Skip to main content

omnigraph/exec/
mutation.rs

1use super::*;
2
3use super::query::literal_to_sql;
4
5// ─── Mutation helpers ────────────────────────────────────────────────────────
6
7/// Resolve an IRExpr to a concrete Literal value at runtime.
8fn resolve_expr_value(expr: &IRExpr, params: &ParamMap) -> Result<Literal> {
9    match expr {
10        IRExpr::Literal(lit) => Ok(lit.clone()),
11        IRExpr::Param(name) => params
12            .get(name)
13            .cloned()
14            .ok_or_else(|| OmniError::manifest(format!("parameter '{}' not provided", name))),
15        other => Err(OmniError::manifest(format!(
16            "unsupported expression in mutation: {:?}",
17            other
18        ))),
19    }
20}
21
22/// Create a single-element or N-element array from a Literal, matching the target DataType.
23fn literal_to_typed_array(
24    lit: &Literal,
25    data_type: &DataType,
26    num_rows: usize,
27) -> Result<ArrayRef> {
28    Ok(match (lit, data_type) {
29        (Literal::Null, _) => arrow_array::new_null_array(data_type, num_rows),
30        (Literal::String(s), DataType::Utf8) => {
31            Arc::new(StringArray::from(vec![s.as_str(); num_rows])) as ArrayRef
32        }
33        (Literal::Integer(n), DataType::Int32) => {
34            Arc::new(Int32Array::from(vec![*n as i32; num_rows]))
35        }
36        (Literal::Integer(n), DataType::Int64) => Arc::new(Int64Array::from(vec![*n; num_rows])),
37        (Literal::Integer(n), DataType::UInt32) => {
38            Arc::new(UInt32Array::from(vec![*n as u32; num_rows]))
39        }
40        (Literal::Integer(n), DataType::UInt64) => {
41            Arc::new(UInt64Array::from(vec![*n as u64; num_rows]))
42        }
43        (Literal::Float(f), DataType::Float32) => {
44            Arc::new(Float32Array::from(vec![*f as f32; num_rows]))
45        }
46        (Literal::Float(f), DataType::Float64) => Arc::new(Float64Array::from(vec![*f; num_rows])),
47        (Literal::Bool(b), DataType::Boolean) => Arc::new(BooleanArray::from(vec![*b; num_rows])),
48        (Literal::Date(s), DataType::Date32) => {
49            let days = crate::loader::parse_date32_literal(s)?;
50            Arc::new(Date32Array::from(vec![days; num_rows]))
51        }
52        (Literal::DateTime(s), DataType::Date64) => Arc::new(Date64Array::from(vec![
53            crate::loader::parse_date64_literal(s)?;
54            num_rows
55        ])),
56        (Literal::List(items), DataType::List(field)) => {
57            typed_list_literal_to_array(items, field.data_type(), num_rows)?
58        }
59        (Literal::List(items), DataType::FixedSizeList(field, dim))
60            if field.data_type() == &DataType::Float32 =>
61        {
62            if items.len() != *dim as usize {
63                return Err(OmniError::manifest(format!(
64                    "vector property expects {} dimensions, got {}",
65                    dim,
66                    items.len()
67                )));
68            }
69            let mut builder = FixedSizeListBuilder::with_capacity(
70                Float32Builder::with_capacity(num_rows * (*dim as usize)),
71                *dim,
72                num_rows,
73            )
74            .with_field(field.clone());
75            for _ in 0..num_rows {
76                for item in items {
77                    match item {
78                        Literal::Integer(value) => builder.values().append_value(*value as f32),
79                        Literal::Float(value) => builder.values().append_value(*value as f32),
80                        _ => {
81                            return Err(OmniError::manifest(
82                                "vector elements must be numeric".to_string(),
83                            ));
84                        }
85                    }
86                }
87                builder.append(true);
88            }
89            Arc::new(builder.finish())
90        }
91        _ => {
92            return Err(OmniError::manifest(format!(
93                "cannot convert {:?} to {:?}",
94                lit, data_type
95            )));
96        }
97    })
98}
99
100fn typed_list_literal_to_array(
101    items: &[Literal],
102    item_type: &DataType,
103    num_rows: usize,
104) -> Result<ArrayRef> {
105    match item_type {
106        DataType::Utf8 => {
107            let mut builder = ListBuilder::new(StringBuilder::new());
108            for _ in 0..num_rows {
109                for item in items {
110                    match item {
111                        Literal::String(value) => builder.values().append_value(value),
112                        _ => builder.values().append_null(),
113                    }
114                }
115                builder.append(true);
116            }
117            Ok(Arc::new(builder.finish()))
118        }
119        DataType::Boolean => {
120            let mut builder = ListBuilder::new(BooleanBuilder::new());
121            for _ in 0..num_rows {
122                for item in items {
123                    match item {
124                        Literal::Bool(value) => builder.values().append_value(*value),
125                        _ => builder.values().append_null(),
126                    }
127                }
128                builder.append(true);
129            }
130            Ok(Arc::new(builder.finish()))
131        }
132        DataType::Int32 => {
133            let mut builder = ListBuilder::new(Int32Builder::new());
134            for _ in 0..num_rows {
135                for item in items {
136                    match item {
137                        Literal::Integer(value) => {
138                            let value = i32::try_from(*value).map_err(|_| {
139                                OmniError::manifest(format!(
140                                    "list value {} exceeds Int32 range",
141                                    value
142                                ))
143                            })?;
144                            builder.values().append_value(value);
145                        }
146                        _ => builder.values().append_null(),
147                    }
148                }
149                builder.append(true);
150            }
151            Ok(Arc::new(builder.finish()))
152        }
153        DataType::Int64 => {
154            let mut builder = ListBuilder::new(Int64Builder::new());
155            for _ in 0..num_rows {
156                for item in items {
157                    match item {
158                        Literal::Integer(value) => builder.values().append_value(*value),
159                        _ => builder.values().append_null(),
160                    }
161                }
162                builder.append(true);
163            }
164            Ok(Arc::new(builder.finish()))
165        }
166        DataType::UInt32 => {
167            let mut builder = ListBuilder::new(UInt32Builder::new());
168            for _ in 0..num_rows {
169                for item in items {
170                    match item {
171                        Literal::Integer(value) => {
172                            let value = u32::try_from(*value).map_err(|_| {
173                                OmniError::manifest(format!(
174                                    "list value {} exceeds UInt32 range",
175                                    value
176                                ))
177                            })?;
178                            builder.values().append_value(value);
179                        }
180                        _ => builder.values().append_null(),
181                    }
182                }
183                builder.append(true);
184            }
185            Ok(Arc::new(builder.finish()))
186        }
187        DataType::UInt64 => {
188            let mut builder = ListBuilder::new(UInt64Builder::new());
189            for _ in 0..num_rows {
190                for item in items {
191                    match item {
192                        Literal::Integer(value) => {
193                            let value = u64::try_from(*value).map_err(|_| {
194                                OmniError::manifest(format!(
195                                    "list value {} exceeds UInt64 range",
196                                    value
197                                ))
198                            })?;
199                            builder.values().append_value(value);
200                        }
201                        _ => builder.values().append_null(),
202                    }
203                }
204                builder.append(true);
205            }
206            Ok(Arc::new(builder.finish()))
207        }
208        DataType::Float32 => {
209            let mut builder = ListBuilder::new(Float32Builder::new());
210            for _ in 0..num_rows {
211                for item in items {
212                    match item {
213                        Literal::Integer(value) => builder.values().append_value(*value as f32),
214                        Literal::Float(value) => builder.values().append_value(*value as f32),
215                        _ => builder.values().append_null(),
216                    }
217                }
218                builder.append(true);
219            }
220            Ok(Arc::new(builder.finish()))
221        }
222        DataType::Float64 => {
223            let mut builder = ListBuilder::new(Float64Builder::new());
224            for _ in 0..num_rows {
225                for item in items {
226                    match item {
227                        Literal::Integer(value) => builder.values().append_value(*value as f64),
228                        Literal::Float(value) => builder.values().append_value(*value),
229                        _ => builder.values().append_null(),
230                    }
231                }
232                builder.append(true);
233            }
234            Ok(Arc::new(builder.finish()))
235        }
236        DataType::Date32 => {
237            let mut builder = ListBuilder::new(Date32Builder::new());
238            for _ in 0..num_rows {
239                for item in items {
240                    match item {
241                        Literal::Date(value) => builder
242                            .values()
243                            .append_value(crate::loader::parse_date32_literal(value)?),
244                        _ => builder.values().append_null(),
245                    }
246                }
247                builder.append(true);
248            }
249            Ok(Arc::new(builder.finish()))
250        }
251        DataType::Date64 => {
252            let mut builder = ListBuilder::new(Date64Builder::new());
253            for _ in 0..num_rows {
254                for item in items {
255                    match item {
256                        Literal::DateTime(value) => builder
257                            .values()
258                            .append_value(crate::loader::parse_date64_literal(value)?),
259                        _ => builder.values().append_null(),
260                    }
261                }
262                builder.append(true);
263            }
264            Ok(Arc::new(builder.finish()))
265        }
266        other => Err(OmniError::manifest(format!(
267            "cannot convert list literal to {:?}",
268            other
269        ))),
270    }
271}
272
273/// Build a single-element blob array from a URI or base64 value string.
274fn build_blob_array_from_value(value: &str) -> Result<ArrayRef> {
275    let mut builder = BlobArrayBuilder::new(1);
276    crate::loader::append_blob_value(&mut builder, value)?;
277    builder
278        .finish()
279        .map_err(|e| OmniError::Lance(e.to_string()))
280}
281
282/// Build a null blob array with one element.
283fn build_null_blob_array() -> Result<ArrayRef> {
284    let mut builder = BlobArrayBuilder::new(1);
285    builder
286        .push_null()
287        .map_err(|e| OmniError::Lance(e.to_string()))?;
288    builder
289        .finish()
290        .map_err(|e| OmniError::Lance(e.to_string()))
291}
292
293/// Build a single-row RecordBatch from resolved assignments.
294fn build_insert_batch(
295    schema: &SchemaRef,
296    id: &str,
297    assignments: &HashMap<String, Literal>,
298    blob_properties: &HashSet<String>,
299) -> Result<RecordBatch> {
300    let mut columns: Vec<ArrayRef> = Vec::with_capacity(schema.fields().len());
301
302    for field in schema.fields() {
303        if field.name() == "id" {
304            columns.push(Arc::new(StringArray::from(vec![id])));
305        } else if blob_properties.contains(field.name()) {
306            if let Some(Literal::String(uri)) = assignments.get(field.name()) {
307                columns.push(build_blob_array_from_value(uri)?);
308            } else if field.is_nullable() {
309                columns.push(build_null_blob_array()?);
310            } else {
311                return Err(OmniError::manifest(format!(
312                    "missing required blob property '{}'",
313                    field.name()
314                )));
315            }
316        } else if field.name() == "src" {
317            let lit = assignments.get("from").ok_or_else(|| {
318                OmniError::manifest("missing required edge endpoint 'from'".to_string())
319            })?;
320            columns.push(literal_to_typed_array(lit, field.data_type(), 1)?);
321        } else if field.name() == "dst" {
322            let lit = assignments.get("to").ok_or_else(|| {
323                OmniError::manifest("missing required edge endpoint 'to'".to_string())
324            })?;
325            columns.push(literal_to_typed_array(lit, field.data_type(), 1)?);
326        } else if let Some(lit) = assignments.get(field.name()) {
327            columns.push(literal_to_typed_array(lit, field.data_type(), 1)?);
328        } else if field.is_nullable() {
329            columns.push(arrow_array::new_null_array(field.data_type(), 1));
330        } else {
331            return Err(OmniError::manifest(format!(
332                "missing required property '{}'",
333                field.name()
334            )));
335        }
336    }
337
338    RecordBatch::try_new(schema.clone(), columns).map_err(|e| OmniError::Lance(e.to_string()))
339}
340
341async fn validate_edge_insert_endpoints(
342    db: &Omnigraph,
343    staging: &MutationStaging,
344    branch: Option<&str>,
345    edge_name: &str,
346    assignments: &HashMap<String, Literal>,
347) -> Result<()> {
348    let catalog = db.catalog();
349    let edge_type = catalog
350        .edge_types
351        .get(edge_name)
352        .ok_or_else(|| OmniError::manifest(format!("unknown edge type '{}'", edge_name)))?;
353    let from = match assignments.get("from") {
354        Some(Literal::String(value)) => value.as_str(),
355        Some(other) => {
356            return Err(OmniError::manifest(format!(
357                "edge {} from endpoint must be a string id, got {}",
358                edge_name,
359                literal_to_sql(other)
360            )));
361        }
362        None => {
363            return Err(OmniError::manifest(format!(
364                "edge {} missing 'from' endpoint",
365                edge_name
366            )));
367        }
368    };
369    let to = match assignments.get("to") {
370        Some(Literal::String(value)) => value.as_str(),
371        Some(other) => {
372            return Err(OmniError::manifest(format!(
373                "edge {} to endpoint must be a string id, got {}",
374                edge_name,
375                literal_to_sql(other)
376            )));
377        }
378        None => {
379            return Err(OmniError::manifest(format!(
380                "edge {} missing 'to' endpoint",
381                edge_name
382            )));
383        }
384    };
385
386    ensure_node_id_exists(db, staging, branch, &edge_type.from_type, from, "src").await?;
387    ensure_node_id_exists(db, staging, branch, &edge_type.to_type, to, "dst").await?;
388    Ok(())
389}
390
391/// Quick scan of pending batches for an `id` value match. Used by the
392/// mutation path's edge endpoint validation to satisfy read-your-writes
393/// for same-query inserts before they're committed to Lance.
394fn pending_batches_contain_id(batches: &[RecordBatch], id: &str) -> bool {
395    for batch in batches {
396        let Some(col) = batch.column_by_name("id") else {
397            continue;
398        };
399        let Some(arr) = col.as_any().downcast_ref::<StringArray>() else {
400            continue;
401        };
402        for i in 0..arr.len() {
403            if arr.is_valid(i) && arr.value(i) == id {
404                return true;
405            }
406        }
407    }
408    false
409}
410
411async fn ensure_node_id_exists(
412    db: &Omnigraph,
413    staging: &MutationStaging,
414    branch: Option<&str>,
415    node_type: &str,
416    id: &str,
417    label: &str,
418) -> Result<()> {
419    let table_key = format!("node:{}", node_type);
420
421    // Prefer the in-query pending accumulator so a same-query insert of
422    // the referenced node is visible to this validation. Fall back to
423    // the pre-mutation manifest snapshot when nothing pending matches.
424    let pending = staging.pending_batches(&table_key);
425    if pending_batches_contain_id(pending, id) {
426        return Ok(());
427    }
428
429    let filter = format!("id = '{}'", id.replace('\'', "''"));
430    let snapshot = db.snapshot_for_branch(branch).await?;
431    let ds = snapshot.open(&table_key).await?;
432    let exists = ds
433        .count_rows(Some(filter))
434        .await
435        .map_err(|e| OmniError::Lance(e.to_string()))?
436        > 0;
437
438    if exists {
439        Ok(())
440    } else {
441        Err(OmniError::manifest(format!(
442            "{} '{}' not found in {}",
443            label, id, node_type
444        )))
445    }
446}
447
448/// Convert an IRMutationPredicate to a Lance SQL filter string.
449fn predicate_to_sql(
450    predicate: &IRMutationPredicate,
451    params: &ParamMap,
452    is_edge: bool,
453) -> Result<String> {
454    let column = if is_edge {
455        match predicate.property.as_str() {
456            "from" => "src".to_string(),
457            "to" => "dst".to_string(),
458            other => other.to_string(),
459        }
460    } else {
461        predicate.property.clone()
462    };
463
464    let value = resolve_expr_value(&predicate.value, params)?;
465    let value_sql = literal_to_sql(&value);
466
467    let op = match predicate.op {
468        CompOp::Eq => "=",
469        CompOp::Ne => "!=",
470        CompOp::Gt => ">",
471        CompOp::Lt => "<",
472        CompOp::Ge => ">=",
473        CompOp::Le => "<=",
474        CompOp::Contains => {
475            return Err(OmniError::manifest(
476                "contains predicate not supported in mutations".to_string(),
477            ));
478        }
479    };
480
481    Ok(format!("{} {} {}", column, op, value_sql))
482}
483
484/// Replace specific columns in a RecordBatch with new literal values.
485///
486/// Blob columns may or may not be present in `batch` depending on the
487/// caller's scan projection:
488/// - If `batch` does NOT contain a blob column AND it has no assignment,
489///   the column is OMITTED from the output. `merge_insert` leaves it
490///   untouched.
491/// - If `batch` DOES contain a blob column AND it has no assignment, the
492///   column is COPIED to the output. This enables coalescing of
493///   different-shape updates into a single full-schema merge batch (the
494///   per-table accumulator in `MutationStaging` requires consistent
495///   schemas across pending batches for `concat_batches`). The
496///   round-tripping cost is acceptable for typical agent-driven
497///   mutations; tables with large blobs and unassigned-blob updates may
498///   want to be split into separate queries.
499/// - If a blob column has a string-URI assignment, build the blob array
500///   inline.
501fn apply_assignments(
502    full_schema: &SchemaRef,
503    batch: &RecordBatch,
504    assignments: &HashMap<String, Literal>,
505    blob_properties: &HashSet<String>,
506) -> Result<RecordBatch> {
507    let mut columns: Vec<ArrayRef> = Vec::with_capacity(full_schema.fields().len());
508    let mut out_fields: Vec<Field> = Vec::with_capacity(full_schema.fields().len());
509
510    for field in full_schema.fields().iter() {
511        if blob_properties.contains(field.name()) {
512            if let Some(Literal::String(uri)) = assignments.get(field.name()) {
513                // Assigned: build a single blob column from the URI.
514                let mut builder = BlobArrayBuilder::new(batch.num_rows());
515                for _ in 0..batch.num_rows() {
516                    crate::loader::append_blob_value(&mut builder, uri)?;
517                }
518                let blob_field = lance::blob::blob_field(field.name(), true);
519                out_fields.push(blob_field);
520                columns.push(
521                    builder
522                        .finish()
523                        .map_err(|e| OmniError::Lance(e.to_string()))?,
524                );
525            } else if let Some(col) = batch.column_by_name(field.name()) {
526                // Unassigned but scan included it: copy through (writes
527                // back the same blob, no observable change but uniform
528                // schema for the accumulator).
529                let blob_field = lance::blob::blob_field(field.name(), field.is_nullable());
530                out_fields.push(blob_field);
531                columns.push(col.clone());
532            }
533            // else: scan did not include this blob column and no
534            // assignment — omit. Caller's accumulator must accept the
535            // narrower schema (legacy single-merge_insert path).
536        } else if let Some(lit) = assignments.get(field.name()) {
537            out_fields.push(field.as_ref().clone());
538            columns.push(literal_to_typed_array(
539                lit,
540                field.data_type(),
541                batch.num_rows(),
542            )?);
543        } else {
544            let col = batch.column_by_name(field.name()).ok_or_else(|| {
545                OmniError::Lance(format!(
546                    "column '{}' not found in scan result",
547                    field.name()
548                ))
549            })?;
550            out_fields.push(field.as_ref().clone());
551            columns.push(col.clone());
552        }
553    }
554
555    RecordBatch::try_new(Arc::new(Schema::new(out_fields)), columns)
556        .map_err(|e| OmniError::Lance(e.to_string()))
557}
558
559// ─── Mutation execution ──────────────────────────────────────────────────────
560
561use super::staging::{MutationStaging, PendingMode};
562
563/// Open a sub-table dataset for read or inline-commit-write within the
564/// current mutation query, capturing pre-write metadata in `staging` on
565/// first touch. The captured version is the publisher's CAS fence at
566/// end-of-query (per-table OCC).
567///
568/// On first touch, opens the dataset at HEAD on the requested branch
569/// via `open_for_mutation_on_branch`, which compares Lance HEAD against
570/// the manifest's pinned version — that fence is the engine's
571/// publisher-style OCC catching cross-writer drift before we make any
572/// changes.
573///
574/// On subsequent touches *within the same query*, behavior depends on
575/// whether the table has already been inline-committed by a delete op:
576///
577/// - **Insert / update path (no inline commit between touches).** Lance
578///   HEAD has not moved since first touch, so a fresh
579///   `open_for_mutation_on_branch` would still match the manifest
580///   pinned version. We just go through it again; `ensure_path` is a
581///   no-op (idempotent on the captured `expected_version`).
582/// - **Delete cascade or multi-delete on the same table.** A prior
583///   `delete_where` on this table has already advanced Lance HEAD past
584///   the manifest's pinned version (the manifest doesn't move until
585///   end-of-query). Going through `open_for_mutation_on_branch` again
586///   would trip its `ensure_expected_version` equality check
587///   (`actual = pinned + 1` vs `expected = pinned`). Instead we route
588///   through `reopen_for_mutation` at the post-inline-commit Lance
589///   version captured in `staging.inline_committed[table_key]`, which
590///   is the source of truth for "where is Lance HEAD right now on
591///   this table within this query."
592///
593/// The `inline_committed` reopen branch closes the multi-delete-on-same-table
594/// failure path that pre-staged-write engines inherited. The branch goes
595/// away once Lance exposes a two-phase delete API
596/// ([lance-format/lance#6658](https://github.com/lance-format/lance/issues/6658))
597/// and we can stage deletes on the same path as inserts/updates.
598async fn open_table_for_mutation(
599    db: &Omnigraph,
600    staging: &mut MutationStaging,
601    branch: Option<&str>,
602    table_key: &str,
603    op_kind: crate::db::MutationOpKind,
604) -> Result<(Dataset, String, Option<String>)> {
605    if let Some(prior) = staging.inline_committed.get(table_key) {
606        let path = staging.paths.get(table_key).ok_or_else(|| {
607            OmniError::manifest_internal(format!(
608                "open_table_for_mutation: inline_committed[{}] without paths entry",
609                table_key
610            ))
611        })?;
612        let ds = db
613            .reopen_for_mutation(
614                table_key,
615                &path.full_path,
616                path.table_branch.as_deref(),
617                prior.table_version,
618                op_kind,
619            )
620            .await?;
621        return Ok((ds, path.full_path.clone(), path.table_branch.clone()));
622    }
623    let (ds, full_path, table_branch) = db
624        .open_for_mutation_on_branch(branch, table_key, op_kind)
625        .await?;
626    let expected_version = ds.version().version;
627    staging.ensure_path(
628        table_key,
629        full_path.clone(),
630        table_branch.clone(),
631        expected_version,
632        op_kind,
633    );
634    Ok((ds, full_path, table_branch))
635}
636
637/// D₂ parse-time check: a single mutation query is either insert/update-only
638/// or delete-only. Mixed → reject before any I/O.
639///
640/// Reason: under the staged-write writer, inserts and updates
641/// accumulate in memory and commit at end-of-query, while deletes still
642/// inline-commit (Lance lacks a public two-phase delete in 4.0.0).
643/// Mixing creates ordering hazards (same-row insert→delete becomes a no-op
644/// because the staged insert isn't visible to delete; cascading deletes
645/// of just-inserted edges break referential integrity by silent design).
646/// Until Lance exposes `DeleteJob::execute_uncommitted`, the parse-time
647/// rejection keeps both paths atomic and correct.
648fn enforce_no_mixed_destructive_constructive(
649    ir: &omnigraph_compiler::ir::MutationIR,
650) -> Result<()> {
651    let mut has_constructive = false;
652    let mut has_delete = false;
653    for op in &ir.ops {
654        match op {
655            MutationOpIR::Insert { .. } | MutationOpIR::Update { .. } => {
656                has_constructive = true;
657            }
658            MutationOpIR::Delete { .. } => {
659                has_delete = true;
660            }
661        }
662    }
663    if has_constructive && has_delete {
664        return Err(OmniError::manifest(format!(
665            "mutation '{}' on the same query mixes inserts/updates and deletes; \
666             split into separate mutations: (1) inserts and updates, then (2) deletes. \
667             This restriction lifts when Lance exposes a two-phase delete API \
668             (tracked: lance-format/lance#6658).",
669            ir.name
670        )));
671    }
672    Ok(())
673}
674
675impl Omnigraph {
676    pub async fn mutate(
677        &self,
678        branch: &str,
679        query_source: &str,
680        query_name: &str,
681        params: &ParamMap,
682    ) -> Result<MutationResult> {
683        self.mutate_as(branch, query_source, query_name, params, None)
684            .await
685    }
686
687    pub async fn mutate_as(
688        &self,
689        branch: &str,
690        query_source: &str,
691        query_name: &str,
692        params: &ParamMap,
693        actor_id: Option<&str>,
694    ) -> Result<MutationResult> {
695        // Engine-layer policy gate (MR-722 fan-out / PR #3). Scope is
696        // `Branch(branch)` to match the HTTP-layer convention at
697        // `server_change` (branch=Some(branch), target_branch=None). When no
698        // PolicyChecker is installed this is a no-op; with policy installed
699        // and actor=None this fails hard (forget-the-actor footgun guard).
700        self.enforce(
701            omnigraph_policy::PolicyAction::Change,
702            &omnigraph_policy::ResourceScope::Branch(branch.to_string()),
703            actor_id,
704        )?;
705        self.mutate_with_current_actor(branch, query_source, query_name, params, actor_id)
706            .await
707    }
708
709    async fn mutate_with_current_actor(
710        &self,
711        branch: &str,
712        query_source: &str,
713        query_name: &str,
714        params: &ParamMap,
715        actor_id: Option<&str>,
716    ) -> Result<MutationResult> {
717        self.ensure_schema_state_valid().await?;
718        let requested = Self::normalize_branch_name(branch)?;
719        // Reject internal `__run__*` / system-prefixed branches at the
720        // public write boundary. Direct-publish paths assert this
721        // explicitly so a caller can't write to legacy or system
722        // staging branches by passing the prefix verbatim.
723        if let Some(name) = requested.as_deref() {
724            crate::db::ensure_public_branch_ref(name, "mutate")?;
725        }
726        let resolved_params = enrich_mutation_params(params)?;
727
728        // Per-query staging accumulator. Inserts and updates push batches
729        // into `pending`; deletes still inline-commit and record into
730        // `inline_committed`. At end-of-query, `finalize` issues one
731        // `stage_*` + `commit_staged` per pending table, then the
732        // publisher commits the manifest atomically across all touched
733        // tables. Branch is threaded explicitly — no coordinator swap.
734        let mut staging = MutationStaging::default();
735
736        let exec_result = self
737            .execute_named_mutation(
738                query_source,
739                query_name,
740                &resolved_params,
741                requested.as_deref(),
742                &mut staging,
743            )
744            .await;
745
746        match exec_result {
747            Err(e) => Err(e),
748            Ok(total) if staging.is_empty() => Ok(total),
749            Ok(total) => {
750                let staged = staging.stage_all(self, requested.as_deref()).await?;
751                // `_queue_guards` holds per-(table_key, branch) write
752                // queues acquired inside `commit_all`. Held across the
753                // manifest publish below so no concurrent writer can
754                // interleave between our commit_staged and our publish
755                // (which would correctly fail our CAS but leave Lance
756                // HEAD advanced — the residual class MR-870 recovers).
757                let (updates, expected_versions, sidecar_handle, _queue_guards) = staged
758                    .commit_all(
759                        self,
760                        requested.as_deref(),
761                        crate::db::manifest::SidecarKind::Mutation,
762                        actor_id,
763                    )
764                    .await?;
765                // Failpoint that wedges the documented finalize→publisher
766                // residual: per-table `commit_staged` calls already
767                // advanced Lance HEAD on every touched table; a failure
768                // injected here mirrors the production-rare case where
769                // the publisher's CAS pre-check rejects (or the manifest
770                // write throws) after staged commits succeeded. The
771                // sidecar written inside `staging.finalize()` persists
772                // across this failure so the next `Omnigraph::open`'s
773                // recovery sweep can roll forward — see
774                // `tests/failpoints.rs::recovery_rolls_forward_after_finalize_publisher_failure`.
775                crate::failpoints::maybe_fail("mutation.post_finalize_pre_publisher")?;
776                self.commit_updates_on_branch_with_expected(
777                    requested.as_deref(),
778                    &updates,
779                    &expected_versions,
780                    actor_id,
781                )
782                .await?;
783                // Phase C succeeded — sidecar can be deleted. If this
784                // delete fails, the next open's sweep classifies every
785                // table as NoMovement (manifest pin == Lance HEAD ==
786                // post_commit_pin) and the sidecar is treated as a
787                // stale artifact (cleaned up via the Phase 2 logic).
788                if let Some(handle) = sidecar_handle {
789                    // Best-effort cleanup: the manifest publish already
790                    // succeeded, so the user's mutation is durable. A
791                    // failed delete leaves the sidecar on disk; the
792                    // next open's recovery sweep classifies every table
793                    // as `NoMovement` (manifest pin == Lance HEAD ==
794                    // post_commit_pin) and tidies up. Failing the user
795                    // here would return an error for a write that
796                    // already landed.
797                    if let Err(err) = crate::db::manifest::delete_sidecar(
798                        &handle,
799                        self.storage_adapter(),
800                    )
801                    .await
802                    {
803                        tracing::warn!(
804                            error = %err,
805                            operation_id = handle.operation_id.as_str(),
806                            "recovery sidecar cleanup failed; the next open's recovery sweep will resolve it"
807                        );
808                    }
809                }
810                Ok(total)
811            }
812        }
813    }
814
815    async fn execute_named_mutation(
816        &self,
817        query_source: &str,
818        query_name: &str,
819        params: &ParamMap,
820        branch: Option<&str>,
821        staging: &mut MutationStaging,
822    ) -> Result<MutationResult> {
823        let query_decl = omnigraph_compiler::find_named_query(query_source, query_name)
824            .map_err(|e| OmniError::manifest(e.to_string()))?;
825
826        let checked = typecheck_query_decl(&self.catalog(), &query_decl)?;
827        match checked {
828            CheckedQuery::Mutation(_) => {}
829            CheckedQuery::Read(_) => {
830                return Err(OmniError::manifest(
831                    "mutation execution called on a read query; use query instead".to_string(),
832                ));
833            }
834        }
835
836        let ir = lower_mutation_query(&query_decl)?;
837        // D₂: reject mixed insert/update + delete before any I/O.
838        enforce_no_mixed_destructive_constructive(&ir)?;
839
840        let mut total = MutationResult::default();
841        for op in &ir.ops {
842            let result = match op {
843                MutationOpIR::Insert {
844                    type_name,
845                    assignments,
846                } => {
847                    self.execute_insert(type_name, assignments, params, branch, staging)
848                        .await?
849                }
850                MutationOpIR::Update {
851                    type_name,
852                    assignments,
853                    predicate,
854                } => {
855                    self.execute_update(
856                        type_name,
857                        assignments,
858                        predicate,
859                        params,
860                        branch,
861                        staging,
862                    )
863                    .await?
864                }
865                MutationOpIR::Delete {
866                    type_name,
867                    predicate,
868                } => {
869                    self.execute_delete(type_name, predicate, params, branch, staging)
870                        .await?
871                }
872            };
873            total.affected_nodes += result.affected_nodes;
874            total.affected_edges += result.affected_edges;
875        }
876        Ok(total)
877    }
878
879    async fn execute_insert(
880        &self,
881        type_name: &str,
882        assignments: &[IRAssignment],
883        params: &ParamMap,
884        branch: Option<&str>,
885        staging: &mut MutationStaging,
886    ) -> Result<MutationResult> {
887        let mut resolved: HashMap<String, Literal> = HashMap::new();
888        for a in assignments {
889            resolved.insert(a.property.clone(), resolve_expr_value(&a.value, params)?);
890        }
891
892        let is_node = self.catalog().node_types.contains_key(type_name);
893        let is_edge = self.catalog().edge_types.contains_key(type_name);
894
895        if is_node {
896            let node_type = &self.catalog().node_types[type_name];
897            let schema = node_type.arrow_schema.clone();
898            let blob_props = node_type.blob_properties.clone();
899            let id = if let Some(key_prop) = node_type.key_property() {
900                match resolved.get(key_prop) {
901                    Some(Literal::String(s)) => s.clone(),
902                    Some(other) => literal_to_sql(other).trim_matches('\'').to_string(),
903                    None => {
904                        return Err(OmniError::manifest(format!(
905                            "insert missing @key property '{}'",
906                            key_prop
907                        )));
908                    }
909                }
910            } else {
911                ulid::Ulid::new().to_string()
912            };
913
914            let batch = build_insert_batch(&schema, &id, &resolved, &blob_props)?;
915            crate::loader::validate_value_constraints(&batch, node_type)?;
916            crate::loader::validate_enum_constraints(&batch, &node_type.properties, type_name)?;
917            let unique_props = crate::loader::unique_property_names_for_node(node_type);
918            if !unique_props.is_empty() {
919                crate::loader::enforce_unique_constraints_intra_batch(
920                    &batch,
921                    type_name,
922                    &unique_props,
923                )?;
924            }
925            let has_key = node_type.key_property().is_some();
926            let table_key = format!("node:{}", type_name);
927            // Capture pre-write metadata on first touch (no Lance write).
928            let insert_kind = if has_key {
929                crate::db::MutationOpKind::Merge
930            } else {
931                crate::db::MutationOpKind::Insert
932            };
933            let (_ds, _full_path, _table_branch) =
934                open_table_for_mutation(self, staging, branch, &table_key, insert_kind).await?;
935            // Accumulate. @key inserts go into the Merge stream (so a
936            // later update on the same id coalesces correctly); no-key
937            // inserts go into the Append stream.
938            let mode = if has_key {
939                PendingMode::Merge
940            } else {
941                PendingMode::Append
942            };
943            staging.append_batch(&table_key, schema, mode, batch)?;
944
945            Ok(MutationResult {
946                affected_nodes: 1,
947                affected_edges: 0,
948            })
949        } else if is_edge {
950            let edge_type = &self.catalog().edge_types[type_name];
951            let schema = edge_type.arrow_schema.clone();
952            let blob_props = edge_type.blob_properties.clone();
953            let id = ulid::Ulid::new().to_string();
954
955            let batch = build_insert_batch(&schema, &id, &resolved, &blob_props)?;
956            validate_edge_insert_endpoints(self, staging, branch, type_name, &resolved).await?;
957            crate::loader::validate_enum_constraints(&batch, &edge_type.properties, type_name)?;
958            let unique_props = crate::loader::unique_property_names_for_edge(edge_type);
959            if !unique_props.is_empty() {
960                crate::loader::enforce_unique_constraints_intra_batch(
961                    &batch,
962                    type_name,
963                    &unique_props,
964                )?;
965            }
966            let table_key = format!("edge:{}", type_name);
967            // Capture pre-write metadata on first touch (no Lance write).
968            let (ds, _full_path, _table_branch) = open_table_for_mutation(
969                self,
970                staging,
971                branch,
972                &table_key,
973                crate::db::MutationOpKind::Insert,
974            )
975            .await?;
976            // Accumulate the new edge row. Edge IDs are ULID-generated so
977            // Append mode is correct (no key-based dedup needed).
978            staging.append_batch(&table_key, schema, PendingMode::Append, batch.clone())?;
979
980            // Edge cardinality validation: scan committed edges via Lance
981            // + iterate pending edges in-memory for the `src` column,
982            // group-by-src. The pending side already includes the row
983            // we just appended (above).
984            validate_edge_cardinality_with_pending(
985                self,
986                &ds,
987                staging,
988                &table_key,
989                edge_type,
990            )
991            .await?;
992
993            self.invalidate_graph_index().await;
994
995            Ok(MutationResult {
996                affected_nodes: 0,
997                affected_edges: 1,
998            })
999        } else {
1000            Err(OmniError::manifest(format!("unknown type '{}'", type_name)))
1001        }
1002    }
1003
1004    async fn execute_update(
1005        &self,
1006        type_name: &str,
1007        assignments: &[IRAssignment],
1008        predicate: &IRMutationPredicate,
1009        params: &ParamMap,
1010        branch: Option<&str>,
1011        staging: &mut MutationStaging,
1012    ) -> Result<MutationResult> {
1013        // Defense in depth: ensure this is a node type
1014        if !self.catalog().node_types.contains_key(type_name) {
1015            return Err(OmniError::manifest(format!(
1016                "update is only supported for node types, not '{}'",
1017                type_name
1018            )));
1019        }
1020
1021        // Reject updates to @key properties — identity is immutable
1022        if let Some(key_prop) = self.catalog().node_types[type_name].key_property() {
1023            if assignments.iter().any(|a| a.property == key_prop) {
1024                return Err(OmniError::manifest(format!(
1025                    "cannot update @key property '{}' — delete and re-insert instead",
1026                    key_prop
1027                )));
1028            }
1029        }
1030
1031        let pred_sql = predicate_to_sql(predicate, params, false)?;
1032        let schema = self.catalog().node_types[type_name].arrow_schema.clone();
1033        let blob_props = self.catalog().node_types[type_name].blob_properties.clone();
1034
1035        let table_key = format!("node:{}", type_name);
1036        let (ds, _full_path, _table_branch) = open_table_for_mutation(
1037            self,
1038            staging,
1039            branch,
1040            &table_key,
1041            crate::db::MutationOpKind::Update,
1042        )
1043        .await?;
1044
1045        // Scan committed via Lance + apply the same predicate to pending
1046        // batches via DataFusion `MemTable` (read-your-writes for prior
1047        // ops in this query). The pending side may include rows from
1048        // earlier `insert` / `update` ops on the same table.
1049        //
1050        // For blob tables we project away the blob columns: Lance's
1051        // scanner doesn't accept the standard projection path on blob
1052        // descriptors and would panic with a `Field::project` assertion.
1053        // The downstream `apply_assignments` synthesizes blob columns
1054        // from explicit assignments and omits unassigned blobs (Lance's
1055        // merge_insert leaves them untouched). Tables without blob
1056        // columns scan the full schema unprojected.
1057        let non_blob_cols: Vec<&str> = schema
1058            .fields()
1059            .iter()
1060            .filter(|f| !blob_props.contains(f.name()))
1061            .map(|f| f.name().as_str())
1062            .collect();
1063        let projection: Option<&[&str]> =
1064            (!blob_props.is_empty()).then_some(non_blob_cols.as_slice());
1065        let pending_batches = staging.pending_batches(&table_key);
1066        let pending_schema = staging.pending_schema(&table_key);
1067        // Use merge semantics on the union: a committed row whose `id`
1068        // also appears in pending has been logically updated by an
1069        // earlier op in this query and is shadowed from the scan,
1070        // otherwise the predicate runs against stale committed values
1071        // and a chained `update where <pred>` can match a row whose
1072        // pending value no longer satisfies <pred>.
1073        let batches = self
1074            .table_store()
1075            .scan_with_pending(
1076                &ds,
1077                pending_batches,
1078                pending_schema,
1079                projection,
1080                Some(&pred_sql),
1081                Some("id"),
1082            )
1083            .await?;
1084
1085        if batches.is_empty() || batches.iter().all(|b| b.num_rows() == 0) {
1086            return Ok(MutationResult {
1087                affected_nodes: 0,
1088                affected_edges: 0,
1089            });
1090        }
1091
1092        // Concat the matched batches (committed + pending) into one. The
1093        // helper trusts that both sides share a schema — Lance returns
1094        // dataset-schema-ordered columns and DataFusion returns
1095        // MemTable-schema-ordered columns; both should match the catalog's
1096        // arrow_schema when the projection is consistent. If they
1097        // diverge (typically a blob-table mid-schema-shift), the helper
1098        // surfaces a clear error directing the caller to split the
1099        // mutation.
1100        let matched = concat_match_batches_to_schema(&schema, &blob_props, batches)?;
1101
1102        let affected_count = matched.num_rows();
1103
1104        let mut resolved: HashMap<String, Literal> = HashMap::new();
1105        for a in assignments {
1106            resolved.insert(a.property.clone(), resolve_expr_value(&a.value, params)?);
1107        }
1108        let updated = apply_assignments(&schema, &matched, &resolved, &blob_props)?;
1109        let node_type = &self.catalog().node_types[type_name];
1110        crate::loader::validate_value_constraints(&updated, node_type)?;
1111        crate::loader::validate_enum_constraints(&updated, &node_type.properties, type_name)?;
1112        let unique_props = crate::loader::unique_property_names_for_node(node_type);
1113        if !unique_props.is_empty() {
1114            crate::loader::enforce_unique_constraints_intra_batch(
1115                &updated,
1116                type_name,
1117                &unique_props,
1118            )?;
1119        }
1120
1121        // Accumulate the updated batch into the Merge-mode pending stream.
1122        // The accumulator may now contain entries with the same id as a
1123        // prior insert or update on this table; `MutationStaging::finalize`
1124        // dedupes by id (last-occurrence wins) before issuing the single
1125        // `stage_merge_insert` call at end-of-query.
1126        let updated_schema = updated.schema();
1127        staging.append_batch(&table_key, updated_schema, PendingMode::Merge, updated)?;
1128
1129        Ok(MutationResult {
1130            affected_nodes: affected_count,
1131            affected_edges: 0,
1132        })
1133    }
1134
1135    async fn execute_delete(
1136        &self,
1137        type_name: &str,
1138        predicate: &IRMutationPredicate,
1139        params: &ParamMap,
1140        branch: Option<&str>,
1141        staging: &mut MutationStaging,
1142    ) -> Result<MutationResult> {
1143        let is_node = self.catalog().node_types.contains_key(type_name);
1144        if is_node {
1145            self.execute_delete_node(type_name, predicate, params, branch, staging)
1146                .await
1147        } else {
1148            self.execute_delete_edge(type_name, predicate, params, branch, staging)
1149                .await
1150        }
1151    }
1152
1153    async fn execute_delete_node(
1154        &self,
1155        type_name: &str,
1156        predicate: &IRMutationPredicate,
1157        params: &ParamMap,
1158        branch: Option<&str>,
1159        staging: &mut MutationStaging,
1160    ) -> Result<MutationResult> {
1161        let pred_sql = predicate_to_sql(predicate, params, false)?;
1162
1163        let table_key = format!("node:{}", type_name);
1164        let (ds, full_path, table_branch) = open_table_for_mutation(
1165            self,
1166            staging,
1167            branch,
1168            &table_key,
1169            crate::db::MutationOpKind::Delete,
1170        )
1171        .await?;
1172        let initial_version = ds.version().version;
1173
1174        // Scan matching IDs for cascade. Per D₂ this never overlaps with
1175        // staged inserts (mixed insert/delete in one query is rejected at
1176        // parse time), so we scan committed only.
1177        let batches = self
1178            .table_store()
1179            .scan(&ds, Some(&["id"]), Some(&pred_sql), None)
1180            .await?;
1181
1182        let deleted_ids: Vec<String> = batches
1183            .iter()
1184            .flat_map(|batch| {
1185                let ids = batch
1186                    .column(0)
1187                    .as_any()
1188                    .downcast_ref::<StringArray>()
1189                    .unwrap();
1190                (0..ids.len())
1191                    .map(|i| ids.value(i).to_string())
1192                    .collect::<Vec<_>>()
1193            })
1194            .collect();
1195
1196        if deleted_ids.is_empty() {
1197            return Ok(MutationResult {
1198                affected_nodes: 0,
1199                affected_edges: 0,
1200            });
1201        }
1202
1203        let affected_nodes = deleted_ids.len();
1204
1205        // Delete nodes — still inline-commit (Lance's `Dataset::delete` is
1206        // not exposed as a two-phase op in 4.0.0). D₂ keeps inserts and
1207        // deletes from coexisting in one query, so this advance of Lance
1208        // HEAD is the only HEAD movement during the query and the
1209        // publisher's CAS captures it intact.
1210        let mut ds = self
1211            .reopen_for_mutation(
1212                &table_key,
1213                &full_path,
1214                table_branch.as_deref(),
1215                initial_version,
1216                crate::db::MutationOpKind::Delete,
1217            )
1218            .await?;
1219        crate::failpoints::maybe_fail("mutation.delete_node_pre_primary_delete")?;
1220        let delete_state = self
1221            .table_store()
1222            .delete_where(&full_path, &mut ds, &pred_sql)
1223            .await?;
1224
1225        staging.record_inline(crate::db::SubTableUpdate {
1226            table_key: table_key.clone(),
1227            table_version: delete_state.version,
1228            table_branch: table_branch.clone(),
1229            row_count: delete_state.row_count,
1230            version_metadata: delete_state.version_metadata,
1231        });
1232
1233        let mut affected_edges = 0usize;
1234        let escaped: Vec<String> = deleted_ids
1235            .iter()
1236            .map(|id| format!("'{}'", id.replace('\'', "''")))
1237            .collect();
1238        let id_list = escaped.join(", ");
1239
1240        let edge_info: Vec<(String, String, String)> = self
1241            .catalog()
1242            .edge_types
1243            .iter()
1244            .map(|(name, et)| (name.clone(), et.from_type.clone(), et.to_type.clone()))
1245            .collect();
1246
1247        for (edge_name, from_type, to_type) in &edge_info {
1248            let mut cascade_filters = Vec::new();
1249            if from_type == type_name {
1250                cascade_filters.push(format!("src IN ({})", id_list));
1251            }
1252            if to_type == type_name {
1253                cascade_filters.push(format!("dst IN ({})", id_list));
1254            }
1255            if cascade_filters.is_empty() {
1256                continue;
1257            }
1258
1259            let edge_table_key = format!("edge:{}", edge_name);
1260            let cascade_filter = cascade_filters.join(" OR ");
1261            let (mut edge_ds, edge_full_path, edge_table_branch) = open_table_for_mutation(
1262                self,
1263                staging,
1264                branch,
1265                &edge_table_key,
1266                crate::db::MutationOpKind::Delete,
1267            )
1268            .await?;
1269
1270            let edge_delete = self
1271                .table_store()
1272                .delete_where(&edge_full_path, &mut edge_ds, &cascade_filter)
1273                .await?;
1274
1275            affected_edges += edge_delete.deleted_rows;
1276
1277            if edge_delete.deleted_rows > 0 {
1278                staging.record_inline(crate::db::SubTableUpdate {
1279                    table_key: edge_table_key,
1280                    table_version: edge_delete.version,
1281                    table_branch: edge_table_branch,
1282                    row_count: edge_delete.row_count,
1283                    version_metadata: edge_delete.version_metadata,
1284                });
1285            }
1286        }
1287
1288        if affected_edges > 0 {
1289            self.invalidate_graph_index().await;
1290        }
1291
1292        Ok(MutationResult {
1293            affected_nodes,
1294            affected_edges,
1295        })
1296    }
1297
1298    async fn execute_delete_edge(
1299        &self,
1300        type_name: &str,
1301        predicate: &IRMutationPredicate,
1302        params: &ParamMap,
1303        branch: Option<&str>,
1304        staging: &mut MutationStaging,
1305    ) -> Result<MutationResult> {
1306        let pred_sql = predicate_to_sql(predicate, params, true)?;
1307
1308        let table_key = format!("edge:{}", type_name);
1309        let (mut ds, full_path, table_branch) = open_table_for_mutation(
1310            self,
1311            staging,
1312            branch,
1313            &table_key,
1314            crate::db::MutationOpKind::Delete,
1315        )
1316        .await?;
1317
1318        let delete_state = self
1319            .table_store()
1320            .delete_where(&full_path, &mut ds, &pred_sql)
1321            .await?;
1322        let affected = delete_state.deleted_rows;
1323
1324        if affected > 0 {
1325            staging.record_inline(crate::db::SubTableUpdate {
1326                table_key,
1327                table_version: delete_state.version,
1328                table_branch,
1329                row_count: delete_state.row_count,
1330                version_metadata: delete_state.version_metadata,
1331            });
1332            self.invalidate_graph_index().await;
1333        }
1334
1335        Ok(MutationResult {
1336            affected_nodes: 0,
1337            affected_edges: affected,
1338        })
1339    }
1340}
1341
1342/// Concat the matched batches from `scan_with_pending` into a single batch.
1343/// `scan_with_pending` returns committed-side and pending-side batches in
1344/// order; both should share a schema if pending was produced through
1345/// `apply_assignments` with full-schema scan input. If schemas drift,
1346/// surface a clear error so the user can split the query.
1347fn concat_match_batches_to_schema(
1348    _schema: &SchemaRef,
1349    _blob_properties: &HashSet<String>,
1350    batches: Vec<RecordBatch>,
1351) -> Result<RecordBatch> {
1352    if batches.len() == 1 {
1353        return Ok(batches.into_iter().next().unwrap());
1354    }
1355    let common = batches[0].schema();
1356    arrow_select::concat::concat_batches(&common, &batches).map_err(|e| {
1357        OmniError::Lance(format!(
1358            "scan_with_pending returned batches with mismatched schemas \
1359             across the committed/pending boundary; this typically indicates \
1360             a blob-column shape mismatch between the committed table and a \
1361             prior in-query insert/update. Split blob-touching mutations \
1362             into separate queries. ({})",
1363            e
1364        ))
1365    })
1366}
1367
1368/// Validate `@card` bounds against committed (Lance) + pending (in-memory)
1369/// edges for one edge table. Engine path: each insert produces a fresh
1370/// ULID id, so committed and pending cannot share a primary key — no
1371/// dedup needed (`dedupe_key_column = None`).
1372async fn validate_edge_cardinality_with_pending(
1373    db: &Omnigraph,
1374    committed_ds: &Dataset,
1375    staging: &MutationStaging,
1376    table_key: &str,
1377    edge_type: &omnigraph_compiler::catalog::EdgeType,
1378) -> Result<()> {
1379    if edge_type.cardinality.is_default() {
1380        return Ok(());
1381    }
1382    let counts = super::staging::count_src_per_edge(
1383        db,
1384        committed_ds,
1385        table_key,
1386        staging,
1387        None,
1388    )
1389    .await?;
1390    super::staging::enforce_cardinality_bounds(edge_type, &counts)
1391}
1392
1393fn enrich_mutation_params(params: &ParamMap) -> Result<ParamMap> {
1394    let mut resolved = params.clone();
1395    if !resolved.contains_key(NOW_PARAM_NAME) {
1396        let now = OffsetDateTime::now_utc()
1397            .format(&Rfc3339)
1398            .map_err(|e| OmniError::manifest(format!("failed to format now(): {}", e)))?;
1399        resolved.insert(NOW_PARAM_NAME.to_string(), Literal::DateTime(now));
1400    }
1401    Ok(resolved)
1402}