feat(linter): add opt-in rollback compatibility rules - #1384
Draft
t-monaghan wants to merge 1 commit into
Draft
t-monaghan wants to merge 1 commit into
t-monaghan wants to merge 1 commit into
Conversation
馃懛 Deploy request for squawkhq pending review.Visit the deploys page to approve it
|
t-monaghan
marked this pull request as draft
October 5, 2026 05:00
This was referenced Oct 5, 2026
t-monaghan
force-pushed
the
compat-opt-in-split
branch
from
October 6, 2026 04:10
0adbd52 to
5a9eb47
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
At Culture Amp the SRE team are proposing using Squawk to review SQL migrations and to increase confidence that we can roll back our applications. As we adopt blue/green deployments, this check becomes more important: an earlier application revision may need to run against a database that has already been migrated.
Rolling back the application does not roll back the database migration or remove data written by the newer revision. The earlier revision must still be able to read and write using the migrated database.
These opt-in rules flag migration operations whose effect on the earlier application revision depends on application usage or database configuration. They help identify risks before deployment, alongside testing earlier revisions against the migrated database.
Context
This PR adds 24 rules that require explicit inclusion:
ban-alter-generated-expressiondetects added generated columns andSET EXPRESSION. Stored-value rewrites are an availability concern separate from whether earlier clients understand the new values.ban-drop-indexdetectsDROP INDEX, which can remove a unique or exclusion guarantee.ban-set-defaultdetectsSET DEFAULTon table, foreign table, view, and domain columns.ban-disable-triggerdetects disabling or enabling triggers and rules, replica-only or always firing, andFORCE/NO FORCE ROW LEVEL SECURITY. Diagnostics distinguish lost side effects from access errors.ban-replica-identitydetects replica identity changes, dropped publications, and changes to published tables or options.ban-drop-policydetectsDROP POLICYandDROP RULE.ban-revokedetectsREVOKE,ALTER GROUP ... DROP USER,DROP ROLE,OWNER TO,REASSIGN OWNED, andDROP OWNED.ban-replace-view-functiondetectsCREATE OR REPLACEon views, functions, procedures, triggers, rules, and aggregates.ban-create-policy,ban-alter-policy-roles,ban-alter-policy-condition, andban-alter-row-level-securitydetect policy and row-level security changes that can change access for the earlier application's role.ban-alter-function-options,ban-alter-view-options,ban-alter-role-options,ban-alter-database-options, andban-alter-system-optionsdetect option and configuration changes that can affect permissions, connection behavior, name resolution, or results.ban-alter-function-optionscovers procedures and routines;ban-alter-role-optionscoversALTER USER.ban-alter-extensiondetects extension updates and member removal. It does not check extension schema moves.ban-new-write-restrictiondetects new table, domain, and foreign-table restrictions, includingNOT VALIDconstraints,NOT NULLconstraints, constrained added columns, unique indexes builtCONCURRENTLY, and tighter constraint timing or enforcement.ban-add-columndetects columns added to existing tables and foreign tables. Added columns can changeSELECT *results and break positional inserts.ban-add-enum-valueandban-add-composite-attributedetect new values or attributes that can break earlier decoders and positional composite input.ban-detach-inheritancedetectsDETACH PARTITIONandNO INHERIT, which can remove rows from parent-table queries.ban-alter-sequence-valuesdetects sequence and identity-sequence changes that can reissue identifiers or change their range. It excludes options that do not change generated values.Some opt-in rules added in this PR omit warnings for changes to objects created earlier in the same SQL input. These rules make a limited assumption from the SQL text, not from the database. With the new
ban-add-columnrule enabled, consider:The
ban-add-columnbehaviour introduced in this PR does not warn aboutADD COLUMNhere. The rule saw an unconditionalCREATE TABLE tearlier in the same SQL input, so it treatstas a new table that an earlier application revision could not have used.CREATE TABLE IF NOT EXISTSdoes not suppress this rule's warning, becausetmight already exist. This check does not query the database or track whether a transaction rolls back. If the assumption is wrong, this rule can miss a change to a table used by the earlier application revision.The PR includes tests, diagnostics, rule documentation, and a changelog entry.