Skip to content

feat: adapt migration schema calls to query-lib value objects - #222

Open
abnegate wants to merge 40 commits into
mainfrom
feat-query-lib
Open

feat: adapt migration schema calls to query-lib value objects#222
abnegate wants to merge 40 commits into
mainfrom
feat-query-lib

Conversation

@abnegate

@abnegate abnegate commented Aug 21, 2026

Copy link
Copy Markdown
Member

Adapts the migration destination's schema calls to the query-lib value objects.

Why this approach

Database::createCollection() takes a Collection only, so destination Appwrite now wraps the collection id, attributes and indexes — along with the named permissions and documentSecurity — in new Collection(...) instead of passing positional arrays.

utopia-php/database is pinned to dev-feat-query-lib as 2.0.0, re-pinned to that branch's head whenever it moves.

Lock repairs that came with the re-pin

Two problems surfaced only when the lock was resolved again rather than reused:

  • utopia-php/query was locked to dev-feat-schema-order, a branch that no longer exists on the remote. The resolution survived only as long as nobody resolved it. database's branch requires query 0.6.*, which is released, so the lock now takes the release.
  • utopia-php/storage moved 4.0.3 → 4.0.4, because 4.0.3 capped utopia-php/validators at ^0.4 while database requires ^0.5. 4.0.4 dropped the validators dependency outright. database has required ^0.5 on main as well as on the branch, so this was already true before the query-lib work and only surfaced now.

A live bug the re-pin exposed

The Appwrite destination passed the 'ASC' / 'DESC' strings a source hands back straight into Utopia\Database\Index, which takes Order cases and rejects anything else. The resulting InvalidArgumentException is not a Migration Exception, so instead of recording a failed index the whole transfer aborted.

This was already true before this PR and simply could not be seen: the lock held query at the deleted branch, whose Index took plain strings, so CI had never built an index against the contract the released library actually has. AppwriteIndexLengthsTest covers it — two of its cases pass ['ASC', 'ASC'], and both went red on the first run against the re-pinned lock and green with the fix.

It is the same defect as the one in appwrite/appwrite#11649's Databases worker, from the same cause.

Chain

Landing order, bottom up:

  1. utopia-php/database#823 — the query-lib migration itself
  2. utopia-php/abuse#124, utopia-php/audit#133, utopia-php/migration#222 — the schema call sites in the libraries
  3. appwrite/appwrite#11649
  4. appwrite-labs/cloud#5410

Stacked on #823 but not part of it, and not required by anything above: #947 (ORM), #948 (repositories and seeding), #949 (migration runner and schema differ).

Every dev-feat-query-lib pin in this train is re-pinned to its branch head whenever one of them moves, so each PR's CI runs against what the others actually contain.

Verified

  • CI green on this head
  • Greptile 5/5, no unresolved threads
  • Pint on the Collection wrap

Not verified

  • The utopia-php/database dependency is still a branch pin. It becomes a released tag only once #823 merges, and this PR should not land before that.

Published 2.0 still used Database::VAR_* and positional createAttribute/createIndex, which feat-query-lib removed. Rebase onto main and pass Attribute/Index/Relationship VOs plus ColumnType/IndexType so Appwrite can pin this branch as 2.0.0.
Appwrite stores ColumnType::BigInteger as biginteger. CSV export
resolved that as an unsupported column type and wrote no rows.
createDocument can return an empty Mongo sequence while a subsequent
getDocument has the ObjectId. Creating database_{seq} from the create
return left table import looking up a collection that did not exist.
Appwrite main added huggingface as a project OAuth2 provider. Without
an allow-list entry, Appwrite-to-Appwrite migrations fail on that
provider even when the rest of the transfer succeeded.
Keep query-lib APIs and the huggingface PROVIDERS allow-list already on main.
Appwrite #11649 locks database at 5719edd. Staying on e593b78 would
only prove the schema VO calls against an older query-lib surface.
@greptile-apps

greptile-apps Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

RetriggerView in GreptileConfidence Score: 5/5

The implementation appears safe to merge, although the non-blocking implementation-coupled CLI help test remains unresolved.

Summary

  • Wraps Appwrite collection schema data in query-lib/database value objects.
  • Converts schema column, index, and ordering values to query-lib enums.
  • Adds migration-attempt ownership and fail-closed database recovery behavior.
  • Updates standalone CLI lifecycle handling, documentation, static analysis coverage, and regression tests.
  • Repairs dependency resolution around database, query, storage, and related packages.

utopia-php/database feat-query-lib keys silenced events with
Coroutine::getCid(). The CI image is vanilla PHP, so Memory-adapter
tests fatalled before they could run.
createDocument can persist a row whose subsequent getDocument is empty.
That throw sat outside the failed-status handler, so a later skip could
flip the unusable database to ready without a backing collection.
@abnegate

Copy link
Copy Markdown
Member Author

Addressed the reload-failure finding.

createDocument can persist a _databases row whose immediately following getDocument is empty (the Mongo sequence miss this branch already reloads for). That throw sat outside the markDatabaseFailed catch, so the document stayed provisioning and a later spec-matching skip could flip it to ready with no backing collection.

Reload + createCollection now share that catch. testReloadFailureMarksTheDatabaseFailed fails without the wrap (provisioning) and passes with it (failed).

Also stubbed Swoole\Coroutine::getCid() in the PHPUnit bootstrap so the Memory-adapter suite can run on the CI image, which has no Swoole extension. utopia-php/database feat-query-lib keys silenced events with it.

@greptile-apps review

Asterisk wildcards on utopia-php packages are replaced with
equivalent caret constraints so Composer ranges stay consistent.
Keep composer.json and composer.lock in sync so `composer validate`
passes, and pin utopia-php/database to the current query-lib HEAD.
@abnegate

Copy link
Copy Markdown
Member Author

@greptileai review

@abnegate

Copy link
Copy Markdown
Member Author

@greptile-apps review

Force re-review of HEAD 7a3a60e. Description updated for factories and caret lock refresh.

Database::createCollection no longer accepts a string id.
Database::checkAttribute now requires Attribute. Build schema models from the resource key so metadata document IDs are not used as attribute keys.
Appwrite E2E migrations failed because checkAttribute now requires
Attribute, and the destination still handed it a metadata Document.
Comment thread src/Migration/Destinations/Appwrite.php
A reload failure leaves a metadata document in `failed` with no backing
collection. Recovery only ran when onDuplicate was not Fail, so the
default policy retried createDocument against the existing ID and
stranded the database.
@abnegate

Copy link
Copy Markdown
Member Author

@greptileai review

abnegate and others added 2 commits August 21, 2026 22:53
Index types already used IndexType; column direction was still a raw
ASC string. Collection constructors with multiple named params were
also jammed on one line.
…atabase

The lock held utopia-php/query at dev-feat-schema-order, a branch that no longer
exists on the remote, so the resolution only survived as long as nobody resolved
it again. database's branch requires query 0.6.*, which is released, so this
takes the release.

storage 4.0.4 comes along because 4.0.3 capped utopia-php/validators at ^0.4
while database requires ^0.5; 4.0.4 dropped the validators dependency outright.
database has required ^0.5 on main as well as on the branch, so this was already
true before the query-lib work and only surfaced now that the lock moved.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Comment thread src/Migration/Destinations/Appwrite.php
Comment thread src/Migration/Destinations/Appwrite.php Outdated
@abnegate

Copy link
Copy Markdown
Member Author

@greptileai review

Comment thread src/Migration/Destinations/Appwrite.php Outdated
Comment thread bin/MigrationCLI.php
Comment thread bin/MigrationCLI.php Outdated
abnegate and others added 3 commits September 1, 2026 11:39
Both store a plain client id and secret, so only the client id is
readable and migratable.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit ea342db)
Comment thread tests/Migration/Unit/Destinations/AppwriteCheckAttributeTest.php Outdated
The lock still pinned 6cc5f8be, two reconciles behind: the branch's green CI
was proving a database revision that will not ship. a137475 carries the merge
with main and the batched upsert read.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@abnegate

abnegate commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

@greptileai review

The guard read Appwrite.php and pinned source fragments, so a reformat broke
it while a real regression could still pass. Transfer a column through the
public entry point instead and record what the project database is handed:
the metadata row beside it is keyed by the composite attribute id, so a
column named after that id is measured against a table that never holds it.

Verified red on both regression shapes. Passing the metadata document fails
the type the collaborator requires; rebuilding the attribute from that
document's array copy reaches checkAttribute with key 1_1_title where the
transfer's column is title.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@abnegate

abnegate commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

@greptileai review

The guard reached resolveDestinationDsn by reflection, so it never ran the
line deciding whether the creation path consults the resolver at all. Writing
the source DSN straight into the row, which is the comuneo incident, left all
three cases green.

Transfer a database through the public entry point instead and read back
_databases.database. Verified red on that shape: every case reports the
source host database_db_fra1_self_hosted_11_0 where the destination must
carry a blank or the resolver's own value.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@abnegate

abnegate commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

@greptileai review

Comment thread tests/Migration/Unit/MigrationCLITest.php Outdated
Five of the ten assertions pinned English sentences from the help text, which
a reword breaks without changing behaviour. The other five are interface
tokens a user types, and one of them carries a property nothing else covers:
the neighbouring test proves --recover-provisioning is refused, not that it
stays unadvertised. Re-adding it to getHelp() fails this test and no other.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@abnegate

abnegate commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

@greptileai review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants