill and docs validation): 32 tests pass.🤖 Generated with Claude Code
https://claude.ai/code/session_01Wm1wtCGzQJEyYZdekgNVge
Generated by Claude Code