Skip to content

[finding] seven more dry-run / report-only CLI commands boot the app seed loader and rewrite seeded rows (the family of #21349) #21391

Description

@objectstack-fleet

Source: the os-dev report on #21349 (PR #21389), out_of_scope_findings[0], class b. Filed by the domain:cli seat, session_01VvcEokUG1tvVxkceYfR5XB. One family card, not seven single cards.

What happens (measured, public door)

The setup is an examples/app-crm database: os build, then os dev -d file:…, which seeds 28 rows across 5 app tables and the first admin. The PR #21389 branch is at a67e290cc7. Each of these commands, run with --database-url in its default no-write mode, rewrote the same 28 seeded rows. The [Seeder] line reported "updated":28, updated_at moved, and organization_id was stamped:

Command Default mode, as documented
os migrate value-shapes "Scan: full report, writes nothing" (content/docs/deployment/cli.mdx, os migrate value-shapes entry)
os migrate summary-nulls "Dry run: full report, writes nothing"
os migrate files-to-references "Dry run: full report, writes nothing"
os migrate recorded-by dry run by default
os migrate resume dry run by default
os secret orphans "Report-only by default: without --delete it writes nothing and deletes nothing."
os storage orphans report-only by default

os migrate account-issuer and os migrate multi-value-columns already boot read-only and left the database identical. These are the controls.

Why

bootSchemaStack (packages/cli/src/utils/schema-migrate.ts) passes skipSeedData to createStandaloneStack only when it is given deferSchemaDdl. None of the seven commands passes it in its no-write mode. So the boot runs the artifact's inline seed loader, whose upserts rewrite every seeded row, and schema sync, which adds missing columns and creates missing tables. Each of these is a write the command's own documentation says does not happen.

Direction for triage

#21349 (PR #21389) fixes two members by passing the read-only boot (deferSchemaDdl: true, readOnlyProbe: true) at their call sites, the boot os migrate plan already takes.

The dev suggests a family-wide fix keyed like runPlatformMigrations: false:

  • the seed is off on every one-shot CLI boot;
  • DDL is deferred on every dry run.

That would also cover the --apply / --delete paths, which still run the boot seed loader today, a write the operator never saw in the preview. Whether to fix per call site or family-wide is triage's call.

Also on this card (carrier)

Two comments now say more than is true. Both list os migrate meta among the boots without deferSchemaDdl; after PR #21389 that holds only with --apply:

  • packages/cli/src/utils/schema-migrate.ts, the runPlatformMigrations: false block;
  • packages/cli/src/utils/platform-migrations-arming.integration.test.ts.

They sit outside #21349's surface, and this card edits the same boot options.

Dedupe words: dry run writes seeded rows; bootSchemaStack skipSeedData; one-shot CLI boot seed loader; report-only command rewrites rows; migrate dry run updated_at.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:clipriority:p1High: required for production / M2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions