docs(tasks): correct how BUG-1011 must be fixed

Gate run 2857 on 36a73761 ran 3,762 tests with one failure, the report
snapshot database test, so it is the last thing between staging and a deploy.

The brief told the executor to move the shared psql and psqlAs helpers to
stdin. That instruction is withdrawn. The two helpers serve 522 calls across
29 test files, and psql -c runs a multi-statement string as one implicit
transaction. selectAsAuthenticated relies on that: it sets the JWT subject
with set_config(..., true), which lasts only for the current transaction.
Statement-at-a-time execution would run every later RLS query with no user
set, so those tests would stop testing what they claim to test. Five other
files also write their own begin, commit or rollback.

The brief now asks for a separate single-transaction stdin helper with an
explicit maxBuffer, used only by the snapshot test, with a test proving a
transaction-local set_config stays visible. It also says that if the snapshot
test then fails a real assertion, that is a product defect to report, not an
assertion to relax.

Privacy scan on this tree before push: zero findings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eEAG8HD3mm8gsKXgk8uU8
This commit is contained in:
Jesse_Chen
2026-09-23 17:29:44 +08:00
co-authored by Claude Opus 5.5
parent 8c2db6874d
commit 451a58089a
3 changed files with 25 additions and 14 deletions
+3 -3
View File
@@ -13430,14 +13430,14 @@
- 状态:investigating(根因已复现,修复待执行;数据库层从未真跑过)
- 首次发现:2026-09-23
- 最近更新:2026-09-23
- 最近更新:2026-09-23(门禁 run 2857 确认为唯一失败)
- 影响面:`frontend/tests/database-personal-report-sections.test.ts` 中报告密度快照一例;`backend-quality-gate` 的数据库测试步骤。生产写入走 RPC 请求体,不经命令行,不受影响。
- 用户现象:无用户界面现象。门禁在含该测试的提交上变红;报告快照行在真实 Postgres 里的写入、幂等与越权隔离从未被验证。
- 触发条件:在 Linux 上以 Docker 跑 `npm run test:db`(即门禁环境)。
- 根因:`tests/helpers/postgres-fixture.ts` 的 `psql` / `psqlAs` 用 `psql -Atc <sql>` 把整段 SQL 作为单个 argv 元素传给 `docker compose exec`。该测试把整份快照(含 374,097 字节的附录 Markdown)内联进 SQL,单个参数 428,557 字节,超过 Linux 单参数上限 `MAX_ARG_STRLEN` 131,072 字节。验收时用同一段 SQL 以同样方式调用 `/bin/true`,稳定得到 `spawn E2BIG`。执行方两轮都因 Docker 地址池耗尽未跑数据库测试,验收机无 Docker,因此一直没暴露。
- 修复:待执行,见 `TASK-report-density-fix2-20260923.md`。
- 修复:待执行,见 `TASK-report-density-fix2-20260923.md` G1。**不得改共享的 `psql` / `psqlAs`**:它们被 29 个文件调用 522 次,`-c` 的多语句单事务语义被依赖(`selectAsAuthenticated` 的 `set_config(…, true)` 只在当前事务内有效)。新增单事务的大脚本专用函数,只给本测试用。
- 验证:待执行。
- 防复发:数据库测试辅助函数不得把 SQL 放进命令行参数,一律经标准输入或文件传入;新增一条断言覆盖超过 131,072 字节的 SQL。
- 防复发:超过数十 KB 的 SQL 一律走单事务的标准输入专用函数,并显式设 `maxBuffer`;专用函数须有测试覆盖超过 131,072 字节的 SQL,并证明事务内 `set_config(…, true)` 对后续语句可见。
- 相关记录:BUG-1005、BUG-1009
- 复发自:无
- 修复版本:—