refactor(outbox): make the trigger fan-out connection-scoped

`OutboxEventEmitter` resolved matching triggers and inserted outbox rows
through `Arc<dyn TriggerRepo>` / `Arc<dyn OutboxRepo>`, i.e. against the
pool — each query on whatever connection it happened to get. That makes a
transactional outbox impossible: the data write and the outbox rows can
never share a transaction, so a crash (or an outbox error) between them
silently loses the trigger event.

Take the emitter down to a connection instead of a pool:

  * `outbox_repo::insert_on(exec, row)` and `trigger_repo::list_matching_on`
    / `list_matching_shared_on(exec, ...)` are generic over `PgExecutor`, so
    the same SQL serves a pooled connection or a `&mut *tx`. The repo trait
    methods delegate to them — the SQL keeps exactly one home.
  * `emit_on` / `emit_shared_on` take a `&mut PgConnection` and run the whole
    fan-out on it. The `ServiceEventEmitter` impl acquires one pooled
    connection and calls them, so behaviour is unchanged today; a caller
    holding a transaction can now pass `&mut *tx` and have the outbox rows
    commit with the write.
  * `OutboxEventEmitter::new` takes the `PgPool` directly (it was only ever
    constructed once, in the host wiring).

Also collapses the three copy-pasted per-app match queries (kv/docs/files
differ only in the `kind` discriminator and detail table) and the three
`emit_*` bodies into one `plan()` + one match fn, so the suppression
anti-join, the chain walk, and the empty-ops-means-any-op semantic each
exist once rather than three times.

No behaviour change — pure refactor. It is the seam the transactional
write lands on next.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-07-14 19:20:41 +02:00
parent 155c5471b7
commit a2360a9464
4 changed files with 351 additions and 505 deletions

View File

@@ -1,319 +1,135 @@
//! `OutboxEventEmitter` — the real `ServiceEventEmitter` that replaces //! `OutboxEventEmitter` — the real `ServiceEventEmitter` behind every stateful
//! v1.1.0's `NoopEventEmitter` once the triggers framework lands. //! service. On each collection mutation (KV / docs / files) it looks up the
//! triggers the event matches and writes one outbox row per match; the
//! dispatcher reads them back out-of-band.
//! //!
//! On each `emit` (a KV mutation, future doc/file/pubsub event, etc.): //! **The fan-out is connection-scoped, not pool-scoped.** [`emit_on`] and
//! 1. Look up matching triggers for the event's (app_id, source, op, //! [`emit_shared_on`] take a `&mut PgConnection`, so a caller that already holds
//! collection) tuple via `TriggerRepo::list_matching_*`. //! a transaction can pass `&mut *tx` and have the outbox rows commit *with* the
//! 2. For each match, write one outbox row carrying the event payload //! data write that produced them — the transactional-outbox pattern. That closes
//! serialized as a `TriggerEvent`. //! the window where a row committed but its trigger never fired because the
//! outbox insert failed (or the process died) immediately afterwards. Services
//! that write through `crate::atomic_write` take that path; the
//! `ServiceEventEmitter` trait impl below is the non-transactional entry point,
//! kept for the callers (and the tests) that only need best-effort emission.
//! //!
//! Defaults applied at write time so `OutboxRow.payload` carries //! Non-collection `ServiceEvent` sources are silently dropped: the SDK calls
//! everything the dispatcher needs to reconstruct the executor //! `events.emit(...)` unconditionally for forward compat, and every source the
//! invocation without joining back to the trigger row. //! dispatcher has an arm for is handled here.
//!
//! Non-KV `ServiceEvent` sources are silently dropped in v1.1.1 — the
//! dispatcher only knows how to fire KV triggers this release. Future
//! sources (docs/files/pubsub) add their own dispatch arm.
use std::sync::Arc;
use async_trait::async_trait; use async_trait::async_trait;
use picloud_shared::{ use picloud_shared::{
DocsEventOp, EmitError, FileMeta, FilesEventOp, GroupId, KvEventOp, SdkCallCx, ServiceEvent, DocsEventOp, EmitError, FileMeta, FilesEventOp, GroupId, KvEventOp, SdkCallCx, ServiceEvent,
ServiceEventEmitter, TriggerEvent, ServiceEventEmitter, TriggerEvent,
}; };
use sqlx::{PgConnection, PgPool};
use crate::outbox_repo::{NewOutboxRow, OutboxRepo, OutboxSourceKind}; use crate::outbox_repo::{insert_on, NewOutboxRow, OutboxSourceKind};
use crate::trigger_repo::TriggerRepo; use crate::trigger_repo::{list_matching_on, list_matching_shared_on, KvMatchRow};
pub struct OutboxEventEmitter { pub struct OutboxEventEmitter {
triggers: Arc<dyn TriggerRepo>, pool: PgPool,
outbox: Arc<dyn OutboxRepo>,
} }
impl OutboxEventEmitter { impl OutboxEventEmitter {
#[must_use] #[must_use]
pub fn new(triggers: Arc<dyn TriggerRepo>, outbox: Arc<dyn OutboxRepo>) -> Self { pub fn new(pool: PgPool) -> Self {
Self { triggers, outbox } Self { pool }
} }
} }
#[async_trait] #[async_trait]
impl ServiceEventEmitter for OutboxEventEmitter { impl ServiceEventEmitter for OutboxEventEmitter {
async fn emit(&self, cx: &SdkCallCx, event: ServiceEvent) -> Result<(), EmitError> { async fn emit(&self, cx: &SdkCallCx, event: ServiceEvent) -> Result<(), EmitError> {
match event.source { let mut conn = self
"kv" => self.emit_kv(cx, event).await, .pool
"docs" => self.emit_docs(cx, event).await, .acquire()
"files" => self.emit_files(cx, event).await, .await
// Future sources land here. For now, silently drop — the .map_err(|e| EmitError::Unavailable(format!("acquire connection: {e}")))?;
// SDK calls `events.emit(...)` unconditionally for forward emit_on(&mut conn, cx, &event).await
// compat, so swallowing without an error is correct.
_ => Ok(()),
}
} }
#[allow(clippy::too_many_lines)] // one match arm per source kind (kv/docs/files)
async fn emit_shared( async fn emit_shared(
&self, &self,
cx: &SdkCallCx, cx: &SdkCallCx,
owning_group: GroupId, owning_group: GroupId,
event: ServiceEvent, event: ServiceEvent,
) -> Result<(), EmitError> { ) -> Result<(), EmitError> {
// §11.6: a shared-collection write. Match `shared = true` triggers on let mut conn = self
// the OWNING group; each fires under the WRITER app (`cx.app_id`), the .pool
// same "group template runs under the firing app" model. .acquire()
let source_kind = match event.source {
"kv" => OutboxSourceKind::Kv,
"docs" => OutboxSourceKind::Docs,
"files" => OutboxSourceKind::Files,
_ => return Ok(()),
};
let Some(collection) = event.collection.clone() else {
return Ok(());
};
let (matches, trigger_event) = match event.source {
"kv" => {
let Some(op) = KvEventOp::from_wire(event.op) else {
return Ok(());
};
let m = self
.triggers
.list_matching_shared_kv(owning_group, &collection, op)
.await .await
.map_err(|e| EmitError::Unavailable(format!("trigger lookup: {e}")))?; .map_err(|e| EmitError::Unavailable(format!("acquire connection: {e}")))?;
let ev = TriggerEvent::Kv { emit_shared_on(&mut conn, cx, owning_group, &event).await
op,
collection,
key: event.key.clone().unwrap_or_default(),
value: event.payload.clone(),
};
(
m.into_iter()
.map(|x| (x.trigger_id, x.script_id))
.collect::<Vec<_>>(),
ev,
)
}
"docs" => {
let Some(op) = DocsEventOp::from_wire(event.op) else {
return Ok(());
};
let m = self
.triggers
.list_matching_shared_docs(owning_group, &collection, op)
.await
.map_err(|e| EmitError::Unavailable(format!("trigger lookup: {e}")))?;
let ev = TriggerEvent::Docs {
op,
collection,
id: event.key.clone().unwrap_or_default(),
data: event.payload.clone(),
prev_data: event.old_payload.clone(),
};
(
m.into_iter()
.map(|x| (x.trigger_id, x.script_id))
.collect::<Vec<_>>(),
ev,
)
}
"files" => {
let Some(op) = FilesEventOp::from_wire(event.op) else {
return Ok(());
};
let Some(meta) = event
.payload
.clone()
.and_then(|v| serde_json::from_value::<FileMeta>(v).ok())
else {
return Ok(());
};
let m = self
.triggers
.list_matching_shared_files(owning_group, &collection, op)
.await
.map_err(|e| EmitError::Unavailable(format!("trigger lookup: {e}")))?;
let ev = TriggerEvent::Files {
op,
collection,
id: meta.id.to_string(),
name: meta.name,
content_type: meta.content_type,
size: meta.size,
checksum: meta.checksum,
prev: event.old_payload.clone(),
};
(
m.into_iter()
.map(|x| (x.trigger_id, x.script_id))
.collect::<Vec<_>>(),
ev,
)
}
_ => return Ok(()),
};
if matches.is_empty() {
return Ok(());
}
let payload = serde_json::to_value(&trigger_event)
.map_err(|e| EmitError::Rejected(format!("event serialize: {e}")))?;
for (trigger_id, script_id) in matches {
self.outbox
.insert(NewOutboxRow {
app_id: cx.app_id,
source_kind,
trigger_id: Some(trigger_id),
script_id: Some(script_id),
reply_to: None,
payload: payload.clone(),
origin_principal: cx.principal.as_ref().map(|p| p.user_id),
trigger_depth: cx.trigger_depth.saturating_add(1),
root_execution_id: Some(cx.root_execution_id),
})
.await
.map_err(|e| EmitError::Unavailable(format!("outbox insert: {e}")))?;
}
Ok(())
} }
} }
impl OutboxEventEmitter { /// Everything the fan-out needs, derived from a `ServiceEvent` with no I/O: the
async fn emit_kv(&self, cx: &SdkCallCx, event: ServiceEvent) -> Result<(), EmitError> { /// trigger-table coordinates to match on, and the `TriggerEvent` the handler
let Some(op) = KvEventOp::from_wire(event.op) else { /// will see as `ctx.event`. `None` for a source or op the dispatcher has no arm
return Ok(()); // unknown op — drop quietly /// for — the caller drops the event quietly.
}; struct EventPlan {
let Some(collection) = event.collection.clone() else { source_kind: OutboxSourceKind,
return Ok(()); // KV events always carry a collection — defensively skip /// `triggers.kind` discriminator. A literal — never user data, since it is
}; /// interpolated into the match SQL.
kind: &'static str,
/// Per-kind detail table. A literal, for the same reason.
detail_table: &'static str,
collection: String,
op_str: &'static str,
trigger_event: TriggerEvent,
}
fn plan(event: &ServiceEvent) -> Option<EventPlan> {
// Collection events always carry a collection; defensively skip if not.
let collection = event.collection.clone()?;
let key = event.key.clone().unwrap_or_default(); let key = event.key.clone().unwrap_or_default();
match event.source {
let matches = self "kv" => {
.triggers let op = KvEventOp::from_wire(event.op)?;
.list_matching_kv(cx.app_id, &collection, op) Some(EventPlan {
.await source_kind: OutboxSourceKind::Kv,
.map_err(|e| EmitError::Unavailable(format!("trigger lookup: {e}")))?; kind: "kv",
detail_table: "kv_trigger_details",
if matches.is_empty() { collection: collection.clone(),
return Ok(()); op_str: op.as_str(),
} trigger_event: TriggerEvent::Kv {
// Serialize the originating event as a TriggerEvent so the
// dispatcher can hand it to the script as `ctx.event` without
// round-tripping back to the trigger row.
let trigger_event = TriggerEvent::Kv {
op, op,
collection, collection,
key, key,
value: event.payload.clone(), value: event.payload.clone(),
}; },
let payload = serde_json::to_value(&trigger_event)
.map_err(|e| EmitError::Rejected(format!("event serialize: {e}")))?;
for m in matches {
self.outbox
.insert(NewOutboxRow {
app_id: cx.app_id,
source_kind: OutboxSourceKind::Kv,
trigger_id: Some(m.trigger_id),
script_id: Some(m.script_id),
reply_to: None,
payload: payload.clone(),
origin_principal: cx.principal.as_ref().map(|p| p.user_id),
trigger_depth: cx.trigger_depth.saturating_add(1),
root_execution_id: Some(cx.root_execution_id),
}) })
.await
.map_err(|e| EmitError::Unavailable(format!("outbox insert: {e}")))?;
} }
Ok(()) "docs" => {
} let op = DocsEventOp::from_wire(event.op)?;
Some(EventPlan {
/// v1.1.2. Mirrors `emit_kv` — fan out a docs mutation across source_kind: OutboxSourceKind::Docs,
/// matching docs triggers + write one outbox row each. The kind: "docs",
/// `prev_data` change-data-capture surface is preserved from the detail_table: "docs_trigger_details",
/// `ServiceEvent.old_payload` field (set by `DocsServiceImpl` on collection: collection.clone(),
/// update and delete; `None` for create). op_str: op.as_str(),
async fn emit_docs(&self, cx: &SdkCallCx, event: ServiceEvent) -> Result<(), EmitError> { trigger_event: TriggerEvent::Docs {
let Some(op) = DocsEventOp::from_wire(event.op) else {
return Ok(());
};
let Some(collection) = event.collection.clone() else {
return Ok(());
};
let id = event.key.clone().unwrap_or_default();
let matches = self
.triggers
.list_matching_docs(cx.app_id, &collection, op)
.await
.map_err(|e| EmitError::Unavailable(format!("trigger lookup: {e}")))?;
if matches.is_empty() {
return Ok(());
}
let trigger_event = TriggerEvent::Docs {
op, op,
collection, collection,
id, id: key,
data: event.payload.clone(), data: event.payload.clone(),
prev_data: event.old_payload.clone(), prev_data: event.old_payload.clone(),
}; },
let payload = serde_json::to_value(&trigger_event)
.map_err(|e| EmitError::Rejected(format!("event serialize: {e}")))?;
for m in matches {
self.outbox
.insert(NewOutboxRow {
app_id: cx.app_id,
source_kind: OutboxSourceKind::Docs,
trigger_id: Some(m.trigger_id),
script_id: Some(m.script_id),
reply_to: None,
payload: payload.clone(),
origin_principal: cx.principal.as_ref().map(|p| p.user_id),
trigger_depth: cx.trigger_depth.saturating_add(1),
root_execution_id: Some(cx.root_execution_id),
}) })
.await
.map_err(|e| EmitError::Unavailable(format!("outbox insert: {e}")))?;
} }
Ok(()) "files" => {
} let op = FilesEventOp::from_wire(event.op)?;
// The payload is the `FileMeta` JSON the files service emitted —
/// v1.1.5. Fan out a files mutation across matching files triggers. // never the blob bytes.
/// The `ServiceEvent.payload` is the file **metadata** (never the let meta: FileMeta = serde_json::from_value(event.payload.clone()?).ok()?;
/// blob bytes); `old_payload` is the prior metadata (the deleted Some(EventPlan {
/// row's metadata on delete). The `TriggerEvent::Files` carries the source_kind: OutboxSourceKind::Files,
/// metadata fields explicitly + `prev` for the change-data-capture kind: "files",
/// surface. detail_table: "files_trigger_details",
async fn emit_files(&self, cx: &SdkCallCx, event: ServiceEvent) -> Result<(), EmitError> { collection: collection.clone(),
let Some(op) = FilesEventOp::from_wire(event.op) else { op_str: op.as_str(),
return Ok(()); trigger_event: TriggerEvent::Files {
};
let Some(collection) = event.collection.clone() else {
return Ok(());
};
// The payload is the FileMeta JSON the FilesServiceImpl emitted.
let Some(meta) = event
.payload
.clone()
.and_then(|v| serde_json::from_value::<FileMeta>(v).ok())
else {
return Ok(());
};
let matches = self
.triggers
.list_matching_files(cx.app_id, &collection, op)
.await
.map_err(|e| EmitError::Unavailable(format!("trigger lookup: {e}")))?;
if matches.is_empty() {
return Ok(());
}
let trigger_event = TriggerEvent::Files {
op, op,
collection, collection,
id: meta.id.to_string(), id: meta.id.to_string(),
@@ -322,26 +138,87 @@ impl OutboxEventEmitter {
size: meta.size, size: meta.size,
checksum: meta.checksum, checksum: meta.checksum,
prev: event.old_payload.clone(), prev: event.old_payload.clone(),
}; },
let payload = serde_json::to_value(&trigger_event) })
.map_err(|e| EmitError::Rejected(format!("event serialize: {e}")))?; }
_ => None,
}
}
/// Fan a collection mutation out over the writing app's own + inherited
/// triggers. Pass `&mut *tx` to have the outbox rows commit with the write.
pub(crate) async fn emit_on(
conn: &mut PgConnection,
cx: &SdkCallCx,
event: &ServiceEvent,
) -> Result<(), EmitError> {
let Some(p) = plan(event) else { return Ok(()) };
let matches = list_matching_on(
&mut *conn,
p.kind,
p.detail_table,
cx.app_id,
&p.collection,
p.op_str,
)
.await
.map_err(|e| EmitError::Unavailable(format!("trigger lookup: {e}")))?;
write_outbox_rows(conn, cx, &p, matches).await
}
/// §11.6: fan a SHARED-collection write out over the `shared = true` triggers on
/// the OWNING group. Each fires under the WRITER app (`cx.app_id`) — the same
/// "a group template runs under the firing app" model as an inherited trigger.
pub(crate) async fn emit_shared_on(
conn: &mut PgConnection,
cx: &SdkCallCx,
owning_group: GroupId,
event: &ServiceEvent,
) -> Result<(), EmitError> {
let Some(p) = plan(event) else { return Ok(()) };
let matches = list_matching_shared_on(
&mut *conn,
p.kind,
p.detail_table,
owning_group,
&p.collection,
p.op_str,
)
.await
.map_err(|e| EmitError::Unavailable(format!("trigger lookup: {e}")))?;
write_outbox_rows(conn, cx, &p, matches).await
}
async fn write_outbox_rows(
conn: &mut PgConnection,
cx: &SdkCallCx,
p: &EventPlan,
matches: Vec<KvMatchRow>,
) -> Result<(), EmitError> {
if matches.is_empty() {
return Ok(());
}
// Serialize the originating event once so the dispatcher can hand it to the
// handler as `ctx.event` without joining back to the trigger row.
let payload = serde_json::to_value(&p.trigger_event)
.map_err(|e| EmitError::Rejected(format!("event serialize: {e}")))?;
for m in matches { for m in matches {
self.outbox insert_on(
.insert(NewOutboxRow { &mut *conn,
NewOutboxRow {
app_id: cx.app_id, app_id: cx.app_id,
source_kind: OutboxSourceKind::Files, source_kind: p.source_kind,
trigger_id: Some(m.trigger_id), trigger_id: Some(m.id.into()),
script_id: Some(m.script_id), script_id: Some(m.script_id.into()),
reply_to: None, reply_to: None,
payload: payload.clone(), payload: payload.clone(),
origin_principal: cx.principal.as_ref().map(|p| p.user_id), origin_principal: cx.principal.as_ref().map(|pr| pr.user_id),
trigger_depth: cx.trigger_depth.saturating_add(1), trigger_depth: cx.trigger_depth.saturating_add(1),
root_execution_id: Some(cx.root_execution_id), root_execution_id: Some(cx.root_execution_id),
}) },
)
.await .await
.map_err(|e| EmitError::Unavailable(format!("outbox insert: {e}")))?; .map_err(|e| EmitError::Unavailable(format!("outbox insert: {e}")))?;
} }
Ok(()) Ok(())
} }
}

View File

@@ -145,9 +145,14 @@ impl PostgresOutboxRepo {
} }
} }
#[async_trait] /// Insert one outbox row on an arbitrary executor — a pooled connection, or a
impl OutboxRepo for PostgresOutboxRepo { /// `&mut *tx` so the row commits atomically with the data write that produced
async fn insert(&self, row: NewOutboxRow) -> Result<Uuid, OutboxRepoError> { /// it (the transactional outbox; see `outbox_event_emitter`). The `insert`
/// trait method delegates here, so the INSERT has exactly one home.
pub(crate) async fn insert_on<'c, E>(exec: E, row: NewOutboxRow) -> Result<Uuid, OutboxRepoError>
where
E: sqlx::PgExecutor<'c>,
{
let (id,): (Uuid,) = sqlx::query_as( let (id,): (Uuid,) = sqlx::query_as(
"INSERT INTO outbox ( \ "INSERT INTO outbox ( \
app_id, source_kind, trigger_id, script_id, reply_to, \ app_id, source_kind, trigger_id, script_id, reply_to, \
@@ -164,11 +169,17 @@ impl OutboxRepo for PostgresOutboxRepo {
.bind(row.origin_principal.map(AdminUserId::into_inner)) .bind(row.origin_principal.map(AdminUserId::into_inner))
.bind(i32::try_from(row.trigger_depth).unwrap_or(0)) .bind(i32::try_from(row.trigger_depth).unwrap_or(0))
.bind(row.root_execution_id.map(ExecutionId::into_inner)) .bind(row.root_execution_id.map(ExecutionId::into_inner))
.fetch_one(&self.pool) .fetch_one(exec)
.await?; .await?;
Ok(id) Ok(id)
} }
#[async_trait]
impl OutboxRepo for PostgresOutboxRepo {
async fn insert(&self, row: NewOutboxRow) -> Result<Uuid, OutboxRepoError> {
insert_on(&self.pool, row).await
}
async fn claim_due( async fn claim_due(
&self, &self,
claimed_by: &str, claimed_by: &str,

View File

@@ -605,20 +605,81 @@ impl PostgresTriggerRepo {
pub fn new(pool: PgPool) -> Self { pub fn new(pool: PgPool) -> Self {
Self { pool } Self { pool }
} }
}
// ----------------------------------------------------------------------------
// Connection-scoped event matching
//
// The three collection-event kinds (kv / docs / files) match identically apart
// from the `triggers.kind` discriminator and their detail table, so both shapes
// — the per-app CHAIN walk and the §11.6 SHARED-collection lookup — live here
// once, parameterized on an executor.
//
// Taking an executor rather than `&self.pool` is what lets the transactional
// outbox work: `outbox_event_emitter` runs the match on the SAME connection
// (`&mut *tx`) as the data write it is fanning out, so the write and its outbox
// rows commit together or not at all. The `list_matching_*` trait methods below
// pass `&self.pool` and behave exactly as before.
//
// `kind` and `detail_table` are interpolated into the SQL, so they must stay
// hard-coded literals from the call sites below — never user data.
// ----------------------------------------------------------------------------
/// Glob + op filtering, in Rust rather than SQL. **Critical**: an empty `ops`
/// array means "any op", which a SQL `$op = ANY(ops)` predicate would silently
/// exclude.
fn filter_match_rows(rows: Vec<KvMatchRow>, collection: &str, op_str: &str) -> Vec<KvMatchRow> {
rows.into_iter()
.filter(|r| collection_matches(&r.collection_glob, collection))
.filter(|r| r.ops.is_empty() || r.ops.iter().any(|o| o == op_str))
.collect()
}
/// Per-app match: the firing app's OWN triggers plus any inherited from an
/// ancestor group, minus the ones a suppression on its chain declines.
pub(crate) async fn list_matching_on<'c, E>(
exec: E,
kind: &str,
detail_table: &str,
app_id: AppId,
collection: &str,
op_str: &str,
) -> Result<Vec<KvMatchRow>, TriggerRepoError>
where
E: sqlx::PgExecutor<'c>,
{
let rows: Vec<KvMatchRow> = sqlx::query_as(&format!(
"{CHAIN_LEVELS_CTE} \
SELECT t.id, t.script_id, t.dispatch_mode, \
t.retry_max_attempts, t.retry_backoff, t.retry_base_ms, \
t.registered_by_principal, \
d.collection_glob, d.ops \
FROM triggers t \
JOIN {detail_table} d ON d.trigger_id = t.id \
JOIN chain c ON (t.app_id = c.app_owner OR t.group_id = c.group_owner) \
WHERE t.kind = '{kind}' AND t.enabled = TRUE \
AND t.shared = FALSE{TRIGGER_SUPPRESSION_ANTIJOIN}"
))
.bind(app_id.into_inner())
.fetch_all(exec)
.await?;
Ok(filter_match_rows(rows, collection, op_str))
}
/// §11.6 shared-collection match: enabled `shared = true` triggers on the /// §11.6 shared-collection match: enabled `shared = true` triggers on the
/// OWNING group, glob + op filtered in Rust (like the per-app path). `kind` /// OWNING group. No chain and no suppression anti-join — a shared trigger is
/// and `detail_table` are hard-coded literals from the three call sites (no
/// injection). No chain / no suppression anti-join — a shared trigger is
/// declared on the group that owns the collection and fires under the writer. /// declared on the group that owns the collection and fires under the writer.
async fn shared_match_rows( pub(crate) async fn list_matching_shared_on<'c, E>(
&self, exec: E,
kind: &str, kind: &str,
detail_table: &str, detail_table: &str,
owning_group: GroupId, owning_group: GroupId,
collection: &str, collection: &str,
op_str: &str, op_str: &str,
) -> Result<Vec<KvMatchRow>, TriggerRepoError> { ) -> Result<Vec<KvMatchRow>, TriggerRepoError>
where
E: sqlx::PgExecutor<'c>,
{
let rows: Vec<KvMatchRow> = sqlx::query_as(&format!( let rows: Vec<KvMatchRow> = sqlx::query_as(&format!(
"SELECT t.id, t.script_id, t.dispatch_mode, \ "SELECT t.id, t.script_id, t.dispatch_mode, \
t.retry_max_attempts, t.retry_backoff, t.retry_base_ms, \ t.retry_max_attempts, t.retry_backoff, t.retry_base_ms, \
@@ -630,14 +691,9 @@ impl PostgresTriggerRepo {
AND t.shared = TRUE AND t.group_id = $1" AND t.shared = TRUE AND t.group_id = $1"
)) ))
.bind(owning_group.into_inner()) .bind(owning_group.into_inner())
.fetch_all(&self.pool) .fetch_all(exec)
.await?; .await?;
Ok(rows Ok(filter_match_rows(rows, collection, op_str))
.into_iter()
.filter(|r| collection_matches(&r.collection_glob, collection))
.filter(|r| r.ops.is_empty() || r.ops.iter().any(|o| o == op_str))
.collect())
}
} }
/// Insert a trigger (parent row + per-kind detail) within an existing /// Insert a trigger (parent row + per-kind detail) within an existing
@@ -1483,48 +1539,16 @@ impl TriggerRepo for PostgresTriggerRepo {
collection: &str, collection: &str,
op: KvEventOp, op: KvEventOp,
) -> Result<Vec<KvTriggerMatch>, TriggerRepoError> { ) -> Result<Vec<KvTriggerMatch>, TriggerRepoError> {
// Fetch all enabled KV triggers for the app — glob matching let rows = list_matching_on(
// happens in Rust so we don't have to teach the query about &self.pool,
// `*` and `prefix:*`. Sets are tiny in practice (one app's "kv",
// worth of triggers, usually a handful). "kv_trigger_details",
let rows: Vec<KvMatchRow> = sqlx::query_as(&format!( app_id,
"{CHAIN_LEVELS_CTE} \ collection,
SELECT t.id, t.script_id, t.dispatch_mode, \ op.as_str(),
t.retry_max_attempts, t.retry_backoff, t.retry_base_ms, \ )
t.registered_by_principal, \
d.collection_glob, d.ops \
FROM triggers t \
JOIN kv_trigger_details d ON d.trigger_id = t.id \
JOIN chain c ON (t.app_id = c.app_owner OR t.group_id = c.group_owner) \
WHERE t.kind = 'kv' AND t.enabled = TRUE \
AND t.shared = FALSE{TRIGGER_SUPPRESSION_ANTIJOIN}"
))
.bind(app_id.into_inner())
.fetch_all(&self.pool)
.await?; .await?;
Ok(rows.into_iter().map(KvMatchRow::into_kv).collect())
let op_str = op.as_str();
let mut out = Vec::new();
for r in rows {
if !collection_matches(&r.collection_glob, collection) {
continue;
}
let any_op = r.ops.is_empty();
if !any_op && !r.ops.iter().any(|o| o == op_str) {
continue;
}
out.push(KvTriggerMatch {
trigger_id: r.id.into(),
script_id: r.script_id.into(),
dispatch_mode: dispatch_from_str(&r.dispatch_mode),
retry_max_attempts: u32::try_from(r.retry_max_attempts).unwrap_or(3),
retry_backoff: BackoffShape::from_wire(&r.retry_backoff)
.unwrap_or(BackoffShape::Exponential),
retry_base_ms: u32::try_from(r.retry_base_ms).unwrap_or(1000),
registered_by_principal: r.registered_by_principal.into(),
});
}
Ok(out)
} }
async fn list_matching_docs( async fn list_matching_docs(
@@ -1533,49 +1557,16 @@ impl TriggerRepo for PostgresTriggerRepo {
collection: &str, collection: &str,
op: DocsEventOp, op: DocsEventOp,
) -> Result<Vec<DocsTriggerMatch>, TriggerRepoError> { ) -> Result<Vec<DocsTriggerMatch>, TriggerRepoError> {
// Mirrors list_matching_kv: pull every enabled docs trigger, let rows = list_matching_on(
// filter glob + ops in Rust. **Critical**: do NOT push the &self.pool,
// ops check into SQL (`WHERE $op = ANY(ops)`) — that would "docs",
// exclude rows with `ops = '{}'` from the results, breaking "docs_trigger_details",
// the empty-array-means-any-op semantic. app_id,
let rows: Vec<KvMatchRow> = sqlx::query_as(&format!( collection,
"{CHAIN_LEVELS_CTE} \ op.as_str(),
SELECT t.id, t.script_id, t.dispatch_mode, \ )
t.retry_max_attempts, t.retry_backoff, t.retry_base_ms, \
t.registered_by_principal, \
d.collection_glob, d.ops \
FROM triggers t \
JOIN docs_trigger_details d ON d.trigger_id = t.id \
JOIN chain c ON (t.app_id = c.app_owner OR t.group_id = c.group_owner) \
WHERE t.kind = 'docs' AND t.enabled = TRUE \
AND t.shared = FALSE{TRIGGER_SUPPRESSION_ANTIJOIN}"
))
.bind(app_id.into_inner())
.fetch_all(&self.pool)
.await?; .await?;
Ok(rows.into_iter().map(KvMatchRow::into_docs).collect())
let op_str = op.as_str();
let mut out = Vec::new();
for r in rows {
if !collection_matches(&r.collection_glob, collection) {
continue;
}
let any_op = r.ops.is_empty();
if !any_op && !r.ops.iter().any(|o| o == op_str) {
continue;
}
out.push(DocsTriggerMatch {
trigger_id: r.id.into(),
script_id: r.script_id.into(),
dispatch_mode: dispatch_from_str(&r.dispatch_mode),
retry_max_attempts: u32::try_from(r.retry_max_attempts).unwrap_or(3),
retry_backoff: BackoffShape::from_wire(&r.retry_backoff)
.unwrap_or(BackoffShape::Exponential),
retry_base_ms: u32::try_from(r.retry_base_ms).unwrap_or(1000),
registered_by_principal: r.registered_by_principal.into(),
});
}
Ok(out)
} }
async fn list_matching_files( async fn list_matching_files(
@@ -1584,46 +1575,16 @@ impl TriggerRepo for PostgresTriggerRepo {
collection: &str, collection: &str,
op: FilesEventOp, op: FilesEventOp,
) -> Result<Vec<FilesTriggerMatch>, TriggerRepoError> { ) -> Result<Vec<FilesTriggerMatch>, TriggerRepoError> {
// Mirrors list_matching_kv: pull every enabled files trigger, let rows = list_matching_on(
// filter glob + ops in Rust (empty ops array means "any op"). &self.pool,
let rows: Vec<KvMatchRow> = sqlx::query_as(&format!( "files",
"{CHAIN_LEVELS_CTE} \ "files_trigger_details",
SELECT t.id, t.script_id, t.dispatch_mode, \ app_id,
t.retry_max_attempts, t.retry_backoff, t.retry_base_ms, \ collection,
t.registered_by_principal, \ op.as_str(),
d.collection_glob, d.ops \ )
FROM triggers t \
JOIN files_trigger_details d ON d.trigger_id = t.id \
JOIN chain c ON (t.app_id = c.app_owner OR t.group_id = c.group_owner) \
WHERE t.kind = 'files' AND t.enabled = TRUE \
AND t.shared = FALSE{TRIGGER_SUPPRESSION_ANTIJOIN}"
))
.bind(app_id.into_inner())
.fetch_all(&self.pool)
.await?; .await?;
Ok(rows.into_iter().map(KvMatchRow::into_files).collect())
let op_str = op.as_str();
let mut out = Vec::new();
for r in rows {
if !collection_matches(&r.collection_glob, collection) {
continue;
}
let any_op = r.ops.is_empty();
if !any_op && !r.ops.iter().any(|o| o == op_str) {
continue;
}
out.push(FilesTriggerMatch {
trigger_id: r.id.into(),
script_id: r.script_id.into(),
dispatch_mode: dispatch_from_str(&r.dispatch_mode),
retry_max_attempts: u32::try_from(r.retry_max_attempts).unwrap_or(3),
retry_backoff: BackoffShape::from_wire(&r.retry_backoff)
.unwrap_or(BackoffShape::Exponential),
retry_base_ms: u32::try_from(r.retry_base_ms).unwrap_or(1000),
registered_by_principal: r.registered_by_principal.into(),
});
}
Ok(out)
} }
async fn list_matching_shared_kv( async fn list_matching_shared_kv(
@@ -1632,8 +1593,8 @@ impl TriggerRepo for PostgresTriggerRepo {
collection: &str, collection: &str,
op: KvEventOp, op: KvEventOp,
) -> Result<Vec<KvTriggerMatch>, TriggerRepoError> { ) -> Result<Vec<KvTriggerMatch>, TriggerRepoError> {
let rows = self let rows = list_matching_shared_on(
.shared_match_rows( &self.pool,
"kv", "kv",
"kv_trigger_details", "kv_trigger_details",
owning_group, owning_group,
@@ -1650,8 +1611,8 @@ impl TriggerRepo for PostgresTriggerRepo {
collection: &str, collection: &str,
op: DocsEventOp, op: DocsEventOp,
) -> Result<Vec<DocsTriggerMatch>, TriggerRepoError> { ) -> Result<Vec<DocsTriggerMatch>, TriggerRepoError> {
let rows = self let rows = list_matching_shared_on(
.shared_match_rows( &self.pool,
"docs", "docs",
"docs_trigger_details", "docs_trigger_details",
owning_group, owning_group,
@@ -1668,8 +1629,8 @@ impl TriggerRepo for PostgresTriggerRepo {
collection: &str, collection: &str,
op: FilesEventOp, op: FilesEventOp,
) -> Result<Vec<FilesTriggerMatch>, TriggerRepoError> { ) -> Result<Vec<FilesTriggerMatch>, TriggerRepoError> {
let rows = self let rows = list_matching_shared_on(
.shared_match_rows( &self.pool,
"files", "files",
"files_trigger_details", "files_trigger_details",
owning_group, owning_group,
@@ -2169,9 +2130,9 @@ struct DlDetailRow {
} }
#[derive(sqlx::FromRow)] #[derive(sqlx::FromRow)]
struct KvMatchRow { pub(crate) struct KvMatchRow {
id: Uuid, pub(crate) id: Uuid,
script_id: Uuid, pub(crate) script_id: Uuid,
dispatch_mode: String, dispatch_mode: String,
retry_max_attempts: i32, retry_max_attempts: i32,
retry_backoff: String, retry_backoff: String,

View File

@@ -169,10 +169,7 @@ pub async fn build_app(
// dispatcher. // dispatcher.
let kv_repo = Arc::new(PostgresKvRepo::new(pool.clone())); let kv_repo = Arc::new(PostgresKvRepo::new(pool.clone()));
let docs_repo = Arc::new(PostgresDocsRepo::new(pool.clone())); let docs_repo = Arc::new(PostgresDocsRepo::new(pool.clone()));
let events: Arc<dyn ServiceEventEmitter> = Arc::new(OutboxEventEmitter::new( let events: Arc<dyn ServiceEventEmitter> = Arc::new(OutboxEventEmitter::new(pool.clone()));
trigger_repo.clone(),
outbox_repo.clone(),
));
let kv: Arc<dyn KvService> = Arc::new(KvServiceImpl::with_max_value_bytes( let kv: Arc<dyn KvService> = Arc::new(KvServiceImpl::with_max_value_bytes(
kv_repo.clone(), kv_repo.clone(),
authz.clone(), authz.clone(),