Repository navigation
fix: require explicit SQLite migration preflight - #283
Conversation
a4abafc to
c69c5c3
Compare
pilipilisbot
left a comment
There was a problem hiding this comment.
Thanks, this is directionally the right fix: ordinary JobQueue construction no longer applies migrations, migrate-db blocks active pending/running/waiting_approval work and takes a backup, and the migration/rollback paths are covered.
I found one blocking regression before this can merge:
plan_update()now callsdatabase_queue_state()unconditionally, and that opens the DB with a read-only SQLite URI. On a fresh install or any operator run where the configured DB has not been created yet,gab updatenow fails withsqlite3.OperationalError: unable to open database filebefore it can even return a noop/update plan. Previouslyplan_update()constructedJobQueue(db), which initialized a fresh DB. The PR summary says fresh database initialization remains automatic, so this path should either preserve fresh initialization for a missing DB or return an empty queue state without usingmode=ro.
Reproducer I ran against this head:
from pathlib import Path
from tempfile import TemporaryDirectory
from github_agent_bridge.autoupdate import plan_update
import subprocess
with TemporaryDirectory() as d:
p = Path(d)
db = p / "missing.sqlite3"
plan_update(
db,
repo_dir=p,
installed_version="1.2.3",
runner=lambda args, cwd: subprocess.CompletedProcess(args, 0, "[]" if "diff" in args else '{"tagName":"v1.2.3"}', ""),
)Validation performed:
git diff origin/main...HEAD --checkgab --db <new-temp-db> migrate-dbthrough a temporary venv- focused regression tests for CLI migration, queue explicit migration, autoupdate migration gating, MCP and webhook legacy migration cases: 9 passed
- full suite:
526 passed, 1 warning(Starlette/httpx deprecation warning)
|
Fixed in
Validation: |
pilipilisbot
left a comment
There was a problem hiding this comment.
Approved. The follow-up commit addresses the blocker from my previous review: plan_update() now treats a missing database as an empty queue without creating or migrating it, while migration-required paths still count pending, running, and waiting_approval jobs even when the executor is paused.
I rechecked the migration boundary and operational paths: ordinary JobQueue construction validates migration history read-only, gab migrate-db gates active jobs before backup/migration, existing quiet databases are backed up before applying pending steps, and the autoupdate live recheck uses the explicit migration preflight semantics.
Validation performed on head 39859cb:
git diff origin/main...HEAD --check- focused migration/autoupdate/legacy-upgrade tests: 10 passed, 1 existing Starlette/httpx deprecation warning
gab --db <new-temp-db> migrate-dbvia the review venv- full suite:
527 passed, 1 warning
Co-authored-by: ecarreras <ecarreras@users.noreply.github.com>
Treat an absent SQLite file as an empty queue without creating or migrating it. Co-authored-by: pilipilisbot <265267145+pilipilisbot@users.noreply.github.com>
39859cb to
9841f33
Compare
|
Post-merge sync completed for #283.
|
|
Post-merge follow-up: rechecked PR #283 after merge.
This corrects the earlier cleanup status; no code changes were made. |
Summary
JobQueueconstruction validate migration history without applying migrations or the rolling schema snapshotgab migrate-dbto rejectpending,running, andwaiting_approvaljobs, including while the executor is pausedWhy
An existing deployment could be mutated by an ordinary CLI, dashboard, or webhook process before the controlled autoupdate migration window. That bypassed the active-job gate and backup/rollback contract. This PR makes migration an explicit operator action and adds the reported
waiting_approvalregression case.Validation
pytest -q— 527 passed, 1 pre-existing Starlette/httpx deprecation warningmigrate-dbleave migration history and feature tables untouchedmigrate-dbcreates a backup and leaves the database valid after applying pending stepsplan_update()treats an absent database as an empty queue without creating the fileOperational impact
Existing databases with pending or missing migration history now fail startup with an actionable
gab migrate-dbinstruction. Operators must resolve active jobs before migrating. The command accepts--backup-dir; autoupdate keeps its existing outer backup/rollback safeguards as well.Requested by: @ecarreras
Related to #260