Repository navigation
Conversation
52b4003 to
8f58489
Compare
996294c to
764088d
Compare
…low multi-source summaries Review of #560/#646 found four problems: 1. Population names came from each node's schema, which `with_schema` may rename. A scan whose `tier` column is named "region" made `tier = 'eu'` read as `{region: eu}`, so a merge with a real `{region: us}` state was accepted and double-counted. Columns are now named from the Scan operator's own schema, and a path that renames a field leaves the population unknown. 2. For the same reason a merge could mix states of different columns (`Named("latency")` reading `size` on a renamed scan). An unknown population only merges with the same input, so this is rejected too. 3. `OperatorNode::map_children` dropped a SummaryAgg's coverage, so rebuilding a merge (e.g. in canonicalize) failed. A rebuild now keeps the declared time bounds and reads source and population again. 4. A SummaryAgg over two sources (a join, an IN subquery over another table) could never validate. It now carries no coverage and cannot be merged. Adds summary_coverage_derivation.rs; the four regression tests fail before this change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
| /// scanned below it and the population its filters restrict to, over | ||
| /// `time_ms`. `None` when `summary` is not a `SummaryAgg` or does not | ||
| /// read exactly one source. | ||
| pub fn for_summary(summary: &OperatorNode, time_ms: Option<Range<i64>>) -> Option<Self> { |
There was a problem hiding this comment.
The naming of time_ms seems not good. I assume you want conceptually a "range" here?
There was a problem hiding this comment.
yes, I will rename to "time_range"
There was a problem hiding this comment.
Done in fea4cc0: CoverageRegion.time_ms is now time_range, and so is the parameter of derive/with_time_range.
| source: summary.scanned_source()?, | ||
| regions: vec![CoverageRegion { | ||
| time_ms, | ||
| population: summary.derived_population().unwrap_or_default(), |
There was a problem hiding this comment.
Bug here: If derived_population() returns None, it will be converted to the default legal value of population.
The problem is in derived_population() semantic, None means I cannot handle this population so it should not be used. While this treacherous unwrap_or_default() silently convert this into a legal value!
Spotting this bug actually makes me feel better: At least it proves reading code is still somehow useful.
There was a problem hiding this comment.
Fixed in fea4cc0. An unreadable population is now an error, UnprovenPopulation, never the empty (unrestricted) map. Such a SummaryAgg is still valid but has no coverage, so it cannot be merged, and a merge with it reports UnprovenPopulation. The same-input exception for unreadable populations is dropped.
| if summary.scanned_source().as_ref() != Some(&self.source) { | ||
| return Err(CoverageError::SourceMismatch); | ||
| } | ||
| let derived = summary.derived_population().unwrap_or_default(); |
There was a problem hiding this comment.
Same. Check if there is bug here
There was a problem hiding this comment.
Same fix: check_against is removed. validate_structure compares the retained coverage with SummaryCoverage::derive, which fails with UnprovenPopulation instead of defaulting.
| } | ||
| if let (Some(coverage), Some(ASAPOp::SummaryAgg { .. })) = (&self.coverage, rebuilt.asap()) | ||
| { | ||
| let population = rebuilt.derived_population().unwrap_or_default(); |
There was a problem hiding this comment.
Seemingly a bug. Check other comments related
…low multi-source summaries Review of #560/#646 found four problems: 1. Population names came from each node's schema, which `with_schema` may rename. A scan whose `tier` column is named "region" made `tier = 'eu'` read as `{region: eu}`, so a merge with a real `{region: us}` state was accepted and double-counted. Columns are now named from the Scan operator's own schema, and a path that renames a field leaves the population unknown. 2. For the same reason a merge could mix states of different columns (`Named("latency")` reading `size` on a renamed scan). An unknown population only merges with the same input, so this is rejected too. 3. `OperatorNode::map_children` dropped a SummaryAgg's coverage, so rebuilding a merge (e.g. in canonicalize) failed. A rebuild now keeps the declared time bounds and reads source and population again. 4. A SummaryAgg over two sources (a join, an IN subquery over another table) could never validate. It now carries no coverage and cannot be merged. Adds summary_coverage_derivation.rs; the four regression tests fail before this change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
b727827 to
34c43f0
Compare
| /// scanned below it and the population its filters restrict to, over | ||
| /// `time_ms`. `None` when `summary` is not a `SummaryAgg` or does not | ||
| /// read exactly one source. | ||
| pub fn for_summary(summary: &OperatorNode, time_ms: Option<Range<i64>>) -> Option<Self> { |
There was a problem hiding this comment.
This function is also treacherous and shady. It is called for_summary but practically only works for SummaryAgg nodes. Some problems in PR #560 is related to this.
There was a problem hiding this comment.
Fixed in fea4cc0. for_summary is gone, and so is of_merge from #560. Coverage is now computed by one function for every summary node:
pub fn derive(node: &OperatorNode, time_range: Option<Range<i64>>) -> Result<SummaryCoverage, CoverageError>SummaryAgg → source, population and columns read from its subtree over time_range; SummaryMerge → the disjoint union of its inputs (time_range must be None); anything else → NotSummary. OperatorNode::new, with_time_range (replaces with_coverage), validate_structure and with_new_children all call it; check_against, same_input and the public scanned_source/derived_population are removed.
…sketches SummaryMerge no longer derives or checks coverage: of_merge, UnknownInput and MergeOutputMismatch are removed and summary_coverage.rs matches main. Coverage for all summary nodes will be derived by one function in #646. The heap-based sketch restriction is also dropped. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SummaryCoverage now records which columns a state summarizes as well as which rows: `input` (the SummaryAgg update expression) and `group_by` (its reduction). with_coverage rejects a SummaryAgg declaration whose columns differ from the node's own (ColumnMismatch), and SummaryMerge requires coverage on every input (UnknownInput) with identical columns. merge_disjoint checks columns too. summary_input_data is removed. A nested SummaryMerge carries no coverage until #646, so it is rejected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SummaryCoverage records which columns a state summarizes (input, group_by) as well as which rows. Update the SummaryAgg and SummaryMerge examples to #560: merges compare coverage columns, carry no coverage until #646, and merged_coverage is gone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…sketches SummaryMerge no longer derives or checks coverage: of_merge, UnknownInput and MergeOutputMismatch are removed and summary_coverage.rs matches main. Coverage for all summary nodes will be derived by one function in #646. The heap-based sketch restriction is also dropped. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SummaryCoverage now records which columns a state summarizes as well as which rows: `input` (the SummaryAgg update expression) and `group_by` (its reduction). with_coverage rejects a SummaryAgg declaration whose columns differ from the node's own (ColumnMismatch), and SummaryMerge requires coverage on every input (UnknownInput) with identical columns. merge_disjoint checks columns too. summary_input_data is removed. A nested SummaryMerge carries no coverage until #646, so it is rejected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
a5eb728 to
7ce0660
Compare
34c43f0 to
fea4cc0
Compare
Mark the summary-operator part as implemented, show the SummaryCoverage fields, list merge_disjoint/validate as private to derive, and replace the dropped same-input merge rule and "checked declarations" with what #646 does: an unreadable population has no coverage and cannot merge, and coverage is never written by hand. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Remove the coverage columns (input, group_by), check_columns and the merge's coverage checks. SummaryMerge now only checks structure: at least one input, every input is State with one state column and an identical schema. Whether a structurally valid merge is semantically valid (same computation, disjoint selections) is decided by summary coverage in #646, following the design in #573. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
Coverage is derived from the node, never declared. For a SummaryAgg, predicate conjuncts that lift through Filter, a range TimeRange, a TimeShift without @ and direct-column Project items, and are a value set or an interval on one column, form the selection; everything else stays in the definition (the SummaryAgg with the selection removed). A TimeRange(w) over TimeShift(s) gives the relative window (-(s+w), -s]. A SummaryMerge is valid only when its inputs have structurally equal definitions (ignoring timing and guarantee) and pairwise disjoint selections; OperatorNode::new and validate_structure enforce it. Its coverage is the shared definition and the union of the selections, joining adjacent windows and value sets. OperatorNode.coverage becomes a private cache behind coverage(): ignored by equality, skipped by serde, emptied on clone. with_coverage, requires_coverage and CoverageError::Missing are removed, as are the coverage fields of CSE keys and FlatNode. Design: docs/design_docs/proposals/asap-primitive-schema.md §4 (#573). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
…ections From an independent review of the derivation: - a column whose (table, name) is not unique in the agg child's schema cannot be named in a selection, so its conjuncts stay in the definition; - value sets compare literals by typed order, so 1 and 1.0 (or NaN) are never proven different; - a partly lifted Scan predicate is rebuilt with only its residual. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
3721101 to
ebd2a93
Compare
…e interface in #646 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
…export Coverage is derived from the node (#646), so timed copies no longer carry it and PhysicalASAPDAGNode drops its coverage field. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
Planned summary states no longer declare coverage: it is derived from the node (#646). Node copies use clone + field updates (the coverage cache is private), physical DAG fixtures drop the removed coverage field, and the design example uses with_new_children (#648). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W7qG9aFyPij5uWsyAJCxDW
Closes #570.
Why
A summary state's schema says what kind of state it is (KLL, k=200, by job), not what it summarizes. #560 makes
SummaryMergestructurally valid, but structure cannot tell a KLL overlatencyfrom one oversize, nor show that two inputs share no row. This PR derives what each summary state covers from its sub-DAG and uses it to decide whether a merge is valid. The design is in #573 (§4), based on Goldstein & Larson's view matching (SIGMOD 2001).Before this PR (main + #560): coverage was declared by whoever built the node and never checked against the sub-DAG.
After this PR: nothing is declared. Both states derive
selection {region ∈ {us}}over the samedefinition, so the merge fails withPossibleOverlap.What
Coverage = definition (what the state computes) + selection (which output rows of that computation it took):
Filter, a rangeTimeRange, aTimeShiftwithout@, and direct-columnProjectitems up to theSummaryAgg(includingSummaryAgg.filterandScan.predicates), and it is a value set (=,!=,IN,NOT IN,ORof equalities) or an interval (<,<=,>,>=) on one column. Columns are identified by(table, name), soshipping.regionandbilling.regionstay distinct. A column whose(table, name)is not unique in the agg child (two items aliasedk) is not lifted, and value sets compare literals by type, so1and1.0are never proven different. One rangeTimeRange(w)overTimeShift(s)gives the relative window(−(s+w), −s]; PromQL ranges are left-open.SummaryAggwith what was lifted removed. Everything else (arithmetic, regex,rate, instant selectors, …) stays in it as a residual, so states that differ there do not merge.timingandguarantee, so ingestion-time and query-time panes can merge) and pairwise disjoint selections. Its coverage is the shared definition and the union of the selections; adjacent windows and value sets join, gaps stay separate boxes. Merges nest.Not in this PR (each follows when a caller needs it, per #573 §4.4):
SummaryMerge { group_by }(rollup), family-specific overlap rules (HLL may overlap), hash-partition constraints, lifting throughAggregate/window/ratepartition columns, and SQL timestamp intervals (the IR has no timestamp literal yet).Key code interfaces
summary_coverage.rs,node.rsOperatorNode::newandvalidate_structurereject an invalidSummaryMerge.with_coverage,requires_coverage,CoverageError::Missing, and the coverage fields of CSE keys andFlatNode.Tests
crates/types/tests/summary_coverage.rscovers each rule: filters and scan predicates lifting, population and value-range merges, overlap rejection, different inputs and different scan schemas, qualified columns, time panes (join, gap, overlap), residuals, instant selectors, nested merges, timing, a forged merge caught byvalidate_structure, and three regressions from an independent review (ambiguous column names, literals of different types, partly lifted scan predicates), each confirmed failing before the fix. Workspace tests,cargo fmtand workspace/all-targets Clippy with warnings denied pass.Base: #560 · Next: #539 · Tracker: #528 · Design: #573
🤖 Generated with Claude Code