EigenStore reads bypass trace/replay and silently use changed live data under strict replay
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Lĩnh vực
- databases, documentation, testing-qa
Hướng nghiên cứu
Start in src/ext_store.c at builtin_store_open and builtin_store_get, then read docs/TRACE.md and policy precedent #148. Run the provided Python reproduction from the checkout root and inspect replay coverage around store_open and store_get. Done means the chosen store replay boundary prevents changed or newly created live data, preserves persistence, documents the boundary in docs/TRACE.md, and adds regression coverage.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
EigenStore reads are neither recorded nor refused during replay. The same program prints a different stored value after the database changes, even with EIGS_REPLAY_STRICT=1, and exits successfully without a warning.
Severity: major correctness issue for deterministic debugging. This is separate from the existing trace threading/ownership issues: the reproduction is single-threaded, uses one database handle, and needs no malformed input.
Reproduction
Confirmed from a fresh default make build of b91768e23c5a874a64e76e4af9ab291e6aa49983. Run this from that checkout's root; all database/tape files are created in a unique temporary directory:
python3 - <<'PY'
import json, os, pathlib, subprocess, tempfile
binary = str(pathlib.Path('src/eigenscript').resolve())
scratch = pathlib.Path(tempfile.mkdtemp(prefix='eigs-store-replay-'))
db = json.dumps(str(scratch / 'probe.db'))
tape = str(scratch / 'run.tape')
base = {k:v for k,v in os.environ.items() if not k.startswith('EIGS_')}
def run(source, **extra):
p = subprocess.run([binary, '-e', source], env=base | extra,
text=True, capture_output=True, timeout=10)
print(p.returncode, repr(p.stdout), repr(p.stderr))
run(f'db is store_open of {db}\nstore_put of [db, "config", {{"_id":"answer","value":10}}]\nstore_close of db\n')
reader = f'db is store_open of {db}\nr is store_get of [db, "config", "answer"]\nprint of r.value\nstore_close of db\n'
run(reader, EIGS_TRACE=tape)
run(f'db is store_open of {db}\nstore_update of [db, "config", "answer", {{"_id":"answer","value":20}}]\nstore_close of db\n')
run(reader, EIGS_REPLAY=tape, EIGS_REPLAY_STRICT='1')
print('N records:', sum(line.startswith('N ') for line in pathlib.Path(tape).read_text().splitlines()))
PY
Actual:
0 '' ''
0 '10\n' ''
0 '' ''
0 '20\n' ''
N records: 0
Expected: replay returns the recorded observation (10), or the store operation raises a clear non-replayable-boundary error before accessing live storage. Silently substituting 20 is neither outcome.
Cause and scope
src/ext_store.c opens the real database in builtin_store_open and reads its current contents in builtin_store_get; it has no trace-record/take hooks or replay refusal. docs/TRACE.md promises replayed nondeterministic inputs and explicitly refuses unsupported subprocess/channel operations, but gives EigenStore no such boundary.
EIGS_REPLAY_STRICT currently checks names on consumed N records. Here there are no N records, so enabling it cannot detect the gap. This report does not claim that strict mode promises a general program-equivalence check.
Define the store's replay boundary as a family: either support logical recorded results and handle lifetime without relying on a live database, or reject unsupported store operations during replay. Simply taping a live handle ID is not sufficient. The minimal confirmed case is store_open + store_get; adjacent queries and writes should be audited when choosing that boundary.
Regression acceptance
- Record a read, change the stored value, then replay the same program. Require recorded output or the explicit refusal, never the changed live value with exit 0.
- Cover a missing database at replay time and confirm the chosen boundary cannot silently create/use a new database.
- Preserve ordinary store persistence behavior and existing replay behavior outside the store.
- Document the boundary in
docs/TRACE.mdand add the real store case to replay coverage.
Related policy precedent: #148. No implementation change is included in this report.
- Ngôn ngữ chính
- C
- Star
- 3
- Fork
- 7
- Merge trung bình
- 4 giờ 1 phút
- Pull request đã merge (30 ngày)
- 121
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của InauguralSystems/EigenScript
-
area:ci kind:gate-defect
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
InauguralSystems/EigenScript#1448 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:ci kind:gate-defect
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
InauguralSystems/EigenScript#1431 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:gates kind:gate-defect
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
InauguralSystems/EigenScript#1429 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:docs kind:docs-drift
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
InauguralSystems/EigenScript#1428 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:docs good first issue kind:docs-drift
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
InauguralSystems/EigenScript#1400 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của InauguralSystems/EigenScript
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
darktable-org/darktable#22455 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
BasedHardware/omi#20084 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 64/100
raspberrypi/pico-sdk#3225 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày