TanStack

Content temporarily unavailable

PR #2079: alias scope review at ad5e0108b

This audit evaluates the ten source-order claims in the external review of ad5e0108be85d221d4061a303da8fac47ce2d312. The repair is a follow-up diff on that head. The authority is packages/db/src/query/live/ARCHITECTURE.md §Identity and law 1: aliases are lexical, captured references retain their source, and compilation addresses Collection inputs by SourceId. The primary executable owner is packages/db/tests/query/includes-alias-shadowing-oracle.test.ts; the generated scope campaign is includes-oracle.property.test.ts.

Law, experiment, inference

Law and authorityWhat the owner previously provedDecisive experimentInference and repair
A captured source and a child source remain distinct under ancestor shadowing (§Identity, law 1; items 01–05).Existing direct, QueryRef, union, grouping, and spread cases covered selected placements, but did not combine an inner FROM alias with a later outer join, merge a joined QueryRef's inherited parent context beside a same-named local child, combine two same-name spreads, spread a grandparent's whole row, or select a captured alias directly.At the public live Collection row after preload, the original implementation returned zero rows for an eager self-join, lost the child's title in a joined include, dropped parent spread fields, and read a child's row for direct parent selection. Renamed controls distinguished name collisions from ordinary joins. An adjacent unmatched LEFT join read the parent ID as the missing joined ID.The missing dimensions were sibling source placement, matched and unmatched joined sides, simultaneous spread keys, whole-alias depth, and direct alias selection. The repair resolves the lazy source by ID, retains the local row when joining inherited context and clears a missing joined alias, makes temporary spread keys unique, collects binding-bearing whole-row refs, and lowers direct alias selection to its expression.
A keyed lazy demand reaches the exact lexical Collection source (§Identity and law 12; item 06).The prior finite demand cases covered direct and wrapped includes, but not the outer join's self-join target with an inner source of the same alias and Collection.The eager self-join was RED at the first public row. Replacing exact source resolution with the old recursive alias search in a temporary hostile mutant made that same assertion fail; the renamed control passed.Alias text selected the inner source before the outer joined source. The target now follows a binding-aware ref to a SourceId. Other lazy join topologies remain an owner gap.
An include cannot reuse one builder's source declaration across ancestor and descendant scopes (§Identity, law 1; item 10).Existing direct, QueryRef, union, and nested-include rejection cells exercise this rule; sibling reuse remains legal.The reported new Query().from({ x: base }) still embeds base and its ancestor source declaration, so it must reject.The guard is correct under the approved API rule. Error 233 now says to start the child from the Collection rather than pass the ancestor builder.

The new finite model joins plain source rows by role and applies ordinary object spread order. It does not use binding IDs, alias maps, compiler metadata, or the optimizer to predict rows. The driver builds public Query plans, preloads live Collections, and compares values and multiplicity at initial publication and the named source writes. The self-join crosses eager and controlled on-demand sync; the joined child and spread cases have a renamed control. The direct alias case crosses shadowed and renamed children. These are bounded witnesses, not a claim that every alias-scope path is closed.

The original implementation's public-row failures were captured before the production edits in /private/tmp/pr2079-selfjoin.log, /private/tmp/pr2079-join-red2.log, and /private/tmp/pr2079-red2.log. The first merge repair still failed the adjacent unmatched LEFT join's initial public-row comparison: joinedId was 1 instead of undefined. Clearing the absent joined alias passed initial, insertion, and deletion checkpoints. The source-ID hostile mutant failed the eager self-join public-row assertion in /private/tmp/pr2079-alias-mutant.log. The review's particular on-demand self-join failure did not reproduce with the finite source adapter: the on-demand cell passed before and after the repair. This does not refute a different provider schedule.

Lossless review ledger

The source review labels two items “7”; IDs 07 and 08 below preserve their source order.

IDClaim and technical verdictPR actionDurable value and destination
01Inner FROM/outer JOIN alias reuse returns empty rows. Confirmed for the eager public path; the claimed on-demand failure was not reproduced with this controlled adapter. The flat alias maps are a plausible mechanism, but the demonstrated wrong target was recursive alias lookup.Fixed-now for the reproduced topology using exact source resolution. No general alias-scope closure claim.Self-join and renamed controls, eager/on-demand cells, source write: primary alias oracle. Other join-subquery and provider schedules: coverage map.
02Joined parent context overwrites a same-name local child. Confirmed at the initial row; a renamed child passed. An unmatched LEFT join exposed the inverse error: the parent ID appeared as the absent joined ID.Fixed-now by preserving local main-row aliases, adding the actual joined source, and clearing it when absent.Child title after preload and update; missing/present/missing joined side: primary alias oracle.
03Captured and local spread sentinels collide. Confirmed at the first child row; a renamed child passed.Fixed-now using unique temporary keys and deterministic select-local rekeying.Both fields after parent/child writes and repeated-build identity: primary alias oracle.
04Grandchild whole-row spread loses a grandparent. Confirmed at the first public row.Fixed-now by collecting binding-bearing single-segment external refs.Grandparent row after preload and update: primary alias oracle.
05Direct .select(() => capturedParent) reads the child. Confirmed under shadowing; renamed child returned missing data.Fixed-now by retaining the captured expression under the spread sentinel.Shadowed/renamed initial and post-write rows: primary alias oracle.
06Lazy target search can choose the nested source by alias text. Confirmed as the wrong target behind 01's eager trace. The broad claim about all subscription shapes is unproved.Fixed-now for this target path with binding-aware traversal and exact SourceId.Primary alias oracle and lazy-target unit; other lazy topologies: coverage map.
07A user-declared pure wrapper is retained and costs another stage. Structurally true.Accepted-design for now: flattening its distinct binding would violate the approved identity rule; no binding-preserving flattening design is established.The wrapper identity cell remains in the primary oracle. A future optimizer design must prove both identity and work.
08Local refs perform parent-context metadata checks per row. Confirmed by the compiled closure and the earlier two-row/two-ref spy (four lookups); no elapsed-time or throughput conclusion follows.Design-decision: whether a compile-time local/parent split earns its code and compatibility cost needs a work target. No correctness law is violated.Performance opportunity in this record; compiler/evaluators.ts is the implementation owner.
09Full-tree cache comparison and function-form misses. Confirmed: a temporary same-source work probe recorded two compiled entries for a shared structured child and three for the same child with fnWhere (including the outer query). The existing cache comparison test shows function-form plans return false.Design-decision: whether to add an identity-safe function-form equivalence and how to bound comparison work. Reusing plans by path alone previously conflated lexical bindings.Cache tests and compiler/query-equivalence.ts; preserve this work count before changing equivalence.
10A fresh wrapper around an ancestor builder is rejected. Refuted as a product bug by the explicit ancestor/descendant source-declaration rule. The old error wording was misleading.Accepted-design for the guard; fixed-now for error 233's instruction.Existing rejection oracle and updated error fixture/docs.

Items 07–09 are work observations. No elapsed-time contract was inferred from them, and none justifies weakening source identity or cache equivalence.

Oracle guide audit

  • ORC-001: The architecture's lexical-binding and source-ID rules authorize the expected rows and demand target. The owner comments and this record bound the finite histories and excluded paths.
  • ORC-002: Expected rows come from plain source-role joins and JavaScript spread order, independent of the compiler's alias and binding machinery.
  • ORC-003: The executable owner states the law before mechanics and places the model, legal axes, public driver, and checkpoint explanations beside the tests. The new lazy-target unit is supporting code, not a second oracle.
  • ORC-004: The new cells are a finite matrix, not a new generated property. The eager/on-demand and shadowed/renamed controls ablate source mode and alias collision. The source IDs, two-level and three-level nesting, and initial/post-write cuts bound range. Same-scope duplicate aliases remain invalid in the existing validation owner. The unchanged generated campaign retains its own reconstruction, ablation, range, and exclusion audit.
  • ORC-005: createLiveQueryCollection and public toArray reach the claimed paths. Row comparisons preserve missing values and multiplicity; the lazy demand owner also compares provider requests.
  • ORC-006: The original implementation failed the new first-row comparisons for 01–05. The alias-only hostile mutant failed 01's public-row assertion, not a setup or timeout gate. No mutant is claimed for every additional topology.
  • ORC-007: The new cells are finite, so fixed/random campaign and replay obligations do not trigger for them. The existing generated owner still runs its fixed and random scope campaign.
  • ORC-008: The new models recompute from plain Maps or fixed rows; they do not add a stateful reference machine.
  • ORC-009: “Parent,” “child,” “manager,” and “joined source” denote source roles. Model rows do not encode production binding IDs or SourceId; those identify the production source implementing each role.
  • ORC-010: withHistoryCleanup retains the primary mismatch and cleans live queries and Collections. The RED evidence is assertion failure at the stated row cut. The tests do not shrink histories.
  • ORC-011: No named model/production shared semantic classifier remains: the role model never resolves aliases. Renamed-query controls add a separate metamorphic comparison, but do not replace the plain row model.
  • ORC-012: This exact-head record provides each applicable outcome and the non-applicable trigger reasons. It claims bounded repairs, not closure of the entire alias-scope class.
  • ORC-013: Shadowed and renamed controls distinguish lexical role from alias text; the alias-only mutant proves the public comparison detects the wrong boundary on the eager self-join. The on-demand schedule claim remains bounded to the controlled fixture.
  • ORC-014: Controlled on-demand sources establish this adapter's preload and write cuts only. A real-provider receiving witness for the review's on-demand schedule remains with the alias-scope coverage owner.

Remaining boundary

The covered contract × history × path × observation is lexical source identity for the finite self-join, joined include, two-spread, grandchild spread, and direct-alias selection histories at their public-row cuts, plus exact source-ID lazy targeting for the eager self-join. The coverage map retains arbitrary join-subquery topologies, deeper captured refs, RIGHT/FULL joins, temporal demand, and real-provider scheduling. Flat alias-keyed metadata remains in the compiler; the tested lazy path no longer relies on its alias-only target search. This record does not claim that every remaining metadata consumer is safe.

The reviewer found five real public-row errors and a related source-target error, with small distinguishing examples. That is high technical signal. The broad attribution to flat alias maps was incomplete, the on-demand claim was not reproduced in this fixture, and item 10's proposed guard removal conflicts with the approved contract. The performance items correctly identify work but do not establish a performance budget or safe replacement.

For reviewer quality, this is a hire recommendation: the review found several distinct public failures that the existing suite missed and supplied useful renamed controls. The reviewer should check approved API rules before proposing guard removal, and use work counts rather than timing claims for performance findings.

Verification of the repair diff

  • The bounded alias and lazy-target suite passed after the unmatched-join addition. The complete query runtime run passed 108 files and 4,490 tests with Vitest's integrated type check disabled; the separate TypeScript project check passed. The earlier integrated run passed 4,717 test assertions but could not write Vitest's temporary type-build file through a read-only dependency symlink. This is a tool-location failure, not an assertion failure.
  • The production error-message oracle passed 19 tests. The generated error-doc check, ESLint, Prettier, and git diff --check passed.
  • The final source simplification and unmatched-join fix were followed by the full query run above. The temporary cache work probe was removed; it is evidence of work, not a permanent performance law.