[finding] the sharing-rule seeder discards compileCelToFilter's reason: a skipped rule logs the fact without the why #13943

Description

@claude

Measured while implementing the observability half of #13639 (PR #13942), which repaired the same shape one seam over. Filed unassigned; no severity asserted, routing is triage's.

Measured, at 577e49e00

compileCelToFilter returns a discriminated result — { ok: false, reason, detail } — where detail names the concrete fault: the CEL shape that would not lower, the current_user.* path that did not resolve, the parse bound that was overrun. celToFilter in the sharing seeder collapses the whole thing to null:

// packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:131exportfunctioncelToFilter(cel: unknown): Record<string,unknown>|null{constresult=compileCelToFilter(celasstring|{source?: string},{variables: {}});returnresult.ok ? (result.filterasRecord<string,unknown>) : null;}

Its one caller then logs the fact without the reason:

// same file, ~line 202logger?.warn?.('[sharing-rule] skipped (missing or untranslatable CEL condition — never seeded as match-all) [experimental]',{rule: r.name,condition: r.condition});

So an operator whose declared sharing rule is silently not granting learns that the condition did not translate, and gets the source text back, but not which part of it the compiler refused or why — the one fact that ends the search, computed and discarded one line earlier.

The !ok consumer census this came from

Every non-test call site of the compile-result family (compileCelToFilter, isPushdownableCel, lowerCelAst), excluding dist/, comments and the defining module:

call sitereads reasonreads detail
packages/plugins/plugin-security/src/rls-compiler.ts✅ (PR #13942)✅ (PR #13942)
packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:132
packages/formula/src/rls-predicate.ts:59 (isSupportedRlsExpression)
packages/lint/scripts/check-doc-formula-expressions.mjs:962
packages/lint/src/validate-rls-predicate-enforceability.ts:283
packages/lint/src/validate-sharing-rule-enforceability.ts:438

Reverse control: the last two rows are what makes the zeroes readable — the same scan that reports celToFilter as discarding finds two consumers that carry detail into user-facing text, so "discards" is a reading, not a blind spot.

Why this is materially LESS severe than #13639, and what is left open

⛔ Not established here: whether any deployment has actually been bitten, and whether the seeder's WARN should carry reason, detail, or both. What is measured is that the information exists at the call site and is dropped.

Related

#13639 / PR #13942 (the same shape in plugin-security/rls-compiler.ts, repaired) · ADR-0058 D1 (compileCelToFilter is the one canonical lowering) · ADR-0049 (an unlowerable condition is never seeded as a permissive match-all — that half is correct and unchanged)


Generated by Claude Code

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

    , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
     blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
    }
    } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
    })();
    (function(){
    try {
    var __m = "github.com";
    var __re = new RegExp('^' + "github\\.com" + '
    
    Skip to content

    [finding] the sharing-rule seeder discards compileCelToFilter's reason: a skipped rule logs the fact without the why #13943

    Description

    @claude

    Measured while implementing the observability half of #13639 (PR #13942), which repaired the same shape one seam over. Filed unassigned; no severity asserted, routing is triage's.

    Measured, at 577e49e00

    compileCelToFilter returns a discriminated result — { ok: false, reason, detail } — where detail names the concrete fault: the CEL shape that would not lower, the current_user.* path that did not resolve, the parse bound that was overrun. celToFilter in the sharing seeder collapses the whole thing to null:

    // packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:131exportfunctioncelToFilter(cel: unknown): Record<string,unknown>|null{constresult=compileCelToFilter(celasstring|{source?: string},{variables: {}});returnresult.ok ? (result.filterasRecord<string,unknown>) : null;}

    Its one caller then logs the fact without the reason:

    // same file, ~line 202logger?.warn?.('[sharing-rule] skipped (missing or untranslatable CEL condition — never seeded as match-all) [experimental]',{rule: r.name,condition: r.condition});

    So an operator whose declared sharing rule is silently not granting learns that the condition did not translate, and gets the source text back, but not which part of it the compiler refused or why — the one fact that ends the search, computed and discarded one line earlier.

    The !ok consumer census this came from

    Every non-test call site of the compile-result family (compileCelToFilter, isPushdownableCel, lowerCelAst), excluding dist/, comments and the defining module:

    call sitereads reasonreads detail
    packages/plugins/plugin-security/src/rls-compiler.ts✅ (PR #13942)✅ (PR #13942)
    packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:132
    packages/formula/src/rls-predicate.ts:59 (isSupportedRlsExpression)
    packages/lint/scripts/check-doc-formula-expressions.mjs:962
    packages/lint/src/validate-rls-predicate-enforceability.ts:283
    packages/lint/src/validate-sharing-rule-enforceability.ts:438

    Reverse control: the last two rows are what makes the zeroes readable — the same scan that reports celToFilter as discarding finds two consumers that carry detail into user-facing text, so "discards" is a reading, not a blind spot.

    Why this is materially LESS severe than #13639, and what is left open

    ⛔ Not established here: whether any deployment has actually been bitten, and whether the seeder's WARN should carry reason, detail, or both. What is measured is that the information exists at the call site and is dropped.

    Related

    #13639 / PR #13942 (the same shape in plugin-security/rls-compiler.ts, repaired) · ADR-0058 D1 (compileCelToFilter is the one canonical lowering) · ADR-0049 (an unlowerable condition is never seeded as a permissive match-all — that half is correct and unchanged)


    Generated by Claude Code

    Metadata

    Metadata

    Assignees

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
      Skip to content

      [finding] the sharing-rule seeder discards compileCelToFilter's reason: a skipped rule logs the fact without the why #13943

      Description

      @claude

      Measured while implementing the observability half of #13639 (PR #13942), which repaired the same shape one seam over. Filed unassigned; no severity asserted, routing is triage's.

      Measured, at 577e49e00

      compileCelToFilter returns a discriminated result — { ok: false, reason, detail } — where detail names the concrete fault: the CEL shape that would not lower, the current_user.* path that did not resolve, the parse bound that was overrun. celToFilter in the sharing seeder collapses the whole thing to null:

      // packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:131exportfunctioncelToFilter(cel: unknown): Record<string,unknown>|null{constresult=compileCelToFilter(celasstring|{source?: string},{variables: {}});returnresult.ok ? (result.filterasRecord<string,unknown>) : null;}

      Its one caller then logs the fact without the reason:

      // same file, ~line 202logger?.warn?.('[sharing-rule] skipped (missing or untranslatable CEL condition — never seeded as match-all) [experimental]',{rule: r.name,condition: r.condition});

      So an operator whose declared sharing rule is silently not granting learns that the condition did not translate, and gets the source text back, but not which part of it the compiler refused or why — the one fact that ends the search, computed and discarded one line earlier.

      The !ok consumer census this came from

      Every non-test call site of the compile-result family (compileCelToFilter, isPushdownableCel, lowerCelAst), excluding dist/, comments and the defining module:

      call sitereads reasonreads detail
      packages/plugins/plugin-security/src/rls-compiler.ts✅ (PR #13942)✅ (PR #13942)
      packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:132
      packages/formula/src/rls-predicate.ts:59 (isSupportedRlsExpression)
      packages/lint/scripts/check-doc-formula-expressions.mjs:962
      packages/lint/src/validate-rls-predicate-enforceability.ts:283
      packages/lint/src/validate-sharing-rule-enforceability.ts:438

      Reverse control: the last two rows are what makes the zeroes readable — the same scan that reports celToFilter as discarding finds two consumers that carry detail into user-facing text, so "discards" is a reading, not a blind spot.

      Why this is materially LESS severe than #13639, and what is left open

      ⛔ Not established here: whether any deployment has actually been bitten, and whether the seeder's WARN should carry reason, detail, or both. What is measured is that the information exists at the call site and is dropped.

      Related

      #13639 / PR #13942 (the same shape in plugin-security/rls-compiler.ts, repaired) · ADR-0058 D1 (compileCelToFilter is the one canonical lowering) · ADR-0049 (an unlowerable condition is never seeded as a permissive match-all — that half is correct and unchanged)


      Generated by Claude Code

      Metadata

      Metadata

      Assignees

      Type

      No type

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions

        , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
        Skip to content

        [finding] the sharing-rule seeder discards compileCelToFilter's reason: a skipped rule logs the fact without the why #13943

        Description

        @claude

        Measured while implementing the observability half of #13639 (PR #13942), which repaired the same shape one seam over. Filed unassigned; no severity asserted, routing is triage's.

        Measured, at 577e49e00

        compileCelToFilter returns a discriminated result — { ok: false, reason, detail } — where detail names the concrete fault: the CEL shape that would not lower, the current_user.* path that did not resolve, the parse bound that was overrun. celToFilter in the sharing seeder collapses the whole thing to null:

        // packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:131exportfunctioncelToFilter(cel: unknown): Record<string,unknown>|null{constresult=compileCelToFilter(celasstring|{source?: string},{variables: {}});returnresult.ok ? (result.filterasRecord<string,unknown>) : null;}

        Its one caller then logs the fact without the reason:

        // same file, ~line 202logger?.warn?.('[sharing-rule] skipped (missing or untranslatable CEL condition — never seeded as match-all) [experimental]',{rule: r.name,condition: r.condition});

        So an operator whose declared sharing rule is silently not granting learns that the condition did not translate, and gets the source text back, but not which part of it the compiler refused or why — the one fact that ends the search, computed and discarded one line earlier.

        The !ok consumer census this came from

        Every non-test call site of the compile-result family (compileCelToFilter, isPushdownableCel, lowerCelAst), excluding dist/, comments and the defining module:

        call sitereads reasonreads detail
        packages/plugins/plugin-security/src/rls-compiler.ts✅ (PR #13942)✅ (PR #13942)
        packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:132
        packages/formula/src/rls-predicate.ts:59 (isSupportedRlsExpression)
        packages/lint/scripts/check-doc-formula-expressions.mjs:962
        packages/lint/src/validate-rls-predicate-enforceability.ts:283
        packages/lint/src/validate-sharing-rule-enforceability.ts:438

        Reverse control: the last two rows are what makes the zeroes readable — the same scan that reports celToFilter as discarding finds two consumers that carry detail into user-facing text, so "discards" is a reading, not a blind spot.

        Why this is materially LESS severe than #13639, and what is left open

        ⛔ Not established here: whether any deployment has actually been bitten, and whether the seeder's WARN should carry reason, detail, or both. What is measured is that the information exists at the call site and is dropped.

        Related

        #13639 / PR #13942 (the same shape in plugin-security/rls-compiler.ts, repaired) · ADR-0058 D1 (compileCelToFilter is the one canonical lowering) · ADR-0049 (an unlowerable condition is never seeded as a permissive match-all — that half is correct and unchanged)


        Generated by Claude Code

        Metadata

        Metadata

        Assignees

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
          Skip to content

          [finding] the sharing-rule seeder discards compileCelToFilter's reason: a skipped rule logs the fact without the why #13943

          Description

          @claude

          Measured while implementing the observability half of #13639 (PR #13942), which repaired the same shape one seam over. Filed unassigned; no severity asserted, routing is triage's.

          Measured, at 577e49e00

          compileCelToFilter returns a discriminated result — { ok: false, reason, detail } — where detail names the concrete fault: the CEL shape that would not lower, the current_user.* path that did not resolve, the parse bound that was overrun. celToFilter in the sharing seeder collapses the whole thing to null:

          // packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:131exportfunctioncelToFilter(cel: unknown): Record<string,unknown>|null{constresult=compileCelToFilter(celasstring|{source?: string},{variables: {}});returnresult.ok ? (result.filterasRecord<string,unknown>) : null;}

          Its one caller then logs the fact without the reason:

          // same file, ~line 202logger?.warn?.('[sharing-rule] skipped (missing or untranslatable CEL condition — never seeded as match-all) [experimental]',{rule: r.name,condition: r.condition});

          So an operator whose declared sharing rule is silently not granting learns that the condition did not translate, and gets the source text back, but not which part of it the compiler refused or why — the one fact that ends the search, computed and discarded one line earlier.

          The !ok consumer census this came from

          Every non-test call site of the compile-result family (compileCelToFilter, isPushdownableCel, lowerCelAst), excluding dist/, comments and the defining module:

          call sitereads reasonreads detail
          packages/plugins/plugin-security/src/rls-compiler.ts✅ (PR #13942)✅ (PR #13942)
          packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:132
          packages/formula/src/rls-predicate.ts:59 (isSupportedRlsExpression)
          packages/lint/scripts/check-doc-formula-expressions.mjs:962
          packages/lint/src/validate-rls-predicate-enforceability.ts:283
          packages/lint/src/validate-sharing-rule-enforceability.ts:438

          Reverse control: the last two rows are what makes the zeroes readable — the same scan that reports celToFilter as discarding finds two consumers that carry detail into user-facing text, so "discards" is a reading, not a blind spot.

          Why this is materially LESS severe than #13639, and what is left open

          ⛔ Not established here: whether any deployment has actually been bitten, and whether the seeder's WARN should carry reason, detail, or both. What is measured is that the information exists at the call site and is dropped.

          Related

          #13639 / PR #13942 (the same shape in plugin-security/rls-compiler.ts, repaired) · ADR-0058 D1 (compileCelToFilter is the one canonical lowering) · ADR-0049 (an unlowerable condition is never seeded as a permissive match-all — that half is correct and unchanged)


          Generated by Claude Code

          Metadata

          Metadata

          Assignees

          Type

          No type

          Projects

          No projects

            Milestone

            No milestone

            Relationships

            None yet

            Development

            No branches or pull requests

            Issue actions

            , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
            Skip to content

            [finding] the sharing-rule seeder discards compileCelToFilter's reason: a skipped rule logs the fact without the why #13943

            Description

            @claude

            Measured while implementing the observability half of #13639 (PR #13942), which repaired the same shape one seam over. Filed unassigned; no severity asserted, routing is triage's.

            Measured, at 577e49e00

            compileCelToFilter returns a discriminated result — { ok: false, reason, detail } — where detail names the concrete fault: the CEL shape that would not lower, the current_user.* path that did not resolve, the parse bound that was overrun. celToFilter in the sharing seeder collapses the whole thing to null:

            // packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:131exportfunctioncelToFilter(cel: unknown): Record<string,unknown>|null{constresult=compileCelToFilter(celasstring|{source?: string},{variables: {}});returnresult.ok ? (result.filterasRecord<string,unknown>) : null;}

            Its one caller then logs the fact without the reason:

            // same file, ~line 202logger?.warn?.('[sharing-rule] skipped (missing or untranslatable CEL condition — never seeded as match-all) [experimental]',{rule: r.name,condition: r.condition});

            So an operator whose declared sharing rule is silently not granting learns that the condition did not translate, and gets the source text back, but not which part of it the compiler refused or why — the one fact that ends the search, computed and discarded one line earlier.

            The !ok consumer census this came from

            Every non-test call site of the compile-result family (compileCelToFilter, isPushdownableCel, lowerCelAst), excluding dist/, comments and the defining module:

            call sitereads reasonreads detail
            packages/plugins/plugin-security/src/rls-compiler.ts✅ (PR #13942)✅ (PR #13942)
            packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:132
            packages/formula/src/rls-predicate.ts:59 (isSupportedRlsExpression)
            packages/lint/scripts/check-doc-formula-expressions.mjs:962
            packages/lint/src/validate-rls-predicate-enforceability.ts:283
            packages/lint/src/validate-sharing-rule-enforceability.ts:438

            Reverse control: the last two rows are what makes the zeroes readable — the same scan that reports celToFilter as discarding finds two consumers that carry detail into user-facing text, so "discards" is a reading, not a blind spot.

            Why this is materially LESS severe than #13639, and what is left open

            ⛔ Not established here: whether any deployment has actually been bitten, and whether the seeder's WARN should carry reason, detail, or both. What is measured is that the information exists at the call site and is dropped.

            Related

            #13639 / PR #13942 (the same shape in plugin-security/rls-compiler.ts, repaired) · ADR-0058 D1 (compileCelToFilter is the one canonical lowering) · ADR-0049 (an unlowerable condition is never seeded as a permissive match-all — that half is correct and unchanged)


            Generated by Claude Code

            Metadata

            Metadata

            Assignees

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              [finding] the sharing-rule seeder discards compileCelToFilter's reason: a skipped rule logs the fact without the why #13943

              Description

              @claude

              Measured while implementing the observability half of #13639 (PR #13942), which repaired the same shape one seam over. Filed unassigned; no severity asserted, routing is triage's.

              Measured, at 577e49e00

              compileCelToFilter returns a discriminated result — { ok: false, reason, detail } — where detail names the concrete fault: the CEL shape that would not lower, the current_user.* path that did not resolve, the parse bound that was overrun. celToFilter in the sharing seeder collapses the whole thing to null:

              // packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:131exportfunctioncelToFilter(cel: unknown): Record<string,unknown>|null{constresult=compileCelToFilter(celasstring|{source?: string},{variables: {}});returnresult.ok ? (result.filterasRecord<string,unknown>) : null;}

              Its one caller then logs the fact without the reason:

              // same file, ~line 202logger?.warn?.('[sharing-rule] skipped (missing or untranslatable CEL condition — never seeded as match-all) [experimental]',{rule: r.name,condition: r.condition});

              So an operator whose declared sharing rule is silently not granting learns that the condition did not translate, and gets the source text back, but not which part of it the compiler refused or why — the one fact that ends the search, computed and discarded one line earlier.

              The !ok consumer census this came from

              Every non-test call site of the compile-result family (compileCelToFilter, isPushdownableCel, lowerCelAst), excluding dist/, comments and the defining module:

              call sitereads reasonreads detail
              packages/plugins/plugin-security/src/rls-compiler.ts✅ (PR #13942)✅ (PR #13942)
              packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:132
              packages/formula/src/rls-predicate.ts:59 (isSupportedRlsExpression)
              packages/lint/scripts/check-doc-formula-expressions.mjs:962
              packages/lint/src/validate-rls-predicate-enforceability.ts:283
              packages/lint/src/validate-sharing-rule-enforceability.ts:438

              Reverse control: the last two rows are what makes the zeroes readable — the same scan that reports celToFilter as discarding finds two consumers that carry detail into user-facing text, so "discards" is a reading, not a blind spot.

              Why this is materially LESS severe than #13639, and what is left open

              ⛔ Not established here: whether any deployment has actually been bitten, and whether the seeder's WARN should carry reason, detail, or both. What is measured is that the information exists at the call site and is dropped.

              Related

              #13639 / PR #13942 (the same shape in plugin-security/rls-compiler.ts, repaired) · ADR-0058 D1 (compileCelToFilter is the one canonical lowering) · ADR-0049 (an unlowerable condition is never seeded as a permissive match-all — that half is correct and unchanged)


              Generated by Claude Code

              Metadata

              Metadata

              Assignees

              Type

              No type

              Projects

              No projects

                Milestone

                No milestone

                Relationships

                None yet

                Development

                No branches or pull requests

                Issue actions

                , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                Skip to content

                [finding] the sharing-rule seeder discards compileCelToFilter's reason: a skipped rule logs the fact without the why #13943

                Description

                @claude

                Measured while implementing the observability half of #13639 (PR #13942), which repaired the same shape one seam over. Filed unassigned; no severity asserted, routing is triage's.

                Measured, at 577e49e00

                compileCelToFilter returns a discriminated result — { ok: false, reason, detail } — where detail names the concrete fault: the CEL shape that would not lower, the current_user.* path that did not resolve, the parse bound that was overrun. celToFilter in the sharing seeder collapses the whole thing to null:

                // packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:131exportfunctioncelToFilter(cel: unknown): Record<string,unknown>|null{constresult=compileCelToFilter(celasstring|{source?: string},{variables: {}});returnresult.ok ? (result.filterasRecord<string,unknown>) : null;}

                Its one caller then logs the fact without the reason:

                // same file, ~line 202logger?.warn?.('[sharing-rule] skipped (missing or untranslatable CEL condition — never seeded as match-all) [experimental]',{rule: r.name,condition: r.condition});

                So an operator whose declared sharing rule is silently not granting learns that the condition did not translate, and gets the source text back, but not which part of it the compiler refused or why — the one fact that ends the search, computed and discarded one line earlier.

                The !ok consumer census this came from

                Every non-test call site of the compile-result family (compileCelToFilter, isPushdownableCel, lowerCelAst), excluding dist/, comments and the defining module:

                call sitereads reasonreads detail
                packages/plugins/plugin-security/src/rls-compiler.ts✅ (PR #13942)✅ (PR #13942)
                packages/plugins/plugin-sharing/src/bootstrap-declared-sharing-rules.ts:132
                packages/formula/src/rls-predicate.ts:59 (isSupportedRlsExpression)
                packages/lint/scripts/check-doc-formula-expressions.mjs:962
                packages/lint/src/validate-rls-predicate-enforceability.ts:283
                packages/lint/src/validate-sharing-rule-enforceability.ts:438

                Reverse control: the last two rows are what makes the zeroes readable — the same scan that reports celToFilter as discarding finds two consumers that carry detail into user-facing text, so "discards" is a reading, not a blind spot.

                Why this is materially LESS severe than #13639, and what is left open

                ⛔ Not established here: whether any deployment has actually been bitten, and whether the seeder's WARN should carry reason, detail, or both. What is measured is that the information exists at the call site and is dropped.

                Related

                #13639 / PR #13942 (the same shape in plugin-security/rls-compiler.ts, repaired) · ADR-0058 D1 (compileCelToFilter is the one canonical lowering) · ADR-0049 (an unlowerable condition is never seeded as a permissive match-all — that half is correct and unchanged)


                Generated by Claude Code

                Metadata

                Metadata

                Assignees

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions