Skip to content

feat(w65): add bounded data-quality evaluator runtime - #250

Merged
akhiabanchian merged 1 commit into
mainfrom
w65-bounded-evaluator-runtime
Oct 4, 2026
Merged

akhiabanchian merged 1 commit into
mainfrom
w65-bounded-evaluator-runtime

Conversation

@ammarheidari

Copy link
Copy Markdown
Contributor

Authority

W65 #214 is ACTIVE. Slice 1/2 contracts and evaluator/progress foundations are already protected-main through PRs #239/#243.

Slice 3

  • add a pure bounded IDataQualityBatchEvaluator runtime;
  • evaluate only the closed admitted rule grammar;
  • support bounded JSON-pointer traversal including RFC6901 ~0/~1 decoding and array indexes;
  • treat invalid JSON/missing/wrong-type values fail-closed for applicable rules;
  • count violating records once while retaining per-rule aggregate counts;
  • return only aggregate evidence + progress metadata;
  • preserve partial/unknown truth for bounded/cancelled/incomplete cycles;
  • enforce policy scope before evaluation;
  • retain no raw payload, key, header, or record exemplar in durable/result contracts.

Safety

  • no Kafka access inside the evaluator;
  • no consumer-group membership or offset commits;
  • no arbitrary scripts/regex/network callbacks;
  • no raw-payload persistence;
  • no unbounded enumeration beyond admitted record snapshots;
  • runtime monitoring worker/lifecycle persistence/API/UI remain separate follow-on slices.

Exact head: 6798cf9feca9cebf0736e41101700f0146958ac2.

Refs #214 #209.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T15:28:29.941790Z 6798cf9 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head 6798cf9feca9cebf0736e41101700f0146958ac2 only. Focus on bounded evaluator correctness, JSON-pointer semantics, aggregate violation accounting, partial/cancelled progress truth, raw-payload non-retention, scope enforcement, and avoiding any arbitrary-code/unbounded behavior.

@akhiabanchian
akhiabanchian merged commit 9f4324f into main Oct 4, 2026
8 checks passed
@akhiabanchian
akhiabanchian deleted the w65-bounded-evaluator-runtime branch October 4, 2026 15:27

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6798cf9fec

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +214 to +216
private static void ValidateScope(
DataQualityPolicyDefinition policy,
DataQualityEvaluationInput input)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Enforce the policy's own evaluation ceilings

When a policy configures a smaller EvaluationWindow, RecordsPerSecond, or BytesPerSecond, this validation checks only cluster/topic/partition while the loop trusts the independently supplied input.Budget. An input admitted under the much larger cycle hard caps can therefore be evaluated and reported under a restrictive policy, bypassing its configured resource ceilings; validate the window and derive effective record/byte limits from policy.Budget before evaluation.

Useful? React with 👍 / 👎.

Comment on lines +110 to +114
var recordViolation =
EvaluateRecord(
record,
policy.Rules,
counts);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Recheck the deadline after evaluating each record

If a record begins just before the deadline but JSON parsing and up to 128 rule evaluations finish after it, this call is followed by no deadline check when it is the final record, so the result is reported as Complete/Available despite exceeding MaxDuration. The same gap prevents cancellation requested during the final record from being reflected; add cooperative checks during expensive work or at least recheck before claiming complete progress.

Useful? React with 👍 / 👎.

Comment on lines +426 to +430
if (!int.TryParse(
segment,
NumberStyles.None,
CultureInfo.InvariantCulture,
out var arrayIndex) ||

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject leading-zero JSON array indices

For an array value, int.TryParse accepts tokens such as "01" and resolves them as index 1, but JSON Pointer array indices must be 0 or a nonzero digit followed by digits. Consequently a rule like /items/01/id can incorrectly pass against the second element instead of failing as an invalid/unresolved pointer; validate the array-index token grammar before parsing it.

Useful? React with 👍 / 👎.

Comment on lines +449 to +451
private static string DecodePointerSegment(
string segment) =>
segment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Fail closed on invalid JSON Pointer escapes

The policy contract currently admits pointer tokens containing escapes other than ~0 and ~1, and this decoder silently leaves them unchanged. Thus /a~2b can match a literal a~2b property even though it is not a valid JSON Pointer token, allowing a malformed rule to produce successful evidence rather than being rejected or treated as unresolved; decode with escape validation and fail closed on any other ~ sequence.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants