feat(pgpm-core): applyBundle — safety wrapper (dry-run, integrity/namespace gate, atomic, timeout) over PgpmMigrate#1421
Open
pyramation wants to merge 5 commits into
Open
feat(pgpm-core): applyBundle — safety wrapper (dry-run, integrity/namespace gate, atomic, timeout) over PgpmMigrate#1421pyramation wants to merge 5 commits into
pyramation wants to merge 5 commits into
Conversation
… lossless read/write
…iable, provenance manifest
…espace gate, atomic, timeout) over PgpmMigrate
Contributor
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Atom #5: a safety-first wrapper that applies a
MigrationBundleto a target database. It powersapplyMigrationBundle/applyTranspiledMigrationBundle.Stacked on the transpiler branch (#1420) → bundle (#1419) → pgpm-ast (#1418); targets
mainso CI runs the full suite. Net new-to-this-PR:bundle/apply.ts+ its test + one export line.Nothing here re-implements deployment — it composes
verifyBundle(integrity gate),materializeBundle(bundle → module dir), andPgpmMigrate.deploy/.verify(execution), adding the safety envelope around them.Safety gates, all before any DB write: refuse if
verifyBundlefinds digest/order issues (unlessallowUnverified), and refuse if the caller'svalidateReferencesreports references outside the target namespace (theapplyTranspiledMigrationBundleguarantee).dryRunreturns the full preview (deploy order + rollback plan) without connecting. Execution materializes to a temp dir (auto-cleaned), deploys in a single transaction so a mid-apply failure rolls the DB back rather than leaving it half-applied, races an optionaltimeoutMs, and returns an explicit result. As with the transpiler, core stays parser-agnostic — the namespace check is a caller callback.Caveat:
timeoutMsis a client-side wall-clock guard; combine with a DB-levelstatement_timeoutfor hard server-side enforcement.Testing
apply.test.ts: 7/7 — pure preview (order/integrity/rollback plan, namespace violations); DB-free gates (dry-run never executes, refuses tampered bundle, refuses namespace violations); live integration (materialize+deploy atomically then verify; re-apply skips already-deployed) viaMigrateTestFixture.pgpm/coresuite green: 71 suites / 469 tests (Postgres up).tsc --noEmitandeslintclean.Link to Devin session: https://app.devin.ai/sessions/ad40d16f38a349b48eb7ce9375e27e6e
Requested by: @pyramation