Skip to content

Align default rendered SQL masking contract - #186

Merged
philipgreat merged 16 commits into
mainfrom
test/masking-contract
Sep 29, 2026
Merged

philipgreat merged 16 commits into
mainfrom
test/masking-contract

Conversation

@philipgreat

@philipgreat philipgreat commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Part of teaql/teaql-conformance#58: default expanded SQL diagnostics with field-aware masking across seven runtimes.

Java runtime changes keep parameterized driver execution and original typed values while making the default operator SQL log field-aware. Missing policy metadata in an old generated descriptor fails closed as UNKNOWN; newly generated descriptors explicitly declare even an empty mask list. Credentials remain redacted under the exact debug acknowledgement.

Evidence for this Java PR head 4db5fdd (test-only successor to published internal candidate source 2f49983):

  • Source masking/conformance tests and GitHub CI (build, examples, PostgreSQL/MySQL and SQL Server jobs) pass.
  • Internal Maven candidate 1.552-mask20260928.6 was built from predecessor 2f49983. 39 modules / 77 POM+JAR artifacts were checked against Registry downloads byte-for-byte; an isolated Maven consumer passed the old-metadata regression.
  • Current generated PostgreSQL and MySQL workspaces consumed .6 and passed live generated Q, audited mutation, original result values, default masked SQL and ordinary-field visibility. Dedicated test databases were removed.
  • The older Pet Store migration evidence is a regenerated-library/application migration, not proof that an unchanged old Java workspace works after only a dependency bump.
  • Official OpenTelemetry failure canary regression passes: driver error text stays out of exported span/log records.

Canonical evidence: release gate and exact Java .6 candidate.

Remaining: final untested output-path review, online generator rollout, old-workspace migration scope, main merge and public Maven publication. This PR remains draft; the internal candidate is not a public release.

Update 2026-09-29 — current draft HEAD 00957ab: Java module tests pass; a throwing RuntimeLogSink no longer turns diagnostic recording into a business failure. The previous internal candidate was built from an earlier source commit and does not contain this production fix; rebuild and rerun the internal Registry candidate gate before treating current HEAD as release-qualified. Seven-language source gate: 7/7 PASS. Fail-open evidence.

Update 2026-09-29 — current HEAD 00957ab is now built as internal Maven candidate 1.552-mask20260929.7. All 72 deployed JARs match Registry downloads byte-for-byte. An independent Maven consumer with a fresh local repository ran the public recordExecutionMetadata path: a throwing ordinary sink did not abort the call, and the canary did not enter the ordinary log projection. This supersedes the prior note that the current fix lacked an internal candidate. Latest generated PostgreSQL/MySQL workspace and live-provider replays are still required for .7; prior .6 results do not transfer. Evidence: https://github.com/teaql/teaql-conformance/blob/docs/masking-release-gate-20260928/2026-09/202609290205-java-v7-fail-open-internal-candidate.md

Update 2026-09-29 — existing generated PostgreSQL workspace upgraded to current .7 candidate passed real Q, audited Create, original-value readback and masked SQL (2 masked entries), with unchanged generated metadata source. The dedicated database was deleted after verification. This is an upgrade replay, not a fresh generator-output gate. Evidence: https://github.com/teaql/teaql-conformance/blob/docs/masking-release-gate-20260928/2026-09/202609290245-java-go-v7-existing-generated-postgres.md

Update 2026-09-29 — current .7 candidate now also passes a retained real PostgreSQL throwing RuntimeLogSink probe in the existing-generated workspace. The sink throws for each SQL record, but generated audited Save/Q succeed; the sink was called at least twice during the probe and ordinary DebugQuery/Parameters did not contain the credential canary. Dedicated test database removed. Evidence: https://github.com/teaql/teaql-conformance/blob/docs/masking-release-gate-20260928/2026-09/202609290245-java-go-v7-existing-generated-postgres.md

@philipgreat

Copy link
Copy Markdown
Contributor Author

Pre-merge conformance update:

  • The branch is cleanly ahead of main with no missing main commits.
  • All checks currently attached to this PR are green.
  • The seven-runtime source gate passes 7/7.
  • Fresh generated consumers for both displayName and display-name aliases pass SQLite Q, audited Mutation and masked-log replay across all seven languages.
  • The merged generator is deployed publicly and its seven-language × 10-action Assist digest gate passes 70/70.
  • HANA was not started; this is a source/main integration gate, not a public package release or HANA live-provider claim.

Canonical cross-language evidence:
https://github.com/teaql/teaql-conformance/blob/docs/masking-release-gate-20260928/2026-09/20260929-seven-language-combined-mask-consumers.md

@philipgreat
philipgreat marked this pull request as ready for review September 29, 2026 03:56
@philipgreat
philipgreat merged commit be25152 into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant