feat: provider-cache bypass knob; reject non-final comparator chain steps
CI / publish (push) Successful in 9s
CI / test (push) Successful in 18s

- check() gains cacheProviderResults (per-check option + policy default): the
  provider cache is a STORE-RETRIEVAL cache (wall-clock), independent of the
  caller's decision { now }; callers who pin time or want fresh retrieval can
  opt out per-check or globally.
- The generator now rejects a comparator evidence referenced at a NON-final
  chain position (a comparator compares values at (src, candidate) but
  provides no candidate set, so it cannot enumerate intermediate nodes).
  Final-position comparators still lower to condition steps.

Tests: cache bypass (per-check + policy), comparator final OK / intermediate
error.
This commit is contained in:
John Dvorak
2026-08-03 15:43:59 -07:00
parent ad365a65a9
commit aa38fbfd8c
4 changed files with 48 additions and 3 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@arbiter/evidence-dsl",
"version": "1.8.0",
"version": "1.9.0",
"description": "Evidence DSL v2 compiler: translates the natural Evidence DSL (ADR-000) into @arbiter/core relation configurations.",
"license": "ISC",
"type": "module",
+9
View File
@@ -1111,6 +1111,15 @@ export class RuleGenerator {
out.push(...this._expandChainSteps(resolved.steps, refStack));
continue;
}
if (resolved.type === 'relational_comparator' && idx !== steps.length - 1) {
// A comparator compares values at (src, candidate) but provides no
// candidate set — it cannot enumerate intermediate nodes, so only
// a FINAL comparator step (verified at the known object) lowers.
this.errors.push(`Chain step '${stepName}' references a comparator evidence at a non-final position. ` +
'Comparators can only be the final chain step (the object is known); intermediate positions are not enumerable.');
out.push(step);
continue;
}
// Condition step: inline the evidence's config as a rule step. As the
// FINAL step the engine verifies it at (intermediate, object); as an
// INTERMEDIATE step the engine EXPANDS it from the current node
+11 -2
View File
@@ -60,6 +60,12 @@ export class DSLRuntime {
this.clock = typeof options.clock === 'function' ? options.clock : (() => Date.now());
// Default provider-result TTL in ms (0 disables caching).
this.defaultProviderCacheTTL = options.policy?.providerCacheTTL ?? options.providerCacheTTL ?? 30_000;
// Provider caching is a STORE-RETRIEVAL cache (wall-clock), deliberately
// independent of the caller's decision `{ now }` — a provider returns the
// store's current data, not a time-travel snapshot. Callers who pin time
// or otherwise want fresh retrieval can disable it per-check
// (options.cacheProviderResults: false) or globally (policy).
this.cacheProviderResults = options.policy?.cacheProviderResults ?? options.cacheProviderResults ?? true;
// Per-fact overrides (ms). DSL-declared ttl behaviors are indexed here too.
this.factTTLs = new Map(Object.entries(options.factTTLs || {}));
}
@@ -593,8 +599,11 @@ export class DSLRuntime {
// provider overrides are one-off observations — they bypass the cache
// entirely (no read, no write) so a fresh override is never masked by
// a cached registered-provider result, nor does it pollute the cache.
// options.cacheProviderResults:false (or the policy default) disables
// the cache for this check.
const cachingEnabled = options.cacheProviderResults ?? this.cacheProviderResults;
const isPerCheckOverride = !!(options.factProviders && fact in options.factProviders);
const cacheHit = isPerCheckOverride ? null : this._providerCacheGet(fact, user, object);
const cacheHit = (cachingEnabled && !isPerCheckOverride) ? this._providerCacheGet(fact, user, object) : null;
let edges = null;
let fromCache = false;
if (cacheHit) {
@@ -626,7 +635,7 @@ export class DSLRuntime {
continue;
}
edges = this._normalizeProviderEdges(result, factMeta, user, object);
if (!isPerCheckOverride) this._providerCacheSet(fact, user, object, edges);
if (cachingEnabled && !isPerCheckOverride) this._providerCacheSet(fact, user, object, edges);
} else {
missingFacts.push({ relation: fact, reason: 'no_provider' });
satisfied.add(fact);
+27
View File
@@ -173,4 +173,31 @@ describe('DSLRuntime provider-result caching', () => {
await rt.check('u:1', 'can_spend', 'doc:9');
assert.equal(calls, 2, 're-invoked past the DSL-declared 1h TTL');
});
it('cacheProviderResults:false bypasses the cache per check', async () => {
const rt = makeRuntime();
rt.addNode('u:1', 'Employee', {});
rt.addNode('doc:9', 'Doc', {});
let calls = 0;
rt.registerFact('owns', async () => { calls++; return 0.9; });
await rt.check('u:1', 'can_read', 'doc:9');
assert.equal(calls, 1);
// Bypass forces a fresh retrieval without clearing the cache.
await rt.check('u:1', 'can_read', 'doc:9', { cacheProviderResults: false });
assert.equal(calls, 2);
// Cache still intact for the next default check.
await rt.check('u:1', 'can_read', 'doc:9');
assert.equal(calls, 2);
});
it('policy.cacheProviderResults:false disables caching globally', async () => {
const rt = makeRuntime({ policy: { cacheProviderResults: false } });
rt.addNode('u:1', 'Employee', {});
rt.addNode('doc:9', 'Doc', {});
let calls = 0;
rt.registerFact('owns', async () => { calls++; return 0.9; });
await rt.check('u:1', 'can_read', 'doc:9');
await rt.check('u:1', 'can_read', 'doc:9');
assert.equal(calls, 2, 'no caching when disabled globally');
});
});