Repository navigation
feat(pg/review): add DISALLOW_DROP_CONSTRAINT, REQUIRE_PRIMARY_KEY, and PRIOR_BACKUP - #445
Conversation
…nd PRIOR_BACKUP The three rules that read a target's synced schema. Each reports only what it can establish from the SQL and the schema; where they leave the answer open, it reports nothing. DISALLOW_DROP_CONSTRAINT and REQUIRE_PRIMARY_KEY check the synced metadata directly instead of rebuilding it in a catalog. A scan follows the change statement by statement and records what each statement may have changed (names created, dropped, renamed, or moved; constraints and columns altered; the search path and role). A name a statement may have changed is not looked up again, a statement whose effect cannot be bounded (DO, CALL, ROLLBACK, a cascading drop of anything but a relation) ends the scan, and a statement the server would refuse (a missing column or constraint, a key or column something depends on without CASCADE) reports nothing. PRIOR_BACKUP mirrors what Bytebase's PostgreSQL backup refuses: a change over the size limit, a missing bbdataarchive schema, UPDATE and DELETE on one table, and an UPDATE or DELETE of a table the change creates. It resolves names as the backup does. TestScanRulesAgainstPostgres runs every change on PostgreSQL 17 and derives the expected findings from the server's catalogs; the rules must never report anything else. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7d6a673702
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
…s free From the Codex review of #445: - Record changed constraints, columns, and tables by schema, so a change to s.t no longer hides public.t. - A drop the scan resolves frees the relation's name, its indexes, partitions, and owned sequences, and with CASCADE the views reading it, so CREATE TABLE IF NOT EXISTS of a freed name counts as creating. Dropped views are recorded in their own schema. - A dropped table's own foreign keys no longer block dropping the key they referenced. - An ALTER TABLE whose other subcommand is certain to fail (adding a column the table has, altering one it lacks, reusing a constraint name, a second primary key) reports none of its drops. - DROP TABLE without CASCADE of a table a view or another table's foreign key depends on is refused, and ends the scan. - PRIOR_BACKUP: a table the change moves with SET SCHEMA does not exist under its new name when the backup runs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5e2c1515e3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… and follow more of the change From the second Codex review of #445: - A cascading DROP COLUMN or DROP CONSTRAINT invalidates only the foreign keys on the dropped key or column, of the resolved table. - A foreign key the change creates blocks only the key it references, recorded with its schema and columns. - A qualified SET SCHEMA keeps a pending table's new schema exact. - A materialized view's indexes go with it when it is dropped. - DROP VIEW and DROP MATERIALIZED VIEW without CASCADE are refused when a view outside the statement reads them. - A repeated DROP in one ALTER TABLE refuses it; a DROP CONSTRAINT after a DROP COLUMN that may have taken the constraint withholds the statement's findings. - An enabled event trigger of the target that fires on a command the change runs leaves the scan's findings unknown, so none are reported. - PRIOR_BACKUP: tables and views of CREATE SCHEMA, and an unqualified creation matched by a qualified UPDATE or DELETE. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 80f73170f3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…TE SCHEMA, refuse missing drops From the third Codex review of #445: - A foreign key the change creates is recorded with its owner and name, and no longer blocks a key drop once its table or the constraint is dropped. - The relations a new view reads are recorded in the schema they resolve to. - DROP without IF EXISTS of a relation the target certainly lacks is refused and ends the scan, as is DROP TABLE of a table whose row type a function returns. - ALTER TABLE validation counts the statement's own additions, so a column or constraint added twice, or a second primary key, refuses it. - REQUIRE_PRIMARY_KEY follows the tables of CREATE SCHEMA, in the new schema. - PRIOR_BACKUP counts a relation the change creates anywhere in it, since the backup runs before every statement. - The scan's doc states its boundary: it does not predict what triggers or functions do at run time. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 23490dd41e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…fuse drops of the wrong kind From the fourth Codex review of #445: - A view's CTE names are not relations it reads. - Dependencies of a view or function the change created are retired when the change drops it; a synced function whose name resolves to one function is retired by DROP FUNCTION. - A function the change creates that returns a table's row type blocks dropping the table. - DROP TABLE of a non-table, DROP VIEW of a table, and DROP INDEX of a constraint's index are refused and end the scan. - CREATE TABLE of a name its schema already holds is refused instead of reported. - PRIOR_BACKUP: CREATE SCHEMA AUTHORIZATION names the schema after the role. - The scan's doc states what a finding claims: its own statement, given that the statements before it ran. Whether the whole change can run is WALK_THROUGH's question. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4fc02547f9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ced views From the fifth Codex review of #445: - CREATE TABLE of a name an earlier statement may have made reports nothing: a name the change touched and did not certainly free, a key constraint's index name, or a name of the form the server generates for an index or sequence after a statement that may have generated it. CREATE TABLE in a schema the target lacks is refused, and a no-op CREATE TABLE IF NOT EXISTS has no effect at all. - ALTER SEQUENCE ... OWNED BY keeps the sequence from going with its old table; CREATE OR REPLACE VIEW retires the replaced view's synced reads. - Relation kinds are told apart, so DROP VIEW of a materialized view is refused. - A view's CTE names hide relations only where visible; a cascading drop follows views of views; dropping one of two new overloads retires neither; event-trigger matching knows function DDL. - An unqualified new foreign key is matched to the table the path finds; ADD COLUMN IF NOT EXISTS of an existing column adds no key; DROP ... IF EXISTS of a name the target lacks leaves it free. - The oracle now rejects any finding on a statement the server refuses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 77454b255b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ma, and ALTER of a missing table From the sixth Codex review of #445: - CREATE TABLE in another database and CREATE SCHEMA of a schema the target has are refused, so neither reports a table it never makes. - ALTER TABLE without IF EXISTS of a table the target certainly lacks is refused; ALTER TABLE validation runs whichever rules are on. - DROP FUNCTION IF EXISTS retires no dependency, since it may name a signature no function has. - CREATE OR REPLACE of a view the change created retires its reads. - A partition's own indexes go with it when it is dropped. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 506354955b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…s a statement's column drops From the seventh Codex review of #445: - DROP SCHEMA of a schema the target lacks: IF EXISTS leaves it missing, and without IF EXISTS the statement is refused. - ALTER TABLE validation skips an ADD COLUMN IF NOT EXISTS of an existing column, constraints included. - Every drop of one ALTER TABLE sees the table as it was before the statement, so a second DROP COLUMN of a key column is followed. - EXPLAIN ANALYZE CREATE MATERIALIZED VIEW records the view's reads. - PRIOR_BACKUP accepts a name qualified with the current database. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 866ae633ec
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ter types, and scope cascades From the eighth Codex review of #445: - CREATE SCHEMA IF NOT EXISTS with schema elements is refused, as PostgreSQL's grammar refuses it. - CREATE VIEW of a name its schema holds, CREATE OR REPLACE VIEW of a relation that is not a view, and CREATE VIEW in a missing schema are refused. - A function the change creates blocks dropping a table whose row type any of its parameters takes, not only its result. - Event-trigger matching knows ALTER SEQUENCE. - A cascading drop settles only pending tables it may drop: a synced table or one inheriting from a dropped table, and only for table drops. - A rename naming a pending table's own schema replaces its old name. - ALTER TABLE validation treats a constraint a column drop of the statement may have taken as freeing its name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: baec6b3e61
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ange drops From the ninth Codex review of #445: - A column's state is the last statement's: renamed away, added, or dropped, so a chain of renames leaves the middle name gone. - A schema DROP SCHEMA removed is gone for later statements; CREATE SCHEMA IF NOT EXISTS of an existing schema changes nothing. - CREATE SEQUENCE of a name its schema holds is refused, and with IF NOT EXISTS does nothing. - Renaming a relation the change created keeps its new dependencies and foreign keys under the new name. - A new view dropped in the same DROP as the view it reads does not hold that drop. - ADD COLUMN IF NOT EXISTS of a column an earlier subcommand added does nothing. - PRIOR_BACKUP: SELECT INTO on a branch of a set operation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d6c7fe5969
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… resolve where unqualified tables go From the twenty-fourth Codex review of the scan: - CREATE TABLE is refused for a key naming a column it lacks or a column twice, or a second primary key, and ALTER TABLE for an added key naming a column twice. - CREATE FUNCTION without OR REPLACE is refused for a signature the change created, or, without arguments, one a synced routine has where it creates. - A pending table records the schema the search path creates it in, so a qualified statement on another schema's table of that name does not settle it; a table the search path puts in pg_temp, or a system schema, is not reported. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7d02240200
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…le errors, missing routine renames, and NOT NULL drops of key columns From the twenty-fifth Codex review of the scan: - A view or query reading an index or a composite type is refused like one reading a missing relation. - An index element of CREATE SCHEMA is checked like CREATE INDEX, and a schema the change created holds only what the change named in it. - CREATE FOREIGN TABLE gets the CREATE TABLE definition checks. - ALTER FUNCTION, PROCEDURE, or ROUTINE ... RENAME or SET SCHEMA of a routine the target certainly lacks ends the scan. - DROP NOT NULL of a column of the primary key the table keeps refuses the statement. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1f518c5aff
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…repeated types, view replacements, sequence alters, and drops the change's objects hold From the twenty-sixth Codex review of the scan: - A pending table a statement settled only by adding a primary key the scan can name is keyless again when a later statement certainly drops that key. - Types the change creates are its own: a second CREATE TYPE of the name is refused, and so is a table of it. - CREATE OR REPLACE VIEW of a relation the change made as another kind, ALTER SEQUENCE of a relation the target lacks or that is no sequence, and DROP of a relation the change made that its own objects depend on, are refused. The PRIOR_BACKUP comment on IF NOT EXISTS creations is declined again: the synced schema can predate an earlier spec of the same plan. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7d5bb59202
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… duplicate signatures, wrong-kind alters, index columns, and ambiguous drops From the twenty-seventh Codex review of the scan: - An ALTER TABLE the server may refuse now ends the scan instead of only withholding its own findings: what follows a statement that may not run is not known. An added foreign key to a table the change created and has not altered is checked against its CREATE, so the common create-then-reference change still runs through. - ALTER TABLE IF EXISTS of a relation the target lacks does nothing. - CREATE FUNCTION is refused for a synced signature with arguments, read from the snapshot's identity arguments for built-in types. - RENAME and SET SCHEMA with ALTER VIEW, MATERIALIZED VIEW, SEQUENCE, or FOREIGN TABLE of another kind, or ALTER TABLE of a composite type, are refused; ALTER INDEX ... RENAME takes any relation, as the server shows. - CREATE INDEX naming a column the known table lacks, and DROP FUNCTION by a name several routines have, are refused. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3c2bcd44df
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…leave possibly inherited checks undropped From the twenty-eighth Codex review of the scan: - Bytebase records a view's column dependencies only, so a view reading a relation without naming a column of it (count(*), SELECT 1 FROM t) was missing. The index now reads each synced view's definition: a relation it names certainly, qualified, the only one of its name, or the one the synced search path finds, is a reader, and one of several maybe; a definition the scan cannot read holds every drop. The oracle syncs view definitions too. - A DROP CONSTRAINT of a check that a table which may be the table's inheritance parent has too, by name and expression, may be refused, and ends the scan. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9caca8b546
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… validate sequence owners, renames, view replacements, and signatures From the twenty-ninth Codex review of the scan: - A trigger, policy, rule, statistics, LOCK, TRUNCATE, REFRESH, CLUSTER, VACUUM, GRANT, or COMMENT ON a relation (or its column) the target certainly lacks ends the scan, and so does a trigger whose function it lacks. - ALTER SEQUENCE ... OWNED BY a table the target lacks, or a column a known table lacks, CREATE TYPE AS with an attribute twice, RENAME CONSTRAINT of a constraint the snapshot does not list, SET SCHEMA of a relation the change made to a schema holding its name, a routine rename to a signature the destination name has, and ALTER TABLE of a view the change made, end the scan. - CREATE OR REPLACE VIEW renaming or dropping a synced view's column, as far as the query names its output, is refused. - DROP FUNCTION by the snapshot's signature of the only function of its name retires its dependencies. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a7d9a81f45
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…iew column changes, and invalid alters of the change's own tables From the thirtieth Codex review of the scan: - ALTER FUNCTION ... RENAME or SET SCHEMA by a signature no routine of the name has, as far as the change and the snapshot's readable signatures tell, and SET SCHEMA to a schema the target lacks or to one where the signature is taken, end the scan. - CREATE OR REPLACE VIEW changing a synced column's type, as far as a cast or a constant states it, and CREATE VIEW naming an output column twice, are refused. - An ALTER TABLE dropping or altering a column a table the change made lacks, or adding one it has, and OWNED BY a column such a table lacks, are refused. - CREATE TRIGGER on a materialized view, and CREATE TYPE AS ENUM with a label twice, are refused; CREATE TABLE AS and materialized views are recorded as the change's own. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 991a3e1502
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…f the change's own objects, and parse generation expressions From the thirty-first Codex review of the scan: - A table the change made keeps its constraint names: DROP CONSTRAINT without IF EXISTS of a name its CREATE did not give, or ADD CONSTRAINT of one it did, ends the scan. - View and trigger elements of CREATE SCHEMA get the checks top-level ones do. - CREATE INDEX on a relation the change made is checked against its kind, columns, and schema's names. - Procedure signatures from ProcedureMetadata are indexed too, and a function the change made follows SET SCHEMA with its dependencies. - A generation expression is parsed for the columns it refers to, so a literal or function name is no dependency. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e8c33b2121
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ggers, missing drop signatures, TRUNCATE kinds, and generated column refs From the thirty-second Codex review of the scan: - CREATE VIEW with more column names than its query's outputs, CREATE SEQUENCE OWNED BY a missing table or column, CREATE TRIGGER of a name the synced table has without OR REPLACE, DROP FUNCTION of a signature no routine of the name has, TRUNCATE of anything but a table, and CREATE TABLE with a generated column of a column it lacks, end the scan. - Procedures listed apart from functions depend on the tables whose row type their signatures name. - A view the change made unqualified is the one a drop naming its schema means. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aeb48d1305
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ex expressions, triggers, and moves the target cannot take From the thirty-third Codex review of the scan: - A table the change makes with a primary key the scan can name is keyless again, and reported, when a later statement drops that key. - INSERT, UPDATE, DELETE, MERGE, SELECT, and EXPLAIN of a relation the target lacks, and CREATE INDEX on an expression of a column the table lacks, end the scan. - A second CREATE TRIGGER of a name on a relation the change made it on, a trigger function no routine of whose name takes no arguments, an inline CREATE SEQUENCE ... OWNED BY a missing table, and SET SCHEMA where an index or sequence moving with the table finds its name taken, end the scan. - Quoted type names in procedure signatures are unquoted. - PRIOR_BACKUP documents why a name the synced schema cannot resolve is reported only when the change creates it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 635ccc6741
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…lters, and drops of renamed constraint indexes From the thirty-fourth Codex review of the scan: - CREATE DOMAIN with a check naming anything but VALUE is refused. - CREATE OR REPLACE FUNCTION or PROCEDURE of a signature a synced routine of the other kind has is refused. - ALTER TYPE ... ADD or RENAME VALUE of a type that is certainly no enum where the name resolves is refused. - DROP INDEX of a constraint's index a rename gave a new name is refused. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: da4024aeaf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…se type moves, event trigger drops, view column comments, and owner changes of missing objects From the thirty-fifth Codex review of the scan: - A trigger element of CREATE SCHEMA is recorded only after it passes its checks, so it is no duplicate of itself, and DROP TRIGGER clears the record of its own relation only. - ALTER TYPE or DOMAIN ... SET SCHEMA to a schema the target lacks, DROP EVENT TRIGGER of one it lacks, COMMENT ON a column a synced view lacks, and ALTER SCHEMA or routine ... OWNER TO of one it lacks, end the scan. - RENAME CONSTRAINT keeps a table the change made, and a pending table's key, under the new name; DROP EXTENSION IF EXISTS of extensions the target lacks does nothing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0c038188fd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…PY and drops of renamed routines, and order CREATE SCHEMA elements as the server runs them - RENAME CONSTRAINT of a synced constraint keeps it under the new name, so a later DROP CONSTRAINT reports it and a later ADD PRIMARY KEY sees the key; the old name is gone, and a key's index takes the new name. - A rename of a resolved relation frees its old name in its schema. - ALTER FUNCTION ... RENAME of a synced routine takes its signature from the old name, so a later DROP or ALTER of it is refused. - COPY of a relation the target lacks, or of a kind COPY refuses, stops the scan. - CREATE SCHEMA elements run as the server runs them: sequences, tables, views, indexes, triggers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8495b4d47c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… relations in regular schemas and types of missing schemas, and stop where the oracle's server stops - Dropping a column of the key a CREATE TABLE declared drops the key, when the statement only drops and nothing the change made depends on the column; a generated column, policy, trigger with WHEN or columns, rule, SQL-standard body, or publication the change made on a table makes a DROP COLUMN of it without CASCADE end the scan. - CREATE TEMP of a relation in a regular schema, and a type in a schema the target lacks, are refused. - A relation the change made earlier on the search path shadows a later one for DROP and the other statements that settle pending tables. - SET SCHEMA onto a name the destination holds, DROP FUNCTION of an unqualified name the change made twice, and ALTER of a signature the change never made are refused. - TestScanRulesAgainstPostgres now fails on any finding after the statement the server rejects, and on a REQUIRE_PRIMARY_KEY finding when the change never ends. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ab23c6374a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…DEX and ALTER FUNCTION of what the target lacks and constraint attributes their kind cannot take - ADD COLUMN ... PRIMARY KEY and ADD PRIMARY KEY (columns) record the key's name and columns, so a later DROP CONSTRAINT or DROP COLUMN of the key reopens the table. - REINDEX of a relation the target lacks, of the wrong kind, or of a schema the target lacks, and ALTER FUNCTION, PROCEDURE, or ROUTINE of a name or signature no routine of its kind has, stop the scan. - NOT VALID or NO INHERIT on a key or exclusion constraint, DEFERRABLE on a check, NO INHERIT on a foreign key, and NOT VALID on a column's constraint stop the scan, as the server's grammar refuses them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
The three SQL Review V2 rules that read a target's synced schema. WALK_THROUGH is left for later. Each rule follows one principle: report only what can be established from the SQL and the synced schema, and report nothing where they leave the answer open.
DISALLOW_DROP_CONSTRAINT / REQUIRE_PRIMARY_KEY
These check the synced metadata directly. They do not rebuild it in
pg/catalog(noLoadMetadata), so they pay no load cost per target and don't depend on how faithfully the catalog replays each kind of DDL.A scan (
scan.go) follows the change statement by statement and records what each statement may have changed:SET search_pathand pg_dump'sset_config, and the role.From that record:
DO,CALL,ROLLBACK,DROP OWNED, event triggers, or a cascading drop of anything but a relation.IF EXISTS, and, without CASCADE, a key a foreign key references or a column a view or foreign key depends on, including dependents the change itself created.DISALLOW_DROP_CONSTRAINT reports
ALTER TABLE ... DROP CONSTRAINTof a primary key, foreign key, unique, or check constraint that the table has in the synced schema. The constraint's type comes from the schema. It does not report:REQUIRE_PRIMARY_KEY reports two things, each only when the change ends that way:
CREATE TABLEwithout a primary key (inline, table-level, or copied byLIKE ... INCLUDING INDEXESfrom a known table);DROP CONSTRAINTor by dropping a key column.A later statement that may add a key, drop the table, or attach it as a partition settles the table, so it isn't reported. This follows renames too. These are never reported:
SELECT INTO;PRIOR_BACKUP
Mirrors what Bytebase's PostgreSQL backup refuses (
taskrun/database_migrate_executor.gobackupData,parser/pg/backup.goTransformDMLToSelect):MaxBackupSize;bbdataarchiveschema;Names resolve the way the backup resolves them: the synced search path without
$user, then anySET search_pathin the change. DDL by itself is not a finding, because the backup ignores it.Tests
TestScanRulesAgainstPostgres(postgres:17-alpine) runs 57 changes on PostgreSQL, statement by statement. It syncs the starting schema into metadata the way Bytebase would and derives the expected findings frompg_constraint/pg_class.target_rules_test.go: unit cases for every rule and every way the scan gives up.TestTargetsScanTheSameStatementsreviews concurrently across targets (clean under-race).TestReview's REQUIRE_IS_NULL case now runs only that rule. Its SQL creates tables without keys, which REQUIRE_PRIMARY_KEY now reports.make test-pgpasses.Known gaps
These are false negatives, never false positives:
SET SCHEMA;DROP SCHEMA ... CASCADE;bytebase/omni#444, the catalog fix the earlier catalog-based draft needed, is independent of this PR.
🤖 Generated with Claude Code