Repository navigation
Conversation
The PG-gated suite is normally gated on TEST_POSTGRES_DSN pointing at the long-lived claimops-postgres container. That volume accumulates rows across runs, and several PG-gated tests assert over whatever a tenant-scoped query returns rather than over the rows they seeded, so their verdicts depend on how much history the volume already holds. infra/postgres/qualify.sh adds a self-contained alternative: its own Postgres container on its own loopback port with no volume, so the database is genuinely empty every run; migrations applied through the repo's own mechanism (infra/postgres/migrations/*.sql, lexicographic, ON_ERROR_STOP=1); the full suite run against it; deterministic teardown via an EXIT/INT/TERM trap. Role topology mirrors .github/workflows/integration.yml (NOSUPERUSER app/worker roles, owner runs migrations) because a superuser app role bypasses RLS and silently inverts every cross-tenant test. It never contacts, restarts or writes to claimops-postgres; the shared port and container name are hard-guarded, not assumed. A run where every PG-backed test self-skipped is reported as a failure, not a pass, and the pre-suite row count is measured so "fresh database" is a fact rather than a claim. `make qualify` is the entrypoint. No test logic, no production code, and no migration is modified.
Add assert_app_role_is_rls_respecting to the qualification harness: it verifies claimops_app is NOSUPERUSER and NOBYPASSRLS after role bootstrap and before migrations, and dies otherwise. Empirically justified — a superuser app role silently inverts every cross-tenant assertion.
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dedicated ephemeral PG qualification environment for the entire PG-gated suite.
What it does:
Evidence: 41/41 with PG genuinely enabled, pre-suite rows 0, 20 PG-backed passes, 0 stray containers — repeatable.
Depends on #119 (merged). Shared claimops-postgres volume untouched; role-bypass guard verified against a negative (superuser) case.