Trusted
Admission steps 4 to 6 alone, for code that drives a QueryBackend directly and owns governance itself: backend conformance tests, tools and benchmarks. Field aliases are replaced by their canonical fields, the operation finishes the query (a cursor's unique tie-breaker sort), and the query is validated against the schema, normalized and resolved. Normalization resolves relative time against one server now per admitted query, encoded as each field stores time, lowers derived operators and simplifies logical nodes. Resolution rebuilds every field-carrying node as a fresh instance and registers its ResolvedField.
No governance runs here: no entry budget or gate, no QueryFilter, no caller scope, no QueryPolicy and no model default scope. The caller gets exactly the query it wrote, validated, normalized and resolved. A query from anyone but trusted code goes through a QueryAdmission instance, as the gateway does.
Functions
Resolves every relative time of the aggregation's filters against now, one moment for all of them.
Appends the model's identity field as the unique tie-breaker sort before resolving.