Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .claude/agents/golang-expert.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,8 @@ You are a Go development specialist for ColdFront.
## Testing Approach

- Table-driven tests preferred
- Integration tests with a real database (the `ci/journey.sh` harness), not mocks
- Integration tests with a real database (the `ci/journey.sh` harness), not
mocks
- Hand-written mocks defined locally in test files when a unit needs one
- Test files next to the code they test
- Use `t.Helper()` in test utilities
7 changes: 4 additions & 3 deletions .claude/agents/postgres-expert.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,11 +23,12 @@ You are a PostgreSQL specialist for ColdFront.
- Index naming: `idx_{table}_{column}`
- Constraint naming: `chk_`, `fk_`, `{table}_{cols}_unique`
- `COMMENT ON` for schema objects
- Parameterized queries only; interpolate only sanitized identifiers, never values
- Parameterized queries only; interpolate only sanitized identifiers, never
values
- pgerrcode for error classification
- Idempotent migrations (`IF NOT EXISTS`)
- NEVER write plpgsql `EXCEPTION`/`SAVEPOINT` in the cold path — pg_duckdb rejects
subtransactions; use precondition checks instead
- NEVER write plpgsql `EXCEPTION`/`SAVEPOINT` in the cold path — pg_duckdb
rejects subtransactions; use precondition checks instead

## Replication Safety

Expand Down
9 changes: 6 additions & 3 deletions .claude/agents/security-auditor.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,11 +17,14 @@ You are a security specialist for ColdFront.

## Standards

- No hardcoded secrets (use config / environment variables / DuckDB persistent secrets)
- No real hostnames, buckets, accounts, keys, or paths in committed code, tests, docs, or commit messages
- No hardcoded secrets (use config / environment variables / DuckDB persistent
secrets)
- No real hostnames, buckets, accounts, keys, or paths in committed code,
tests, docs, or commit messages
- Parameterized queries; never concatenate values into SQL
- Input validation at all boundaries
- gitleaks must pass (no committed secrets)
- gosec findings must be addressed
- Principle of least privilege for database connections and app roles
(`grant_app_access`, the SECURITY DEFINER attach helpers, PGC_SUSET config GUCs)
(`grant_app_access`, the SECURITY DEFINER attach helpers, PGC_SUSET config
GUCs)
6 changes: 4 additions & 2 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,12 @@

## Checklist

- [ ] `./run-ci-local.sh` passes (gofmt, golangci-lint, build, pg_regress, journey)
- [ ] `./run-ci-local.sh` passes (gofmt, golangci-lint, build, pg_regress,
journey)
- [ ] Tests added/updated (test-first)
- [ ] Docs updated where applicable (README / USAGE / INSTALL / ARCHITECTURE)
- [ ] Bakery / mesh / distributed changes: TLA+ model updated and TLC re-checked (`docs/formal/`)
- [ ] Bakery / mesh / distributed changes: TLA+ model updated and TLC
re-checked (`docs/formal/`)
- [ ] Commit messages are short and imperative

## Related issues
Expand Down
14 changes: 8 additions & 6 deletions DUCKDB_1.5_PATCHED.md
Original file line number Diff line number Diff line change
Expand Up @@ -121,12 +121,14 @@ inside `DoTableUpdates` (PG `PRE_COMMIT`, while the ticket is held):
3 then land the write on the live head. An expired start snapshot keeps the
error.

**Formally verified** before the code (the project rule):
`docs/formal/Bakery.tla` models the async ordering; `Bakery_async.cfg`
(patched) holds `NoLakekeeperConflict`, `Bakery_race.cfg` (async **without**
the patch) violates it — the standing proof the patch is mandatory for async.
**Validated** over Azure ADLS: journey 6b (4 concurrent mixed-tier writers →
8/8, 0 loss) and 9b (8 concurrent cold writers → 8/8).
### Formally verified

Before the code (the project rule): `docs/formal/Bakery.tla` models the async
ordering; `Bakery_async.cfg` (patched) holds `NoLakekeeperConflict`,
`Bakery_race.cfg` (async **without** the patch) violates it — the standing
proof the patch is mandatory for async. **Validated** over Azure ADLS: journey
6b (4 concurrent mixed-tier writers → 8/8, 0 loss) and 9b (8 concurrent cold
writers → 8/8).

## 3. Strict-reader interop (two patches + one upstream fix)

Expand Down
20 changes: 16 additions & 4 deletions LICENSE.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,12 +2,24 @@ The PostgreSQL License

Portions copyright (c) 2026, pgEdge, Inc.

Permission to use, copy, modify, and distribute this software and its documentation for any purpose, without fee, and without a written agreement is hereby granted, provided that the above copyright notice and this paragraph and the following two paragraphs appear in all copies.
Permission to use, copy, modify, and distribute this software and its
documentation for any purpose, without fee, and without a written agreement is
hereby granted, provided that the above copyright notice and this paragraph and
the following two paragraphs appear in all copies.

IN NO EVENT SHALL pgEdge, Inc. BE LIABLE TO ANY PARTY FOR DIRECT, INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES, INCLUDING LOST PROFITS, ARISING OUT OF THE USE OF THIS SOFTWARE AND ITS DOCUMENTATION, EVEN IF pgEdge, Inc. HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
IN NO EVENT SHALL pgEdge, Inc. BE LIABLE TO ANY PARTY FOR DIRECT, INDIRECT,
SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES, INCLUDING LOST PROFITS, ARISING
OUT OF THE USE OF THIS SOFTWARE AND ITS DOCUMENTATION, EVEN IF pgEdge, Inc. HAS
BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

pgEdge, Inc. SPECIFICALLY DISCLAIMS ANY WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE SOFTWARE PROVIDED HEREUNDER IS ON AN "AS IS" BASIS, AND pgEdge, Inc. HAS NO OBLIGATIONS TO PROVIDE MAINTENANCE, SUPPORT, UPDATES, ENHANCEMENTS, OR MODIFICATIONS.
pgEdge, Inc. SPECIFICALLY DISCLAIMS ANY WARRANTIES, INCLUDING, BUT NOT LIMITED
TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE. THE SOFTWARE PROVIDED HEREUNDER IS ON AN "AS IS" BASIS, AND pgEdge,
Inc. HAS NO OBLIGATIONS TO PROVIDE MAINTENANCE, SUPPORT, UPDATES, ENHANCEMENTS,
OR MODIFICATIONS.

---

This software redistributes third-party components under their own licenses (DuckDB, pg_duckdb, duckdb-iceberg, and others). Those copyright and license notices are reproduced in [THIRD_PARTY_NOTICES.md](THIRD_PARTY_NOTICES.md).
This software redistributes third-party components under their own licenses
(DuckDB, pg_duckdb, duckdb-iceberg, and others). Those copyright and license
notices are reproduced in [THIRD_PARTY_NOTICES.md](THIRD_PARTY_NOTICES.md).
Loading
Loading