Skip to content

fix: enforce bounded SELECT results - #33

Merged
marianfoo merged 6 commits into
masterfrom
codex/base-run-004
Aug 7, 2026
Merged

marianfoo merged 6 commits into
masterfrom
codex/base-run-004

Conversation

@marianfoo

Copy link
Copy Markdown
Owner

Summary

  • reject explicit zero, invalid, overflowing, and above-maximum SELECT row limits before code generation
  • normalize unsafe saved defaults and cap all multirow SELECT paths at 10,000 rows
  • add parser and set-query regressions and remove the former unlimited-mode documentation

Root cause

ABAP treats a zero UP TO value as up to 2,147,483,647 rows on the supported releases. ZTOAD stripped the clause and reused initial fw_rows as an “omit the cap” sentinel in every generated SELECT path. A saved default of zero reached the same bypass.

TDD evidence

  • Red candidate ccea897 on NPL: 113 tests, 112 passed; only LTC_QUERY_PARSER->REJECTS_ZERO_LIMIT failed
  • Frozen source candidate: 832d057656dc2923e79b87eff5016b718dad42fe
  • Source SHA-256: b8d5d7807e42832b105deabe4d55f142ee10408a4f1ef975cf9530d17cf2ebb4

Validation

  • Local: npm ci, npm test, configured abaplint zero findings, repository/installation contracts, and git diff --check passed
  • NPL / SAP_BASIS 750: active syntax clean; ABAP Unit 120/120; active/inactive state equal; zero inactive ZTOAD parts; DEFAULT ATC unchanged at 85; no new ST22 dump
  • A4H / S/4HANA 2023: active syntax passed with the seven documented POSIX warnings; ABAP Unit 120/120; active/inactive state equal; zero inactive ZTOAD parts; Cloud ATC improved from 709 to 706 with no new finding signature
  • Fresh WebGUI smoke: UP TO 0 ROWS was rejected before execution; a positive two-row limit returned exactly two rows; no new ST22 dump
  • Both shared systems were restored to merged master and verified at 113/113 tests with zero inactive ZTOAD parts

The S/4HANA readiness variant showed zero displayed findings, but remains recorded as incomplete because prerequisite execution could not be proven.

Tracking: BASE-RUN-004.

Copy link
Copy Markdown
Owner Author

Final post-green audit complete on head 24404eb16e0a50d58a3432e4d2f9721b1cbe31b9.

  • Second Quality run 31196499583 is green.
  • Required checks: Repository quality passed; abaplint passed; abaplint observations is neutral by design.
  • The seven-file PR inventory matches the reviewed diff, with no unresolved review threads or comments.
  • The audit corrected the stale unlimited-override checklist wording and added separate validation guidance for explicit versus persisted/default sentinel values.
  • No src/ or serialized-object file changed after frozen source commit 832d057, so the recorded NPL/A4H evidence remains valid.
  • PR is cleanly mergeable.

@marianfoo
marianfoo marked this pull request as ready for review August 7, 2026 16:14
@marianfoo
marianfoo merged commit b6acc14 into master Aug 7, 2026
3 checks passed
@marianfoo
marianfoo deleted the codex/base-run-004 branch August 7, 2026 16:14
This was referenced Aug 7, 2026
marianfoo pushed a commit that referenced this pull request Aug 7, 2026
🤖 I have created a release *beep* *boop*
---


## [5.0.1](5.0.0...5.0.1)
(2026-08-07)


### Bug Fixes

* bound temporary subroutine pools
([#32](#32))
([ef54657](ef54657))
* classify ZTOAD table as not extensible
([#26](#26))
([e5ae759](e5ae759))
* enforce bounded SELECT results
([#33](#33))
([b6acc14](b6acc14))
* execute queries safely in WebGUI
([#24](#24))
([5218476](5218476))
* execute UNION as one SQL set
([a5ad27c](a5ad27c))
* generate aggregate CASE result types
([#21](#21))
([d532b2e](d532b2e))
* isolate generated query failures
([#31](#31))
([b0b4d9f](b0b4d9f))
* parse top-level SQL clauses
([#28](#28))
([c5ca65b](c5ca65b))
* support ABAP SQL string functions
([#27](#27))
([0f056e8](0f056e8))
* verify complete native-abapGit installation
([#22](#22))
([2360fe4](2360fe4))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant