Documentation
¶
Overview ¶
Package audit orchestrates audit use cases at the application layer. input: generated DDL coverage catalog JSON (embedded at compile time) and optional filesystem catalog paths output: catalog entries, catalog version, and filtered query results pos: application catalog query core for the CLI ddl-coverage command note: if this file changes, update this header and module README.md.
Package audit orchestrates audit use cases at the application layer. input: extracted domain statements and the registered rule engine output: aggregated report results with statement/global findings and preserved statement-level impact estimates pos: application evaluation step between extraction/metadata refinement and reporting note: if this file changes, update this header and module README.md.
Package audit enriches evaluated findings with shared explanation metadata. input: rule findings, shipped catalog entries, and optional statement metadata context output: additive per-finding explanation data without changing verdict semantics pos: application explanation enrichment between evaluation and report aggregation note: if this file changes, update this header and module README.md.
Package audit orchestrates audit use cases at the application layer. input: application-owned parsed SQL statements and parser-neutral extractors output: first-pass StatementSpec values plus attached shape-only impact facts for later rule evaluation pos: application extraction step between parsing and rule execution note: if this file changes, update this header and module README.md.
Package audit orchestrates audit use cases at the application layer. input: extracted statement-local DML shape facts plus optional metadata snapshots for refinement output: conservative DML impact estimates attached during extraction and upgraded after metadata enrichment pos: application impact estimation step between extraction, metadata enrichment, and rule evaluation note: if this file changes, update this header and module README.md.
Package audit orchestrates audit use cases at the application layer. input: optional metadata providers plus parsed statement targets for enrichment output: metadata-enriched statements with resolved target schemas for rules that can use live instance or schema facts pos: application-layer bridge between provider-backed metadata and domain statements note: if this file changes, update this header and module README.md.
Package audit provides application-layer parser mismatch hints. input: parser-failed MySQL or TiDB SQL text masked of literals and comments output: bounded PostgreSQL-syntax notice tokens without raw SQL payloads pos: application diagnostic hinting beside parser-error aggregation note: if this file changes, update this header and module README.md.
Package audit orchestrates audit use cases at the application layer. input: SQL text, selected dialect, shared input normalization, statement boundaries, and infrastructure-backed parser adapters output: application-owned parsed statements plus bounded per-statement parse failures for later audit aggregation pos: application parsing entrypoint between interfaces and parser infrastructure note: if this file changes, update this header and module README.md.
Package audit orchestrates audit use cases at the application layer. input: audit requests carrying SQL text, dialect, optional policy override paths, optional metadata providers, and shared input normalization output: end-to-end audit results assembled from policy loading, parsing, extraction, metadata enrichment, rule evaluation, and a review floor for partial parser failures and structured unsupported statements pos: application service entrypoint for the unified offline/metadata-aware SQL audit use case with preserved statement impact estimates note: if this file changes, update this header and module README.md.
Package audit orchestrates audit use cases at the application layer. input: normalized SQL text and its selected MySQL, TiDB, or PostgreSQL dialect output: ordered top-level statement slices with 1-based source start locations pos: bounded lexical statement-boundary scanner before dialect parser adapters note: if this file changes, update this header and module README.md.
Index ¶
- Constants
- Variables
- func AuditSQL(ctx context.Context, request Request) (report.Result, error)
- func EvaluateStatements(ctx context.Context, registry *rule.Registry, statements []spec.Statement) (report.Result, error)
- func Extract(ctx context.Context, parsed ParsedSQL) ([]spec.Statement, error)
- type CatalogEntry
- type CatalogQuery
- type CatalogResult
- type IndexOwnerResolver
- type MetadataProvider
- type MetadataRequest
- type ObjectResolver
- type ParsedSQL
- type ParsedStatement
- type PlanEstimator
- type PostgreSQLCapabilityBoundaryError
- type Request
- type Service
Constants ¶
const ( // DiagnosticParserError classifies parser-error outcomes. DiagnosticParserError = "parser_error" // DiagnosticUnsupportedStatement classifies structured unsupported outcomes. DiagnosticUnsupportedStatement = "unsupported_statement" // ParserErrorActionHint is the generic safe next step for parser-error diagnostics. ParserErrorActionHint = "" /* 138-byte string literal not displayed */ // UnsupportedActionHint is the generic safe next step for unsupported-statement diagnostics. UnsupportedActionHint = "" /* 131-byte string literal not displayed */ // DiagnosticGuidanceParserUpgradeCandidate identifies parser-error cases that would become // parseable after an upstream parser/library upgrade. DiagnosticGuidanceParserUpgradeCandidate = "parser_upgrade_candidate" // ParserUpgradeCandidateEvidenceRef is the stable GitHub documentation URL for parser-upgrade // candidate evidence. ParserUpgradeCandidateEvidenceRef = "https://github.com/Fanduzi/DeltaScope/blob/main/docs/reference/cli.md#parser-upgrade-candidate-evidence-v02500" )
Variables ¶
var ( // ErrEmptySQL indicates the request did not include auditable SQL text. ErrEmptySQL = errors.New("audit SQL must not be empty") // ErrUnknownDialect indicates the request did not specify a supported dialect. ErrUnknownDialect = errors.New("audit dialect must be mysql, tidb, or postgresql") // ErrUnsupportedStatement indicates at least one parsed statement is recognized but unsupported. ErrUnsupportedStatement = errors.New("audit includes unsupported statements") )
Functions ¶
Types ¶
type CatalogEntry ¶ added in v0.280.0
type CatalogEntry struct {
Dialect string `json:"dialect"`
Family string `json:"family"`
Form string `json:"form"`
Classification string `json:"classification"`
FindingRuleIDs []string `json:"finding_rule_ids"`
GuidanceCode string `json:"guidance_code,omitempty"`
EvidenceRef string `json:"evidence_ref,omitempty"`
Notes string `json:"notes"`
}
CatalogEntry represents a single DDL coverage catalog entry returned by QueryCatalog. Fields mirror the v0.270.0 catalog JSON schema.
func LoadCatalog ¶ added in v0.280.0
func LoadCatalog(path string) ([]CatalogEntry, error)
LoadCatalog reads the DDL coverage catalog from the given file path and returns entries in their canonical (deterministic) order.
func LoadCatalogFile ¶ added in v0.490.0
func LoadCatalogFile(path string) (string, []CatalogEntry, error)
LoadCatalogFile reads the generated catalog from path and returns its version plus entries in their canonical (deterministic) order.
func LoadEmbeddedCatalog ¶ added in v0.490.0
func LoadEmbeddedCatalog() (string, []CatalogEntry, error)
LoadEmbeddedCatalog returns the generated catalog compiled into the binary.
type CatalogQuery ¶ added in v0.280.0
type CatalogQuery struct {
Dialect string
Classification string
GuidanceCode string
Family string
Form string
Search string
Limit int
}
CatalogQuery holds filter parameters for querying the DDL coverage catalog. All string fields are optional; zero values mean "no filter".
func (CatalogQuery) Validate ¶ added in v0.280.0
func (q CatalogQuery) Validate() error
Validate checks that enum filter values are recognized. Returns an error describing the first invalid field, or nil.
type CatalogResult ¶ added in v0.280.0
type CatalogResult struct {
Entries []CatalogEntry `json:"entries"`
Total int `json:"total"`
}
CatalogResult holds the query output: a filtered slice of entries plus summary metadata.
func QueryCatalog ¶ added in v0.280.0
func QueryCatalog(entries []CatalogEntry, q CatalogQuery) CatalogResult
QueryCatalog filters entries according to the query parameters. It returns a CatalogResult with the matching entries preserving their original deterministic order, and a total count. Empty results are a success, not an error.
type IndexOwnerResolver ¶ added in v0.18.0
type IndexOwnerResolver interface {
ResolveTableForIndex(ctx context.Context, dialect spec.Dialect, schema string, index string) (string, error)
}
IndexOwnerResolver optionally resolves standalone index statements back to owning tables.
type MetadataProvider ¶
type MetadataProvider interface {
LoadInstanceFacts(ctx context.Context, dialect spec.Dialect, schema string) (*spec.InstanceFacts, error)
LoadTableSnapshot(ctx context.Context, dialect spec.Dialect, schema string, table string) (*spec.TableSnapshot, error)
}
MetadataProvider supplies optional instance and schema facts for one audit run.
type MetadataRequest ¶
type MetadataRequest struct {
Schema string
Provider MetadataProvider
}
MetadataRequest describes one optional metadata-aware audit invocation.
type ObjectResolver ¶ added in v0.90.0
type ObjectResolver interface {
ResolveObject(ctx context.Context, dialect spec.Dialect, request spec.ObjectLookupRequest) (*spec.ObjectSnapshot, error)
}
ObjectResolver optionally resolves non-table database objects from live metadata.
type ParsedSQL ¶
type ParsedSQL struct {
Dialect spec.Dialect `json:"dialect"`
Statements []ParsedStatement `json:"statements"`
Warnings []string `json:"warnings,omitempty"`
// contains filtered or unexported fields
}
ParsedSQL is the application-owned parsing result used by later extraction steps.
type ParsedStatement ¶
type ParsedStatement struct {
Kind spec.Kind `json:"kind"`
RawSQL string `json:"raw_sql"`
Line int `json:"line,omitempty"`
Column int `json:"col,omitempty"`
Extractor spec.StatementExtractor `json:"-"`
}
ParsedStatement keeps application-facing statement metadata while hiding parser nodes.
type PlanEstimator ¶ added in v0.18.0
type PlanEstimator interface {
LoadPlanEstimate(ctx context.Context, statement spec.Statement) (*spec.ImpactEstimate, error)
}
PlanEstimator optionally loads planner-backed DML impact estimates.
type PostgreSQLCapabilityBoundaryError ¶ added in v0.20.0
type PostgreSQLCapabilityBoundaryError struct {
Message string
}
PostgreSQLCapabilityBoundaryError reports that PostgreSQL parsing needs a PostgreSQL-capable build.
func (*PostgreSQLCapabilityBoundaryError) Error ¶ added in v0.20.0
func (e *PostgreSQLCapabilityBoundaryError) Error() string
type Request ¶
type Request struct {
SQL string
Dialect spec.Dialect
ConfigPath string
Schema string
MetadataProvider MetadataProvider
Metadata *MetadataRequest
}
Request describes one application-level audit invocation.