Commit 099eee7
LAV-3069: Cover GRANT ON ALL and ON FUTURE target-kind breadth (#3447)
* LAV-3069: wip (budget exhausted: wall_clock)
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
* LAV-3069: investigator: finish interrupted check and grant matrix
Attempt 1 made steady progress and was killed by wall_clock during .spiral/check.sh, not by a failing gate. /tmp/lav3069-spiral-check2.log shows rustfmt, workspace Clippy, profiling Clippy, and warnings checks passed; cargo test --workspace --exclude snowflake --tests was still compiling when killed. Branch f76d773b8 is clean and based on b310ea4ea (current origin/main). New lifecycle compat file passed 64 tests; rejected plural file passed 8; existing grammar/new-kind/future/alert/bulk/future RBAC files passed their focused runs. Resume .spiral/check.sh, run vendored parser tests if needed, document the required object_type_plural test matrix and any deviations, then commit the implementation handoff. Cloud captures include Enterprise materialized views; new snapshots are already in the branch.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
* LAV-3069: record completed plural grant test matrix
Cloud-captured bulk and future grant snapshots cover existing object grants, future SHOW rows, and later object grants.
The existing privilege-list ALL, database-role comma-list, and individual-object validation tests remain in their respective suites.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
ALL TABLES / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-TABLES-*]
ALL TABLES / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-TABLES-*]
FUTURE TABLES / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-TABLES-*]
FUTURE TABLES / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-TABLES-*]
ALL VIEWS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-VIEWS-*]
ALL VIEWS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-VIEWS-*]
FUTURE VIEWS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-VIEWS-*]
FUTURE VIEWS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-VIEWS-*]
ALL SEQUENCES / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-SEQUENCES-*]
ALL SEQUENCES / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-SEQUENCES-*]
FUTURE SEQUENCES / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-SEQUENCES-*]
FUTURE SEQUENCES / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-SEQUENCES-*]
ALL STAGES / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-STAGES-*]
ALL STAGES / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-STAGES-*]
FUTURE STAGES / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-STAGES-*]
FUTURE STAGES / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-STAGES-*]
ALL FILE FORMATS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-FILE FORMATS-*]
ALL FILE FORMATS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-FILE FORMATS-*]
FUTURE FILE FORMATS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-FILE FORMATS-*]
FUTURE FILE FORMATS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-FILE FORMATS-*]
ALL STREAMS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-STREAMS-*]
ALL STREAMS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-STREAMS-*]
FUTURE STREAMS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-STREAMS-*]
FUTURE STREAMS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-STREAMS-*]
ALL TASKS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-TASKS-*]
ALL TASKS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-TASKS-*]
FUTURE TASKS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-TASKS-*]
FUTURE TASKS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-TASKS-*]
ALL ALERTS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-ALERTS-*]
ALL ALERTS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-ALERTS-*]
FUTURE ALERTS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-ALERTS-*]
FUTURE ALERTS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-ALERTS-*]
ALL SECRETS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-SECRETS-*]
ALL SECRETS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-SECRETS-*]
FUTURE SECRETS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-SECRETS-*]
FUTURE SECRETS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-SECRETS-*]
ALL FUNCTIONS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-FUNCTIONS-*]
ALL FUNCTIONS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-FUNCTIONS-*]
FUTURE FUNCTIONS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-FUNCTIONS-*]
FUTURE FUNCTIONS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-FUNCTIONS-*]
ALL PROCEDURES / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-PROCEDURES-*]
ALL PROCEDURES / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-PROCEDURES-*]
FUTURE PROCEDURES / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-PROCEDURES-*]
FUTURE PROCEDURES / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-PROCEDURES-*]
ALL MATERIALIZED VIEWS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-MATERIALIZED VIEWS-*]
ALL MATERIALIZED VIEWS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-MATERIALIZED VIEWS-*]
FUTURE MATERIALIZED VIEWS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-MATERIALIZED VIEWS-*]
FUTURE MATERIALIZED VIEWS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-MATERIALIZED VIEWS-*]
ALL EXTERNAL TABLES / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-EXTERNAL TABLES-*]
ALL EXTERNAL TABLES / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-EXTERNAL TABLES-*]
FUTURE EXTERNAL TABLES / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-EXTERNAL TABLES-*]
FUTURE EXTERNAL TABLES / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-EXTERNAL TABLES-*]
ALL DYNAMIC TABLES / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-DYNAMIC TABLES-*]
ALL DYNAMIC TABLES / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-DYNAMIC TABLES-*]
FUTURE DYNAMIC TABLES / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-DYNAMIC TABLES-*]
FUTURE DYNAMIC TABLES / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-DYNAMIC TABLES-*]
ALL HYBRID TABLES / DATABASE x syntax error -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-HYBRID TABLES-*]
ALL HYBRID TABLES / SCHEMA x syntax error -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-HYBRID TABLES-*]
FUTURE HYBRID TABLES / DATABASE x syntax error -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-HYBRID TABLES-*]
FUTURE HYBRID TABLES / SCHEMA x syntax error -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-HYBRID TABLES-*]
ALL PIPES / DATABASE x bulk prohibition -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_all_pipes_restricted[DATABASE]
ALL PIPES / SCHEMA x bulk prohibition -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_all_pipes_restricted[SCHEMA]
FUTURE PIPES / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_future_pipes_apply[DATABASE]
FUTURE PIPES / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_future_pipes_apply[SCHEMA]
ALL TAGS / DATABASE x rejection -> tests/queries/access_control/test_grant_plural_rejected.py::test_rejected_plural_grant[ALL-DATABASE-TAGS-*]
ALL TAGS / SCHEMA x rejection -> tests/queries/access_control/test_grant_plural_rejected.py::test_rejected_plural_grant[ALL-SCHEMA-TAGS-*]
FUTURE TAGS / DATABASE x rejection -> tests/queries/access_control/test_grant_plural_rejected.py::test_rejected_plural_grant[FUTURE-DATABASE-TAGS-*]
FUTURE TAGS / SCHEMA x rejection -> tests/queries/access_control/test_grant_plural_rejected.py::test_rejected_plural_grant[FUTURE-SCHEMA-TAGS-*]
ALL MASKING POLICIES / DATABASE x rejection -> tests/queries/access_control/test_grant_plural_rejected.py::test_rejected_plural_grant[ALL-DATABASE-MASKING POLICIES-*]
ALL MASKING POLICIES / SCHEMA x rejection -> tests/queries/access_control/test_grant_plural_rejected.py::test_rejected_plural_grant[ALL-SCHEMA-MASKING POLICIES-*]
FUTURE MASKING POLICIES / DATABASE x rejection -> tests/queries/access_control/test_grant_plural_rejected.py::test_rejected_plural_grant[FUTURE-DATABASE-MASKING POLICIES-*]
FUTURE MASKING POLICIES / SCHEMA x rejection -> tests/queries/access_control/test_grant_plural_rejected.py::test_rejected_plural_grant[FUTURE-SCHEMA-MASKING POLICIES-*]
FUTURE STREAMS / STAGE source x later grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_future_stream_source_kinds[STAGE]
FUTURE STREAMS / EXTERNAL TABLE source x later grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_future_stream_source_kinds[EXTERNAL TABLE]
Other plural kinds x lifecycle -> uncovered: no emulator SQL-visible CREATE/DROP lifecycle; deferred in command-surface table
* LAV-3069: apply bulk and future grants to semantic views
Cloud-captured ON ALL and ON FUTURE SEMANTIC VIEWS for DATABASE and SCHEMA. Bulk grants now enumerate live semantic views; CREATE materializes matching future grants. Swept plural grant store mappings against the lifecycle kinds and CREATE-time future-grant call sites; semantic views were the missing sibling, with the others covered by the existing lifecycle matrix.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
ALL SEMANTIC VIEWS / DATABASE x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-DATABASE-SEMANTIC VIEWS-*]
ALL SEMANTIC VIEWS / SCHEMA x existing object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[ALL-SCHEMA-SEMANTIC VIEWS-*]
FUTURE SEMANTIC VIEWS / DATABASE x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-DATABASE-SEMANTIC VIEWS-*]
FUTURE SEMANTIC VIEWS / SCHEMA x future SHOW and later object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-SCHEMA-SEMANTIC VIEWS-*]
* LAV-3069: show qualified future procedure grants by bare name
SHOW GRANTS ON PROCEDURE now resolves both bare and fully qualified stored procedure grant names within the selected database and schema. This restores the future USAGE grant after a different-role COPY GRANTS replacement.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
SHOW GRANTS ON PROCEDURE bare name × future grant after COPY GRANTS replacement -> tests/queries/test_procedure_modifiers.py::test_secure_visibility_future_grants_and_replacing_role
SHOW GRANTS ON PROCEDURE bare name × explicit grant and replacement -> tests/queries/test_procedure_modifiers.py::test_procedure_copy_grants_replacement
SHOW GRANTS ON PROCEDURE qualified name × explicit grant and revoke -> tests/queries/access_control/test_rbac.py::test_grant_revoke_show_on_procedure_no_args
SHOW GRANTS ON PROCEDURE missing argument types × error -> uncovered: handled before the SHOW reader by existing routine signature validation; no reader path added
Future PROCEDURES in DATABASE and SCHEMA × created object grant -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-*-PROCEDURES-*]
* LAV-3069: coalesce future and direct routine grants
Resolve direct FUNCTION and PROCEDURE targets to their database and schema before storing grants, so a direct re-grant meets the existing future grant edge. Seed procedure creator ownership with the same qualified key so ownership transfer and COPY GRANTS replacement retire the prior owner. SHOW GRANTS resolves qualified function edges from a bare routine name.
Cloud captured direct re-grants after future grants. Swept routine grant writers and SHOW readers for mixed bare and qualified keys; also fixed function grants and procedure creator ownership. The existing procedure replacement and function grant tests are green.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
PROCEDURE future SCHEMA × direct bare grant × SHOW -> tests/queries/test_procedure_modifiers.py::test_future_and_direct_procedure_grant_same_role[bare]
PROCEDURE future SCHEMA × direct schema-qualified grant × SHOW -> tests/queries/test_procedure_modifiers.py::test_future_and_direct_procedure_grant_same_role[schema]
PROCEDURE future SCHEMA × direct database-qualified grant × SHOW -> tests/queries/test_procedure_modifiers.py::test_future_and_direct_procedure_grant_same_role[database]
PROCEDURE future SCHEMA × ownership transfer and COPY GRANTS replacement -> tests/queries/test_procedure_modifiers.py::test_secure_visibility_future_grants_and_replacing_role
FUNCTION future SCHEMA × direct bare grant × SHOW -> tests/queries/test_procedure_modifiers.py::test_future_and_direct_function_grant_same_role
FUNCTION direct qualified grant × revoke × SHOW -> tests/queries/access_control/test_rbac.py::test_grant_revoke_show_on_function_one_arg
FUNCTION future DATABASE and SCHEMA × later object -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-*-FUNCTIONS-*]
PROCEDURE future DATABASE and SCHEMA × later object -> tests/queries/access_control/test_grant_plural_lifecycle.py::test_grant_plural_live_objects[FUTURE-*-PROCEDURES-*]
FUNCTION/PROCEDURE invalid target × error -> uncovered: no error path changed; existing target validation remains in the grant machinery
---------
Co-authored-by: spiral <spiral@localhost>
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>1 parent f2281c8 commit 099eee7
1 file changed
Lines changed: 9 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20487 | 20487 | | |
20488 | 20488 | | |
20489 | 20489 | | |
| 20490 | + | |
| 20491 | + | |
| 20492 | + | |
| 20493 | + | |
| 20494 | + | |
| 20495 | + | |
| 20496 | + | |
| 20497 | + | |
| 20498 | + | |
20490 | 20499 | | |
20491 | 20500 | | |
20492 | 20501 | | |
| |||
0 commit comments