writeonce/tests/corpus/run/table-residency-legal/fixture.wo
shoney.arickathil e120129f2c feat(woc): WO-E224 — refuse a durable ref into a volatile table
Task 2 of docs/superpowers/plans/2026-08-26-table-residency.md.

- the check lives in `check_field_types`, which already runs over the raw AST
  (so the diagnostic lands at the field's own position, once per declaration)
  in Pass 2 with `syms` fully built
- only the durable -> volatile direction is refused. volatile -> durable is
  legal: the referencing row is the one that disappears, so nothing is left
  holding a stale id
- the message names both classes and both escapes, because "this is wrong" is
  less useful than "make Session durable, or declare Order volatile too"
- sees through a `?` wrapper, so `?ref S` is caught too
- code picked as 24 by sweeping `<stage>_prefix ^ "NN"` — 01-23, 25, 26 and
  50 were taken, so 24 was a genuine hole. Grepping the literal WO-E224
  would have found nothing, which is how ten codes once went missing
- catalogued in the same commit, and the completeness sweep re-run: 53
  emitted, 54 catalogued (the extra is retired WO-W201), none missing

PLAN CORRECTION: the plan's second step said to apply the same check to
`backlink` fields. Dropped — a backlink is "NOT a stored column" (ast.ml:72),
so after a restart it resolves to an EMPTY COLLECTION, which is a legal state
indistinguishable from "nothing references me". There is no id to dangle.
Implementing it would have refused correct programs; a spurious diagnostic is
worse than a missing one. A run fixture now pins that the backlink shape stays
legal, so the check cannot silently grow over-broad later.

Gates: woc-test 557/0, oop-e2e 118/0 (was 116 — one compile-fail and one run
fixture added), employee 8/0, db-actor 8/0; employee, db-bench, db-actor,
porch, log-watcher and gc-cycle all still typecheck.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-26 23:09:40 +02:00

39 lines
1.1 KiB
Text

-- databasev2 2: the directions that are LEGAL, so WO-E224 cannot quietly
-- grow over-broad. Three shapes must all compile and run:
-- 1. volatile -> durable ref: the referencing row is the one that
-- disappears, so nothing is left holding a stale id.
-- 2. a backlink on a durable table whose referencer is volatile: a
-- backlink stores NO column, so after a restart it resolves to an
-- empty collection — a legal state, not a dangling id.
-- 3. durable -> durable, the ordinary case.
@table(name: "users", index: [name])
class User {
name: Text
visits: backlink Visit.who
}
@table(name: "visits", durable: false, index: [who])
class Visit {
who: ref User
note: Text
}
@table(name: "audits", index: [who])
class Audit {
who: ref User
what: Text
}
fn main() -> Int {
let u = insert User { name: "asha" };
insert Visit { who: u, note: "scratch" };
insert Audit { who: u, what: "kept" };
for v in from x in Visit select x {
print("visit ${v.note}");
}
for a in from x in Audit select x {
print("audit ${a.what}");
}
return 0;
}