Skip to content

feat(projects): enforce Project membership and retire the connector - #8590

Draft
mzxchandra wants to merge 86 commits into
feat/project-workspace-column-expandfrom
codex/project-entity-enforcement
Draft

mzxchandra wants to merge 86 commits into
feat/project-workspace-column-expandfrom
codex/project-entity-enforcement

Conversation

@mzxchandra

@mzxchandra mzxchandra commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Complete the migration to workspace.project_id after #8830 has deployed. Release 2 migrations run before application promotion, while release 1 still serves traffic. The registered runner therefore switches the sole membership authority before incremental backfill, keeping live writes and reconciliation consistent without dual writes or synchronization triggers.

  • SQL 0407 is a placeholder; the existing TypeScript migration runner owns 0031_project_membership. Expansion is 0406, following upstream 0405 OAuth. The final schema stores one Project foreign key on each workspace, enforces NOT NULL and ON DELETE RESTRICT, and removes project_workspace.
  • Under the operator session mutex, cutover runs in a short bounded transaction with workspace ACCESS EXCLUSIVE NOWAIT. Connector mode requires an intact connector and all columns NULL. The transaction updates only the checked singleton to column mode and commits before discovery or bulk backfill. Transient contention retries the whole transaction; an already committed switch is idempotent and never reversed on later failure.
  • Compatible feat(projects): move Project membership to the workspace column #8830 transactions hold the shared workspace barrier before selecting authority, including before repeatable-read snapshots. After cutover, they write the column and read legacy assignments only where the column is NULL. Final application code uses the column directly.
  • Reconcile in bounded transactions: at most 50 singletons or one complete fork family per assignment transaction. Preserve legitimate Project identity; validate grouping, ownership, scope, lineage and lifecycle before final enforcement. Never unarchive workspaces or workflows. Ambiguous membership or ownership and unfinished provider cleanup stop for reviewed remediation; committed progress and cleanup journal state survive retries.
  • Manual assignment/repair requires column mode and current drain acknowledgment; read-only planning remains available beforehand. Fresh final schema push initializes column authority only for the explicitly verified empty final-schema bootstrap and preserves the marker on replay. Expansion databases cannot bypass the registered migration through schema push.

Deployment prerequisites and rollback

Deploy #8830 first. With ALL_AT_ONCE routing, old servers receive no fresh requests after traffic cutover. Before this migration switches authority, verify the exact compatible digest and completion of concrete membership-sensitive old in-flight operations and worker activity. Mere container retention or long workflow execution does not establish a membership dependency. The database barrier drains participating transactions; operational drain evidence and the deployment preflight remain required.

If reconciliation stops after switching, keep column mode, resolve the reported conflicts through the reviewed operator path, and resume the normal migration runner. Operator invocation outside the deployment workflow still requires fresh release/drain evidence and a direct primary connection; never insert a completion receipt manually.

The authority-aware #8830 release is the oldest supported application rollback after the switch and after contraction. Keep the expanded/contracted schema and project_membership_rollout column-phase row. Never demote authority or deploy pre-#8830 code. No third compatibility release or marker-cleanup release is required.

Type of Change

  • Feature / database migration

Testing

  • Synchronized the expansion lint fix through a merge. The final-release tree is unchanged: connector-phase application tests remain intentionally absent after retirement.
  • Current head: e5da5c8abdb6c649fe73d855c95c24277a88614f, integrating expansion b9bc57287107d1ebe7618f5031725a0131c7c291 and staging OAuth0405; Project expansion0406 and enforcement0407.
  • Thirteen focused cutover/enforcement checks pass, covering the real marker migration, interrupted discovery and resume, live column writes after cutover, receipt retry, and shadow-schema isolation with caller search-path restoration. Nine real database/Redis repair cases and final-schema push/replay pass. Fresh migration through0407 and the affected OAuth fixture regression pass; targeted typechecks and schema drift checks pass.
  • Actual registered-runner HTTP proof: six connector-phase checks pass, then the runner assigns nine workspaces in five batches and completes0031. Three post-contraction checks pass on the same R1 process, preserving membership, ownership, archive states and workflow content and exercising create/fork/detach/archive/account deletion.
  • Direct-port old/new cases establish conditional compatibility only. They do not imply fresh requests reach old servers after production cutover. External provider/storage cleanup and live production drainage remain explicit prerequisites outside the synthetic proof.
  • Full hosted CI and fresh Greptile/cubic reviews are pending for this head. The standard repository integration matrix applies, with no additional Project-specific PostgreSQL16 CI or broad local CI repetition.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (exact-head hosted CI and reviews pending)
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 10, 2026 5:46am UTC

Request Review

@mzxchandra mzxchandra changed the title feat(projects): enforce membership after the staged backfill feat(projects): backfill and enforce membership in SQL Oct 3, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 162 files

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/projects/backfill-repair.ts Outdated
Comment thread apps/sim/scripts/backfill-projects.ts Outdated
Comment thread apps/sim/lib/workflows/lifecycle.ts
Lock and verify effective legacy memberships before materializing reviewed
assignments and applying the shared detach policy. Reject resume reports
whose code hash differs before changing their checkpoint. Isolate local
pubsub subscriber failures so healthy archive subscribers still receive
notifications.

Extend existing CLI and real-database integration coverage for mixed
memberships, concurrent and stale connector changes, unchanged mismatched
reports, replay, and local subscriber delivery.
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 165 files

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/projects/__integration__/backfill-repair.integration.ts Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 166 files

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread packages/db/scripts/reconcile-project-membership.ts
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile Please review the current head 406a78f, including authority cutover before reconciliation, shared enforcement search-path isolation, and final expansion integration.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile Please review current head e5da5c8. This merge synchronizes the expansion lint fix; the enforcement source tree is unchanged from 406a78f.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

This branch was previously deployed

1 inactive deployment
Preview — e5da5c8a Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant