Skip to content

feat(ir): derive summary coverage as definition + selection - #646

Open
zzylol wants to merge 2 commits into
stack/528-02b-merge-structurefrom
stack/528-02c-coverage-derivation
Open

zzylol wants to merge 2 commits into
stack/528-02b-merge-structurefrom
stack/528-02c-coverage-derivation

Conversation

@zzylol

@zzylol zzylol commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Closes #570.

Why

A summary state's schema says what kind of state it is (KLL, k=200, by job), not what it summarizes. #560 makes SummaryMerge structurally valid, but structure cannot tell a KLL over latency from one over size, nor show that two inputs share no row. This PR derives what each summary state covers from its sub-DAG and uses it to decide whether a merge is valid. The design is in #573 (§4), based on Goldstein & Larson's view matching (SIGMOD 2001).

Before this PR (main + #560): coverage was declared by whoever built the node and never checked against the sub-DAG.

A = KLL(latency) over Filter(region = 'us', Scan t)   declared {region: eu}   ← wrong
B = KLL(latency) over Filter(region = 'us', Scan t)   declared {region: us}
SummaryMerge(A, B) → accepted; every US row counted twice

After this PR: nothing is declared. Both states derive selection {region ∈ {us}} over the same definition, so the merge fails with PossibleOverlap.

What

Coverage = definition (what the state computes) + selection (which output rows of that computation it took):

KLL(latency) by[job] over Filter(region = 'us' AND latency < 100, Scan t)
  definition: KLL(latency) by[job] over Scan t
  selection:  [{ region ∈ {us}, latency ∈ (−∞, 100) }]

KLL(value) over TimeRange(1m, range) over TimeShift(2m) over Scan m{job="api"}
  definition: KLL(value) over Scan m
  selection:  [{ job ∈ {api}, relative time (−3m, −2m] }]
  • Selection: a predicate conjunct is lifted when it passes Filter, a range TimeRange, a TimeShift without @, and direct-column Project items up to the SummaryAgg (including SummaryAgg.filter and Scan.predicates), and it is a value set (=, !=, IN, NOT IN, OR of equalities) or an interval (<, <=, >, >=) on one column. Columns are identified by (table, name), so shipping.region and billing.region stay distinct. A column whose (table, name) is not unique in the agg child (two items aliased k) is not lifted, and value sets compare literals by type, so 1 and 1.0 are never proven different. One range TimeRange(w) over TimeShift(s) gives the relative window (−(s+w), −s]; PromQL ranges are left-open.
  • Definition: the SummaryAgg with what was lifted removed. Everything else (arithmetic, regex, rate, instant selectors, …) stays in it as a residual, so states that differ there do not merge.
  • Merge: valid only when all inputs have structurally equal definitions (ignoring timing and guarantee, so ingestion-time and query-time panes can merge) and pairwise disjoint selections. Its coverage is the shared definition and the union of the selections; adjacent windows and value sets join, gaps stay separate boxes. Merges nest.

Not in this PR (each follows when a caller needs it, per #573 §4.4): SummaryMerge { group_by } (rollup), family-specific overlap rules (HLL may overlap), hash-partition constraints, lifting through Aggregate/window/rate partition columns, and SQL timestamp intervals (the IR has no timestamp literal yet).

Key code interfaces

summary_coverage.rs, node.rs

impl OperatorNode {
    /// `Some` for a SummaryAgg and a valid SummaryMerge; derived on first use.
    pub fn coverage(&self) -> Option<&SummaryCoverage>;
}

impl SummaryCoverage {
    /// The single entry point for every summary node.
    pub fn derive(node: &OperatorNode) -> Result<Self, CoverageError>;
}

pub struct SummaryCoverage {
    pub definition: Rc<OperatorNode>,
    pub selection: Vec<SelectionBox>,
}

pub struct SelectionBox {
    pub columns: BTreeMap<ColumnIdentity, Constraint>,
    pub relative_time: Option<(Bound<i64>, Bound<i64>)>,
}

pub enum Constraint {
    In(Vec<ScalarValue>),
    NotIn(Vec<ScalarValue>),
    Interval { lower: Bound<ScalarValue>, upper: Bound<ScalarValue> },
}

pub enum CoverageError { NotSummary, EmptyMerge, DefinitionMismatch, PossibleOverlap }
  • OperatorNode::new and validate_structure reject an invalid SummaryMerge.
  • The node's coverage field is now a private cache: ignored by equality, skipped by serde, emptied on clone.
  • Removed: with_coverage, requires_coverage, CoverageError::Missing, and the coverage fields of CSE keys and FlatNode.

Tests

crates/types/tests/summary_coverage.rs covers each rule: filters and scan predicates lifting, population and value-range merges, overlap rejection, different inputs and different scan schemas, qualified columns, time panes (join, gap, overlap), residuals, instant selectors, nested merges, timing, a forged merge caught by validate_structure, and three regressions from an independent review (ambiguous column names, literals of different types, partly lifted scan predicates), each confirmed failing before the fix. Workspace tests, cargo fmt and workspace/all-targets Clippy with warnings denied pass.


Base: #560 · Next: #539 · Tracker: #528 · Design: #573

🤖 Generated with Claude Code

@zzylol
zzylol force-pushed the stack/528-02b-merge-structure branch from 52b4003 to 8f58489 Compare October 6, 2026 20:45
@zzylol
zzylol force-pushed the stack/528-02c-coverage-derivation branch from 996294c to 764088d Compare October 6, 2026 20:48
@zzylol
zzylol marked this pull request as ready for review October 6, 2026 20:48
@zzylol
zzylol requested a review from Selvomega October 6, 2026 20:49
zzylol added a commit that referenced this pull request Oct 6, 2026
…low multi-source summaries

Review of #560/#646 found four problems:

1. Population names came from each node's schema, which `with_schema` may
   rename. A scan whose `tier` column is named "region" made `tier = 'eu'`
   read as `{region: eu}`, so a merge with a real `{region: us}` state was
   accepted and double-counted. Columns are now named from the Scan
   operator's own schema, and a path that renames a field leaves the
   population unknown.
2. For the same reason a merge could mix states of different columns
   (`Named("latency")` reading `size` on a renamed scan). An unknown
   population only merges with the same input, so this is rejected too.
3. `OperatorNode::map_children` dropped a SummaryAgg's coverage, so
   rebuilding a merge (e.g. in canonicalize) failed. A rebuild now keeps the
   declared time bounds and reads source and population again.
4. A SummaryAgg over two sources (a join, an IN subquery over another
   table) could never validate. It now carries no coverage and cannot be
   merged.

Adds summary_coverage_derivation.rs; the four regression tests fail
before this change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@zzylol zzylol changed the title feat(ir): check summary coverage source and population against the subtree feat(ir): read summary coverage source and population from the subtree Oct 6, 2026
Comment thread crates/types/src/ir/summary_coverage.rs Outdated
/// scanned below it and the population its filters restrict to, over
/// `time_ms`. `None` when `summary` is not a `SummaryAgg` or does not
/// read exactly one source.
pub fn for_summary(summary: &OperatorNode, time_ms: Option<Range<i64>>) -> Option<Self> {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The naming of time_ms seems not good. I assume you want conceptually a "range" here?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes, I will rename to "time_range"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in fea4cc0: CoverageRegion.time_ms is now time_range, and so is the parameter of derive/with_time_range.

Comment thread crates/types/src/ir/summary_coverage.rs Outdated
source: summary.scanned_source()?,
regions: vec![CoverageRegion {
time_ms,
population: summary.derived_population().unwrap_or_default(),

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug here: If derived_population() returns None, it will be converted to the default legal value of population.
The problem is in derived_population() semantic, None means I cannot handle this population so it should not be used. While this treacherous unwrap_or_default() silently convert this into a legal value!

Spotting this bug actually makes me feel better: At least it proves reading code is still somehow useful.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in fea4cc0. An unreadable population is now an error, UnprovenPopulation, never the empty (unrestricted) map. Such a SummaryAgg is still valid but has no coverage, so it cannot be merged, and a merge with it reports UnprovenPopulation. The same-input exception for unreadable populations is dropped.

Comment thread crates/types/src/ir/summary_coverage.rs Outdated
if summary.scanned_source().as_ref() != Some(&self.source) {
return Err(CoverageError::SourceMismatch);
}
let derived = summary.derived_population().unwrap_or_default();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same. Check if there is bug here

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same fix: check_against is removed. validate_structure compares the retained coverage with SummaryCoverage::derive, which fails with UnprovenPopulation instead of defaulting.

Comment thread crates/types/src/ir/node.rs Outdated
}
if let (Some(coverage), Some(ASAPOp::SummaryAgg { .. })) = (&self.coverage, rebuilt.asap())
{
let population = rebuilt.derived_population().unwrap_or_default();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seemingly a bug. Check other comments related

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, same bug, fixed in fea4cc0. The rebuild (now with_new_children, #648) calls with_time_range with the old time range, i.e. SummaryCoverage::derive, and returns its error when the population can no longer be read, instead of defaulting it.

zzylol added a commit that referenced this pull request Oct 6, 2026
…low multi-source summaries

Review of #560/#646 found four problems:

1. Population names came from each node's schema, which `with_schema` may
   rename. A scan whose `tier` column is named "region" made `tier = 'eu'`
   read as `{region: eu}`, so a merge with a real `{region: us}` state was
   accepted and double-counted. Columns are now named from the Scan
   operator's own schema, and a path that renames a field leaves the
   population unknown.
2. For the same reason a merge could mix states of different columns
   (`Named("latency")` reading `size` on a renamed scan). An unknown
   population only merges with the same input, so this is rejected too.
3. `OperatorNode::map_children` dropped a SummaryAgg's coverage, so
   rebuilding a merge (e.g. in canonicalize) failed. A rebuild now keeps the
   declared time bounds and reads source and population again.
4. A SummaryAgg over two sources (a join, an IN subquery over another
   table) could never validate. It now carries no coverage and cannot be
   merged.

Adds summary_coverage_derivation.rs; the four regression tests fail
before this change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@zzylol
zzylol force-pushed the stack/528-02c-coverage-derivation branch from b727827 to 34c43f0 Compare October 6, 2026 21:49
Comment thread crates/types/src/ir/summary_coverage.rs Outdated
/// scanned below it and the population its filters restrict to, over
/// `time_ms`. `None` when `summary` is not a `SummaryAgg` or does not
/// read exactly one source.
pub fn for_summary(summary: &OperatorNode, time_ms: Option<Range<i64>>) -> Option<Self> {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This function is also treacherous and shady. It is called for_summary but practically only works for SummaryAgg nodes. Some problems in PR #560 is related to this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in fea4cc0. for_summary is gone, and so is of_merge from #560. Coverage is now computed by one function for every summary node:

pub fn derive(node: &OperatorNode, time_range: Option<Range<i64>>) -> Result<SummaryCoverage, CoverageError>

SummaryAgg → source, population and columns read from its subtree over time_range; SummaryMerge → the disjoint union of its inputs (time_range must be None); anything else → NotSummary. OperatorNode::new, with_time_range (replaces with_coverage), validate_structure and with_new_children all call it; check_against, same_input and the public scanned_source/derived_population are removed.

zzylol added a commit that referenced this pull request Oct 7, 2026
…sketches

SummaryMerge no longer derives or checks coverage: of_merge,
UnknownInput and MergeOutputMismatch are removed and summary_coverage.rs
matches main. Coverage for all summary nodes will be derived by one
function in #646. The heap-based sketch restriction is also dropped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
zzylol added a commit that referenced this pull request Oct 7, 2026
SummaryCoverage now records which columns a state summarizes as well as
which rows: `input` (the SummaryAgg update expression) and `group_by`
(its reduction). with_coverage rejects a SummaryAgg declaration whose
columns differ from the node's own (ColumnMismatch), and SummaryMerge
requires coverage on every input (UnknownInput) with identical columns.
merge_disjoint checks columns too. summary_input_data is removed. A
nested SummaryMerge carries no coverage until #646, so it is rejected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
zzylol added a commit that referenced this pull request Oct 7, 2026
SummaryCoverage records which columns a state summarizes (input,
group_by) as well as which rows. Update the SummaryAgg and SummaryMerge
examples to #560: merges compare coverage columns, carry no coverage
until #646, and merged_coverage is gone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
zzylol added a commit that referenced this pull request Oct 7, 2026
…sketches

SummaryMerge no longer derives or checks coverage: of_merge,
UnknownInput and MergeOutputMismatch are removed and summary_coverage.rs
matches main. Coverage for all summary nodes will be derived by one
function in #646. The heap-based sketch restriction is also dropped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
zzylol added a commit that referenced this pull request Oct 7, 2026
SummaryCoverage now records which columns a state summarizes as well as
which rows: `input` (the SummaryAgg update expression) and `group_by`
(its reduction). with_coverage rejects a SummaryAgg declaration whose
columns differ from the node's own (ColumnMismatch), and SummaryMerge
requires coverage on every input (UnknownInput) with identical columns.
merge_disjoint checks columns too. summary_input_data is removed. A
nested SummaryMerge carries no coverage until #646, so it is rejected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@zzylol
zzylol force-pushed the stack/528-02b-merge-structure branch from a5eb728 to 7ce0660 Compare October 7, 2026 14:55
@zzylol
zzylol force-pushed the stack/528-02c-coverage-derivation branch from 34c43f0 to fea4cc0 Compare October 7, 2026 15:02
@zzylol zzylol changed the title feat(ir): read summary coverage source and population from the subtree feat(ir): derive summary coverage from the subtree with one SummaryCoverage::derive Oct 7, 2026
@zzylol zzylol changed the title feat(ir): derive summary coverage from the subtree with one SummaryCoverage::derive feat(ir): derive summary coverage from the subtree with SummaryCoverage::derive Oct 7, 2026
zzylol added a commit that referenced this pull request Oct 7, 2026
Mark the summary-operator part as implemented, show the SummaryCoverage
fields, list merge_disjoint/validate as private to derive, and replace
the dropped same-input merge rule and "checked declarations" with what
#646 does: an unreadable population has no coverage and cannot merge, and
coverage is never written by hand.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
zzylol added a commit that referenced this pull request Oct 7, 2026
Remove the coverage columns (input, group_by), check_columns and the
merge's coverage checks. SummaryMerge now only checks structure: at least
one input, every input is State with one state column and an identical
schema. Whether a structurally valid merge is semantically valid (same
computation, disjoint selections) is decided by summary coverage in #646,
following the design in #573.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
zzylol and others added 2 commits October 7, 2026 23:00
Coverage is derived from the node, never declared. For a SummaryAgg,
predicate conjuncts that lift through Filter, a range TimeRange, a
TimeShift without @ and direct-column Project items, and are a value set
or an interval on one column, form the selection; everything else stays
in the definition (the SummaryAgg with the selection removed). A
TimeRange(w) over TimeShift(s) gives the relative window (-(s+w), -s].

A SummaryMerge is valid only when its inputs have structurally equal
definitions (ignoring timing and guarantee) and pairwise disjoint
selections; OperatorNode::new and validate_structure enforce it. Its
coverage is the shared definition and the union of the selections,
joining adjacent windows and value sets.

OperatorNode.coverage becomes a private cache behind coverage():
ignored by equality, skipped by serde, emptied on clone. with_coverage,
requires_coverage and CoverageError::Missing are removed, as are the
coverage fields of CSE keys and FlatNode.

Design: docs/design_docs/proposals/asap-primitive-schema.md §4 (#573).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
…ections

From an independent review of the derivation:
- a column whose (table, name) is not unique in the agg child's schema
  cannot be named in a selection, so its conjuncts stay in the definition;
- value sets compare literals by typed order, so 1 and 1.0 (or NaN) are
  never proven different;
- a partly lifted Scan predicate is rebuilt with only its residual.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
@zzylol
zzylol force-pushed the stack/528-02c-coverage-derivation branch from 3721101 to ebd2a93 Compare October 7, 2026 23:07
zzylol added a commit that referenced this pull request Oct 7, 2026
…e interface in #646

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
@zzylol zzylol changed the title feat(ir): derive summary coverage from the subtree with SummaryCoverage::derive feat(ir): derive summary coverage as definition + selection Oct 7, 2026
zzylol added a commit that referenced this pull request Oct 7, 2026
…export

Coverage is derived from the node (#646), so timed copies no longer carry
it and PhysicalASAPDAGNode drops its coverage field.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
zzylol added a commit that referenced this pull request Oct 7, 2026
Planned summary states no longer declare coverage: it is derived from the
node (#646). Node copies use clone + field updates (the coverage cache is
private), physical DAG fixtures drop the removed coverage field, and the
design example uses with_new_children (#648).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants