Repository navigation
feat: establish shared file ownership foundation - #8609
mzxchandra wants to merge 39 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
Add canonical entity ownership while preserving legacy workspace writers. Make storage accounting, lifecycle cleanup, search, document artifacts, and realtime transport tolerate project-owned data before feature activation. Keep Project file user/API/tool entry points in the stacked feature change.
9a1af75 to
6f8882e
Compare
|
@cubic-dev-ai review this PR |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
|
Comments Outside DiffThese findings could not be posted inline.
|
|
@greptileai review |
|
@cubic-dev-ai review |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 216 files
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Turn on auto-fix | Re-trigger cubic
|
@greptileai review — current code includes the historical repair fixture migration-boundary fix; its 9 PostgreSQL/Redis cases pass. |
|
@cubic-dev-ai review — current code includes the historical repair fixture migration-boundary fix; its 9 PostgreSQL/Redis cases pass. |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 217 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Turn on auto-fix | Re-trigger cubic
|
@greptileai review — current head e3e0f52 addresses the verified lifecycle, search, storage, realtime and audit-base findings with focused regression coverage. |
|
@cubic-dev-ai review — current head e3e0f52 addresses the verified findings. Individual threads include fixes or current-code evidence for rejected findings. |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
|
@greptileai review — 9569da8 uses supported copy-and-sort/reverse array operations; the input identity regression passes. |
|
@cubic-dev-ai review — 9569da8 uses supported copy-and-sort/reverse array operations; the input identity regression passes. |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 220 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Turn on auto-fix | Re-trigger cubic
|
@greptileai review — d43cdd4 corrects the branch boundary: foundation owned-file creation uses its existing billing API; the newer accounting helper remains in #8610. |
|
@cubic-dev-ai review — d43cdd4 corrects the branch boundary: foundation owned-file creation uses its existing billing API; the newer accounting helper remains in #8610. |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 220 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Turn on auto-fix | Re-trigger cubic
Summary
project_idFK alongsideworkspace_idandorganization_id; enforce at most one owner. Existing personal/chat attachments retain their ownerless representation and policy.entityType/entityIdinterface above storage. Native FKs enforce owner existence; shared locks and lifecycle helpers cover files, folders, versions, billing, search, sharing and cleanup.Stack: #8590 → #8609 → #8610 → #8781. Includes the lifecycle prerequisite #8762 for local integration; keep its independent merge dependency. #8580 has merged.
Rollout and rollback
Keep the current PR split: #8609 owns shared file ownership and compatible consumers; #8610 owns Project backend/APIs; #8781 owns browser/Mothership integration. PR boundaries do not require separate deployments. Use two file releases with an explicit wait between them; this stack has no separate file-enforcement release.
PROJECT_FILES_ENABLEDoff. SQL 0408–0414 and the registered file scripts run before image promotion, while the preceding app still serves traffic. They install ownership constraints, validate existing file/folder/version bindings, backfill verified public-share owners, and validate workspace bindings. The currently serving release must tolerate these changes. Resolve blocking ownership anomalies from authoritative records; do not infer ownership from uploader identity. Unresolved public-share targets reported by the backfill still need explicit review. Earlier draft migrations were used only on disposable databases.Consumer drain gate: record the deployed app/realtime image digests and Trigger.dev version; verify the relevant older work has completed or cannot resume on incompatible code. Sim uses all-at-once app traffic cutover: retired app servers receive no fresh requests through normal routing. Container termination is separate; already-running file registration/finalization, content/version writes, copy, deletion and creator-handoff operations can still finish. Check the separate realtime rollout and any old sockets/persist work that can affect files. Trigger.dev promotion follows app cutover and does not prove old runs have drained: check
workspace-file-search-dispatch,workspace-file-search-index,cleanup-dispatch,cleanup-file-versions,cleanup-soft-deletesandprocess-outbox, including queued retries/resumptions and their producers. Verify cron/self-hosted equivalents where deployed. Scope other workflow/background runs to actual affected file paths; their existence alone is not an ownership writer.A fixed wait is not proof. Use deployment/task and worker-run evidence. Compatible pending outbox work may remain; an empty outbox is not required. New HTTP callbacks reach the current app after cutover, but existing upload sessions and already-started provider transfers can outlive a request or URL expiry. Preserve compatible finalization/recovery, upload retirement and delayed/durable storage cleanup; those are ongoing correctness mechanisms, not temporary deployment scaffolding.
Rollback after Project-owned rows exist: #8609 is the minimum file-aware, data-preserving rollback target. Disable Project file admission and retain compatible realtime/background cleanup consumers and the expanded schema. Foundation-only rollback does not preserve Project backend/upload availability; pending uploads need compatible recovery/cleanup. Do not roll any relevant consumer back below the foundation or treat flag-off as proof that admitted work has stopped. Deployment, drain and rollback verification are operational gates, not claims made by this PR's CI results.
Type of Change
Testing
Hosted CI and standalone desktop-e2e passed on
d43cdd46eec6e3ce638481965b27cee5ac2ea2cc; Greptile and Cubic completed, with all review threads answered and resolved.Current membership alignment:
workspace.project_id, native deferred constraints, and marker-free rollback. File creation, organization transfer, account teardown, creator handoff, and copy prerequisites use the direct membership column.Checklist