[E00-S03-T02] pg/Kysely imports isolated to database-postgres #177

Closed
opened 2026-08-27 00:07:20 +00:00 by kpcto · 12 comments
Owner

Parent story: [E00-S03] PostgreSQL adapter and migration runner (#60)

Intent

Isolate pg/Kysely imports to the database-postgres package.

Acceptance criteria

  • pg/Kysely imports are isolated to database-postgres
  • no other package imports the database driver directly

Explicitly out of scope

  • PostgreSQL 18.6 container (E00-S03-T01)
  • migration ledger (E00-S03-T03)
  • advisory lock (E00-S03-T04)

Test plan

  • grep/static check confirms driver imports live only in database-postgres

Rollback note

  • revert any import changes that relocate the driver

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E00-S03] PostgreSQL adapter and migration runner (#60) ## Intent Isolate `pg`/Kysely imports to the `database-postgres` package. ## Acceptance criteria - `pg`/Kysely imports are isolated to `database-postgres` - no other package imports the database driver directly ## Explicitly out of scope - PostgreSQL 18.6 container (E00-S03-T01) - migration ledger (E00-S03-T03) - advisory lock (E00-S03-T04) ## Test plan - grep/static check confirms driver imports live only in database-postgres ## Rollback note - revert any import changes that relocate the driver ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 0 milestone 2026-08-27 00:07:20 +00:00
kpcto added the
status
ready
kind
task
labels 2026-08-27 00:07:20 +00:00
bot-dispatcher added
status
proposed
and removed
status
ready
kind
task
labels 2026-08-27 00:07:22 +00:00
Member

Auto-reverted by dispatcher: DoR lint: required section "Intent" is empty; required section "Acceptance criteria" is empty; required section "Explicitly out of scope" is empty; required section "Test plan" is empty; required section "Rollback note" is empty; acceptance criteria: no bullet assertions found

status/ready may only be applied by a human maintainer.

> Auto-reverted by dispatcher: DoR lint: required section "Intent" is empty; required section "Acceptance criteria" is empty; required section "Explicitly out of scope" is empty; required section "Test plan" is empty; required section "Rollback note" is empty; acceptance criteria: no bullet assertions found `status/ready` may only be applied by a human maintainer.
kpcto added the
kind
task
label 2026-08-27 21:24:38 +00:00
kpcto added
status
ready
and removed
status
proposed
labels 2026-08-29 11:04:50 +00:00
bot-dispatcher added
loop
1
status
in-progress
and removed
status
ready
labels 2026-08-29 11:05:00 +00:00
Member
agent: dispatcher
phase: complete
plan_summary: Dispatch #177: [E00-S03-T02] pg/Kysely imports isolated to database-postgres (platform, security-gated)
```yaml agent: dispatcher phase: complete plan_summary: Dispatch #177: [E00-S03-T02] pg/Kysely imports isolated to database-postgres (platform, security-gated) ```
bot-dispatcher added the needs/security-reviewneeds/security-review labels 2026-08-29 11:05:00 +00:00
Member
agent: implementer
phase: start
issue: "177"
objective: "[E00-S03-T02] pg/Kysely imports isolated to database-postgres"
plan:
  - create: "packages/database-postgres (@personal-blog/database-postgres) — the single workspace package owning the PostgreSQL driver: declares pg + kysely as exact dependencies and imports them in src/index.ts (driver boundary module)"
  - lockfile: "regenerate pnpm-lock.yaml with pg/kysely/@types/pg resolved for the new importer (frozen-install keeps working)"
  - tests: "tests/database-postgres-imports.test.mjs — static scan of every workspace package source: pg/kysely import specifiers resolve only to packages/database-postgres; owner really imports the driver (non-vacuous); mutation probes (inject a pg import into another package -> fails); manifest isolation (no other package declares the driver)"
  - locking-tests: "update package-set fixtures in workspace-layout / workspace-config / strict-tsconfig / typescript-pin to include packages/database-postgres"
  - ci: "add database-postgres-imports job to .gitea/workflows/ci.yml so the isolation criterion gates PRs"
  - pr: "open PR from feature/177 with criterion -> test table"
out_of_scope: [PostgreSQL 18.6 container (E00-S03-T01), migration ledger (E00-S03-T03), advisory lock (E00-S03-T04)]
```yaml agent: implementer phase: start issue: "177" objective: "[E00-S03-T02] pg/Kysely imports isolated to database-postgres" plan: - create: "packages/database-postgres (@personal-blog/database-postgres) — the single workspace package owning the PostgreSQL driver: declares pg + kysely as exact dependencies and imports them in src/index.ts (driver boundary module)" - lockfile: "regenerate pnpm-lock.yaml with pg/kysely/@types/pg resolved for the new importer (frozen-install keeps working)" - tests: "tests/database-postgres-imports.test.mjs — static scan of every workspace package source: pg/kysely import specifiers resolve only to packages/database-postgres; owner really imports the driver (non-vacuous); mutation probes (inject a pg import into another package -> fails); manifest isolation (no other package declares the driver)" - locking-tests: "update package-set fixtures in workspace-layout / workspace-config / strict-tsconfig / typescript-pin to include packages/database-postgres" - ci: "add database-postgres-imports job to .gitea/workflows/ci.yml so the isolation criterion gates PRs" - pr: "open PR from feature/177 with criterion -> test table" out_of_scope: [PostgreSQL 18.6 container (E00-S03-T01), migration ledger (E00-S03-T03), advisory lock (E00-S03-T04)] ```
Member

security worker exited with code 1 after all model fallbacks — status/blocked + needs/human-decision.

> security worker exited with code 1 after all model fallbacks — status/blocked + needs/human-decision.
Member
agent: implementer
phase: complete
issue: "177"
objective: "[E00-S03-T02] pg/Kysely imports isolated to database-postgres"
result:
  pr: "https://gitea:3000/Fabrika/PersonalBlog/pulls/391"
  branch: "feature/177"
  head_sha: "97c530676844779297247650aa92f1d6a54c70b6"
  ci: "green (run #82, head 97c5306): Frozen lockfile install ok, Secrets not embedded ok, Database-postgres import isolation ok, Compose config ok"
  local: "full suite 122 pass / 0 fail / 9 skip (Node 24 + pnpm 11.23.0, frozen install; skips = docker-gated probes + nested root-command guard)"
changes:
  - "packages/database-postgres (@personal-blog/database-postgres): new driver-owner package — exact pins pg@8.23.0 + kysely@0.29.5 (deps), @types/pg@8.23.1 (dev); src/index.ts imports and re-exports Pool/Kysely/PostgresDialect so the isolation is real"
  - "pnpm-lock.yaml: packages/database-postgres importer + resolved pg/kysely tree (pnpm 11.23.0; frozen install passes byte-identically in CI)"
  - "tests/database-postgres-imports.test.mjs: comment-aware static scan of every workspace package source (static/dynamic import, export-from, require, subpaths); owner-manifest pin + no-other-package manifest check; mutation probes (inject pg import into apps/server/src/index.ts -> fails naming file+driver; clean copy passes); specifier-matcher + comment-stripping unit probes; CI-enforcement assertion"
  - "tests/workspace-layout / workspace-config / strict-tsconfig / typescript-pin: package-set fixtures include packages/database-postgres (layout<->lockfile parity, strict-base compile, pinned-TS resolution)"
  - ".gitea/workflows/ci.yml: new database-postgres-imports job runs tests/database-postgres-imports.test.mjs on every PR (additive, same action majors, no secrets context, no untrusted interpolation)"
  - "docs/development/non-container.md: package table + build expectations updated"
acceptance:
  - "pg/Kysely imports are isolated to database-postgres -> owner package pins + imports the driver (non-vacuous); real-workspace scan finds every pg/kysely specifier only under packages/database-postgres (tests/database-postgres-imports.test.mjs)"
  - "no other package imports the database driver directly -> scan finds zero driver imports outside the owner; manifest isolation check; mutation probe (injected pg import in apps/server fails the scan) proves the scan catches a misplaced driver import"
verification: "PR #391 open, mergeable, CI green at head (run #82: all 4 jobs success incl. the new database-postgres-imports job), criterion -> test table in PR description"
notes: "CI workflow touched (pipeline tripwire): change is strictly additive and matches the security-reviewed #390 precedent; a human decision on the new merge gate may be requested per review-checklist."
out_of_scope: [PostgreSQL 18.6 container (E00-S03-T01), migration ledger (E00-S03-T03), advisory lock (E00-S03-T04)]
```yaml agent: implementer phase: complete issue: "177" objective: "[E00-S03-T02] pg/Kysely imports isolated to database-postgres" result: pr: "https://gitea:3000/Fabrika/PersonalBlog/pulls/391" branch: "feature/177" head_sha: "97c530676844779297247650aa92f1d6a54c70b6" ci: "green (run #82, head 97c5306): Frozen lockfile install ok, Secrets not embedded ok, Database-postgres import isolation ok, Compose config ok" local: "full suite 122 pass / 0 fail / 9 skip (Node 24 + pnpm 11.23.0, frozen install; skips = docker-gated probes + nested root-command guard)" changes: - "packages/database-postgres (@personal-blog/database-postgres): new driver-owner package — exact pins pg@8.23.0 + kysely@0.29.5 (deps), @types/pg@8.23.1 (dev); src/index.ts imports and re-exports Pool/Kysely/PostgresDialect so the isolation is real" - "pnpm-lock.yaml: packages/database-postgres importer + resolved pg/kysely tree (pnpm 11.23.0; frozen install passes byte-identically in CI)" - "tests/database-postgres-imports.test.mjs: comment-aware static scan of every workspace package source (static/dynamic import, export-from, require, subpaths); owner-manifest pin + no-other-package manifest check; mutation probes (inject pg import into apps/server/src/index.ts -> fails naming file+driver; clean copy passes); specifier-matcher + comment-stripping unit probes; CI-enforcement assertion" - "tests/workspace-layout / workspace-config / strict-tsconfig / typescript-pin: package-set fixtures include packages/database-postgres (layout<->lockfile parity, strict-base compile, pinned-TS resolution)" - ".gitea/workflows/ci.yml: new database-postgres-imports job runs tests/database-postgres-imports.test.mjs on every PR (additive, same action majors, no secrets context, no untrusted interpolation)" - "docs/development/non-container.md: package table + build expectations updated" acceptance: - "pg/Kysely imports are isolated to database-postgres -> owner package pins + imports the driver (non-vacuous); real-workspace scan finds every pg/kysely specifier only under packages/database-postgres (tests/database-postgres-imports.test.mjs)" - "no other package imports the database driver directly -> scan finds zero driver imports outside the owner; manifest isolation check; mutation probe (injected pg import in apps/server fails the scan) proves the scan catches a misplaced driver import" verification: "PR #391 open, mergeable, CI green at head (run #82: all 4 jobs success incl. the new database-postgres-imports job), criterion -> test table in PR description" notes: "CI workflow touched (pipeline tripwire): change is strictly additive and matches the security-reviewed #390 precedent; a human decision on the new merge gate may be requested per review-checklist." out_of_scope: [PostgreSQL 18.6 container (E00-S03-T01), migration ledger (E00-S03-T03), advisory lock (E00-S03-T04)] ```
Author
Owner
agent: reviewer
verdict: request-changes
reviewed:
  pr: 391
  issue: 177
  head_branch: feature/177
  head_sha: 97c530676844779297247650aa92f1d6a54c70b6
summary: |
  Human review of PR #391. The isolation package is well-structured and the
  import-scan tests are thorough (comment-aware scan, manifest check, mutation
  probes), but the dependency pins deviate from the architecture doc's golden
  tuple (section 7, Technology-Stack section 5.2): the doc pins pg 8.22.0 and
  Kysely 0.29.4, while this PR pins pg 8.23.0 and kysely 0.29.5. Reproducibility
  requires the exact documented versions.
findings:
  - id: 1
    file: packages/database-postgres/package.json
    severity: should
    what: |
      dependencies pin pg@8.23.0 and kysely@0.29.5, but the architecture doc
      golden tuple (section 7) and Technology-Stack (section 5.2) pin pg@8.22.0
      and Kysely@0.29.4. The committed versions must match the documented ones.
    fix: |
      Set dependencies to pg@8.22.0 and kysely@0.29.4; align @types/pg to the
      8.22.x release if one is published (otherwise closest matching). Regenerate
      pnpm-lock.yaml and update the exact-pin assertions in
      tests/database-postgres-imports.test.mjs to the corrected versions.
```yaml agent: reviewer verdict: request-changes reviewed: pr: 391 issue: 177 head_branch: feature/177 head_sha: 97c530676844779297247650aa92f1d6a54c70b6 summary: | Human review of PR #391. The isolation package is well-structured and the import-scan tests are thorough (comment-aware scan, manifest check, mutation probes), but the dependency pins deviate from the architecture doc's golden tuple (section 7, Technology-Stack section 5.2): the doc pins pg 8.22.0 and Kysely 0.29.4, while this PR pins pg 8.23.0 and kysely 0.29.5. Reproducibility requires the exact documented versions. findings: - id: 1 file: packages/database-postgres/package.json severity: should what: | dependencies pin pg@8.23.0 and kysely@0.29.5, but the architecture doc golden tuple (section 7) and Technology-Stack (section 5.2) pin pg@8.22.0 and Kysely@0.29.4. The committed versions must match the documented ones. fix: | Set dependencies to pg@8.22.0 and kysely@0.29.4; align @types/pg to the 8.22.x release if one is published (otherwise closest matching). Regenerate pnpm-lock.yaml and update the exact-pin assertions in tests/database-postgres-imports.test.mjs to the corrected versions. ```
bot-dispatcher added the
loop
1
label 2026-08-29 11:22:37 +00:00
Member
agent: dispatcher
phase: complete
plan_summary: Dispatch #177: [E00-S03-T02] pg/Kysely imports isolated to database-postgres (platform, security-gated)
```yaml agent: dispatcher phase: complete plan_summary: Dispatch #177: [E00-S03-T02] pg/Kysely imports isolated to database-postgres (platform, security-gated) ```
bot-dispatcher added the needs/security-reviewneeds/security-review labels 2026-08-29 11:22:38 +00:00
bot-dispatcher removed the needs/security-review
loop
1
needs/security-review
labels 2026-08-29 11:29:10 +00:00
Member

security worker exited with code 1 after all model fallbacks — status/blocked + needs/human-decision.

> security worker exited with code 1 after all model fallbacks — status/blocked + needs/human-decision.
Author
Owner

Human-maintainer decision (kpcto) — security review + CI pipeline-tripwire sign-off for PR #391 (head 09b7a40d). The automated security worker exhausted model fallbacks, so this gate is resolved by the human.

Security assessment (manual trace of the diff): the PR adds a new workspace package (@personal-blog/database-postgres) importing pg/kysely and re-exporting Pool/Kysely/PostgresDialect, a comment-aware import-isolation test suite, package-set fixture updates, and an additive CI job. No secrets are committed (gitleaks-clean tree per prior tasks; only dev defaults already present on main); no new routes/handlers/auth surface; no untrusted input reaches any subprocess (test code uses spawnSync with argv arrays and reads local files only); no deserialization/SSRF surface. The .gitea/workflows/ci.yml change is additive (trigger unchanged, same action majors, no secrets: context, no untrusted ${{ }} interpolation into run:) and matches merged precedents #389/#390 — I sign off on the new database-postgres-imports merge gate.

agent: security
verdict: approve
issue: 177
pr: 391
head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa
human_signoff: kpcto
findings: []
> **Human-maintainer decision (kpcto)** — security review + CI pipeline-tripwire sign-off for PR #391 (head `09b7a40d`). The automated security worker exhausted model fallbacks, so this gate is resolved by the human. Security assessment (manual trace of the diff): the PR adds a new workspace package (`@personal-blog/database-postgres`) importing `pg`/`kysely` and re-exporting `Pool`/`Kysely`/`PostgresDialect`, a comment-aware import-isolation test suite, package-set fixture updates, and an additive CI job. No secrets are committed (gitleaks-clean tree per prior tasks; only dev defaults already present on main); no new routes/handlers/auth surface; no untrusted input reaches any subprocess (test code uses `spawnSync` with argv arrays and reads local files only); no deserialization/SSRF surface. The `.gitea/workflows/ci.yml` change is additive (trigger unchanged, same action majors, no `secrets:` context, no untrusted `${{ }}` interpolation into `run:`) and matches merged precedents #389/#390 — I sign off on the new `database-postgres-imports` merge gate. ```yaml agent: security verdict: approve issue: 177 pr: 391 head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa human_signoff: kpcto findings: [] ```
Member

reviewer worker exited with code 1 after all model fallbacks — status/blocked + needs/human-decision.

> reviewer worker exited with code 1 after all model fallbacks — status/blocked + needs/human-decision.
Member

Security approved; dispatching reviewer.

> Security approved; dispatching reviewer.
Author
Owner
agent: reviewer
verdict: approve
reviewed:
  pr: 391
  issue: 177
  head_branch: feature/177
  head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa
summary: |
  Human-maintainer review (the reviewer worker exhausted model fallbacks, so the
  human decision on this blocked card is to approve directly). Reviewed the
  corrected PR #391 against the acceptance criteria and EPPP standards:

  - packages/database-postgres: new driver-owner package with exact pins
    pg@8.22.0 and kysely@0.29.4 (matching the architecture doc golden tuple §7
    / Technology-Stack §5.2) and @types/pg@8.21.0 (closest published; no
    8.22.x exists). src/index.ts imports and re-exports Pool/Kysely/PostgresDialect.
  - pnpm-lock.yaml: driver tree regenerated (frozen install passes in CI).
  - tests/database-postgres-imports.test.mjs: comment-aware scan of all package
    sources proves pg/kysely imports live only in the owner package; manifest
    isolation check; mutation probes prove the scan is non-vacuous.
  - package-set fixtures (workspace-layout/workspace-config/strict-tsconfig/
    typescript-pin) and docs updated for the new package.
  - .gitea/workflows/ci.yml: additive database-postgres-imports job.
  - CI green (Actions run #83, head 09b7a40d: all 4 jobs success); security
    approved (human sign-off on the CI merge gate given).
  - My prior request-changes (finding #1: pg/kysely version mismatch) is
    resolved: package.json now pins the documented versions.
findings: []
```yaml agent: reviewer verdict: approve reviewed: pr: 391 issue: 177 head_branch: feature/177 head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa summary: | Human-maintainer review (the reviewer worker exhausted model fallbacks, so the human decision on this blocked card is to approve directly). Reviewed the corrected PR #391 against the acceptance criteria and EPPP standards: - packages/database-postgres: new driver-owner package with exact pins pg@8.22.0 and kysely@0.29.4 (matching the architecture doc golden tuple §7 / Technology-Stack §5.2) and @types/pg@8.21.0 (closest published; no 8.22.x exists). src/index.ts imports and re-exports Pool/Kysely/PostgresDialect. - pnpm-lock.yaml: driver tree regenerated (frozen install passes in CI). - tests/database-postgres-imports.test.mjs: comment-aware scan of all package sources proves pg/kysely imports live only in the owner package; manifest isolation check; mutation probes prove the scan is non-vacuous. - package-set fixtures (workspace-layout/workspace-config/strict-tsconfig/ typescript-pin) and docs updated for the new package. - .gitea/workflows/ci.yml: additive database-postgres-imports job. - CI green (Actions run #83, head 09b7a40d: all 4 jobs success); security approved (human sign-off on the CI merge gate given). - My prior request-changes (finding #1: pg/kysely version mismatch) is resolved: package.json now pins the documented versions. findings: [] ```
bot-dispatcher added
status
review
and removed
status
blocked
needs/human-decisionneeds/human-decision
labels 2026-08-29 23:02:23 +00:00
kpcto added
kind
task
status
done
and removed
status
review
labels 2026-08-29 23:04:58 +00:00
kpcto closed this issue 2026-08-29 23:05:02 +00:00
Sign in to join this conversation.