sqlite-web 0.7.2
gitea.db
action
Create
Query
access
access_token
action
action_artifact
action_run
action_run_index
action_run_job
action_runner
action_runner_token
action_schedule
action_schedule_spec
action_task
action_task_output
action_task_step
action_tasks_version
action_variable
app_state
attachment
auth_token
badge
branch
collaboration
comment
commit_status
commit_status_index
commit_status_summary
commit_sync_log
commit_sync_status
dbfs_data
dbfs_meta
deploy_key
email_address
email_hash
external_login_user
follow
gpg_key
gpg_key_import
hook_task
issue
issue_assignees
issue_content_history
issue_dependency
issue_index
issue_label
issue_pin
issue_user
issue_watch
label
language_stat
lfs_lock
lfs_meta_object
login_source
milestone
mirror
notice
notification
oauth2_application
oauth2_authorization_code
oauth2_grant
org_user
package
package_blob
package_blob_upload
package_cleanup_rule
package_file
package_property
package_version
project
project_board
project_issue
protected_branch
protected_tag
public_key
pull_auto_merge
pull_request
push_mirror
reaction
release
renamed_branch
repo_archiver
repo_hidden_file
repo_indexer_status
repo_license
repo_redirect
repo_topic
repo_transfer
repo_unit
repository
review
review_state
secret
session
sqlite_sequence
star
stopwatch
system_setting
task
team
team_invite
team_repo
team_unit
team_user
topic
tracked_time
two_factor
upload
user
user_badge
user_blocking
user_open_id
user_redirect
user_setting
version
watch
webauthn_credential
webhook
Toggle helper tables
Structure
Content
Query
Insert
Drop
Import
Export
Update row 33310 in action
id
Primary key.
INTEGER NOT NULL
user_id
INTEGER
op_type
INTEGER
act_user_id
INTEGER
repo_id
INTEGER
comment_id
INTEGER
is_deleted
INTEGER NOT NULL (default 0
ref_name
refs/heads/main
TEXT
is_private
INTEGER NOT NULL (default 0
content
{"Commits":[{"Sha1":"7d146c8223362cf5c810735820885bfab3a52e17","Message":"chore(release): 0.103.1 — canonical UUID identity and the Trigger target under the Work role\n\nVersion, catalog revision, README, roadmap and runbook entries for the two fixes in the previous commits (Trigger\nCase / Task target under the Work role with database faults mapped to stable rejections; lowercase canonical UUID\nidentity with sameId comparisons). No SQL migration. Isolated PostgreSQL 16, restricted erk_app, full check: 212 tests,\n209 pass, 0 fail, 3 conditional skips; static gates green. Nothing deployed by this commit.\n\nCo-Authored-By: Claude Sonnet 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-29T02:09:37-07:00"},{"Sha1":"a64323c194523cb08d30023793f071c0814299c5","Message":"fix(identity): canonical lowercase UUID identity at the command boundary; compare identities with sameId\n\nA UUID spelled in another letter case is the same identity, but the kernel compared actor / principal / owner ids\nas raw strings. The independence guards (self-approval, independent review, one vote per approver, blocker and\ndependency waiver independence, creator / owner checks) therefore treated the same person written in another case as\n\"another person\" and let the action through. Reproduced on 0.103.0: with an uppercase spelling, a Case lesson could be\nreviewed by its author and an independent-review requirement was not enforced (test/kernel.integration.test.js and\nnine other integration tests now fail on 0.103.0 for exactly this reason).\n\nFix:\n- kernel/guards.js: canonicalId / sameId / includesId / canonicalActor. Non-UUID strings (tenant slugs, refs, the '*'\n scope) keep exact comparison; a missing value is never an identity.\n- kernel/canonical-envelope.js: the envelope ids (commandId, correlationId, causationId, actor, principal,\n delegationRef) and every payload position the field contract declares as uuid ($ref #/definitions/uuid, 163\n positions, none declared any other way) are lowercased on entry. The plan is compiled from the contract at import\n and refuses schema constructs that could hide a UUID. Free text, evidence and external references are not touched.\n- kernel/unit-of-work.js: canonicalize first, so validation, request digest, advisory lock, receipts and events see one\n spelling. A receipt written before this change (digest over the caller's original spelling) still matches a\n byte-identical retry instead of turning into IDEMPOTENCY_CONFLICT.\n- auth.js / http.js / tool-gateway.js: tokens carry and yield canonical identity (old uppercase tokens still verify);\n ACTOR_MISMATCH and tool-invocation ownership compare with sameId.\n- contexts and kernel.js: every identity comparison uses sameId / includesId (also the dependency self-loop check);\n the one SQL comparison on a payload string uses lower(). test/identity-canonical.test.js rejects a raw ===/!== on\n actor / principal ids anywhere in src/.\n\nCompatibility: no SQL migration, no grant change; the previous binary keeps working on the same database and the\nchange can be reverted freely (reverting restores the bypass). Historical rows keep the spelling they were stored\nwith.\n\nProvenance: the work was found uncommitted in a parallel worktree (base 0.94.1, 27 files); it applied to 0.103.0\nwithout conflicts and was reviewed hunk by hunk, then re-verified here.\n\nVerification (PostgreSQL 16, throwaway container, migrations 001-095 as owner, tests as restricted erk_app,\nTEST/MIGRATION/DATABASE_URL on one database):\n- Full suite with the trigger fix: 212 tests, 209 pass, 0 fail, 3 skipped (the same three conditional skips as\n 0.103.0, which has 171 tests, 168 pass).\n- The 15 new or changed test files all fail on unfixed 0.103.0 (real assertions, e.g. a missing\n INDEPENDENT_REVIEW_REQUIRED rejection) and pass with the fix.\n- A schema scan finds no UUID-shaped constraint outside #/definitions/uuid, so the canonicalizer covers every\n payload UUID field, including those added after 0.94.1.\n- Live signed HTTP on a candidate server: an uppercase spelling of the token's actor is accepted, a different actor is\n still ACTOR_MISMATCH (403), a retry with an uppercase commandId returns the first receipt.\n- Read-only history and role gates on the test database: db-roles, cross-refs, task / core / all events, audit chain,\n partition gates, schedule / trigger histories, external SalesOrder history: exit 0. check:integration-events reports\n one OPEN delivery incident there; the unfixed 0.103.0 database after its own test run reports the same, it is left\n behind by the delivery-incident tests.\nNot verified: a real identity provider's token casing (K4.3b / P2.3a), the backup/restore drill, the live service.\n\nCo-Authored-By: Claude Sonnet 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-29T02:07:29-07:00"},{"Sha1":"131dd90de18f6926cbdd6ad41db62761ca105200","Message":"fix(trigger): run the Trigger's Work target under the Work role\n\nFireTrigger runs under the erk_shared owner role and executed CreateTask\n(and OpenCase / TriageCase / AssignCaseOwner) in that same role. A task\ntemplate carrying `schedule` (INSERT work.task_schedule_revision) or\n`evaluationDefinitionVersionId` (SELECT ... FOR SHARE on\noutcome.evaluation_definition, which needs UPDATE) hit SQLSTATE 42501.\nThat is not a DomainError, so HTTP returned 500, shared.command_rejection\ngot no row, and the TriggerInstance stayed AUTHORIZED (retryable, always\nfailing) until it expired. Reproduced on 0.92.0 over signed HTTP: the\nplain template returned 200, the schedule and evaluation templates 500.\n\nFix: option (b), no new cross-owner write.\n\n- UnitOfWork.runAsOwner(ctx, owner, step) runs a step under that Owner's\n role, with exactly the privileges of the Owner's standalone command, and\n restores the caller's role. FireTrigger runs its Case/Task target\n (requireCaseOwner, OpenCase, TriageCase, AssignCaseOwner, CreateTask and\n the correlation update) inside it; policy checks, the trigger_instance\n update and TriggerFired stay in the Trigger's own role. It is the only\n handler that invokes another Owner's commands.\n- Why not option (a): the ledger is a shrink-only debt list. It would add\n shared -\u003e work.task_schedule_revision and shared -\u003e\n outcome.evaluation_definition, and the latter needs UPDATE for FOR SHARE,\n i.e. write access to another Owner's definition table. It would also\n break again for every future CreateTask feature until yet another\n exception is registered. With (b) both stay unregistered.\n\nDatabase faults inside a handler are now rejections, not 500s:\n\n- 42501 -\u003e DB_PERMISSION_DENIED (403), 22xxx -\u003e DB_DATA_EXCEPTION (400),\n 23xxx -\u003e DB_INTEGRITY_VIOLATION (409). They take the existing in-\n transaction rejection path: guard HANDLER, one command_rejection row, all\n handler writes and events rolled back, no receipt, same commandId\n retryable. 42501 is a kernel role-model defect rather than a lack of\n caller authority, so it gets its own code, distinct from\n AUTHORITY_DENIED.\n- The message carries the SQLSTATE only (driver text can echo submitted\n values or key data). The driver error stays in DomainError.cause and the\n HTTP handler logs it, so mapping does not hide a kernel fault from\n operators. Only the handler's own errors are translated; receipt write,\n replay and every other SQLSTATE (connection, deadlock, undefined object,\n ...) remain 500. A NUL byte in a submitted title, previously a 500 from\n 22021, is now a 400.\n\nCompatibility: no SQL migration and no grant or ledger change, so the\nprevious binary keeps working on the same database and this change can be\nreverted freely. Isolated-database evidence: with erk_shared stripped of\nevery write on work.case_record and of INSERT on work.task, all\ntrigger tests still pass; only STATE-trigger FOR SHARE needs UPDATE on\nwork.task. shared -\u003e work.case_record is therefore unused and shared -\u003e\nwork.task can shrink to UPDATE. Both are left as they are here, because\ngrants follow the migrate-time ledger and narrowing them together with the\ncode would make a rollback fail with 42501; shrink them after this is\ndeployed (K4.1).\n\nVerification (PostgreSQL 16.15, throwaway container, migrations 001-085 as\nowner, tests as restricted erk_app, TEST/MIGRATION/DATABASE_URL on one\ndatabase):\n- New tests fail before the change (42501 from CreateTask) and pass after;\n mutation runs (no translation, no role switch, no restore, restore\n masking the original error, widened ledger without role switch) each\n turn the matching test red.\n- pnpm check (final tree): exit 0, 151 tests, 149 pass, 0 fail, 2 skipped\n (the monthly-shadow test, skipped in code since the 083 cutover, and the\n backup/restore drill, which needs a second cluster).\n- check:db-roles (34 exceptions, unchanged), check:all-events,\n check:integration-events, check:cross-refs, check:audit-chain, task /\n core events and the four trigger history checks: all exit 0.\n- Signed-HTTP smokes on a candidate server: smoke:trigger, trigger-incident,\n trigger-correlation, human-trigger, state-trigger, time-trigger,\n schedule-trigger, trigger-condition: all passed.\nNot verified: the backup/restore drill (needs a second cluster) and the live\nlocal service; nothing was deployed.\n\nCo-Authored-By: Claude Sonnet 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-28T20:58:02-07:00"}],"HeadCommit":{"Sha1":"7d146c8223362cf5c810735820885bfab3a52e17","Message":"chore(release): 0.103.1 — canonical UUID identity and the Trigger target under the Work role\n\nVersion, catalog revision, README, roadmap and runbook entries for the two fixes in the previous commits (Trigger\nCase / Task target under the Work role with database faults mapped to stable rejections; lowercase canonical UUID\nidentity with sameId comparisons). No SQL migration. Isolated PostgreSQL 16, restricted erk_app, full check: 212 tests,\n209 pass, 0 fail, 3 conditional skips; static gates green. Nothing deployed by this commit.\n\nCo-Authored-By: Claude Sonnet 5.5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-29T02:09:37-07:00"},"CompareURL":"luoanwu/seven-domain-five-dimension-unified-model/compare/69bbce20907cf89f2a1fd58b7937d66d48e15520...7d146c8223362cf5c810735820885bfab3a52e17","Len":3}
TEXT
created_unix
INTEGER
Update
Cancel