fix(vector): harden direct pgvector parity
This commit is contained in:
@@ -48,3 +48,28 @@ deprecation warnings.
|
||||
- The legacy single `connection` form stays read-only through the public port, matching its
|
||||
previous adapter behavior, while remaining available to the explicitly documented bulk-loader
|
||||
transition.
|
||||
|
||||
## Review fix wave
|
||||
|
||||
The Task 1 review findings were addressed in a follow-up TDD cycle:
|
||||
|
||||
- Search now validates requested kinds against the global known-kind set, intersects valid kinds
|
||||
with each collection, and skips unrelated collections. A direct-versus-HTTP parity test covers
|
||||
the multi-collection case.
|
||||
- Health requires all three allowlisted tables, an `embedding vector(N)` column on every table,
|
||||
the expected dimension on every table, and the appropriate read or write table privileges for
|
||||
each configured side. Empty and partial schemas return deterministic, credential-free details;
|
||||
unexpected database failures expose only their exception class.
|
||||
- The Docker L0 fixture now provisions separate least-privilege reader and writer roles. Tests
|
||||
prove the reader cannot insert, the writer cannot execute the cosine-search SELECT, and the
|
||||
adapter still routes search to the reader and upsert/hash operations to the writer. Direct
|
||||
upsert uses an atomic `INSERT ... ON CONFLICT DO NOTHING` followed by `UPDATE` for an existing
|
||||
key, avoiding broad SELECT authority while retaining conflict-safe hash/upsert semantics.
|
||||
|
||||
Fresh verification after the fix wave:
|
||||
|
||||
- Docker L0 + HTTP port/search parity: `42 passed` (earlier checkpoint); the final L0 file has
|
||||
`16 passed` including the stricter raw-role search denial.
|
||||
- Expanded focused adapter/config suite: `56 passed`.
|
||||
- Full harness: `466 passed, 5 deselected`.
|
||||
- Changed-file Ruff lint/format and `git diff --check`: clean.
|
||||
|
||||
Reference in New Issue
Block a user