Unbounded Query

adobe/skills/plugins/aem/cloud-service/skills/code-assessment/unbounded-query

作者 adobe940b8795c0dfApache-2.0197 個星標收錄於 2026年10月9日更新於 2026年10月8日儲存庫今天更新

AEM Cloud Service expert skill — handle an explicitly-unbounded query (`p.limit=-1` predicate or JCR `setLimit(-1)`): bound it when capping is provably safe, otherwise flag it for human pagination. Use for "bound my query", "unbounded query", "query causing OOM", or a scan that flags `p.limit=-1`. Top CSO OOM cause: an unbounded result set traversed in a loop fills the heap and saturates the instance. The analyzer locates the explicit markers; the recipe triages each by how the result is consumed — single-result → 1, already-bounded list → N, iterate-all on the request path → escalate. Never silently cap a result the caller reads in full.

AI 產生的概覽

分診 AEM Cloud Service 的無界查詢(p.limit=-1 或 setLimit(-1)),僅在可證明安全處加上界限,其餘標記待人工處理。

功能
此技能處理 AEM Cloud Service 中明確無界的查詢,辨識依據是 QueryBuilder 的 p.limit=-1 述詞或 JCR 的 setLimit(-1) 呼叫。它依結果的取用方式分類每個被標記的呼叫點,僅在可證明安全時套用較窄的界限,例如只讀取單筆結果或清單本身已有界的情況。在請求路徑上逐筆走訪全部資料列的呼叫點不做修改,而是升級為人工分頁處理。它從不提交,所有已套用的修改都會在 diff 中審閱。
適用情境
當某個查詢與記憶體耗盡或堆積記憶體事故相關、掃描標記出無界查詢,或有人要求為查詢加上界限時使用。適用於「為我的查詢加上界限」「無界查詢」「造成 OOM 的查詢」等請求。不適用於已設定正數界限的查詢,也不適用於對已有界查詢做分頁調校。
執行需求
僅為說明性內容,不附帶指令碼。需要 AEM Cloud Service 程式碼庫,並引用了分析指令碼與執行手冊檔案,這些檔案不在本技能資料夾內。

Unbounded query — AEM as a Cloud Service

This pattern is executed by the code-assessment runbook — follow ../references/runbook.md for the full flow (preflight → plan → apply → verify, run log). This skill supplies the detection + recipe the runbook applies.

Overview

A query asked to return everything — a QueryBuilder predicate p.limit=-1, or a JCR Query.setLimit(-1) — loads the entire result set into heap. When that result grows and the rows are traversed in a loop, the heap fills and the instance OOMs: this is the top co-occurring cause of out-of-memory outages in the CSO dataset.

-1 means the caller wants every row, so capping is not behaviour-neutral. Lowering it to a fixed bound silently drops rows whenever the real result exceeds the cap — trading a loud OOM for a silent data/count/UI bug. So this pattern does not blanket-cap: it triages each site by how the result is consumed (Resolution contract below), bounds only where that is provably safe, and escalates the rest for human pagination rather than editing them. The skill never commits — every applied edit is reviewed in the diff.

Classification — confirm this pattern applies

  • A QueryBuilder predicate map sets p.limit to -1 (…put("p.limit", "-1")), or a JCR/javax.jcr.query.Query (or QueryManager-built query) calls setLimit(-1).
  • The user asks to "bound a query", mentions an "unbounded query", or a query implicated in an OOM / heap incident; or a scan flagged unbounded-query.
  • Not this pattern: a query that already sets a positive bound (p.limit=100, setLimit(100)); a -1 on a different predicate key (only p.limit is the marker); pagination tuning of an already-bounded query.

Discovery

Detection is performed by the analyzer (../scripts/analyze.sh), run by the runbook:

bash
bash ../scripts/analyze.sh <workspace-root> --pattern unbounded-query

Match criteria (what the detector flags): the two explicit unbounded markers, matched on source literals (parse-level, no type resolution):

  • …put("p.limit", "-1") — a QueryBuilder predicate-map entry whose key is exactly p.limit and value is "-1", written inline or referenced through a same-file final constant (e.g. UNLIMITED_RESULT = "-1").
  • …setLimit(-1) — a setLimit call whose single argument is -1, inline or via a same-file final constant.

Emitted at the call's line, with the call as the snippet. The match is on the marker value (literal or a same-file constant resolving to it), so a bounded query ("100", setLimit(100)) or a -1 on any other key is not flagged — precise by construction, no scope analysis needed.

Resolution contract

guided — triage each flagged site by how the result is consumed; the safe automatic edit is narrow, and the default for "iterate-all on the request path" is to flag for human pagination, not edit. Cardinal rule: never silently cap a result the caller reads in full.

Call-site shapeActionDisposition
Single-result — reads first hit only (.get(0), .next() once, getFirstResource()), no getTotalMatches()bound → 1apply
Already-bounded list — caller shows top-N / already pagesbound → N / page sizeapply
Iterate-all, local + simple — query build + result loop in one method, stable sort, no post-filterwrap in p.offset loopapply (mark review)
Iterate-all, request path — cross-method, post-filtered, aggregate/count, or unsorteddo not editskipped: needs-pagination
Off-request migration / batchskipskipped: bound-changes-correctness
Test code (src/test/)skipskipped: test-scope

Bounding is the exception (provably safe sites); escalation is the default when safety cannot be proven. The recipe gives the per-branch edits and the exact reason strings.

Review checklist

  • The fix matches how the result is consumed (single-hit → 1; bounded list → N; iterate-all → paginate or escalate)
  • No request-path query that consumes all rows was silently capped — those are skipped: needs-pagination
  • Where a bound was applied, the caller cannot legitimately exceed it (or paging was added)
  • No getTotalMatches() / count dependency broken by the new limit
  • Paging (where added) has a stable sort and survives any post-query filter
  • Surgical edit — no reformatting

Recipe

Read recipe.md [blocked] in full before editing: input contract, the triage decision table, per-branch edits (QueryBuilder predicate, JCR setLimit, offset paging), the escalation reason strings, skip policy, before/after, editing strategy.

Handoff

The skill never commits. See ../references/git-workflow.md for git vs in-place handoff and the suggested commit message.

來源與署名

來源:adobe/skills位於plugins/aem/cloud-service/skills/code-assessment/unbounded-query提交940b879

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架