🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

🔧 Programmierung 🕛 kürzlich 4 Min Lesezeit
0

9 silent-row-loss fixes in 7 days across 7 OSS databases

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

A pattern: a JavaScript database re-implements four common SQL operators - upper/lower, length/substr, case-insensitive match, range comparison. The implementation looks right. The tests pass. The CI is green. And then the moment a user's data contains the German ß, a fi ligature, an emoji, a Turkish dotted-i, or a CJK Extension B character, the operator silently returns the wrong rows. No error. No log. Just less data than the user expected, or the wrong data.



I've now shipped this exact bug class to seven open-source JavaScript database query layers in seven days. Nine PRs. None of them throw. All of them silently return wrong rows. Here's the streak:





  1. PowerSync (#644) - LIKE/range semantics. Merged. Funded a paid 48-hour follow-on sprint.


  2. PowerSync (#645) - CAST semantics. Merged.


  3. PowerSync (#646) - division by zero. Merged.


  4. PowerSync (#647) - json_each over scalar. Merged.


  5. PowerSync (#662) - JOIN parsing silently syncs zero rows. Open.


  6. PowerSync (#663) - upper/lower ASCII vs Unicode case-fold divergence. Open.


  7. PowerSync (#664) - length() UTF-16 code units vs SQLite code points. Open.


  8. PowerSync (#665) - substring() splitting surrogate pairs. Open.


  9. TanStack DB (#1574) - ASCII case fold in upper/lower/ilike. Open today.



Plus earlier same-class fixes in Rocicorp's Zero, InstantDB, ElectricSQL, Dexie, and RxDB.






The pattern is always the same shape



A JS database re-implements a SQL operator in JavaScript:




CODE
// PowerSync sync-rules - before
const upper = { call(value) { return value?.toUpperCase() ?? null } }

// TanStack DB - before
case `upper`: return (data) => {
const value = arg(data)
return typeof value === `string` ? value.toUpperCase() : value
}






String.prototype.toUpperCase() is locale-aware and length-changing:

































input .toUpperCase() SQLite's upper()
'straße'
'STRASSE' (6 -> 7)
'STRAßE'
'file'
'FILE' (3 -> 4)
'fiLE'
'İ'.toLowerCase()
'i̇' (1 -> 2, combining dot above)
'i'

'I'.toLowerCase() (tr-TR)
'ı' 'i'


When the JS re-implementation and the source database disagree, the bucket key the client looks up and the bucket key the server wrote silently mismatch. The row doesn't appear on the client. No error fires.



Same pattern for length() - JavaScript's String.prototype.length counts UTF-16 code units, SQLite's length() counts code points. They disagree by 2x on every emoji, CJK Extension B-G character, and ancient script glyph. Same for substring() - JS slices on code units and can return unpaired surrogates. Same for case-insensitive LIKE / ilike - same toLowerCase() length-change problem.






The fix is always the same shape too



Stop calling locale-aware JS string methods on data the database is supposed to be authoritative about. Use ASCII-only case fold loops, iterate by code points (for...of or [...text]), and walk surrogate pairs deliberately.



It's about 30 lines of JS to catch the four common cases. I packaged it:




CODE
npm i silentdrop






. Or smaller scope - one specific operator I find a divergence on, repro + fix + PR delivered - $500: https://buy.polar.sh/polar_cl_G0fuUHHZ1tg9E0oe7gluje9gs44l8FAqVnfwS2AJkbw.



Otherwise, npm i silentdrop is free and the first bug it finds will pay you back in the prevented hours of debugging.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten 9 silent-row-loss fixes in 7 days across 7 OSS databases

Thematisch verwandte Begriffe: silentrowloss, fixes, days, across · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...