Skip to content

fix(store): gate Ward audit schema by fingerprint - #675

Merged
BunsDev merged 2 commits into
mainfrom
fix/threads-3jx-audit-schema
Aug 8, 2026
Merged

BunsDev merged 2 commits into
mainfrom
fix/threads-3jx-audit-schema

Conversation

@BunsDev

@BunsDev BunsDev commented Aug 8, 2026

Copy link
Copy Markdown
Member

Summary

  • pin coven-threads-core to PR Roadmap: establish Discord progress update cadence #23 commit c102844, preserving exact deployed Phase-5 schema fingerprints
  • replace SQL-substring/component-version routing with the four-state fingerprint contract
  • fail closed on unknown drift, roll back guarded SQL failures, and safely converge concurrent legacy migrators

Validation

  • cargo test --locked -p coven-cli ward_audit_
  • cargo test --locked -p coven-cli concurrent_store_initialization_serializes_migrations
  • cargo clippy --locked --workspace --all-targets -- -D warnings
  • python scripts/check-secrets.py
  • python3 scripts/check-coven-privacy.py --staged

Dependency

Requires OpenCoven/coven-threads#23 at c102844 (threads-3jx). Unknown or drifted schemas are never rebuilt or stamped.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings August 8, 2026 09:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates coven-cli’s Ward audit schema handling to rely on a fingerprinted schema-state contract from coven-threads-core, so initialization/migration is fail-closed on drift and safer under concurrent legacy migrators.

Changes:

  • Replace SQL substring/component-version routing with a four-state ward_audit schema fingerprint query and state-driven migration/initialization.
  • Add guarded DDL execution with rollback handling and reclassification to safely converge concurrent legacy migrators.
  • Pin coven-threads-core to a specific commit to preserve deployed Phase-5 schema fingerprints.

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated 2 comments.

File Description
crates/coven-cli/src/store.rs Switches Ward audit schema detection to fingerprint states; adds guarded migration execution and new/updated tests for drift + concurrency.
crates/coven-cli/Cargo.toml Pins coven-threads-core git rev to the commit that defines the expected fingerprint contract.
Cargo.lock Updates the locked coven-threads-core git source to match the pinned revision.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +4447 to +4448
"SELECT COUNT(*) FROM pragma_table_info('ward_audit', 'main')
WHERE name = 'unexpected'",

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The existing order is intentional and correct for SQLite table-valued PRAGMAs: pragma_table_info(table-name, schema-name), so pragma_table_info('ward_audit', 'main') inspects main.ward_audit. The pinned core also has executable coverage (schema_qualified_table_valued_pragmas_resolve_main_and_temp_separately) proving main/temp separation with this exact argument order. No code change needed.

Comment on lines +411 to 415
WARD_AUDIT_SCHEMA_STATE_UNKNOWN => {
anyhow::bail!("unsupported ward_audit schema fingerprint")
}
WardAuditSchemaAction::None => {}
_ => anyhow::bail!("unsupported ward_audit schema fingerprint state"),
}

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in cfe28e7. Unexpected state errors now include the returned fingerprint value, with ward_audit_unrecognized_fingerprint_state_names_the_value covering the fail-closed diagnostic.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@BunsDev
BunsDev merged commit b955c89 into main Aug 8, 2026
13 checks passed
@BunsDev
BunsDev deleted the fix/threads-3jx-audit-schema branch August 8, 2026 22:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants