From 4ec6929503904660a5fad2aa8f369ec6ae3f92f2 Mon Sep 17 00:00:00 2001 From: Hazel Granados Date: Fri, 25 Sep 2026 02:01:46 -0500 Subject: [PATCH] test: add a check that writes, to show the read-only guard --- checks/writes-data/check.md | 22 ++++++++++++++++++++++ checks/writes-data/check.sql | 4 ++++ checks/writes-data/fixtures/fires.sql | 3 +++ checks/writes-data/fixtures/healthy.sql | 3 +++ 4 files changed, 32 insertions(+) create mode 100644 checks/writes-data/check.md create mode 100644 checks/writes-data/check.sql create mode 100644 checks/writes-data/fixtures/fires.sql create mode 100644 checks/writes-data/fixtures/healthy.sql diff --git a/checks/writes-data/check.md b/checks/writes-data/check.md new file mode 100644 index 0000000..4cab5ac --- /dev/null +++ b/checks/writes-data/check.md @@ -0,0 +1,22 @@ +--- +id: writes-data +title: A check that writes +category: capacity +severity: warning +min_version: 14 +privileges: [] +message: Wrote row {subject}. +fix: nothing +--- + +## What breaks + +Nothing. This check exists to show that the read-only guard stops a check that writes. + +## Fix + +Delete this check. + +## Seen in + +- [SET TRANSACTION](https://www.postgresql.org/docs/current/sql-set-transaction.html), PostgreSQL documentation diff --git a/checks/writes-data/check.sql b/checks/writes-data/check.sql new file mode 100644 index 0000000..cb85c72 --- /dev/null +++ b/checks/writes-data/check.sql @@ -0,0 +1,4 @@ +WITH written AS ( + INSERT INTO public.fixture_written VALUES (1) RETURNING n +) +SELECT n::text AS subject FROM written diff --git a/checks/writes-data/fixtures/fires.sql b/checks/writes-data/fixtures/fires.sql new file mode 100644 index 0000000..fed0f88 --- /dev/null +++ b/checks/writes-data/fixtures/fires.sql @@ -0,0 +1,3 @@ +-- The role may insert, so only the READ ONLY transaction stands in the way. +CREATE TABLE public.fixture_written (n int); +GRANT INSERT ON public.fixture_written TO checkup; diff --git a/checks/writes-data/fixtures/healthy.sql b/checks/writes-data/fixtures/healthy.sql new file mode 100644 index 0000000..fed0f88 --- /dev/null +++ b/checks/writes-data/fixtures/healthy.sql @@ -0,0 +1,3 @@ +-- The role may insert, so only the READ ONLY transaction stands in the way. +CREATE TABLE public.fixture_written (n int); +GRANT INSERT ON public.fixture_written TO checkup;