fix(pgpm dump): restore extension schemas to the dump's search_path #5931
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI tests | |
| on: | |
| push: | |
| branches: | |
| - main | |
| - v1 | |
| paths-ignore: | |
| - '**.md' | |
| - '**/*.md' | |
| - '.agents/skills/**' | |
| - 'docs/**' | |
| pull_request: | |
| branches: | |
| - main | |
| - v1 | |
| paths-ignore: | |
| - '**.md' | |
| - '**/*.md' | |
| - '.agents/skills/**' | |
| - 'docs/**' | |
| workflow_dispatch: | |
| workflow_call: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }}-tests | |
| cancel-in-progress: true | |
| # --------------------------------------------------------------------------- | |
| # Build-once, test-many architecture with tiered service containers. | |
| # | |
| # Phase 1 – build: single job installs deps + builds the monorepo once. | |
| # Phase 2 – fan-out: test jobs download the build artifact and run tests. | |
| # | |
| # The build artifact is a tar archive to preserve symlinks and all files. | |
| # Test jobs extract the tar and run pnpm install to restore node_modules. | |
| # | |
| # Service tiers (avoids spinning up unneeded containers): | |
| # unit-tests → no services (pure JS/TS) | |
| # pg-tests → PostgreSQL only | |
| # integration-tests → PostgreSQL + MinIO | |
| # ai-tests → PostgreSQL + Ollama | |
| # --------------------------------------------------------------------------- | |
| jobs: | |
| # ========================================================================= | |
| # BUILD (single job – runs once, shared by all test jobs) | |
| # ========================================================================= | |
| build: | |
| if: github.event.pull_request.draft != true | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - name: Configure Git (for tests) | |
| run: | | |
| git config --global user.name "CI Test User" | |
| git config --global user.email "ci@example.com" | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v2 | |
| with: | |
| version: 10 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: 'pnpm' | |
| - name: Install dependencies | |
| run: pnpm install | |
| # Fails when pnpm-workspace.yaml no longer matches pnpm-policy.yaml, or when | |
| # a third-party waiver has passed its expiry date. | |
| - name: Check supply-chain policy | |
| run: pnpm run policy:check | |
| # A package with tests that no batch below claims runs nowhere, and until | |
| # this check existed nothing said so. | |
| - name: Check test coverage of the CI matrix | |
| run: node scripts/check-test-coverage.cjs | |
| - name: Build | |
| run: pnpm run build | |
| - name: Create build archive | |
| run: tar -czf /tmp/workspace.tar.gz --exclude='.git' --exclude='node_modules' . | |
| - name: Upload workspace | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: workspace-build | |
| path: /tmp/workspace.tar.gz | |
| retention-days: 1 | |
| # ========================================================================= | |
| # TIER 1 – Unit tests (no services needed) | |
| # ========================================================================= | |
| unit-tests: | |
| needs: build | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - batch: uploads | |
| packages: 'uploads/mime-bytes uploads/uuid-hash uploads/uuid-stream uploads/etag-hash uploads/etag-stream uploads/stream-to-etag uploads/content-type-stream uploads/upload-names uploads/s3-utils' | |
| - batch: packages-core | |
| packages: 'packages/url-domains postgres/query-builder packages/csrf packages/oauth packages/12factor-env packages/orm packages/express-context packages/errors packages/llm-env packages/node-type-registry packages/query-spec packages/server-utils postgres/pg-cache postgres/pg-env' | |
| - batch: packages-services | |
| packages: 'packages/postmaster packages/smtppostmaster packages/csv-to-pg packages/cli postgres/pgsql-client postgres/pg-ast' | |
| - batch: graphql | |
| packages: 'graphql/query graphql/codegen' | |
| - batch: graphile-unit | |
| packages: 'graphile/graphile-plugin-utils graphile/graphile-realtime-subscriptions graphile/graphile-sql-expression-validator graphile/graphile-upload-plugin' | |
| - batch: agentic | |
| packages: 'agentic/protocol agentic/agentic-kit agentic/agent agentic/harness agentic/chat agentic/cli agentic/pi agentic/react agentic/agentic-server agentic/anthropic agentic/openai agentic/ollama' | |
| - batch: pgpm-unit | |
| packages: 'pgpm/types pgpm/naming-spec pgpm/diff pgpm/import pgpm/slice pgpm/transform' | |
| - batch: pglite | |
| packages: 'postgres/pglite-adapter postgres/pglite-test examples/pglite-socket examples/pgpm-projections' | |
| steps: | |
| - name: Download workspace | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: workspace-build | |
| - name: Extract workspace | |
| run: tar -xzf workspace.tar.gz && rm workspace.tar.gz | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v2 | |
| with: | |
| version: 10 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: 'pnpm' | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Test ${{ matrix.batch }} | |
| run: | | |
| for pkg in ${{ matrix.packages }}; do | |
| echo "::group::Testing $pkg" | |
| (cd ./$pkg && pnpm test) | |
| echo "::endgroup::" | |
| done | |
| # ========================================================================= | |
| # TIER 1b – Windows compatibility (native runner, no Linux containers) | |
| # | |
| # Windows runners cannot use service containers, so this job uses the | |
| # PostgreSQL install that ships with the runner image. It covers the | |
| # platform-specific failure modes: path separators in glob patterns, | |
| # spaces in paths, and the PG client binaries on PATH. | |
| # ========================================================================= | |
| windows-tests: | |
| if: github.event.pull_request.draft != true | |
| runs-on: windows-latest | |
| timeout-minutes: 25 | |
| env: | |
| PGHOST: localhost | |
| PGPORT: '5432' | |
| PGUSER: postgres | |
| PGPASSWORD: root | |
| NODE_OPTIONS: '--max-old-space-size=4096' | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v2 | |
| with: | |
| version: 10 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: 'pnpm' | |
| - name: Configure Git (for tests) | |
| run: | | |
| git config --global user.name "CI Test User" | |
| git config --global user.email "ci@example.com" | |
| - name: Start PostgreSQL | |
| shell: pwsh | |
| run: | | |
| $service = Get-Service -Name 'postgresql*' | Select-Object -First 1 | |
| if (-not $service) { throw 'No PostgreSQL service found on the runner image' } | |
| Set-Service -Name $service.Name -StartupType Manual | |
| Start-Service -Name $service.Name | |
| $bin = (Get-ChildItem 'C:\Program Files\PostgreSQL\*\bin' | Select-Object -First 1).FullName | |
| if (-not $bin) { throw 'No PostgreSQL bin directory found on the runner image' } | |
| Add-Content -Path $env:GITHUB_PATH -Value $bin | |
| - name: Wait for PostgreSQL | |
| shell: pwsh | |
| run: | | |
| for ($i = 0; $i -lt 30; $i++) { | |
| pg_isready -h localhost -p 5432 | |
| if ($LASTEXITCODE -eq 0) { exit 0 } | |
| Start-Sleep -Seconds 2 | |
| } | |
| throw 'PostgreSQL did not become ready' | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Build pgpm | |
| run: pnpm --filter pgpm... build | |
| # Database-free suites: workspace/module discovery, dependency | |
| # resolution, plan parsing. These are the codepaths that regress when | |
| # native path separators leak into glob patterns. | |
| - name: Test @pgpmjs/core (no database) | |
| run: pnpm --filter @pgpmjs/core exec jest __tests__/workspace __tests__/resolution __tests__/core __tests__/files __tests__/roles __tests__/modules | |
| - name: pgpm end-to-end smoke (deploy → verify → revert) | |
| run: node scripts/pgpm-smoke.mjs | |
| # ========================================================================= | |
| # TIER 2 – PostgreSQL-only tests | |
| # ========================================================================= | |
| pg-tests: | |
| needs: build | |
| runs-on: blacksmith-2vcpu-ubuntu-2404 | |
| timeout-minutes: 15 | |
| strategy: | |
| fail-fast: false | |
| # Each package's actual `pnpm test` step runs only a few seconds, while | |
| # every matrix job pays ~50s of fixed overhead (service container init | |
| # dominates). Batch packages into a few jobs that run tests sequentially | |
| # against one shared Postgres container to amortize that overhead. | |
| matrix: | |
| include: | |
| - batch: pg-core | |
| packages: 'pgpm/ast pgpm/traverse pgpm/bundle pgpm/core pgpm/cli pgpm/portability pgpm/export packages/client packages/safegres postgres/pg-codegen' | |
| - batch: pg-postgres | |
| packages: 'postgres/pgsql-test postgres/drizzle-orm-test postgres/introspectron graphile/graphile-test graphile/graphile-connection-filter graphile/graphile-postgis' | |
| - batch: pg-graphql | |
| packages: 'graphile/graphile-search graphile/graphile-ltree graphile/graphile-bulk-mutations graphile/graphile-function-bindings graphile/graphile-history graphile/graphile-meta graphile/graphile-schema graphql/orm-test graphql/test graphql/playwright-test' | |
| - batch: pg-graphile-extras | |
| packages: 'graphile/graphile-i18n graphile/graphile-pg-aggregates graphile/graphile-query graphile/graphile-realtime-test' | |
| env: | |
| PGHOST: localhost | |
| PGPORT: 5432 | |
| PGUSER: postgres | |
| PGPASSWORD: password | |
| # packages/client reads TEST_DATABASE_URL; harmless for the others. | |
| TEST_DATABASE_URL: postgres://postgres:password@localhost:5432/postgres | |
| # Pin an explicit heap cap: on smaller runners Node's memory-derived | |
| # default can land near ~2GB and OOM Jest. | |
| NODE_OPTIONS: '--max-old-space-size=4096' | |
| services: | |
| pg_db: | |
| image: ghcr.io/constructive-io/docker/postgres-plus:18 | |
| env: | |
| POSTGRES_USER: postgres | |
| POSTGRES_PASSWORD: password | |
| options: >- | |
| --health-cmd "pg_isready -U postgres" | |
| --health-interval 3s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| ports: | |
| - 5432:5432 | |
| steps: | |
| - name: Download workspace | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: workspace-build | |
| - name: Extract workspace | |
| run: tar -xzf workspace.tar.gz && rm workspace.tar.gz | |
| - name: Configure Git (for tests) | |
| run: | | |
| git config --global user.name "CI Test User" | |
| git config --global user.email "ci@example.com" | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v2 | |
| with: | |
| version: 10 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: 'pnpm' | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| # Durability is irrelevant for throwaway CI databases. Disabling fsync | |
| # and synchronous commit avoids checkpoint I/O stalls on CI runners. | |
| - name: Tune Postgres for CI (disable durability) | |
| run: pnpm --filter pgpm exec node dist/index.js tune --yes | |
| - name: Seed app_user | |
| run: | | |
| pnpm --filter pgpm exec node dist/index.js admin-users bootstrap --yes | |
| pnpm --filter pgpm exec node dist/index.js admin-users add --test --yes | |
| - name: Install pgpm fixture modules | |
| run: pnpm fixtures:install | |
| - name: Test ${{ matrix.batch }} | |
| # `pgpm diff db:<name>` shells out to pg_dump, and the dump restore | |
| # test pipes an 18-format dump (`\restrict`) into psql; both clients | |
| # must match the Postgres 18 server. Rather than install client tools | |
| # on the runner, run them straight from the postgres-plus:18 service | |
| # container. | |
| env: | |
| # -e PGUSER: docker exec does not inherit the runner env, and pg_dump | |
| # would otherwise default to the container's OS user (no such role). | |
| PGPM_PG_DUMP: docker exec -e PGUSER=postgres ${{ job.services.pg_db.id }} pg_dump | |
| # -i: the dump arrives on stdin, since the runner's filesystem is not | |
| # visible inside the container. | |
| PGPM_PSQL: docker exec -i -e PGUSER=postgres ${{ job.services.pg_db.id }} psql | |
| run: | | |
| for pkg in ${{ matrix.packages }}; do | |
| echo "::group::Testing $pkg" | |
| (cd ./$pkg && pnpm test) | |
| echo "::endgroup::" | |
| done | |
| # ========================================================================= | |
| # TIER 3 – Integration tests (PostgreSQL + MinIO) | |
| # ========================================================================= | |
| integration-tests: | |
| needs: build | |
| runs-on: blacksmith-2vcpu-ubuntu-2404 | |
| timeout-minutes: 15 | |
| strategy: | |
| fail-fast: false | |
| # Batched to amortize per-job fixed overhead (service container init | |
| # dominates) — see the pg-tests tier for rationale. | |
| matrix: | |
| include: | |
| - batch: integration-graphql | |
| packages: 'graphql/server-test graphql/server graphql/env pgpm/env' | |
| - batch: integration-uploads | |
| packages: 'uploads/s3-streamer packages/upload-client packages/bucket-provisioner graphile/graphile-settings graphile/graphile-presigned-url-plugin graphile/graphile-bucket-provisioner-plugin' | |
| env: | |
| PGHOST: localhost | |
| PGPORT: 5432 | |
| PGUSER: postgres | |
| PGPASSWORD: password | |
| CDN_ENDPOINT: http://localhost:9000 | |
| AWS_ACCESS_KEY: minioadmin | |
| AWS_SECRET_KEY: minioadmin | |
| AWS_REGION: us-east-1 | |
| # uploads/s3-streamer reads BUCKET_NAME; harmless for the others. | |
| BUCKET_NAME: test-bucket | |
| # Pin an explicit heap cap: on smaller runners Node's memory-derived | |
| # default can land near ~2GB and OOM Jest. | |
| NODE_OPTIONS: '--max-old-space-size=4096' | |
| services: | |
| pg_db: | |
| image: ghcr.io/constructive-io/docker/postgres-plus:18 | |
| env: | |
| POSTGRES_USER: postgres | |
| POSTGRES_PASSWORD: password | |
| options: >- | |
| --health-cmd "pg_isready -U postgres" | |
| --health-interval 3s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| ports: | |
| - 5432:5432 | |
| minio_cdn: | |
| image: minio/minio:edge-cicd | |
| env: | |
| MINIO_ROOT_USER: minioadmin | |
| MINIO_ROOT_PASSWORD: minioadmin | |
| ports: | |
| - 9000:9000 | |
| - 9001:9001 | |
| options: >- | |
| --health-cmd "curl -f http://localhost:9000/minio/health/live || exit 1" | |
| --health-interval 3s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| steps: | |
| - name: Download workspace | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: workspace-build | |
| - name: Extract workspace | |
| run: tar -xzf workspace.tar.gz && rm workspace.tar.gz | |
| - name: Configure Git (for tests) | |
| run: | | |
| git config --global user.name "CI Test User" | |
| git config --global user.email "ci@example.com" | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v2 | |
| with: | |
| version: 10 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: 'pnpm' | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| # Durability is irrelevant for throwaway CI databases. Disabling fsync | |
| # and synchronous commit avoids checkpoint I/O stalls on CI runners. | |
| - name: Tune Postgres for CI (disable durability) | |
| run: pnpm --filter pgpm exec node dist/index.js tune --yes | |
| - name: Seed app_user | |
| run: | | |
| pnpm --filter pgpm exec node dist/index.js admin-users bootstrap --yes | |
| pnpm --filter pgpm exec node dist/index.js admin-users add --test --yes | |
| - name: Install pgpm fixture modules | |
| run: pnpm fixtures:install | |
| - name: Test ${{ matrix.batch }} | |
| run: | | |
| for pkg in ${{ matrix.packages }}; do | |
| echo "::group::Testing $pkg" | |
| (cd ./$pkg && pnpm test) | |
| echo "::endgroup::" | |
| done | |
| # ========================================================================= | |
| # TIER 4 – AI integration tests (PostgreSQL + Ollama) | |
| # ========================================================================= | |
| ai-tests: | |
| needs: build | |
| runs-on: blacksmith-2vcpu-ubuntu-2404 | |
| timeout-minutes: 15 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - package: graphile/graphile-llm | |
| env: {} | |
| env: | |
| PGHOST: localhost | |
| PGPORT: 5432 | |
| PGUSER: postgres | |
| PGPASSWORD: password | |
| # Pin an explicit heap cap: on smaller runners Node's memory-derived | |
| # default can land near ~2GB and OOM Jest. | |
| NODE_OPTIONS: '--max-old-space-size=4096' | |
| services: | |
| pg_db: | |
| image: ghcr.io/constructive-io/docker/postgres-plus:18 | |
| env: | |
| POSTGRES_USER: postgres | |
| POSTGRES_PASSWORD: password | |
| options: >- | |
| --health-cmd "pg_isready -U postgres" | |
| --health-interval 3s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| ports: | |
| - 5432:5432 | |
| steps: | |
| - name: Download workspace | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: workspace-build | |
| - name: Extract workspace | |
| run: tar -xzf workspace.tar.gz && rm workspace.tar.gz | |
| - name: Configure Git (for tests) | |
| run: | | |
| git config --global user.name "CI Test User" | |
| git config --global user.email "ci@example.com" | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v2 | |
| with: | |
| version: 10 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: 'pnpm' | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| # Durability is irrelevant for throwaway CI databases. Disabling fsync | |
| # and synchronous commit avoids checkpoint I/O stalls on CI runners. | |
| - name: Tune Postgres for CI (disable durability) | |
| run: pnpm --filter pgpm exec node dist/index.js tune --yes | |
| - name: Seed app_user | |
| run: | | |
| pnpm --filter pgpm exec node dist/index.js admin-users bootstrap --yes | |
| pnpm --filter pgpm exec node dist/index.js admin-users add --test --yes | |
| - name: Install Ollama | |
| run: | | |
| curl -fsSL https://ollama.com/install.sh | sh | |
| ollama serve & | |
| sleep 3 | |
| ollama pull nomic-embed-text | |
| - name: Test ${{ matrix.package }} | |
| run: cd ./${{ matrix.package }} && pnpm test | |
| env: ${{ matrix.env }} |