Skip to content

fix: avoid crash on invalid selection sets - #336

Merged
kamilkisiela merged 2 commits into
mainfrom
fix/composition-crash-on-unresolvable-selection-set
Sep 22, 2026
Merged

kamilkisiela merged 2 commits into
mainfrom
fix/composition-crash-on-unresolvable-selection-set

Conversation

@kamilkisiela

@kamilkisiela kamilkisiela commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Composition could throw while validating @requires, @key, @provides, or @fromContext selection sets when subgraphs disagreed on a field type.

The selection-dependent validation rules were running before other supergraph rules had a chance to report errors such as EXTERNAL_TYPE_MISMATCH.

This changes validation to:

  1. Run the regular supergraph rules first.
  2. Return immediately if they report composition errors.
  3. Run satisfiability and auth-related selection validation only when the merged supergraph state is valid.

Also adds a regression test for EXTERNAL_TYPE_MISMATCH with a field referenced by @requires.

@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Snapshot Release (alpha)

The latest changes of this PR are available as alpha on npm (based on the declared changesets):

Package Version Info
@theguild/federation-composition 0.26.3-alpha-20260922143049-1f136474dd0ee3b4421ec6680d81c9e78ff9db28 npm ↗︎ unpkg ↗︎

…ection set

`@requires`/`@key`/`@provides`/`@fromContext` selection sets are written against a
single subgraph, but `SelectionResolver` and the auth rules resolve them against the
merged supergraph state. When subgraphs disagree on a field's type, the selection can
point at a field the merged type does not have, and both throw a raw `Error`.

All `postSupergraphRules` ran in one pass, and `SatisfiabilityRule` built its graph at
rule-construction time, so the throw beat `FieldsOfTheSameTypeRule` to reporting the
mismatch that caused it.

Run the selection-dependent rules in a second pass, only once the other rules confirmed
the merged state is coherent. Costs one extra traversal on the happy path, ~2% on an
18-subgraph compose.
@kamilkisiela
kamilkisiela force-pushed the fix/composition-crash-on-unresolvable-selection-set branch from eac3247 to b937358 Compare September 22, 2026 14:23
@kamilkisiela kamilkisiela changed the title fix: report composition error instead of throwing on unresolvable selection set fix: avoid crash on invalid selection sets Sep 22, 2026
Comment thread .changeset/lucky-beers-invite.md Outdated
@kamilkisiela
kamilkisiela merged commit 12a4834 into main Sep 22, 2026
5 checks passed
@kamilkisiela
kamilkisiela deleted the fix/composition-crash-on-unresolvable-selection-set branch September 22, 2026 14:44
kamilkisiela pushed a commit that referenced this pull request Sep 22, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @theguild/federation-composition@0.26.3

### Patch Changes

-
[#336](#336)
[`12a4834`](12a4834)
Thanks [@kamilkisiela](https://github.com/kamilkisiela)! - Report
composition errors instead of throwing when `@requires`, `@key`,
`@provides`, or `@fromContext` selections cannot be resolved against the
merged supergraph.

Selection-dependent validation now runs only after the other supergraph
rules confirm the merged state is valid.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant