Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.
Findings
- TELEMETRY-001 [thrift, sea]: the terminal statement.complete telemetry event never populates resultFormat or compressed, so the inline-Arrow delivery shape and uncompressed payload are never reported
- failing test:
TELEMETRY-001 — successful sync execute emits exactly one terminal event with operation metadata [thrift], TELEMETRY-001 — successful sync execute emits exactly one terminal event with operation metadata [sea] (see the coverage PR diff under tests/)
- TELEMETRY-002 [thrift, sea]: statement error telemetry copies the raw server error message and JS stack verbatim, leaking SQL-derived identifiers (sensitive_table) out of the customer process instead of a sanitized error category
- failing test:
TELEMETRY-002 — failed statement emits sanitized error telemetry without SQL text [thrift], TELEMETRY-002 — failed statement emits sanitized error telemetry without SQL text [sea] (see the coverage PR diff under tests/)
- TELEMETRY-005 [thrift, sea]: for a CloudFetch/external-links result the terminal event still reports no resultFormat/compressed, so EXTERNAL_LINKS delivery and server-declared compression are indistinguishable from an inline result
- failing test:
TELEMETRY-005 — telemetry reports external-links delivery and compression [thrift], TELEMETRY-005 — telemetry reports external-links delivery and compression [sea] (see the coverage PR diff under tests/)
- TELEMETRY-002: statement error telemetry copies the raw server error message and JS stack verbatim into errorMessage/errorStack, leaking SQL-derived identifiers (table/column names, and any literals the server quotes) out of the customer process; the error descriptor should be sanitized to an aggregatable category/name
- TELEMETRY-001: the terminal statement.complete telemetry event never populates resultFormat or compressed (both are declared on TelemetryEvent and accepted by emitStatementComplete), so the result-delivery shape of an inline result (INLINE_ARROW, uncompressed) is never reported and downstream delivery-shape aggregates are blind
- TELEMETRY-005: for a CloudFetch/external-links result the terminal statement.complete event still reports no resultFormat/compressed, so EXTERNAL_LINKS delivery and the server-declared LZ4_FRAME compression are never distinguishable from an inline result in telemetry
Context
Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.
Findings
TELEMETRY-001 — successful sync execute emits exactly one terminal event with operation metadata [thrift], TELEMETRY-001 — successful sync execute emits exactly one terminal event with operation metadata [sea](see the coverage PR diff undertests/)TELEMETRY-002 — failed statement emits sanitized error telemetry without SQL text [thrift], TELEMETRY-002 — failed statement emits sanitized error telemetry without SQL text [sea](see the coverage PR diff undertests/)TELEMETRY-005 — telemetry reports external-links delivery and compression [thrift], TELEMETRY-005 — telemetry reports external-links delivery and compression [sea](see the coverage PR diff undertests/)Context