Skip to content

Preserve lexical ordering in streaming template interpolation - #6988

Merged
tim-smart merged 3 commits into
mainfrom
audit/repro-unstable-http-template-order
Aug 4, 2026
Merged

Preserve lexical ordering in streaming template interpolation#6988
tim-smart merged 3 commits into
mainfrom
audit/repro-unstable-http-template-order

Conversation

@fubhy

@fubhy fubhy commented Aug 4, 2026

Copy link
Copy Markdown
Member

Summary

Template.stream allows later static and fast segments to overtake an earlier delayed interpolation, changing a${slow}b${fast}c into abfastcslow rather than aslowbfastc.

Important

This PR starts with focused failing reproduction tests. Add the implementation fix to this same branch; CI is expected to fail until that fix is included.

Streaming interpolation does not preserve template order

Module: Template
Audit ID: unstable-http-template-stream-order
Severity / confidence: medium / high

What happens

Template.stream allows later static and fast segments to overtake an earlier delayed interpolation, changing a${slow}b${fast}c into abfastcslow rather than aslowbfastc.

Why it happens

The lexical segment stream is flattened with concurrency set to unbounded, so later segments can emit before an earlier effect or stream interpolation completes.

Expected behavior

A template stream must emit static and interpolated segments in lexical template order.

Relevant implementation

These links and excerpts are pinned to audit base c9b56ab507f224426ee8388dc450da447ec4715f.

View problematic code at packages/effect/src/unstable/http/Template.ts:218-223
  return Stream.flatMap(
    Stream.fromIterable(chunks),
    (chunk) =>
      typeof chunk === "string" ? Stream.succeed(chunk) : Effect.isEffect(chunk) ? Stream.fromEffect(chunk) : chunk,
    { concurrency: "unbounded" }
  )

View exact lines on GitHub

Reproduction

pnpm test --run packages/effect/test/unstable/http/Template.test.ts

Observed failure: Failed deterministically under TestClock with abfastcslow instead of aslowbfastc.

Implementation handoff

The initial reproduction tests on this branch are the regression specification for the implementation fix that should follow in this PR.

  1. Start with the pinned implementation excerpts and the Why it happens analysis above.
  2. Change the implementation so it satisfies the stated Expected behavior; do not weaken or remove the reproduction assertions.
  3. Run the focused reproduction command(s) and confirm the observed failures become passing tests:
pnpm test --run packages/effect/test/unstable/http/Template.test.ts
  1. Run the affected package's existing tests, then the repository lint and type checks before requesting review.

Audit provenance

  • Audit base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Reproduction base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Findings: unstable-http-template-stream-order
  • Initial patch: focused reproduction tests; implementation fix pending

Closes EFF-425

@fubhy fubhy added the audit Findings originating from the Effect runtime correctness audit label Aug 4, 2026
@changeset-bot

changeset-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 46b805a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 30 packages
Name Type
effect Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node-shared Patch
@effect/platform-node Patch
@effect/vitest Patch
@effect/ai-anthropic Patch
@effect/ai-openai-compat Patch
@effect/ai-openai Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/docgen Patch
@effect/doctest Patch
@effect/openapi-generator Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@effect-slopcop effect-slopcop Bot added 4.0 bug Something isn't working labels Aug 4, 2026

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

This PR currently adds only the failing regression test; the implementation fix that would make it pass is still missing. Merging now would leave main with a failing test and broken CI.

Reviewed changes

  • Added packages/effect/test/unstable/http/Template.test.ts with a deterministic Template.stream ordering regression test. The test correctly fails under the current implementation (abfastcslow vs. expected aslowbfastc) and will pass once the flattening is made sequential.

⚠️ Implementation fix still needed

The reproduction test is good, but the corresponding fix in packages/effect/src/unstable/http/Template.ts is not included. The current implementation flattens the ordered chunks array with { concurrency: "unbounded" }, which allows later segments to overtake earlier delayed interpolations.

Remove the concurrency option (or use Stream.concatMap) at packages/effect/src/unstable/http/Template.ts:218-223 so each chunk is emitted in lexical template order.

Technical details
# Missing sequential flattening for Template.stream

## Affected sites
- packages/effect/src/unstable/http/Template.ts:218-223 — `Stream.flatMap` with `{ concurrency: "unbounded" }` reorders segments

## Required outcome
- `Template.stream` must emit static and interpolated segments in lexical template order.
- The reproduction test `packages/effect/test/unstable/http/Template.test.ts` must pass.

## Suggested approach
- Remove `{ concurrency: "unbounded" }` from the `Stream.flatMap` call, or replace it with `Stream.concatMap`.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | Fix it ➔View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@@ -218,8 +218,7 @@ export function stream<A extends ReadonlyArray<InterpolatedWithStream>>(
return Stream.flatMap(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we can use mapEffect instead to preserve order and concurrency?

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

  • Replaced the original Stream.flatMap(..., { concurrency: "unbounded" }) in packages/effect/src/unstable/http/Template.ts with a two-stage pipeline: Stream.mapEffect(..., { concurrency: "unbounded" }) evaluates effect interpolations concurrently, and a sequential Stream.flatMap flattens the results in lexical template order.
  • Added a regression test ("preserves template segment order") that verifies a delayed interpolation no longer gets overtaken by later segments.
  • Added a second test ("evaluates effect interpolations concurrently") that confirms the two-stage design still starts consecutive effect interpolations in parallel.
  • Added a patch changeset .changeset/tidy-cats-stream.md.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@tim-smart
tim-smart enabled auto-merge (squash) August 4, 2026 23:21
@tim-smart
tim-smart merged commit db4c2cc into main Aug 4, 2026
18 of 19 checks passed
@tim-smart
tim-smart deleted the audit/repro-unstable-http-template-order branch August 4, 2026 23:38
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 7.06 KB 7.06 KB 0.00 KB (0.00%)
batching.ts 9.86 KB 9.86 KB 0.00 KB (0.00%)
brand.ts 6.34 KB 6.34 KB 0.00 KB (0.00%)
cache.ts 10.71 KB 10.71 KB 0.00 KB (0.00%)
config.ts 20.60 KB 20.60 KB 0.00 KB (0.00%)
differ.ts 20.20 KB 20.20 KB 0.00 KB (0.00%)
http-client.ts 21.58 KB 21.54 KB +0.04 KB (+0.19%)
logger.ts 10.84 KB 10.84 KB 0.00 KB (0.00%)
metric.ts 8.98 KB 8.98 KB 0.00 KB (0.00%)
optic.ts 7.18 KB 7.18 KB 0.00 KB (0.00%)
pubsub.ts 14.99 KB 14.99 KB 0.00 KB (0.00%)
queue.ts 11.66 KB 11.66 KB 0.00 KB (0.00%)
schedule.ts 10.83 KB 10.83 KB 0.00 KB (0.00%)
schema-class.ts 19.14 KB 19.14 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 28.96 KB 28.96 KB 0.00 KB (0.00%)
schema-representation-roundtrip.ts 25.29 KB 25.29 KB 0.00 KB (0.00%)
schema-string-transformation.ts 13.38 KB 13.38 KB 0.00 KB (0.00%)
schema-string.ts 10.94 KB 10.94 KB 0.00 KB (0.00%)
schema-template-literal.ts 15.17 KB 15.17 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.94 KB 21.94 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 24.34 KB 24.34 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 19.18 KB 19.18 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 19.01 KB 19.01 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.87 KB 18.87 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.60 KB 22.60 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.52 KB 19.52 KB 0.00 KB (0.00%)
schema.ts 18.41 KB 18.41 KB 0.00 KB (0.00%)
stm.ts 12.63 KB 12.63 KB 0.00 KB (0.00%)
stream.ts 9.80 KB 9.80 KB 0.00 KB (0.00%)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 audit Findings originating from the Effect runtime correctness audit bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants