fix(clickhouse): render mutation params without connection context - #111086
Conversation
|
😎 Merged successfully - details. |
|
Risk: No findings The change makes Sentinel reviewed |
|
[Medium risk] Changes how mutation SQL parameters are escaped in the database layer. The PR appears safe to merge. Reviews (1) · Last reviewed commit: "Merge branch 'master' of github.com:Post..." |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
🧰 Additional context used📚 Code guidelines (6)📝 WalkthroughWalkthroughWhen Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to Time-range deletion lookups with timezone-aware datetimes should now work on a fresh ClickHouse client. No merge-blocking risk remains. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change restores timezone-aware deletion requests through the existing database client and parameter controls. No expanded database authority or new security issue was demonstrated. Recovery after an interrupted initialization query remains unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 1✅ Passed checks (1 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: PostHog/posthog/.coderabbit.yaml
Review profile: QUIET
Plan: Enterprise
Run ID: 4f9d5e6e-a4cb-4173-b4c2-962b92389689
📒 Files selected for processing (2)
posthog/clickhouse/cluster.pyposthog/clickhouse/test/test_cluster.py
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.
HostHog preview —
|
🤖 CI report
|
…posthog into bc/fix-mutation-tz-param-render
There was a problem hiding this comment.
🧹 Nitpick comments (1)
posthog/clickhouse/test/test_cluster.py (1)
430-433: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winState the invariant, not the change history.
This docstring describes how the previous implementation failed. Replace that account with the test’s required behavior: a fresh client renders timezone-aware parameters in the server timezone. As per coding guidelines, “Never record how the code got here.”
Source: Coding guidelines
ℹ️ Review info
⚙️ Run configuration
- Configuration used: Repository: PostHog/posthog/.coderabbit.yaml
- Review profile: QUIET
- Plan: Enterprise
- Run ID:
16788e6b-0492-4f23-aedd-177c0d8b10d9
📒 Files selected for processing (2)
posthog/clickhouse/cluster.pyposthog/clickhouse/test/test_cluster.py
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.
Problem
Data deletion requests that carry a time range (
event_removalin immediate mode) fail before any mutation is submitted, with'NoneType' object has no attribute 'get_timezone', so the deletion never runs.MutationRunner.find_existing_mutationsrenders each command withclient.substitute_params(..., client.connection.context). For tz-awaredatetimeparameters, clickhouse-driver readscontext.server_info.get_timezone(), butserver_infostaysNoneuntil the client has executed a query. Clients pulled fresh from the pool hit this on their first call.Changes
find_existing_mutationsconnects a not-yet-connected client withSELECT 1, then renders with the client's own context, matching howclient.executerenders the submitted mutation in the server timezone.SELECT 1is used instead offorce_connect(), which leaves the connection marked mid-query and makes the nextexecuteraisePartiallyConsumedQueryError.$__sql$heredoc protection is unchanged: rendered commands are still bound as ordinary parameters.How did you test this code?
pytest posthog/clickhouse/test/test_cluster.py -k "tz_aware or delimiter_shaped"run locally.Test rationale:
test_find_existing_mutations_renders_tz_aware_datetimes_before_connectingcovers an unconnected client with a tz-aware datetime against a non-UTC server, asserting the client connects first and the lookup renders in the server timezone like submission does. The closest existing test,test_find_existing_mutations_handles_delimiter_shaped_parameter_value, uses no datetimes, so it could not catch either failure. It runs against real ClickHouse and still passes, which confirms the connect path and the injection fix.👉 Stay up-to-date with PostHog coding conventions for a smoother review.
Release status
Automatic notifications
Docs update
None.
🤖 Agent context
Autonomy: Human-driven (agent-assisted)
Agent: Claude Code, claude-opus-5-5
system.mutations/ query log, then confirmed in the clickhouse-driver source.🤖 Generated with Claude Code