fix(vector): harden packaged migrations
This commit is contained in:
@@ -50,3 +50,33 @@ No unresolved Task 2 correctness concern found. One deliberate contract choice i
|
||||
writer `INSERT` and `UPDATE` are table-level because the approved direct adapter health probe uses
|
||||
`has_table_privilege` for those authorities. Least privilege is retained by withholding broad
|
||||
`SELECT`, `DELETE`, DDL, ownership, and credentials.
|
||||
|
||||
## Review fix wave
|
||||
|
||||
The post-implementation review found four production-boundary gaps. They are fixed as follows:
|
||||
|
||||
- Migration SQL now ships inside the `tht` wheel (`tht/migrations/vector`) via explicit
|
||||
setuptools package-data and is discovered through `importlib.resources`, rather than relying on
|
||||
a source-checkout-relative directory.
|
||||
- Both status and apply reject ledger versions absent from the installed manifest, including
|
||||
nonnumeric future version labels. This treats a binary/database downgrade as drift instead of
|
||||
silently reporting a healthy state.
|
||||
- Migration files are ordered by parsed integer version; spellings such as `2` and `02` are
|
||||
rejected as duplicate versions.
|
||||
- Every migration transaction pins `search_path` locally to `pg_catalog, pg_temp`; catalog calls
|
||||
and the ledger are schema-qualified. pgvector is installed into the locked `vectors` schema,
|
||||
tables use `vectors.vector`, and `PgVectorStore` qualifies vector casts and the cosine operator.
|
||||
A hostile admin default path with a writable shadow schema cannot redirect migration objects.
|
||||
- The core image build asserts CLI discovery. Image verification now starts an ephemeral pgvector
|
||||
database, runs the installed image's migration command, and compares pristine apply/status JSON.
|
||||
|
||||
Additional verification after the fix wave:
|
||||
|
||||
- Focused migration, adapter, hostile-path, and wheel suite: `27 passed`.
|
||||
- Full harness: `477 passed, 5 deselected`.
|
||||
- Production core image build: passed, including build-time CLI discovery.
|
||||
- Core-image apply/status smoke against `pgvector/pgvector:pg16`: passed.
|
||||
- Changed production and test files: Ruff clean; `git diff --check` clean.
|
||||
- Full Ruff remains at the same 34 pre-existing unrelated test-file findings documented above.
|
||||
|
||||
No dependency changed, so the committed Python requirements lock did not require regeneration.
|
||||
|
||||
Reference in New Issue
Block a user