feat(platform)!: string equality for enums in propertyConstraints rules (PV14) - #5042
Conversation
…es (PV14)
A propertyConstraints rule may now compare a string property with string
constants: `{ "equal": [path, { "const": "closed" }] }` or notEqual,
either way round, and `{ "in": [path, ["open", "pending"]] }`. Strings are
only compared for equality; a string the document leaves out equals no
constant. When the property declares an enum, every constant compared
with it must be one of its values, so a typo is refused at registration.
is_key_id_schema's $ref-following walker is extracted as schema_at_path,
shared with the enum check, without behaviour change.
Extended in place in meta-schema v3 and parse_property_constraints 0:
every declaration valid before parses and evaluates as it did.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
📖 Book Preview built successfully. Download the preview from the workflow artifacts. Updated at 2026-09-27T08:24:12.993Z |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: dashpay/platform/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (12)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughProperty constraints now support string-property equality, inequality, and membership conditions. Schema validation checks property types and enum values. Tests and documentation cover the new forms and their behavior for missing or non-string values. ChangesString property constraints
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to The string constraints remain scoped to version 14, and enum constants are validated. No identified issue blocks merging after normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to String-based rules can now determine whether contracts and document writes are accepted. The inspected registration and validation paths retain type, enum, size, and protocol-version controls, and no concrete security bypass was established. Direct evidence for string rules on replacement and recovery paths remains limited, so the consensus impact warrants review. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🕓 Queued for automated review — 2nd in line, estimated start in ~15 min (commit 4626038)
|
Basic explanation
What this does: A
propertyConstraintsrule can now compare a string property with fixed strings, which is how enum-style properties likestatusare written:{ "equal": ["status", { "const": "closed" }] },notEqual, or{ "in": ["status", ["open", "pending"]] }. Until now rules could only read numbers and booleans.Value: Rules like "a closed order must have a
closedAt" or "only a cancelled offer may carry a refund" become expressible for the many schemas that use string enums. When the property declares anenum, a misspelled constant ("closd") is refused when the contract registers. Without that check it would silently make the rule never hold.Risks: Low. This changes consensus validation, but only in protocol version 14, which is not on mainnet. It only widens what is accepted: a string constant was refused everywhere before, and every rule that registered before evaluates the same way.
Issue being fixed or feature implemented
Follow-up to the
propertyConstraintsseries (#4962, #5036, #5037, #5038, #5040). Conditional rules usually hinge on an enum-like status, and most schemas spell those as strings.What was done?
Grammar
In an operand a string on its own is a property path, so a string constant needs a wrapper.
constis JSON Schema's word for "exactly this value":{ "equal": [path, { "const": "closed" }] }ornotEqual, with the constant on either side. The other side must be a property path, not an expression.{ "in": [path, ["open", "pending"]] }. The values aninlists are literals, so strings need no wrapper. There must be two or more, with no two alike and no mixing with integers.lessThanwith aconst, or aconstinside arithmetic, is refused.Before, this rule was refused when the contract registered (the meta-schema knew no
const). Now it registers:{}{ "status": "open" }{ "status": "closed", "closedAt": 1000 }{ "status": "closed" }closedNeedsClosedAtNotMetSemantics
notEqualholds for it, whileequalandindo not.presentandabsenttest for it directly. Unlike integers there is no default value.PropertyConstraintViolationis added.Registration checks (on every parse)
enum, every constant compared with it must be one of the enum's values:rule "r" compares "status" with "closd", which is not one of its enum values. Otherwise any string is allowed.const:{ "equal": ["status", "closed"] }still means two paths. That read now points at the string forms:... has type string, not integer or boolean: a string property is compared with a { "const": ... } by equal or notEqual, or with the strings an in lists.constcounts as one node, soequalof a path and aconstcosts 3 nodes, the same as comparing a path with a number. Aninover strings costs 2 plus one per value.Code
property_constraints/mod.rs:PropertyConstraint::TextCompare { comparison, path, value }(the constant is normalised to one side, so either spelling is the same condition) andTextIn { path, values: BTreeSet<String> };PropertyRead::Textandtext_constants();text_comparisonandin_text_values;text_value.try_from_schema/mod.rs:Textread check and the enum check;is_key_id_schema's$ref-following schema walker extracted asschema_at_path, which both now use. Behaviour is unchanged, since it returnsNoneexactly where the old code returnedfalse.const(a string) as an operand key, andinvalues that are all integers or all strings, plus description updates.SystemLimits,DocumentTypeV2andPROPERTY_CONSTRAINTSdocs.How Has This Been Tested?
property_constraints/tests.rs:in;const, a non-stringconst, twoconsts, aconstagainst an expression, aconstinside arithmetic, stringinshape, mixed and duplicate values;text_constants, and the either-side repeat.try_from_schema/v3/property_constraints_tests.rs(theorderschema gains an enumstate):equaland ininrefused;constand bad stringinlists.batch/tests/document/property_constraints.rs: theofferfixture gains an enumstatusand aclosedAt, withclosedNeedsClosedAt(notEqual/const) andclosedAtOnlyWhenClosed(stringin).should_compare_a_string_property_with_constantsruns real creates (two refused with 10422, three accepted).cargo test -p dpp --lib(4862 passed),cargo test -p drive-abci --lib property_constraints(13 passed),cargo clippy -p dpp --all-features --all-targets -- -D warnings,cargo clippy -p drive-abci --all-targets -- -D warnings.Breaking Changes
Consensus, protocol version 14 only: contracts may now register rules comparing string properties with constants, which earlier 4.2 builds refuse. Meta-schema v3,
parse_property_constraints0 andvalidate_property_constraints0 were introduced in protocol version 14, which is not released on mainnet, so they are extended in place. Every declaration valid before parses and evaluates identically.is_key_id_schema(theencryptedForkey id check) was refactored without behaviour change.Rust API:
PropertyConstraintgainsTextCompareandTextIn, andPropertyReadgainsText.Checklist:
structure.rs, regeneratedgrovedb-structure.json, and checked the structure viewer link posted on this pull requestFor repository code-owners and collaborators only
🤖 Generated with Claude Code
PR Hygiene ·
4626038/skip-botsproceeds without the ones not yet reported/self-reviewedonce the bots are donejs-wasm-sdk(packages/js-evo-sdk/README.md) — shumkovdpp— you own itrs-drive-abci— you own itWhen every box is checked the
PR Hygienecheck passes and this can merge.Summary by CodeRabbit