fix(checkpoint-postgres,checkpoint-sqlite): scope namespace matching to segment boundaries (#8478)

## Summary

Namespace scoping in the Postgres and SQLite stores matched the
dot-joined prefix with `LIKE '<path>%'`, which does not respect the `.`
separator — a search scoped to `("foo",)` also returned rows under
`("foobar",)`. Scoping now matches the namespace exactly or requires the
separator before any remainder, and pattern metacharacters in labels are
escaped.

`list_namespaces` moves to segment-aware matching for prefix and suffix
conditions, since neither `LIKE` nor `GLOB` can express "any character
except the separator".

Per-package reasoning is in the commit message.

## Compatibility

`*` in a `list_namespaces` match path now spans exactly one segment,
restoring the documented behavior (`NamespacePath` documents `("cache",
"*", "v1")` as "any cache category with v1 version") and matching
`InMemoryStore`. To match at any depth, combine both conditions, which
are ANDed: `list_namespaces(prefix=["uid"], suffix=["alice"])`.

## Test plan

- [x] `make format` / `make lint` / `make test` from
`libs/checkpoint-postgres` (224 passed) and `libs/checkpoint-sqlite`
(112 passed, 3 skipped)
This commit is contained in:
Elior Nataf Lackritz
2026-07-30 13:52:16 -04:00
committed by GitHub
parent 4134145734
commit 66ebe1a0da
6 changed files with 554 additions and 36 deletions
@@ -716,3 +716,32 @@ async def test_search_items(
for ns in test_namespaces:
key = f"item_{ns[-1]}"
await store.adelete(ns, key)
async def test_async_namespace_segment_boundary(store: AsyncSqliteStore) -> None:
"""Segment-aware scoping on the async path.
Also covers that the namespace-match SQLite function is registered on the
async connection -- aiosqlite's create_function is a coroutine, so it is
registered in setup() rather than __init__.
"""
for namespace in [
("foo",),
("foo", "child"),
("foobar",),
("uid", "users", "alice"),
("uid", "users", "malice"),
("user_1",),
("userX1",),
]:
await store.aput(namespace, "k", {"v": 1})
found = {item.namespace for item in await store.asearch(("foo",), limit=100)}
assert found == {("foo",), ("foo", "child")}
found = {item.namespace for item in await store.asearch(("user_1",), limit=100)}
assert found == {("user_1",)}
assert set(await store.alist_namespaces(suffix=["alice"], limit=100)) == {
("uid", "users", "alice"),
}