Source: the os-dev report on #21349 (PR #21389), out_of_scope_findings[0], class b. Filed by the domain:cli seat, session_01VvcEokUG1tvVxkceYfR5XB. One family card, not seven single cards.
What happens (measured, public door)
The setup is an examples/app-crm database: os build, then os dev -d file:…, which seeds 28 rows across 5 app tables and the first admin. The PR #21389 branch is at a67e290cc7. Each of these commands, run with --database-url in its default no-write mode, rewrote the same 28 seeded rows. The [Seeder] line reported "updated":28, updated_at moved, and organization_id was stamped:
| Command |
Default mode, as documented |
os migrate value-shapes |
"Scan: full report, writes nothing" (content/docs/deployment/cli.mdx, os migrate value-shapes entry) |
os migrate summary-nulls |
"Dry run: full report, writes nothing" |
os migrate files-to-references |
"Dry run: full report, writes nothing" |
os migrate recorded-by |
dry run by default |
os migrate resume |
dry run by default |
os secret orphans |
"Report-only by default: without --delete it writes nothing and deletes nothing." |
os storage orphans |
report-only by default |
os migrate account-issuer and os migrate multi-value-columns already boot read-only and left the database identical. These are the controls.
Why
bootSchemaStack (packages/cli/src/utils/schema-migrate.ts) passes skipSeedData to createStandaloneStack only when it is given deferSchemaDdl. None of the seven commands passes it in its no-write mode. So the boot runs the artifact's inline seed loader, whose upserts rewrite every seeded row, and schema sync, which adds missing columns and creates missing tables. Each of these is a write the command's own documentation says does not happen.
Direction for triage
#21349 (PR #21389) fixes two members by passing the read-only boot (deferSchemaDdl: true, readOnlyProbe: true) at their call sites, the boot os migrate plan already takes.
The dev suggests a family-wide fix keyed like runPlatformMigrations: false:
- the seed is off on every one-shot CLI boot;
- DDL is deferred on every dry run.
That would also cover the --apply / --delete paths, which still run the boot seed loader today, a write the operator never saw in the preview. Whether to fix per call site or family-wide is triage's call.
Also on this card (carrier)
Two comments now say more than is true. Both list os migrate meta among the boots without deferSchemaDdl; after PR #21389 that holds only with --apply:
packages/cli/src/utils/schema-migrate.ts, the runPlatformMigrations: false block;
packages/cli/src/utils/platform-migrations-arming.integration.test.ts.
They sit outside #21349's surface, and this card edits the same boot options.
Dedupe words: dry run writes seeded rows; bootSchemaStack skipSeedData; one-shot CLI boot seed loader; report-only command rewrites rows; migrate dry run updated_at.
Generated by Claude Code
Source: the os-dev report on #21349 (PR #21389),
out_of_scope_findings[0], class b. Filed by thedomain:cliseat,session_01VvcEokUG1tvVxkceYfR5XB. One family card, not seven single cards.What happens (measured, public door)
The setup is an
examples/app-crmdatabase:os build, thenos dev -d file:…, which seeds 28 rows across 5 app tables and the first admin. The PR #21389 branch is ata67e290cc7. Each of these commands, run with--database-urlin its default no-write mode, rewrote the same 28 seeded rows. The[Seeder]line reported"updated":28,updated_atmoved, andorganization_idwas stamped:os migrate value-shapescontent/docs/deployment/cli.mdx,os migrate value-shapesentry)os migrate summary-nullsos migrate files-to-referencesos migrate recorded-byos migrate resumeos secret orphans--deleteit writes nothing and deletes nothing."os storage orphansos migrate account-issuerandos migrate multi-value-columnsalready boot read-only and left the database identical. These are the controls.Why
bootSchemaStack(packages/cli/src/utils/schema-migrate.ts) passesskipSeedDatatocreateStandaloneStackonly when it is givendeferSchemaDdl. None of the seven commands passes it in its no-write mode. So the boot runs the artifact's inline seed loader, whose upserts rewrite every seeded row, and schema sync, which adds missing columns and creates missing tables. Each of these is a write the command's own documentation says does not happen.Direction for triage
#21349 (PR #21389) fixes two members by passing the read-only boot (
deferSchemaDdl: true, readOnlyProbe: true) at their call sites, the bootos migrate planalready takes.The dev suggests a family-wide fix keyed like
runPlatformMigrations: false:That would also cover the
--apply/--deletepaths, which still run the boot seed loader today, a write the operator never saw in the preview. Whether to fix per call site or family-wide is triage's call.Also on this card (carrier)
Two comments now say more than is true. Both list
os migrate metaamong the boots withoutdeferSchemaDdl; after PR #21389 that holds only with--apply:packages/cli/src/utils/schema-migrate.ts, therunPlatformMigrations: falseblock;packages/cli/src/utils/platform-migrations-arming.integration.test.ts.They sit outside #21349's surface, and this card edits the same boot options.
Dedupe words: dry run writes seeded rows; bootSchemaStack skipSeedData; one-shot CLI boot seed loader; report-only command rewrites rows; migrate dry run updated_at.
Generated by Claude Code