Skip to content

feat: establish shared file ownership foundation - #8609

Draft
mzxchandra wants to merge 39 commits into
codex/project-entity-enforcementfrom
codex/file-ownership-foundation
Draft

mzxchandra wants to merge 39 commits into
codex/project-entity-enforcementfrom
codex/file-ownership-foundation

Conversation

@mzxchandra

@mzxchandra mzxchandra commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Prepare shared file infrastructure for Project files while preserving workspace behavior. Add a nullable project_id FK alongside workspace_id and organization_id; enforce at most one owner. Existing personal/chat attachments retain their ownerless representation and policy.
  • Keep the common entityType/entityId interface above storage. Native FKs enforce owner existence; shared locks and lifecycle helpers cover files, folders, versions, billing, search, sharing and cleanup.
  • Integrate the successor handoff from fix(lifecycle): retain shared resources when creators leave #8762 so shared files survive account deletion while existing uploader ID contracts remain non-null. Preserve distinct acting-principal and billing identities.
  • Clean staged content after explicit PostgreSQL COMMIT rejection while retaining bytes after uncertain commit outcomes. Share the narrow error classifier with transaction-owning consumers.
  • Add migrations 0408–0414 and compatible owner-aware consumers, including realtime admission and search invalidation. Project operations/API/CLI follow in feat(files): add the Project file backend and APIs #8610; browser and Mothership integration live in feat(files): integrate Project files with the browser and Mothership #8781.

Stack: #8590 → #8609 → #8610 → #8781. Includes the lifecycle prerequisite #8762 for local integration; keep its independent merge dependency. #8580 has merged.

Rollout and rollback

Keep the current PR split: #8609 owns shared file ownership and compatible consumers; #8610 owns Project backend/APIs; #8781 owns browser/Mothership integration. PR boundaries do not require separate deployments. Use two file releases with an explicit wait between them; this stack has no separate file-enforcement release.

  1. Prerequisites: satisfy feat(projects): enforce Project membership and retire the connector #8590's membership deployment/drain gates and the fix(lifecycle): retain shared resources when creators leave #8762 lifecycle dependency. A merged PR or passing CI does not establish deployment or drain.
  2. Release 1 — foundation, Project files disabled: deploy feat: establish shared file ownership foundation #8609 across app, realtime and background consumers with PROJECT_FILES_ENABLED off. SQL 0408–0414 and the registered file scripts run before image promotion, while the preceding app still serves traffic. They install ownership constraints, validate existing file/folder/version bindings, backfill verified public-share owners, and validate workspace bindings. The currently serving release must tolerate these changes. Resolve blocking ownership anomalies from authoritative records; do not infer ownership from uploader identity. Unresolved public-share targets reported by the backfill still need explicit review. Earlier draft migrations were used only on disposable databases.
  3. Wait and verify the consumer gate below.
  4. Release 2 — backend/product: deploy feat(files): add the Project file backend and APIs #8610 and feat(files): integrate Project files with the browser and Mothership #8781, with Mothership feat(models): added temp controls for gpt-4.1 family of models #594 for its integration. They add no migrations. Keep admission disabled until the intended app/realtime/background versions and companion worker are ready, then enable the existing Project and Project-files gates. No queue contraction or other implementation change is part of this rollout description.

Consumer drain gate: record the deployed app/realtime image digests and Trigger.dev version; verify the relevant older work has completed or cannot resume on incompatible code. Sim uses all-at-once app traffic cutover: retired app servers receive no fresh requests through normal routing. Container termination is separate; already-running file registration/finalization, content/version writes, copy, deletion and creator-handoff operations can still finish. Check the separate realtime rollout and any old sockets/persist work that can affect files. Trigger.dev promotion follows app cutover and does not prove old runs have drained: check workspace-file-search-dispatch, workspace-file-search-index, cleanup-dispatch, cleanup-file-versions, cleanup-soft-deletes and process-outbox, including queued retries/resumptions and their producers. Verify cron/self-hosted equivalents where deployed. Scope other workflow/background runs to actual affected file paths; their existence alone is not an ownership writer.

A fixed wait is not proof. Use deployment/task and worker-run evidence. Compatible pending outbox work may remain; an empty outbox is not required. New HTTP callbacks reach the current app after cutover, but existing upload sessions and already-started provider transfers can outlive a request or URL expiry. Preserve compatible finalization/recovery, upload retirement and delayed/durable storage cleanup; those are ongoing correctness mechanisms, not temporary deployment scaffolding.

Rollback after Project-owned rows exist: #8609 is the minimum file-aware, data-preserving rollback target. Disable Project file admission and retain compatible realtime/background cleanup consumers and the expanded schema. Foundation-only rollback does not preserve Project backend/upload availability; pending uploads need compatible recovery/cleanup. Do not roll any relevant consumer back below the foundation or treat flag-off as proof that admitted work has stopped. Deployment, drain and rollback verification are operational gates, not claims made by this PR's CI results.

Type of Change

  • Other: shared ownership and rollout compatibility foundation

Testing

Hosted CI and standalone desktop-e2e passed on d43cdd46eec6e3ce638481965b27cee5ac2ea2cc; Greptile and Cubic completed, with all review threads answered and resolved.

Current membership alignment:

  • Merge the finalized feat(projects): enforce Project membership and retire the connector #8590 implementation, preserving required workspace.project_id, native deferred constraints, and marker-free rollback. File creation, organization transfer, account teardown, creator handoff, and copy prerequisites use the direct membership column.
  • Preserve workflow-test and changelog file contexts across storage, history and cleanup.
  • Focused local validation: 75 unit tests; 124 PostgreSQL application checks covering Project lifecycle, file history, billing and shared-resource handoff; 14 additional teardown/creator/organization checks; 20 file/folder/version database checks; 9 historical repair checks against isolated PostgreSQL and Redis. Fresh migration, schema-generation drift check, and migration safety passed.
  • Removed an obsolete fixture that loaded the retired trigger-based membership migration and asserted database-owned nonempty lifecycle. The existing application lifecycle suite validates the supported guarantees.
  • Review follow-ups: deletion previews share creator-successor validation with the transaction; owner revocation preserves billed-account ownership transfer; search contention is retryable; compiled dependency identities are stable; Project key inference and first-seed retirement fencing are corrected. Focused coverage passed: 28 shared-resource, 6 Redis editor, 16 realtime admission, 14 purge/changelog, 1 creator-lifetime, 5 unit, and 13 audit-base cases.
  • Each stack layer uses its available billing API: foundation retains its existing owned-file accounting; feat(files): add the Project file backend and APIs #8610 adopts the newer shared accounting helper.
  • Full validation runs in hosted CI. The first synchronized run found stale admin-route imports/helpers and the obsolete fixture; these were corrected. A subsequent historical fixture tried to run newer file script migrations against its older schema; its script boundary was corrected and all 9 cases pass locally. Check current-head CI separately from local evidence and historical runs.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Relevant tests updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 10, 2026 9:58pm UTC

Request Review

Add canonical entity ownership while preserving legacy workspace writers.
Make storage accounting, lifecycle cleanup, search, document artifacts, and
realtime transport tolerate project-owned data before feature activation.

Keep Project file user/API/tool entry points in the stacked feature change.
@mzxchandra
mzxchandra force-pushed the codex/file-ownership-foundation branch from 9a1af75 to 6f8882e Compare October 5, 2026 21:02
@mzxchandra mzxchandra changed the title feat: establish entity-owned file compatibility feat: establish shared file ownership foundation Oct 5, 2026
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@greptile-apps

greptile-apps Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical impact] The PR appears safe to merge based on the changes since the previous review.

Summary

This PR establishes shared ownership, lifecycle, billing, search, and realtime infrastructure for Project files while retaining workspace-file behavior.

  • The latest revision replaces a billing-helper call unavailable in this stack layer with the existing workspace billing API.
  • Document input identity now uses a copied array for sorting.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Workspace or Project owner] --> B[Owner-scoped file metadata]
  B --> C[Storage and version lifecycle]
  B --> D[Billing and search]
  B --> E[Realtime document access]
Loading

Reviews (28) · Last reviewed commit: "Keep foundation owned-file creation on i..." · Reviewed by Greptile

Comment thread apps/realtime/src/handlers/file-doc.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 181 files

Re-trigger cubic

Comment thread apps/realtime/src/handlers/file-doc-app.ts
Comment thread apps/realtime/src/handlers/file-doc.ts
Comment thread apps/realtime/vitest.config.ts
Comment thread apps/sim/lib/uploads/documents/compile.ts Outdated
Comment thread apps/realtime/src/middleware/permissions.ts Outdated
Comment thread apps/sim/lib/uploads/contexts/workspace/workspace-file-versions.ts
Comment thread apps/sim/lib/projects/files/purge.ts
Comment thread apps/sim/lib/uploads/documents/references.ts Outdated
Comment thread apps/sim/lib/projects/files/prefix-cleanup.ts
Comment thread packages/auth/src/principal.ts
@greptile-apps

greptile-apps Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Comments Outside Diff

These findings could not be posted inline.

  • P1 Committed file content can disappear apps/sim/lib/uploads/contexts/workspace/workspace-file-manager.ts:829 ▶

    If the database commits a workflow test or changelog release but the connection fails before confirming it, db.transaction can throw even though the file and owner records were saved. This catch always deletes the uploaded object, leaving the committed test source or release body unreadable. The nearby file-content finalizer retains bytes when the commit outcome is uncertain; this path needs the same distinction.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptileai review

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 216 files

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/workspaces/organization-workspaces.ts
Comment thread apps/realtime/src/handlers/file-doc-project.integration.ts
Comment thread apps/sim/lib/projects/account-deletion.ts
Comment thread apps/sim/lib/uploads/documents/input-identity.ts Outdated
Comment thread apps/sim/lib/uploads/shared/types.ts
Comment thread apps/sim/lib/projects/files/__integration__/private-purge.integration.ts Outdated
Comment thread packages/db/migrations/0408_file_entity_ownership.sql
Comment thread apps/realtime/src/handlers/file-doc-store.ts Outdated
Comment thread packages/db/migrations/0410_file_creator_lifetime.sql Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptileai review — current code includes the historical repair fixture migration-boundary fix; its 9 PostgreSQL/Redis cases pass.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review — current code includes the historical repair fixture migration-boundary fix; its 9 PostgreSQL/Redis cases pass.

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review — current code includes the historical repair fixture migration-boundary fix; its 9 PostgreSQL/Redis cases pass.

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 217 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptileai review — current head e3e0f52 addresses the verified lifecycle, search, storage, realtime and audit-base findings with focused regression coverage.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review — current head e3e0f52 addresses the verified findings. Individual threads include fixes or current-code evidence for rejected findings.

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review — current head e3e0f52 addresses the verified findings. Individual threads include fixes or current-code evidence for rejected findings.

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptileai review — 9569da8 uses supported copy-and-sort/reverse array operations; the input identity regression passes.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review — 9569da8 uses supported copy-and-sort/reverse array operations; the input identity regression passes.

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review — 9569da8 uses supported copy-and-sort/reverse array operations; the input identity regression passes.

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/lib/uploads/contexts/workspace/workspace-file-manager.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 220 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptileai review — d43cdd4 corrects the branch boundary: foundation owned-file creation uses its existing billing API; the newer accounting helper remains in #8610.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review — d43cdd4 corrects the branch boundary: foundation owned-file creation uses its existing billing API; the newer accounting helper remains in #8610.

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review — d43cdd4 corrects the branch boundary: foundation owned-file creation uses its existing billing API; the newer accounting helper remains in #8610.

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 220 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

This branch was previously deployed

1 inactive deployment
Preview — d43cdd46 Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants