Severity: P2 (downgraded from P1 by the verifier). Confidence: medium.
Affected files:
providers/azure/services/database/client.go:321
providers/azure/services/synapse/client.go:271
providers/azure/recommendations.go:407
providers/azure/services/compute/exchange.go:146
Evidence:
database/client.go:321 builds the calculatePrice/purchase body with "reservedResourceType": "SqlDatabase" and synapse/client.go:271 with "SqlDW". The vendored armreservations v1.1.0 enum defines ReservedResourceTypeSQLDatabases = "SqlDatabases" and ReservedResourceTypeSQLDataWarehouse = "SqlDataWarehouse"; neither hand-written variant appears in PossibleReservedResourceTypeValues(). The codebase's own inbound Advisor mapping agrees with the plural form (case "sqldatabases"), and the compute client correctly uses the SDK constant for reads. Per known-issues #731, non-VM Azure purchases have been 403-blocked, so these values have plausibly never been exercised live.
Impact:
When the #731 role fix lands, Azure SQL Database / Synapse reservation calculatePrice calls will likely be rejected with a 400 for an invalid reservedResourceType, breaking the purchase path for those services. Repeats the exact failure mode of PR #1047 ("MEMORY_MB" instead of SDK "MEMORY") flagged in the project's memory garden.
Recommendation:
Replace the raw literals with string(armreservations.ReservedResourceTypeSQLDatabases) / ReservedResourceTypeSQLDataWarehouse; audit "SearchService" and managedredis "RedisCache" against the live catalog; add a unit test asserting every purchase body's reservedResourceType is a member of PossibleReservedResourceTypeValues(). Also check the singular 'SqlDatabase' Advisor filter at database/client.go:173.
Verifier verdict: downgraded to P2 - fully verified factually, but the failure mode is fail-loud and side-effect-free (calculatePrice rejects before money moves) and the path is unreachable live today, so it is a latent within-months bug, not P1.
Source: docs/reviews/codebase-review-2026-06-10.md (automated multi-dimension code review, adversarially verified for P1/P2)
Severity: P2 (downgraded from P1 by the verifier). Confidence: medium.
Affected files:
providers/azure/services/database/client.go:321providers/azure/services/synapse/client.go:271providers/azure/recommendations.go:407providers/azure/services/compute/exchange.go:146Evidence:
database/client.go:321 builds the calculatePrice/purchase body with
"reservedResourceType": "SqlDatabase"and synapse/client.go:271 with"SqlDW". The vendored armreservations v1.1.0 enum definesReservedResourceTypeSQLDatabases = "SqlDatabases"andReservedResourceTypeSQLDataWarehouse = "SqlDataWarehouse"; neither hand-written variant appears in PossibleReservedResourceTypeValues(). The codebase's own inbound Advisor mapping agrees with the plural form (case "sqldatabases"), and the compute client correctly uses the SDK constant for reads. Per known-issues #731, non-VM Azure purchases have been 403-blocked, so these values have plausibly never been exercised live.Impact:
When the #731 role fix lands, Azure SQL Database / Synapse reservation calculatePrice calls will likely be rejected with a 400 for an invalid reservedResourceType, breaking the purchase path for those services. Repeats the exact failure mode of PR #1047 ("MEMORY_MB" instead of SDK "MEMORY") flagged in the project's memory garden.
Recommendation:
Replace the raw literals with
string(armreservations.ReservedResourceTypeSQLDatabases)/ReservedResourceTypeSQLDataWarehouse; audit "SearchService" and managedredis "RedisCache" against the live catalog; add a unit test asserting every purchase body's reservedResourceType is a member of PossibleReservedResourceTypeValues(). Also check the singular 'SqlDatabase' Advisor filter at database/client.go:173.Verifier verdict: downgraded to P2 - fully verified factually, but the failure mode is fail-loud and side-effect-free (calculatePrice rejects before money moves) and the path is unreachable live today, so it is a latent within-months bug, not P1.
Source: docs/reviews/codebase-review-2026-06-10.md (automated multi-dimension code review, adversarially verified for P1/P2)