feat(2): mattermost-lts P4 data-integrity overlay (ops.py postgres ci_marker seed + test_install/upgrade/backup/restore) — verifying recipe's PGDATA-dir restore brings the marker back

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-30 01:11:10 +01:00
co-authored by Claude Opus 4.8
parent 0599477440
commit 80ad0a9ed1
5 changed files with 136 additions and 0 deletions
+46
View File
@@ -0,0 +1,46 @@
"""mattermost-lts — pre-op seed hooks (Phase 1e HC3). The orchestrator runs these BEFORE each op; the
matching test_<op>.py asserts post-op (assertion-only). The marker is a dedicated `ci_marker` row in
postgres (mattermost's own schema migrations don't touch it), written via psql in the `db` service
(POSTGRES_USER=mattermost, POSTGRES_DB=mattermost, password /run/secrets/postgres_password). The
recipe's `db` service is backupbot-labelled (pg_dump pre-hook + the whole PGDATA dir at
backup.path=/var/lib/postgresql/data/), so the marker rides the backup→restore cycle."""
import os
import sys
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "..", "..", "runner"))
from harness import lifecycle # noqa: E402
def _psql(domain, sql):
cmd = (
"PGPASSWORD=$(cat /run/secrets/postgres_password) "
f'psql -U mattermost -d mattermost -tAc "{sql}"'
)
return lifecycle.exec_in_app(domain, ["sh", "-c", cmd], service="db").strip()
def _seed(domain, value):
_psql(
domain,
"CREATE TABLE IF NOT EXISTS ci_marker(v text); DELETE FROM ci_marker; "
f"INSERT INTO ci_marker VALUES('{value}');",
)
assert _psql(domain, "SELECT v FROM ci_marker;") == value
def pre_upgrade(domain, meta):
_seed(domain, "upgrade-survives")
def pre_backup(domain, meta):
_seed(domain, "original")
def pre_restore(domain, meta):
# drop the marker table (diverge from the backup) so a successful restore is observable
_psql(domain, "DROP TABLE ci_marker;")
assert _psql(domain, "SELECT to_regclass('public.ci_marker');") in (
"",
"NULL",
), "drop did not take"