Commit 6faf43f
LAV-3112: Implement application-role container and lifecycle (#3766)
* LAV-3112: add application container and scoped role lifecycle
Add the applications container, current-application session slot, role scope
kind, application role parser/rewrites and lifecycle UDFs. Retire grants,
caller grants and projected principals on replace, role drop and application
retirement. Fold native-app scope readers into applications. Capture missing
container and outside-context behaviour from Snowflake Cloud.
Cloud-backed tests: test_application_role_lifecycle.py (12 cases), existing
ADR 107 outside-context test. Local populated-container smoke test passed
for create, replace, rename, comments, grants, quoting, isolation and drop.
The temporary smoke test was removed after validation because there is no
Cloud fixture until the Native App installer exists.
test_edit_waiver: tests/queries/access_control/test_adr107_baselines.py
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
CREATE unqualified outside, basic -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context
CREATE unqualified outside, OR REPLACE / OR ALTER / IF NOT EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_outside_application_context
CREATE qualified missing container, basic / IF NOT EXISTS / quoted role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER qualified missing container, SET COMMENT / IF EXISTS UNSET -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
DROP qualified missing container, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER/DROP unqualified missing role, IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role_if_exists
CREATE populated context, basic / OR REPLACE / OR ALTER / IF NOT EXISTS / COMMENT -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
ALTER populated context, RENAME / SET COMMENT / UNSET COMMENT -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
DROP populated context, basic / IF EXISTS -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Qualified/quoted names and two-application isolation, happy path -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Implicit owner grant and grant/caller-grant/projection retirement -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
## Deviations
ADR 107 suggests one parameterized lifecycle UDF family for database and application roles. I added application-role UDFs alongside the established database-role family to preserve its existing status and error behavior while sharing its projection mechanism.
The applications table retains kind and database_name from native_app_scopes to preserve existing APPLICATION PACKAGE metadata lookups; it adds ADR 107's owner, package and lifecycle fields.
Positive Cloud snapshots are env-blocked: this checkout has no Native App installer or application fixture. I exercised the lifecycle with a temporary local populated-container smoke test and removed that non-Cloud test under the snapshot rule.
* LAV-3112: preserve quoted dots in application-role grantees
Pass unqualified application-role grantees to the grant store with an
explicit current-application marker. This preserves quoted role names that
contain a dot, which cannot be distinguished from a qualifier by splitting
SQL text. The GRANT and REVOKE paths both resolve through the shared helper.
Capture the quoted-dot missing-grantee error from Snowflake Cloud, including
its privilege hint and position.
Focused checks: make check; test_application_role_lifecycle.py (quoted case);
test_application_role_outside_context. The repository gate reached the broad
compat selection without a failure; I stopped that run when this additional
Cloud-backed case was added. The driver will run the gate on this commit.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
Unqualified plain application-role grantee, missing -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context
Unqualified quoted-dot application-role grantee, missing -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_grantee_with_quoted_dot
Unqualified quoted-dot application-role grantee, existing -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Qualified application-role grantee, existing -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
## Deviations
Positive application-role grant snapshots remain env-blocked until the Native App installer can create a Cloud application fixture. The quoted missing-grantee case is Cloud-captured.
* LAV-3112: investigator: finish repository gate on committed branch
Attempt 2 ended at the worker wall-clock limit while .spiral/check.sh was still running its serial init-hooks compat stage. Its lint, workspace tests, vendored parser tests, policy guards, and the first broad compat stage had passed. The focused application-role tests and make check also passed. The earlier test-edit waiver was used in ba26dd162; no new waiver is needed. Resume by running the final gate promptly and let its built-in 55-minute test budget finish. The preceding check was deliberately stopped to fix the quoted-dot grantee case, which is now committed in baf7d9e21.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
* LAV-3112: validate application-role lifecycle against repository gate
The branch is current with origin/main. .spiral/check.sh passed, including
formatting, lint, workspace tests, vendored parser tests, policy guards,
serial init-hook and telemetry tests, and the full SQL/API compat suite.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
CREATE outside application, basic -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context
CREATE outside application, modifiers -> tests/queries/access_control/test_application_role_lifecycle.py::test_outside_application_context
CREATE qualified missing container, basic / IF NOT EXISTS / quoted role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER qualified missing container, SET COMMENT / IF EXISTS UNSET -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
DROP qualified missing container, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER/DROP unqualified missing role, IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role_if_exists
GRANT missing unqualified role, plain -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context
GRANT missing unqualified role, quoted dot -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_grantee_with_quoted_dot
CREATE populated context, basic / OR REPLACE / OR ALTER / IF NOT EXISTS / COMMENT -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
ALTER populated context, RENAME / SET COMMENT / UNSET COMMENT -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
DROP populated context, basic / IF EXISTS -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Qualified/quoted names and two-application isolation, happy path -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Implicit owner grant and grant/caller-grant/projection retirement -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
GRANT existing quoted-dot application role -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
## Deviations
ADR 107 suggests one parameterized lifecycle UDF family for database and application roles. Application-role UDFs sit alongside the established database-role family to preserve its status and error behavior while sharing projection.
The applications table retains kind and database_name from native_app_scopes for existing APPLICATION PACKAGE metadata lookups and adds ADR 107's owner, package and lifecycle fields.
Positive Cloud snapshots remain env-blocked until the Native App installer provides an application fixture; local populated-container smoke validation was performed in the earlier implementation round.
* LAV-3112: project application-role grants and match unqualified errors
Cloud-captured unqualified ALTER and DROP missing-role errors now resolve to the current database with Snowflake's authorization message. Project grants to application roles onto their PG principals, include implicit application-role membership in the authorization closure, and rederive schema usage for scoped application roles.
Swept RBAC grant projection and closure readers for application-role grantees; also fixed table, dynamic-table, database and schema paths. Existing account-role and database-role branches remain covered by the selected compat suite.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
CREATE unqualified outside application, basic and modifiers -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context; tests/queries/access_control/test_application_role_lifecycle.py::test_outside_application_context
CREATE qualified missing container, basic / IF NOT EXISTS / quoted name -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER qualified missing container, SET / IF EXISTS UNSET -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
DROP qualified missing container, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER unqualified missing role, no IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role
DROP unqualified missing role, no IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role
ALTER/DROP unqualified missing role, IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role_if_exists
GRANT missing application-role grantee, plain / quoted dot -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context; tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_grantee_with_quoted_dot
CREATE populated application, replace / alter / IF NOT EXISTS / comment -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
ALTER populated application, rename / SET / UNSET / quoting / isolation -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
DROP populated application, basic / IF EXISTS -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Implicit owner membership and grant closure -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
GRANT/REVOKE table or dynamic-table privilege to live application role -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
GRANT/REVOKE database or schema USAGE to live application role -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Replace/drop application role with live grants -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
## Deviations
Positive Cloud snapshots remain env-blocked until the Native App installer provides an application fixture. The new missing-role snapshots were captured from Snowflake Cloud; the focused emulator replay and make check passed.
* LAV-3112: investigator: finish gate and review after RBAC fix
Attempt 3 ended at its wall-clock limit after commit 5451a7e8f fixed both reviewer gaps: Cloud-captured unqualified ALTER/DROP errors and application-role grant projection plus authorization closure. The focused lifecycle suite passed 15 tests and make check passed. The second .spiral/check.sh run passed lint, workspace and vendored parser tests, policy guards, and serial init-hooks; it had reached the Ubuntu/telemetry stage without a reported failure when the implementer budget expired. Resume the repository gate and reviewer on the committed tree. Positive Cloud snapshots remain deferred because the Native App installer has not yet supplied an application fixture; the prior reviewer accepted that environmental limitation.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
* LAV-3112: validate lifecycle and RBAC after main merge
.spiral/check.sh passed on the committed application-role implementation after merging origin/main. This includes lint, live-PG integration tests, vendored parser tests, policy guards, serial init-hook and telemetry tests, and the full SQL/API compat suite.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
CREATE unqualified outside application, basic and modifiers -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context; tests/queries/access_control/test_application_role_lifecycle.py::test_outside_application_context
CREATE qualified missing container, basic / IF NOT EXISTS / quoted name -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER qualified missing container, SET / IF EXISTS UNSET -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
DROP qualified missing container, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER unqualified missing role, no IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role
DROP unqualified missing role, no IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role
ALTER/DROP unqualified missing role, IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role_if_exists
GRANT missing application-role grantee, plain / quoted dot -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context; tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_grantee_with_quoted_dot
CREATE populated application, OR REPLACE / OR ALTER / IF NOT EXISTS / COMMENT -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
ALTER populated application, RENAME / SET COMMENT / UNSET COMMENT / quoting / isolation -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
DROP populated application, basic / IF EXISTS -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Implicit owner membership and grant closure -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
GRANT/REVOKE table, dynamic-table, database, and schema privileges to a live application role -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
Replace/drop application role with live grants -> uncovered: env-blocked until Native App installer provides a Cloud application fixture
## Deviations
ADR 107 suggests one parameterized lifecycle UDF family for database and application roles. Application-role UDFs sit alongside the established database-role family to preserve its status and error behavior while sharing projection.
The applications table retains kind and database_name from native_app_scopes for existing APPLICATION PACKAGE metadata lookups and adds ADR 107's owner, package and lifecycle fields.
Positive Cloud snapshots remain env-blocked until the Native App installer provides an application fixture; the outside-context, missing-container, and missing-role snapshots were captured from Snowflake Cloud.
* LAV-3112: wip (budget exhausted: wall_clock)
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
* LAV-3112: investigator: replay final grant changes and run gate
Attempt 4 ended at wall-clock limit while the final focused emulator replay was still provisioning. WIP cb509dd11 addresses the reviewer gaps: bulk/future grant paths resolve application-role grantees; retirement soft-deletes their future rules; rename rekeys them; materialization filters live roles. It also covers REVOKE GRANT OPTION and captures five missing-application Cloud errors. The earlier focused lifecycle file passed 17 cases, and make check passed after the last edits. Next: run test_application_role_lifecycle.py against the emulator, including the three newly captured REVOKE cases; fix any mismatch; then run .spiral/check.sh and reviewer. This is a new reviewer-gap fix, not a repeat of the previous gate-only exhaustion. Positive lifecycle Cloud captures still need the separate Native App fixture and were accepted as env-blocked by the reviewer.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
* LAV-3112: investigator: finish gate and review after focused replay
Dispatch 5 ended at the four-hour worker cap during .spiral/check.sh, after the latest grant fix. The final implementer transcript records 20/20 application-role lifecycle tests passing and make check passing on cb509dd11. The repository gate passed lint, workspace/parser tests, guards, serial init hooks, and was progressing through telemetry with no reported failure; the SQL/API suite had not finished. Start .spiral/check.sh promptly on this committed tree, then run reviewer. The latest reviewer gaps are addressed in grants.rs and roles.rs: bulk/future paths resolve grantees; retirement deletes future grants; rename rekeys them; materialization checks live application roles. Positive lifecycle Cloud captures remain dependent on a Native App fixture as previously accepted by review. This is a newly fixed reviewer gap since the earlier gate-only round, not a repeated code blocker.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
* LAV-3112: validate application-role lifecycle and grant paths
The committed grant changes resolve application-role grantees across ordinary,
bulk, and future grants, rekey future rules on rename, retire them with the
role, and check role liveness before materialization. Swept the grant recording
and materialization entry points for unresolved application-role names; the
ordinary, bulk, future, revoke, rename, and retirement paths now use the
scoped identity.
Validation: .spiral/check.sh passed formatting, lint, workspace tests,
vendored parser tests, policy guards, serial init hooks, and telemetry. Its
budgeted broad SQL/API lane was green through 62%, then reached the built-in
deadline; the state-snapshot lane was skipped for the same budget. The focused
application-role lifecycle file passed 20/20 on this checkout.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
CREATE outside application, basic -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context
CREATE outside application, OR REPLACE / OR ALTER / IF NOT EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_outside_application_context
CREATE qualified missing application, basic / IF NOT EXISTS / quoted dot -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER qualified missing application, SET / IF EXISTS UNSET -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
DROP qualified missing application, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER unqualified missing role, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role; tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role_if_exists
DROP unqualified missing role, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role; tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role_if_exists
GRANT ordinary privilege to missing quoted-dot role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_grantee_with_quoted_dot
GRANT / REVOKE ALL to missing qualified role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_bulk_and_future_grantee
GRANT / REVOKE FUTURE to missing qualified role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_bulk_and_future_grantee
REVOKE GRANT OPTION from missing qualified role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_bulk_and_future_grantee
CREATE populated application, basic / OR REPLACE / OR ALTER / IF NOT EXISTS / COMMENT -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
ALTER populated application, RENAME / SET COMMENT / UNSET COMMENT / quoted name -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
DROP populated application, basic / IF EXISTS -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
Two-application isolation and implicit owner grant -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
Live role ordinary / bulk grant projection and revoke -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
Live role future grant, rename, replacement, drop, and application retirement -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
## Deviations
ADR 107 suggests one parameterized lifecycle UDF family for database and application roles. The implementation retains separate application-role UDFs to preserve established database-role status and errors while sharing projection.
The applications table retains kind and database_name from native_app_scopes for existing APPLICATION PACKAGE metadata lookups and adds ADR 107's owner, package, and lifecycle fields.
Positive Cloud lifecycle and grant snapshots remain env-blocked until the Native App installer supplies an application fixture. The missing-container, missing-role, and missing-grantee paths are Cloud-captured.
* LAV-3112: merge main reset fix and validate CI snapshot lane
Merged origin/main, including LAV-3469's fix for the unrelated reset test
failure that made PR #3766 red. No application-role code changed in this round.
Validation: make check passed; the focused application-role lifecycle suite
passed 20/20; .spiral/check.sh passed all mandatory gates. Its full SQL/API
stage ran green to 75% before the built-in time budget and skipped snapshots.
The full state-snapshot lane passed separately (43 passed, 1 skipped),
including the formerly failing reset test.
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>
## Test matrix
CREATE outside application, basic -> tests/queries/access_control/test_adr107_baselines.py::test_application_role_outside_context
CREATE outside application, OR REPLACE / OR ALTER / IF NOT EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_outside_application_context
CREATE qualified missing application, basic / IF NOT EXISTS / quoted dot -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER qualified missing application, SET / IF EXISTS UNSET -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
DROP qualified missing application, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_container
ALTER unqualified missing role, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role; tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role_if_exists
DROP unqualified missing role, basic / IF EXISTS -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role; tests/queries/access_control/test_application_role_lifecycle.py::test_missing_unqualified_role_if_exists
GRANT ordinary privilege to missing quoted-dot role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_grantee_with_quoted_dot
GRANT / REVOKE ALL to missing qualified role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_bulk_and_future_grantee
GRANT / REVOKE FUTURE to missing qualified role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_bulk_and_future_grantee
REVOKE GRANT OPTION from missing qualified role -> tests/queries/access_control/test_application_role_lifecycle.py::test_missing_application_role_bulk_and_future_grantee
CREATE populated application, basic / OR REPLACE / OR ALTER / IF NOT EXISTS / COMMENT -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
ALTER populated application, RENAME / SET COMMENT / UNSET COMMENT / quoted name -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
DROP populated application, basic / IF EXISTS -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
Two-application isolation and implicit owner grant -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
Live role ordinary / bulk grant projection and revoke -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
Live role future grant, rename, replacement, drop, and application retirement -> uncovered: env-blocked until the Native App installer supplies a Cloud application fixture
## Deviations
ADR 107 suggests one parameterized lifecycle UDF family for database and application roles. The implementation retains separate application-role UDFs to preserve established database-role status and errors while sharing projection.
The applications table retains kind and database_name from native_app_scopes for existing APPLICATION PACKAGE metadata lookups and adds ADR 107's owner, package, and lifecycle fields.
Positive Cloud lifecycle and grant snapshots remain env-blocked until the Native App installer supplies an application fixture. The missing-container, missing-role, and missing-grantee paths are Cloud-captured.
---------
Co-authored-by: spiral <spiral@localhost>
Co-authored-by: Sabir Akhadov <sabir.akhadov@localstack.cloud>1 parent d9fbf7f commit 6faf43f
4 files changed
Lines changed: 108 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4155 | 4155 | | |
4156 | 4156 | | |
4157 | 4157 | | |
| 4158 | + | |
| 4159 | + | |
| 4160 | + | |
| 4161 | + | |
| 4162 | + | |
| 4163 | + | |
| 4164 | + | |
| 4165 | + | |
| 4166 | + | |
| 4167 | + | |
| 4168 | + | |
| 4169 | + | |
| 4170 | + | |
4158 | 4171 | | |
4159 | 4172 | | |
4160 | 4173 | | |
| |||
4303 | 4316 | | |
4304 | 4317 | | |
4305 | 4318 | | |
| 4319 | + | |
| 4320 | + | |
| 4321 | + | |
| 4322 | + | |
| 4323 | + | |
| 4324 | + | |
| 4325 | + | |
| 4326 | + | |
| 4327 | + | |
4306 | 4328 | | |
4307 | 4329 | | |
4308 | 4330 | | |
| |||
7957 | 7979 | | |
7958 | 7980 | | |
7959 | 7981 | | |
| 7982 | + | |
| 7983 | + | |
| 7984 | + | |
| 7985 | + | |
| 7986 | + | |
| 7987 | + | |
| 7988 | + | |
| 7989 | + | |
| 7990 | + | |
| 7991 | + | |
| 7992 | + | |
| 7993 | + | |
| 7994 | + | |
| 7995 | + | |
| 7996 | + | |
7960 | 7997 | | |
7961 | 7998 | | |
7962 | 7999 | | |
| |||
8054 | 8091 | | |
8055 | 8092 | | |
8056 | 8093 | | |
| 8094 | + | |
| 8095 | + | |
| 8096 | + | |
| 8097 | + | |
8057 | 8098 | | |
8058 | 8099 | | |
8059 | 8100 | | |
| |||
13000 | 13041 | | |
13001 | 13042 | | |
13002 | 13043 | | |
| 13044 | + | |
| 13045 | + | |
13003 | 13046 | | |
13004 | 13047 | | |
13005 | 13048 | | |
| |||
13039 | 13082 | | |
13040 | 13083 | | |
13041 | 13084 | | |
| 13085 | + | |
13042 | 13086 | | |
13043 | 13087 | | |
13044 | 13088 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
398 | 398 | | |
399 | 399 | | |
400 | 400 | | |
| 401 | + | |
401 | 402 | | |
402 | 403 | | |
403 | 404 | | |
| |||
439 | 440 | | |
440 | 441 | | |
441 | 442 | | |
| 443 | + | |
442 | 444 | | |
443 | 445 | | |
444 | 446 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
272 | 272 | | |
273 | 273 | | |
274 | 274 | | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
275 | 281 | | |
276 | 282 | | |
277 | 283 | | |
| |||
877 | 883 | | |
878 | 884 | | |
879 | 885 | | |
| 886 | + | |
| 887 | + | |
880 | 888 | | |
881 | 889 | | |
882 | 890 | | |
| |||
5038 | 5046 | | |
5039 | 5047 | | |
5040 | 5048 | | |
| 5049 | + | |
| 5050 | + | |
| 5051 | + | |
| 5052 | + | |
| 5053 | + | |
| 5054 | + | |
| 5055 | + | |
| 5056 | + | |
| 5057 | + | |
| 5058 | + | |
| 5059 | + | |
| 5060 | + | |
| 5061 | + | |
| 5062 | + | |
| 5063 | + | |
| 5064 | + | |
| 5065 | + | |
| 5066 | + | |
| 5067 | + | |
| 5068 | + | |
| 5069 | + | |
| 5070 | + | |
| 5071 | + | |
| 5072 | + | |
| 5073 | + | |
| 5074 | + | |
| 5075 | + | |
5041 | 5076 | | |
5042 | 5077 | | |
5043 | 5078 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5757 | 5757 | | |
5758 | 5758 | | |
5759 | 5759 | | |
| 5760 | + | |
| 5761 | + | |
5760 | 5762 | | |
5761 | 5763 | | |
5762 | 5764 | | |
| |||
8110 | 8112 | | |
8111 | 8113 | | |
8112 | 8114 | | |
| 8115 | + | |
| 8116 | + | |
| 8117 | + | |
| 8118 | + | |
| 8119 | + | |
| 8120 | + | |
| 8121 | + | |
| 8122 | + | |
| 8123 | + | |
| 8124 | + | |
| 8125 | + | |
| 8126 | + | |
| 8127 | + | |
| 8128 | + | |
| 8129 | + | |
| 8130 | + | |
| 8131 | + | |
| 8132 | + | |
| 8133 | + | |
| 8134 | + | |
| 8135 | + | |
| 8136 | + | |
| 8137 | + | |
8113 | 8138 | | |
8114 | 8139 | | |
8115 | 8140 | | |
| |||
8601 | 8626 | | |
8602 | 8627 | | |
8603 | 8628 | | |
| 8629 | + | |
| 8630 | + | |
8604 | 8631 | | |
8605 | 8632 | | |
8606 | 8633 | | |
| |||
0 commit comments