upgrade to the latest commit on docmost #1

Merged
ulysia merged 5 commits from testing into main 2026-08-31 18:04:04 +02:00
Owner
No description provided.
feat: upstream 5b854645, plus compatibility tests and CI
Some checks failed
Upstream compatibility / compatibility (push) Failing after 2m14s
31de2af2ad
Moves the pin from 7439da2f to 5b854645 (42 upstream commits) and adds a
test suite for the seams that break silently when upstream moves.

Upgrade:
- 0008 regenerated by hand. Upstream's `feat: search group members`
  (d92716d8) restructured group-members.tsx, breaking two of three hunks;
  the three edits are unchanged in intent, re-seated on the new structure.
- 0010 regenerated. It still applied under GNU patch but only with fuzz, and
  git apply rejected it. Verified the fuzzy package.json hunk had landed in
  the right place rather than assuming it.
- SearchDTO.query became optional upstream (917195b2, filter-only search), so
  AttachmentSearchParams.query is optional too. Type-only: the service already
  guarded a missing query. Filter-only attachment search still returns nothing.
- Lockfile and wrapper Dockerfile regenerated; pnpm 11.15.1 -> 11.23.0.

Tests (upstream-contract/):
Core loads every EE feature with require() in a try/catch, so a moved or
renamed hook is not an error — it means "not bundled", and the feature just
disappears. Postgres functions named in a `sql` template are resolved at
execution time, so a dropped one is a 500 on one endpoint and silence
everywhere else. Neither is visible to tsc, to the patches, or to di-check,
which checks our half of the contract and treats core's half as a comment.

The suite checks both directions, including a scan of core for require() of
this bundle that fails on anything the inventory does not list. That is how
oauth/services/oauth-strategy.service was found arriving with upstream's MCP
OAuth (e56de8eb): we do not implement it, so MCP clients cannot authenticate.
Recorded as unimplemented rather than silently missing. Verified the suite can
fail, with negative controls for a vanished hook, an unlisted hook, a dropped
SQL function and a changed arity.

Also:
- scripts/check-upstream.sh — one command for pin invariant, contract tests
  and patches/typecheck, replacing three commands and the tribal knowledge
  that all three needed running.
- .github/workflows/test.yml — runs it on main, testing and every PR,
  deriving node and pnpm from upstream's own files so CI cannot drift from
  what the image builds with.
- verify-patches.sh printed "All checks passed" while tsc was failing: the
  same `cmd && echo ok` trap its own step 1 documents. It was masking three
  real errors on this upgrade.
- Licence branding is no longer both a patch and a parent commit. Having it in
  both meant the working tree could never be pristine and 0002 regenerated
  incomplete; documented in patches/README.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
fix(ci): build every workspace package, not just editor-ext
All checks were successful
Upstream compatibility / compatibility (push) Successful in 2m19s
d022267715
Run #4 failed the server typecheck with "Cannot find module
'@docmost/base-formula/server'". Both @docmost/editor-ext and
@docmost/base-formula expose their entry points through dist/, so each has to
be built before tsc sees the apps — and only editor-ext was.

It passed locally for the worst reason: base-formula's dist/ was already on
disk from an earlier build, so the missing step was invisible until CI ran it
on a clean tree. Which is the argument for having CI at all.

Globbing packages/* rather than naming the two: a package upstream adds later
gets built too, instead of failing as "upstream's own module is missing",
which reads like upstream broke something rather than a missing build step.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
ci: gate the image build on the compatibility checks
All checks were successful
Verify and publish / Upstream compatibility (push) Successful in 2m27s
Verify and publish / Build and push image (push) Has been skipped
36429cf9ec
A push to main used to build and push an image regardless of whether the
checks passed — they ran in a separate workflow, beside the build rather than
in front of it.

Folded into one workflow with two jobs: `compatibility` always runs (main,
testing, PRs, manual), and `docker` declares `needs: compatibility` plus an
`if:` limiting it to main. `needs:` cannot reference a job in another
workflow, and `workflow_run` is not known to work on this Forgejo version, so
one workflow is the only construction where the gate actually holds.

A failed check now leaves the previous image as the newest one. No release is
better than a broken release.

Also corrects Confluence import in VERIFICATION.md and the hook inventory:
README's status table records it as deliberately dropped, and both described
it as merely unimplemented, which reads like an oversight to close.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
test(ci): TEMPORARY gate probe - verify needs blocks on failure
Some checks failed
Verify and publish / Upstream compatibility (push) Failing after 2m46s
Verify and publish / Gate probe (temporary) (push) Has been skipped
Verify and publish / Build and push image (push) Has been skipped
aad1d21b96
Adds an echo-only job depending on compatibility, and deliberately breaks one
SQL-object check. If the probe job runs, needs: is not enforced and the gate
does not protect releases. Both are reverted in the next commit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
docs: record what production use has confirmed; revert the gate probe
All checks were successful
Verify and publish / Upstream compatibility (push) Successful in 2m2s
Verify and publish / Build and push image (push) Has been skipped
Verify and publish / Upstream compatibility (pull_request) Successful in 1m58s
Verify and publish / Build and push image (pull_request) Has been skipped
d898984b9e
The gate is verified. Run #7 broke a check deliberately and added a temporary
echo-only job with `needs: compatibility` and no `if:`. That job was never
dispatched — no log at all — which proves `needs:` blocks on failure here
rather than merely ordering jobs. `docker` carries the same `needs:`, so a
failed check on main cannot publish. Probe and deliberate breakage reverted;
the finding is recorded in the workflow header, along with the fact that the
runner logs a harmless "'runs-on' key not defined" line on every run.

VERIFICATION.md opened with "Nothing has been run against a database", which
has been false for a while. Rewritten around what the live instance has
actually shown, with the evidence rather than a bare assertion:

- Audit logging persists — rows exist, containing logouts and API key
  create/delete. Closes the highest-priority unknown: AuditEeService does win
  the AUDIT_SERVICE binding over core's NoopAuditModule, so the "last global
  module wins" assumption holds.
- SCIM against real Authentik, including deprovisioning ending a live session
  on the next request and reassignment restoring it. This was the riskiest
  thing here — the only part written from a spec rather than reverse-engineered
  from a client contract.
- Externally-synced groups are locked in the UI (patch 0008): badge shown, no
  direct rename or delete, no manual member removal.
- OIDC SSO, group-driven workspace roles, and Bases/Kanban across all six
  stages — Bases having been the single largest untested surface in the bundle.

Remaining unverified is now three items: PDF export, Tika, MFA. Offset-based
row pagination is reframed as a known tradeoff rather than an unknown.

Also adds a "Running SQL against the instance" section. The file asked for SQL
checks without ever saying how to run one, and the two ways that goes wrong
are worth writing down: POSTGRES_USER is only honoured on first initialisation
of the data directory, and a container TUI can silently attach you to an
unrelated Postgres container — both of which surface as
`role "docmost" does not exist`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
ulysia merged commit 3c5e358e0d into main 2026-08-31 18:04:04 +02:00
ulysia deleted branch testing 2026-08-31 18:04:05 +02:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ulysia/docmost-freenterprise!1
No description provided.