Ruled: 5950942037 · letter A · 2026-10-02T11:03Z
Filing gate: ① a defect with named positions, filed under the reach exception for possible data disclosure: a server-log line can carry a statement's bound values. ⚠️ Classes and positions only: no statement, value or reproduction here. This is the third position of the driver-fault redaction family, after #21274 (PR #21335) and #21345 (PR #21384, open).
reach: measured at the public engine door ObjectQL.execute, over a real SqlDriver on better-sqlite3, live PostgreSQL 16 and live MySQL 8.0, by #21345's dev (os-dev-report on #21345, open_questions[0] and out_of_scope_findings[0]). A synthetic sentinel bound into a raw statement reached the driver's own raw-terminal WARN line, for the four listed leading verbs and for unlisted ones alike, on all three dialects. The other four lines below are the same family by the driver's own words; they are read from source, not driven.
Filed by domain:engine#1 (seat post #6367, session_017xfMoEjKUuSh2xYB8sCozp). Reader who acts: the maintainer. The fix would amend the log half of an earlier maintainer ruling, so this card goes to the decision box, and the analysis is the next comment. ⛔ Not a claim.
Positions (packages/drivers/driver-sql/src/sql-driver.ts at origin/main 43e928dd4)
Five WARN lines say, in their own words, that the dialect message they write is "kept server-side" because it carries the statement and, on the dialects that inline them, the bound literals:
- The raw terminal (near
:10284, before rawStatementFaultError). The line also writes the statement the door sent. This is the line the probe measured.
- The read terminal (near
:10215, before backendStatementFaultError): "it carries the compiled statement, and on the dialects that inline them the bound literals too".
- The unresolvable WHERE column (near
:10087, INVALID_FILTER): "because it inlines the statement bound literals".
- The unresolvable groupBy / aggregation column (near
:10960, INVALID_FIELD): the same words.
- The unresolvable listed distinct column (near
:11253, INVALID_FIELD): the same words.
Each line runs inside the driver, before the engine's boundary helper (redactPropagatedDriverFault, #21274) sees the fault. So the engine-boundary cut, and #21345's by-construction cut at ObjectQL.execute, both stop above these lines.
Governing text: two positions that disagree
#21274's premise reaches the engine's carriers; the 2026-08-17 design places the driver's own log inside the data's trust boundary. Which one governs the driver's log lines is the maintainer's call.
Dedupe
Through mcp__github__search_issues, repo-scoped, open and closed: 「driver-sql server log line writes compiled statement bound values rawStatementFault backendStatementFault kept server-side」 gave 4 hits:
None covers the driver's own log lines.
Dedupe words: driver-sql raw terminal log bound values · rawStatementFault server log statement · backendStatementFault dialect text log · driver log line redaction · statement kept server-side operator log
Generated by Claude Code
Ruled: 5950942037 · letter A · 2026-10-02T11:03Z
Filing gate: ① a defect with named positions, filed under the reach exception for possible data disclosure: a server-log line can carry a statement's bound values.⚠️ Classes and positions only: no statement, value or reproduction here. This is the third position of the driver-fault redaction family, after #21274 (PR #21335) and #21345 (PR #21384, open).
reach:measured at the public engine doorObjectQL.execute, over a realSqlDriveron better-sqlite3, live PostgreSQL 16 and live MySQL 8.0, by #21345's dev (os-dev-report on #21345,open_questions[0]andout_of_scope_findings[0]). A synthetic sentinel bound into a raw statement reached the driver's own raw-terminal WARN line, for the four listed leading verbs and for unlisted ones alike, on all three dialects. The other four lines below are the same family by the driver's own words; they are read from source, not driven.Filed by
domain:engine#1(seat post #6367,session_017xfMoEjKUuSh2xYB8sCozp). Reader who acts: the maintainer. The fix would amend the log half of an earlier maintainer ruling, so this card goes to the decision box, and the analysis is the next comment. ⛔ Not a claim.Positions (
packages/drivers/driver-sql/src/sql-driver.tsatorigin/main43e928dd4)Five WARN lines say, in their own words, that the dialect message they write is "kept server-side" because it carries the statement and, on the dialects that inline them, the bound literals:
:10284, beforerawStatementFaultError). The line also writes the statement the door sent. This is the line the probe measured.:10215, beforebackendStatementFaultError): "it carries the compiled statement, and on the dialects that inline them the bound literals too".:10087,INVALID_FILTER): "because it inlines the statement bound literals".:10960,INVALID_FIELD): the same words.:11253,INVALID_FIELD): the same words.Each line runs inside the driver, before the engine's boundary helper (
redactPropagatedDriverFault, #21274) sees the fault. So the engine-boundary cut, and #21345's by-construction cut atObjectQL.execute, both stop above these lines.Governing text: two positions that disagree
#21274's premise reaches the engine's carriers; the 2026-08-17 design places the driver's own log inside the data's trust boundary. Which one governs the driver's log lines is the maintainer's call.
Dedupe
Through
mcp__github__search_issues, repo-scoped, open and closed: 「driver-sql server log line writes compiled statement bound values rawStatementFault backendStatementFault kept server-side」 gave 4 hits:driver-fault-redaction.tshas one entry and no way to notice a second is missing (observation) #9160 (closed): the value-bearing-diagnostic list indriver-fault-redaction.ts, a different subject.None covers the driver's own log lines.
Dedupe words:
driver-sql raw terminal log bound values·rawStatementFault server log statement·backendStatementFault dialect text log·driver log line redaction·statement kept server-side operator logGenerated by Claude Code