deer-flow/backend/tests/test_persistence_forward_revision_compat.py
Zeren Wang 5951c89b5b
feat(projects): project workspaces with scoped chats and thread membership (#5265)
* feat(projects): project workspaces with scoped chats and thread membership

Backend:
- projects table model and migration; fail-closed ProjectRepository with
  ownership checks, CRUD/archive/restore/delete router, and atomic thread
  move between projects
- threads_meta.project_id column exposed as reserved deerflow_project_id
  metadata; project-aware thread create/search with pagination bounds and
  membership echoed in create responses
- first-run admission assigns the project only at genuine first run, seeded
  at write time and dropped when invalid; serialized against project
  deletion and thread assignment
- branch creation inherits the source thread's project membership (an
  archived/deleted project degrades the branch to unassigned instead of
  failing the request)

Frontend:
- projects data layer, thread move API, and sidebar projects section with
  flat/grouped modes, archived-project threads, and stable virtual-list
  offsets
- project detail page with project-scoped new chat
  (/workspace/chats/new?project=) and paginated thread list
- move-to-project thread menu, new-project dialog, archived-project gates
- project-scoped new chats pre-create the thread with membership before the
  first submit or /goal set, so runs never proceed outside the project
- goal-set preparation is fenced against conversation switches: a stale
  continuation is dropped instead of saving the goal or launching the
  abandoned submission on the newly opened conversation
- project thread lists join thread lifecycle invalidations (stop, pin) so
  an open project page never keeps stale titles, recency, or pagination

* fix(chats): keep archive undo toast when the sidebar row unmounts

The archive success toast was fired from per-mutate callbacks passed to
mutation.mutate. React Query drops those handlers when the observer
component unmounts before the mutation settles; archiving the open chat
removes its sidebar row mid-flight, so the undo toast never appeared and
the e2e archive-undo test timed out waiting for it.

Move the success/error handlers to the mutation level (useArchiveThread
options, same pattern as useMoveThreadToProject) where callbacks are
delivered even after the originating row unmounts.

* fix(projects): pin project thread listing contract and exclude archived chats

GET /api/projects/{id}/threads returned the thread store row verbatim
(list[dict], no response_model): user_id/assistant_id leaked, any future
ThreadMetaRow column would auto-leak, and the OpenAPI schema was empty.
Return a narrow ProjectThreadResponse (the exact fields ProjectThread
declares) with the same metadata secret redaction the surrounding thread
endpoints get from _MetadataRedactingResponse.

The listing also ran search() without the archived filter, so a retired
chat rendered as a normal row on the project page while the sidebar hid
it. Search archived=False to mirror the sidebar's archived:false lists;
restore stays on the global Archived tab.

Both regressions pinned by new router tests: wire-shape allowlist and
archived-member exclusion.

* docs(migrations): record the 0019/0020 chain against the bootstrap reservation

The tree now chains 0018 -> 0019_projects -> 0020_threads_meta_project_id,
so migrations/AGENTS.md was stale twice over: the revision index stopped at
0018 and the rolling-forward section still claimed the tree 'deliberately
remains at 0018'.

Document the new head and record the intentional numeric-prefix reuse of
0019: 0019_projects is in-chain while 0019_thread_incarnations stays the
reserved, allowlisted out-of-tree rollout id. The owning rollout revision
must re-parent onto this tree's head when it merges so alembic never sees
two heads off 0018; bootstrap.py now cross-references that note next to
_FORWARD_COMPATIBLE_REVISION.

* fix(chats): invalidate project thread lists on archive/restore

useArchiveThread refreshed the infinite sidebar cache, threads/search and
the per-thread metadata cache but not the project-scoped list
([...PROJECTS_QUERY_KEY, 'threads', id]) this PR adds — the one thread
mutation not wired to that key, after usePinThread, useRenameThread,
useDeleteThread, useMoveThreadToProject and invalidateStoppedThreadCaches.

An archive from a sidebar row while a project page is open therefore left
the archived chat rendered as a normal row until remount (and undo left it
missing). Invalidate the prefix in the mutation-level success handler.

Regression test asserts the project-list prefix is invalidated on success.

* fix(projects): fetch project discovery only in grouped sidebar mode

RecentChatList mounted two useProjects queries per sidebar render, but
knownProjectIds is consumed only by the grouped-mode exclusion filter; in
the default flat mode every page load paid two GET /api/projects?status=
round trips for data nothing read. Gate both queries on grouped mode —
GroupedProjectList fetches the same keys when the toggle is on and
TanStack dedupes the observers.

Also set retry: false on useProject: a deleted or foreign project 404s
deterministically, and the page renders a dedicated not-found state for
it, so the default 1s/2s/4s retry backoff kept deep links in 'loading'
for ~7s before that state appeared. Matches useThreadMetadata /
useThreadTokenUsage.

* fix(threads): fail closed on project-scoped create in memory mode

MemoryThreadMetaStore.create accepted project_id and silently ignored it,
making memory mode the one membership path that fails open: POST
/api/threads with a project id returned 200 and the run started
unassigned, violating the invariant that a run never proceeds outside the
selected project (the SQL store raises ProjectNotAssignableError inside
the insert transaction for the same request).

Raise ProjectNotAssignableError whenever project_id is present so the
router's existing 404 mapping applies, the frontend keeps the composer
text for a retry, and memory mode behaves exactly like SQL mode.
set_project already reports rejection; create now matches it.

Store-level test (raises, nothing persisted, project filter stays empty,
unscoped creates still work) plus a router-level test asserting the 404
and that no row is left behind.

* fix(projects): window the project page thread list

ProjectThreadsSection rendered every loaded page as a plain Link row, so a
long-lived project accumulated unbounded DOM on the page's scroll surface:
each load-more appended another 100 rows and every formatTimeAgo tick
re-rendered the whole list.

Reuse VirtualThreadList (now generic over any row shape with a
thread_id), pointing its scroll parent at this page's ScrollArea viewport
via the shared [data-slot="scroll-area-viewport"] selector used by
/workspace/chats; under the 60-row threshold it falls back to the plain
render, so small projects are unchanged.

* fix(projects): restore row dividers and pin them with a render test

The row class template literal concatenated transition-colors directly
with the conditional border-b token, so non-final rows rendered the
invalid class 'transition-colorsborder-b' and lost both the divider and
the transition. Compose the row classes with cn() and a boolean guard
instead.

The section moved out of page.tsx into a testable component so the row
markup finally has coverage: a DOM test asserts every row except the
final data row carries border-b (index-based, not last: — correct under
virtualization where the last mounted row is not the last data row), and
the untitled fallback plus load-more button render for a partial page.

* fix(projects): validate forward schemas and fence membership reads
2026-09-08 17:00:26 +08:00

447 lines
17 KiB
Python

"""Forward-compatibility tests for an old Gateway against migration 0019."""
from __future__ import annotations
import asyncio
import os
import threading
import uuid
from datetime import UTC, datetime, timedelta
from pathlib import Path
from urllib.parse import parse_qsl, urlencode, urlsplit, urlunsplit
import pytest
import sqlalchemy as sa
from alembic import command as alembic_command
from alembic.util.exc import CommandError
from sqlalchemy.ext.asyncio import async_sessionmaker, create_async_engine
import deerflow.persistence.models # noqa: F401
from deerflow.config.database_config import DatabaseConfig
from deerflow.persistence import bootstrap as bootstrap_mod
from deerflow.persistence.bootstrap import (
_FORWARD_COMPATIBLE_REVISION,
_get_alembic_config,
_upgrade,
bootstrap_schema,
)
from deerflow.persistence.engine import close_engine, get_engine, init_engine_from_config
from deerflow.persistence.mcp_tasks import McpTaskRepository
from deerflow.persistence.thread_meta import ThreadMetaRepository
HEAD = "0020_threads_meta_project_id"
POSTGRES_URL = os.environ.get("TEST_POSTGRES_URI")
def _url(tmp_path: Path, name: str) -> str:
return f"sqlite+aiosqlite:///{(tmp_path / name).as_posix()}"
def _postgres_url(url: str) -> str:
parts = urlsplit(url)
query = urlencode([(key, value) for key, value in parse_qsl(parts.query, keep_blank_values=True) if key not in {"sslmode", "channel_binding"}])
return urlunsplit(parts._replace(query=query))
async def _database_revision(engine) -> str | None:
async with engine.connect() as conn:
result = await conn.execute(sa.text("SELECT version_num FROM alembic_version"))
return result.scalar_one_or_none()
async def _set_database_revision(engine, revision: str) -> None:
async with engine.begin() as conn:
await conn.execute(sa.text("UPDATE alembic_version SET version_num = :revision"), {"revision": revision})
async def _seed_head(engine) -> None:
await bootstrap_schema(engine, backend="sqlite")
assert await _database_revision(engine) == HEAD
async def _seed_original_forward_schema(engine) -> None:
# The rollout predates projects: seeding today's head masks missing columns.
await asyncio.to_thread(_upgrade, _get_alembic_config(engine), "0018_oauth_identity_pg_partial")
await _add_forward_columns(engine)
await _set_database_revision(engine, _FORWARD_COMPATIBLE_REVISION)
@pytest.mark.asyncio
@pytest.mark.parametrize("concurrent", [False, True])
async def test_original_forward_schema_fails_closed(tmp_path: Path, monkeypatch: pytest.MonkeyPatch, concurrent: bool) -> None:
engine = create_async_engine(_url(tmp_path, "original-forward.db"))
try:
await _seed_original_forward_schema(engine)
if concurrent:
await _set_database_revision(engine, "0018_oauth_identity_pg_partial")
def concurrent_upgrade(_cfg, _revision):
asyncio.run(_set_database_revision(engine, _FORWARD_COMPATIBLE_REVISION))
raise CommandError("revision advanced concurrently")
monkeypatch.setattr(bootstrap_mod, "_upgrade", concurrent_upgrade)
with pytest.raises(RuntimeError, match="missing.*projects.*threads_meta.project_id"):
await bootstrap_schema(engine, backend="sqlite")
assert await _database_revision(engine) == _FORWARD_COMPATIBLE_REVISION
async with engine.connect() as conn:
tables = await conn.run_sync(lambda sync: sa.inspect(sync).get_table_names())
assert "projects" not in tables
finally:
await engine.dispose()
@pytest.mark.asyncio
@pytest.mark.parametrize(
("ddl", "missing"),
[
("DROP TABLE projects", "projects"),
("ALTER TABLE projects DROP COLUMN instructions", "projects.instructions"),
("ALTER TABLE threads_meta DROP COLUMN project_id", "threads_meta.project_id"),
],
)
async def test_forward_revision_rejects_partial_project_schema(tmp_path: Path, ddl: str, missing: str) -> None:
engine = create_async_engine(_url(tmp_path, "partial-projects.db"))
try:
await _seed_head(engine)
await _add_forward_columns(engine)
async with engine.begin() as conn:
if "DROP COLUMN project_id" in ddl:
await conn.execute(sa.text("DROP INDEX ix_threads_meta_project_id"))
await conn.execute(sa.text(ddl))
await _set_database_revision(engine, _FORWARD_COMPATIBLE_REVISION)
with pytest.raises(RuntimeError, match=f"missing required local schema: {missing};"):
await bootstrap_schema(engine, backend="sqlite")
assert await _database_revision(engine) == _FORWARD_COMPATIBLE_REVISION
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_audited_original_forward_schema_can_upgrade_preserving_incarnations(tmp_path: Path) -> None:
engine = create_async_engine(_url(tmp_path, "forward-recovery.db"))
try:
await _seed_original_forward_schema(engine)
async with engine.begin() as conn:
await conn.execute(
sa.text("INSERT INTO threads_meta (thread_id, status, metadata_json, created_at, updated_at, incarnation) VALUES ('existing', 'idle', '{}', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP, :incarnation)"),
{"incarnation": "a" * 32},
)
# Documented offline operator recovery, only after verifying the exact
# 0018 + two nullable columns shape. Bootstrap never re-stamps an unknown DB.
await asyncio.to_thread(alembic_command.stamp, _get_alembic_config(engine), "0018_oauth_identity_pg_partial", purge=True)
await bootstrap_schema(engine, backend="sqlite")
assert await _database_revision(engine) == HEAD
repository = ThreadMetaRepository(async_sessionmaker(engine, expire_on_commit=False))
assert [row["thread_id"] for row in await repository.search(user_id=None)] == ["existing"]
assert (await repository.create("new", user_id=None))["thread_id"] == "new"
async with engine.connect() as conn:
assert (await conn.execute(sa.text("SELECT incarnation FROM threads_meta WHERE thread_id = 'existing'"))).scalar_one() == "a" * 32
columns = await conn.run_sync(lambda sync: sa.inspect(sync).get_columns("mcp_tasks"))
assert "thread_incarnation" in {column["name"] for column in columns}
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_known_older_revision_upgrades_normally(tmp_path: Path) -> None:
engine = create_async_engine(_url(tmp_path, "known.db"))
try:
cfg = _get_alembic_config(engine)
await asyncio.to_thread(_upgrade, cfg, "0017_personal_access_tokens")
await bootstrap_schema(engine, backend="sqlite")
assert await _database_revision(engine) == HEAD
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_exact_forward_revision_skips_upgrade_with_warning(
tmp_path: Path,
caplog: pytest.LogCaptureFixture,
) -> None:
engine = create_async_engine(_url(tmp_path, "forward.db"))
try:
await _seed_head(engine)
await _set_database_revision(engine, _FORWARD_COMPATIBLE_REVISION)
with caplog.at_level("WARNING", logger="deerflow.persistence.bootstrap"):
await bootstrap_schema(engine, backend="sqlite")
assert await _database_revision(engine) == _FORWARD_COMPATIBLE_REVISION
assert any(_FORWARD_COMPATIBLE_REVISION in record.getMessage() and "explicitly forward-compatible" in record.getMessage() for record in caplog.records)
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_other_unknown_revision_fails_closed(tmp_path: Path) -> None:
engine = create_async_engine(_url(tmp_path, "unknown.db"))
try:
await _seed_head(engine)
await _set_database_revision(engine, "9999_unknown")
with pytest.raises(RuntimeError, match="not known to this build"):
await bootstrap_schema(engine, backend="sqlite")
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_sqlite_upgrade_race_recovers_when_other_process_applies_forward_revision(
tmp_path: Path,
monkeypatch: pytest.MonkeyPatch,
caplog: pytest.LogCaptureFixture,
) -> None:
url = _url(tmp_path, "forward-race.db")
old_gateway = create_async_engine(url)
new_gateway = create_async_engine(url)
upgrade_started = threading.Event()
continue_upgrade = threading.Event()
original_upgrade = bootstrap_mod._upgrade
def delayed_upgrade(cfg, revision):
upgrade_started.set()
if not continue_upgrade.wait(timeout=5):
raise TimeoutError("timed out waiting for the forward migration")
return original_upgrade(cfg, revision)
try:
await _seed_head(old_gateway)
monkeypatch.setattr(bootstrap_mod, "_upgrade", delayed_upgrade)
old_bootstrap = asyncio.create_task(bootstrap_schema(old_gateway, backend="sqlite"))
assert await asyncio.to_thread(upgrade_started.wait, 5)
await _add_forward_columns(new_gateway)
await _set_database_revision(new_gateway, _FORWARD_COMPATIBLE_REVISION)
with caplog.at_level("WARNING", logger="deerflow.persistence.bootstrap"):
continue_upgrade.set()
await old_bootstrap
assert await _database_revision(old_gateway) == _FORWARD_COMPATIBLE_REVISION
assert any("advanced concurrently" in record.getMessage() and _FORWARD_COMPATIBLE_REVISION in record.getMessage() for record in caplog.records)
finally:
continue_upgrade.set()
await old_gateway.dispose()
await new_gateway.dispose()
@pytest.mark.asyncio
async def test_sqlite_upgrade_error_stays_fatal_without_forward_revision(
tmp_path: Path,
monkeypatch: pytest.MonkeyPatch,
) -> None:
engine = create_async_engine(_url(tmp_path, "upgrade-error.db"))
try:
await _seed_head(engine)
def fail_upgrade(_cfg, _revision):
raise CommandError("broken migration")
monkeypatch.setattr(bootstrap_mod, "_upgrade", fail_upgrade)
with pytest.raises(CommandError, match="broken migration"):
await bootstrap_schema(engine, backend="sqlite")
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_local_forward_migration_error_stays_fatal(
tmp_path: Path,
monkeypatch: pytest.MonkeyPatch,
) -> None:
engine = create_async_engine(_url(tmp_path, "local-forward-error.db"))
try:
await _seed_head(engine)
monkeypatch.setattr(
bootstrap_mod,
"_get_revision_metadata",
lambda: (_FORWARD_COMPATIBLE_REVISION, frozenset({HEAD, _FORWARD_COMPATIBLE_REVISION})),
)
def fail_upgrade(_cfg, _revision):
raise CommandError("local 0019 migration failed")
monkeypatch.setattr(bootstrap_mod, "_upgrade", fail_upgrade)
with pytest.raises(CommandError, match="local 0019 migration failed"):
await bootstrap_schema(engine, backend="sqlite")
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_empty_alembic_version_fails_closed(tmp_path: Path) -> None:
engine = create_async_engine(_url(tmp_path, "empty-version.db"))
try:
await _seed_head(engine)
async with engine.begin() as conn:
await conn.execute(sa.text("DELETE FROM alembic_version"))
with pytest.raises(RuntimeError, match="expected exactly one alembic_version row, found 0"):
await bootstrap_schema(engine, backend="sqlite")
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_multiple_alembic_versions_fail_closed(tmp_path: Path) -> None:
engine = create_async_engine(_url(tmp_path, "multiple-versions.db"))
try:
await _seed_head(engine)
async with engine.begin() as conn:
await conn.execute(
sa.text("INSERT INTO alembic_version (version_num) VALUES (:revision)"),
{"revision": "0017_personal_access_tokens"},
)
with pytest.raises(RuntimeError, match="expected exactly one alembic_version row, found 2"):
await bootstrap_schema(engine, backend="sqlite")
finally:
await engine.dispose()
async def _add_forward_columns(engine) -> None:
async with engine.begin() as conn:
await conn.execute(sa.text("ALTER TABLE threads_meta ADD COLUMN incarnation VARCHAR(32)"))
await conn.execute(sa.text("ALTER TABLE mcp_tasks ADD COLUMN thread_incarnation VARCHAR(32)"))
@pytest.mark.asyncio
async def test_old_thread_repository_tolerates_forward_nullable_column(tmp_path: Path) -> None:
engine = create_async_engine(_url(tmp_path, "thread-repository.db"))
try:
await _seed_head(engine)
await _add_forward_columns(engine)
session_factory = async_sessionmaker(engine, expire_on_commit=False)
repository = ThreadMetaRepository(session_factory)
created = await repository.create("thread-1", user_id=None)
assert created["thread_id"] == "thread-1"
assert "incarnation" not in created
async with engine.begin() as conn:
await conn.execute(
sa.text("UPDATE threads_meta SET incarnation = :incarnation WHERE thread_id = :thread_id"),
{"incarnation": "a" * 32, "thread_id": "thread-1"},
)
fetched = await repository.get("thread-1", user_id=None)
assert fetched is not None
assert "incarnation" not in fetched
await repository.update_status("thread-1", "busy", user_id=None)
async with engine.connect() as conn:
incarnation = (
await conn.execute(
sa.text("SELECT incarnation FROM threads_meta WHERE thread_id = :thread_id"),
{"thread_id": "thread-1"},
)
).scalar_one()
assert incarnation == "a" * 32
finally:
await engine.dispose()
@pytest.mark.asyncio
async def test_old_mcp_task_repository_tolerates_forward_nullable_column(tmp_path: Path) -> None:
engine = create_async_engine(_url(tmp_path, "mcp-repository.db"))
try:
await _seed_head(engine)
await _add_forward_columns(engine)
session_factory = async_sessionmaker(engine, expire_on_commit=False)
repository = McpTaskRepository(session_factory)
now = datetime.now(UTC)
created = await repository.create(
task_id="task-1",
user_id="user-1",
thread_id="thread-1",
run_id="run-1",
tool_call_id="call-1",
server_name="reports",
driver_name="fake",
remote_task_id="remote-1",
task_name="Generate report",
status="working",
result=None,
result_preview=None,
result_truncated=False,
result_artifact=None,
error=None,
input_required=None,
next_poll_at=now - timedelta(seconds=1),
)
assert created["id"] == "task-1"
assert "thread_incarnation" not in created
async with engine.begin() as conn:
await conn.execute(
sa.text("UPDATE mcp_tasks SET thread_incarnation = :incarnation WHERE id = :task_id"),
{"incarnation": "b" * 32, "task_id": "task-1"},
)
fetched = await repository.get("task-1", user_id="user-1")
assert fetched is not None
assert "thread_incarnation" not in fetched
claimed = await repository.claim_due_tasks(
now=now,
lease_owner="worker-1",
lease_seconds=60,
limit=1,
)
assert [task["id"] for task in claimed] == ["task-1"]
async with engine.connect() as conn:
incarnation = (
await conn.execute(
sa.text("SELECT thread_incarnation FROM mcp_tasks WHERE id = :task_id"),
{"task_id": "task-1"},
)
).scalar_one()
assert incarnation == "b" * 32
finally:
await engine.dispose()
@pytest.mark.asyncio
@pytest.mark.skipif(not POSTGRES_URL, reason="requires TEST_POSTGRES_URI for a real PostgreSQL restart")
async def test_old_gateway_restarts_against_forward_postgres_revision() -> None:
assert POSTGRES_URL is not None
schema = f"forward_revision_{uuid.uuid4().hex}"
config = DatabaseConfig(
backend="postgres",
postgres_url=_postgres_url(POSTGRES_URL),
postgres_schema=schema,
)
try:
await init_engine_from_config(config)
engine = get_engine()
assert engine is not None
async with engine.begin() as conn:
await conn.execute(sa.text("ALTER TABLE threads_meta ADD COLUMN incarnation VARCHAR(32)"))
await conn.execute(sa.text("ALTER TABLE mcp_tasks ADD COLUMN thread_incarnation VARCHAR(32)"))
await conn.execute(
sa.text("UPDATE alembic_version SET version_num = :revision"),
{"revision": _FORWARD_COMPATIBLE_REVISION},
)
await close_engine()
await init_engine_from_config(config)
restarted_engine = get_engine()
assert restarted_engine is not None
assert await _database_revision(restarted_engine) == _FORWARD_COMPATIBLE_REVISION
finally:
engine = get_engine()
if engine is not None:
async with engine.begin() as conn:
await conn.execute(sa.text(f'DROP SCHEMA IF EXISTS "{schema}" CASCADE'))
await close_engine()