• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

orneryd / NornicDB / 36363936437
87%

Build:
DEFAULT BRANCH: main
Ran 28 Sep 2026 01:08AM UTC
Jobs 1
Files 653
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 12:54AM UTC coverage: 86.977% (-0.005%) from 86.982%
36363936437

push

github

orneryd
fix(security): reject bare transaction commands on shared executors

The lane-3 shared-executor transaction finding was only half closed in
0a3da5e4: the one-statement script form (BEGIN ... COMMIT/ROLLBACK) runs
on a private clone, but a bare BEGIN still opened a transaction on the
shared cached executor through parseTransactionStatement for any context
not marked as a client statement. The embedded API (DB.Cypher /
DB.ExecuteCypher) runs on the shared base executor with an unmarked
context, so one caller's BEGIN made every concurrent auto-commit
statement and subsequent one-statement script run inside that caller's
transaction.

Cached per-database executors are now marked shared (SetSharedExecutor):
the embedded base executor, the HTTP executor cache and the Bolt
autocommit executor cache reject bare BEGIN/COMMIT/ROLLBACK with the same
Neo.ClientError.Statement.SyntaxError a client statement gets, and never
hold a transaction. Protocol transaction owners (HTTP/Bolt sessions) run
on their own per-session executors, which keep the pattern; embedded
callers wanting explicit transactions create their own session executor.

Regression coverage:
- pkg/cypher: bare commands rejected on shared executors (unmarked and
  transaction-owner contexts), scripts still isolated, concurrent
  scripts+autocommit race with zero lost writes, non-shared session
  executors keep BEGIN/COMMIT, client-statement rejection unchanged.
- pkg/nornicdb: DB.Cypher/ExecuteCypher reject bare commands on the
  shared executor; concurrent callers stay isolated.
- pkg/server: the cached executor rejects bare commands and leaves no
  transaction; session executors keep explicit transactions; scripts work.

Benchmarks (M2 Max, BenchmarkStatementRouting simple_match_limit):
autocommit 17.4-18.0 us/op, 11246 B, 161 allocs (recorded band
16.4-17.6 us/op, 160-163 allocs); explicit tx 11.16-11.20 us/op, 5679 B,
88 allocs (band 10.4-11.1 us/op, 87-90 allocs). Allocation-identical,
within noise.

18 of 18 new or added lines in 5 files covered. (100.0%)

23 existing lines in 8 files now uncovered.

175148 of 201373 relevant lines covered (86.98%)

1.02 hits per line

Coverage Regressions

Lines Coverage ∆ File
8
78.69
-4.37% pkg/storage/badger_label_index_backfill.go
4
87.69
-0.51% pkg/nornicdb/search_services.go
3
90.07
-0.24% pkg/nornicdb/db_admin.go
2
95.08
-0.82% pkg/cypher/merge_semantic_validation.go
2
90.79
-0.66% pkg/cypher/optimized_executors.go
2
91.62
-1.05% pkg/linkpredict/hybrid.go
1
96.39
-0.3% pkg/nornicdb/apoc_storage_adapter.go
1
86.36
-0.08% pkg/nornicdb/embed_queue.go
Jobs
ID Job ID Ran Files Coverage
1 36363936437.1 28 Sep 2026 01:08AM UTC 653
86.98
GitHub Action Run
Source Files on build 36363936437
  • Tree
  • List 653
  • Changed 18
  • Source Changed 0
  • Coverage Changed 18
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 5e3ec642 on github
  • Prev Build on main (#36363171412)
  • Next Build on main (#36364865879)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc