feat(linter): add rollback compatibility rules - #1381
Closed
t-monaghan wants to merge 15 commits into
Closed
t-monaghan wants to merge 15 commits into
t-monaghan wants to merge 15 commits into
Conversation
👷 Deploy request for squawkhq pending review.Visit the deploys page to approve it
|
t-monaghan
force-pushed
the
compat-rules-extended
branch
from
October 5, 2026 00:42
ae9caf5 to
15d732b
Compare
t-monaghan
marked this pull request as draft
October 5, 2026 00:45
…lit generated drop
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Detect PostgreSQL migrations that can break an application-only rollback. The migration and data written by the new application remain in place when the old application returns.
Context
Migration availability and application compatibility are different checks.
NOT VALIDavoids checking existing rows but still restricts new writes;CONCURRENTLYlimits index-creation locking but a unique index still rejects duplicates. The new opt-in rules identify operations that need application context. A lint result does not prove rollback compatibility.New default rules
ban-drop-extension:DROP EXTENSIONcan remove functions, types, and operators still used by the old application.ban-drop-generated-expression:DROP EXPRESSIONchanges a generated column into an ordinary column.ban-drop-constraintandban-alter-identityare now enabled by default. Dropping a unique constraint can make an oldINSERT ... ON CONFLICTfail immediately. The generated-expression rule is split: replacement withSET EXPRESSIONand addition of a generated column remain opt-in underban-alter-generated-expression.New opt-in rules
ban-new-write-restriction: new table, domain, and foreign-table restrictions, includingNOT VALIDconstraints,NOT NULL, unique indexes createdCONCURRENTLY, and tighter constraint enforcement or timing, can reject old-application writes. Suppressions for objects unconditionally created earlier in the migration are statement-level approximations, not schema knowledge.ban-add-enum-value: the new application can write a label that an old decoder or workflow does not handle. IncludesBEFORE,AFTER, andIF NOT EXISTS.ban-add-composite-attribute: an added attribute can change positional composite input and result decoding.ban-detach-inheritance:DETACH PARTITIONandNO INHERITcan remove rows from queries through a parent table.ban-alter-sequence-values: sequence and identity-sequence option changes or restarts can reissue identifiers or change their supported range.ban-create-policy,ban-alter-policy-roles,ban-alter-policy-condition, andban-alter-row-level-security: policy and RLS changes can hide rows, reject writes, or change access for the old application's role.ban-alter-function-options,ban-alter-view-options,ban-alter-role-options, andban-alter-database-options: option changes can change permissions, query behavior, or the ability of the old application to connect.Extended existing rules
NOT ENFORCED.ban-disable-triggerdetects replica-only trigger and rule firing, which stops them from firing on normal application writes, as well as the relevant RLS enforcement variants. Diagnostics distinguish lost side effects from access errors.ban-alter-generated-expressiondetectsSET EXPRESSION. Stored-value rewrites are an availability concern separate from whether old clients understand the resulting values.The PR adds tests, diagnostics, rule documentation, changelog entries, and an application rollback verification guide. The guide covers data migrations, procedural SQL, privileges, plain
TRUNCATE, and old-application tests that a statement-level linter cannot replace.Verification
cargo test --workspacewith Rust 1.94 and offline vendored dependencies: all tests passed (one ignored).cargo check --workspaceandcargo fmt --all --checkpassed.