Align default rendered SQL masking contract - #27
Merged
Merged
Conversation
added 13 commits
September 28, 2026 08:47
Contributor
Author
|
Pre-merge conformance update:
Canonical cross-language evidence: |
philipgreat
marked this pull request as ready for review
September 29, 2026 03:57
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of teaql/teaql-conformance#58: default expanded SQL diagnostics with field-aware masking across seven runtimes.
Python runtime changes keep original typed SQL bindings while projecting policy-aware default logs. Old generated descriptors without entity-level mask metadata fail closed even if an older property said
plain; explicit empty metadata permits ordinary fields. Querycomment/purposein old generated requests are recovered when not explicitly set on the wrapper, and runtime-controlled warning/log outputs do not print private driver errors.Evidence for this Python PR head
57874a8(test-only successor to internal candidate source735f800):0.2.8+mask20260928.6was built from predecessor735f800, downloaded from the loopback Registry with identical SHA-256 and installed in an isolated venv.[REDACTED]while business results stay intact.PYTHONPATH=src: 283 passed, 8 skipped.Canonical evidence: release gate, Python
.6wheel, and current PostgreSQL/MySQL gates.Remaining: final untested output-path review, online generator rollout, main merge and public PyPI publication. This PR remains draft; the internal wheel is not public.
Update 2026-09-29 — current draft HEAD
1bde439: PYTHONPATH=src suite: 284 passed, 8 skipped. A successful query remains successful when its diagnostic sink throws. The previous internal candidate was built from an earlier source commit and does not contain this production fix; rebuild and rerun the internal Registry candidate gate before treating current HEAD as release-qualified. Seven-language source gate: 7/7 PASS. Fail-open evidence.Current-head artifact update: internal wheel
0.2.8+mask20260929.7was built from1bde439, byte-verified after Registry round-trip, and installed from the private PyPI index by a separate venv. The installed package passed 284 tests (8 skipped), including 37 SQL lifecycle tests. Temporary PATs were revoked. Exact candidate evidence. PostgreSQL/MySQL and newly generated workspaces still need.7replays; earlier.6results are historical, not.7proof.Update 2026-09-29 — current installed .7 wheel now passes an existing-generated PostgreSQL workspace upgrade replay (repeated schema ensure, generated audited Save/Q, original values, masked SQL), direct PostgreSQL provider new/legacy-metadata cases (2 passed), and a retained real PostgreSQL throwing-diagnostic-sink probe. The exact installed wheel version was asserted and dedicated databases were deleted. This is not yet a fresh-generator or MySQL .7 gate. Evidence and fixture: https://github.com/teaql/teaql-conformance/blob/docs/masking-release-gate-20260928/2026-09/202609290345-python-v7-postgres-generated-fail-open.md