Repository navigation
v0.2.1
OxideR-Query v0.2.1
A hygiene release. No change to library behaviour: everything in v0.2.0 behaves identically. What changed is the lock file and the test suite, and the reason for cutting a new tag is that v0.2.0 went out on a commit whose CI then failed.
Upgrade if you consume the repository by tag. Nothing in your own code has to change.
Why v0.2.0 was tagged red
make release runs the full local gate before tagging, and that gate passed. It is not CI, and the difference is exactly where the two problems hid:
- The PostgreSQL end-to-end suite skips itself when
OXIDER_POSTGRES_URLis unset, so locally it ran nothing. - Nothing local ran
cargo audit.
CI has a Postgres service and an audit job, so it found both within a minute of the tag being pushed.
What is fixed
The PostgreSQL suite raced itself. Every test drops and recreates the same tables on one shared server, so running them concurrently means one clearing another's rows mid-assertion, or both issuing the DDL and one losing:
ERROR 42P07: relation "ox_users" already exists
It passed locally only because the make target pinned it to a single thread, which hid the defect rather than fixing it. The suite serialises itself with a mutex now, and the flag is gone, so a local run and CI do the same thing. The SQLite suite never had this problem because each of its tests gets a private in-memory database.
cargo audit flagged RUSTSEC-2023-0071, the rsa timing sidechannel, against a crate nothing here compiles. sqlx/chrono fans the feature out to every backend, so enabling it pulled sqlx-mysql and its dependencies into Cargo.lock for a driver this workspace never builds. Enabling chrono on the Postgres driver directly keeps the lock to what is actually used, and takes the advisory with it. No audit.toml ignore was added; the dependency is simply gone.
make release now runs an advisory check before tagging, and says so plainly when cargo-audit is missing rather than skipping in silence. make check still does not require it, since not every contributor will have it installed.
What is still true from v0.2.0
The builder targets PostgreSQL, MySQL and SQLite. Execution covers PostgreSQL and SQLite; schema codegen is SQLite only. On MySQL you render here and bind with your own driver.
Pre-1.0: the API tracks latest stable Rust and will change.
Known gaps
Unchanged from v0.2.0: the MySQL execution backend, PostgreSQL and MySQL codegen backends, #[derive(Projection)], a GroupBy transformer, the renderer's per-Value clone, and the recursive drop of deeply nested subqueries.