Skip to content

feat(projects): backfill and enforce membership in SQL - #8590

Draft
mzxchandra wants to merge 12 commits into
feat/project-entity-foundationfrom
codex/project-entity-enforcement
Draft

mzxchandra wants to merge 12 commits into
feat/project-entity-foundationfrom
codex/project-entity-enforcement

Conversation

@mzxchandra

@mzxchandra mzxchandra commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Stack on feat(projects): add project identity and lifecycle foundation #8580's additive schema and compatible application lifecycle handling. Run the data backfill and enforcement together as Drizzle SQL migration 0395; there is no standalone backfill CLI or writer activation flag.
  • Backfill only families missing membership, one bounded fork family per transaction. Leave complete existing Project assignments intact. Use per-environment advisory locks shared with compatible writers, nonblocking row/Project lock acquisition, and retries that release locks before waiting. Preserve committed progress and Project IDs across reruns; reject ambiguous legacy assignments.
  • Bound each family transaction to five seconds on PostgreSQL 17+. An overlong family aborts the migration connection and rolls back that family; previously committed families remain safe to resume.
  • Validate without write-blocking table locks. Install lifecycle triggers in a separate brief transaction with nonblocking table-lock acquisition and a five-second transaction-wide timeout, then validate again before journaling success. PostgreSQL lock inspection verifies that a stalled migration client releases all three table locks; a busy-table check verifies prompt failure and cleanup.
  • Independently check the compatible ECS rollout before migrating an existing hosted database. Relevant old worker runs still require operator confirmation. Project API exposure remains separately controlled.
  • Keep workflow creation and restore guarded by workspace share locks in feat(projects): add project identity and lifecycle foundation #8580. Do not install workflow triggers or serialize workflow writes on the Project row. Project/environment membership and archive constraints remain enforced.
  • Seed and remove integration-test Projects atomically with their environments; exercise schema-push and full-migration provisioning in CI.

Merge only after #8580 is deployed and pre-foundation servers and relevant workers have drained. The PR2 migration then performs backfill and enforcement before PR2's app version is served. Retarget this PR to staging after the foundation lands. Verify the workflow role's AWS read permissions before rollout; live AWS verification has not been performed.

Review scope: 95 of the 103 changed files are integration/E2E tests or fixture helpers. They now seed workspace/Project membership together and clean up empty fixture Projects under the enforced schema. No production knowledge-base behavior changes are included. The other eight files contain SQL/Drizzle metadata, the schema annotation, and deployment preflight wiring.

Type of Change

  • New feature

Testing

  • 28 SQL migration checks passed against disposable PostgreSQL, covering real Drizzle journaling, replay, conflict remediation, concurrent writes/forks, cancellation, and an intentionally stalled family that exceeds the transaction timeout. A multi-family fixture covers separately committed batches.
  • All 179 database-package integration checks passed against the full migration sequence, including the 28 Project SQL checks. Complete existing Projects are covered separately from legacy families, including Projects above the legacy batch limit.
  • All 62 targeted application integration checks passed under both full migrations and schema-push provisioning, covering Projects, fork-sync, Power BI, and knowledge-base-list fixtures. The restore/archive race failed before its PR1 fix; concurrent workflow writes failed with the removed trigger and pass without it, with the Project row version unchanged.
  • Application and database type-checks, lint, all 58 repository audits, and migration safety passed. Removing either side's backfill lock guard makes its concurrency regression tests fail.
  • Fresh PR2 hosted validation is running at 8be18e5d47. Both fixture failures from the previous staging-merge run are fixed and pass locally through both provisioning paths.
  • Live AWS rollout verification and hosted migration execution have not been performed.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Added/updated Project tests pass the test-audit authoring gate and targeted runs
  • Final hosted test/build workflow passes, including both database provisioning paths and HTTP end-to-end tests
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 3, 2026 1:24am UTC

Request Review

@mzxchandra mzxchandra changed the title feat(projects): enforce membership after the staged backfill feat(projects): backfill and enforce membership in SQL Oct 3, 2026

This branch was successfully deployed

1 active deployment
Preview — 8be18e5d Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant