Skip to content

Stop installing uuid-ossp in migration 1 - #580

Merged
devhawk merged 1 commit into
mainfrom
drop-uuid-ossp
Sep 25, 2026
Merged

devhawk merged 1 commit into
mainfrom
drop-uuid-ossp

Conversation

@devhawk

@devhawk devhawk commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator

Migration 1 ran CREATE EXTENSION IF NOT EXISTS "uuid-ossp", which nothing in the schema uses: every generated UUID comes from the built-in gen_random_uuid(). CREATE EXTENSION needs CREATE on the database, even for a trusted extension, so a role granted only USAGE, CREATE on a pre-created DBOS schema could not migrate a new system database:

ERROR:  permission denied to create extension "uuid-ossp"

Change

  • Removes the statement from migration 1 in MigrationManager.
  • Databases that already ran migration 1 are unaffected. The extension stays installed where it was, and nothing drops it.
  • MigrationManagerTest.getOriginalMigration1() keeps its copy of the statement, since it stands for a database an older release created.

Test. MigrationManagerTest.aSchemaScopedRoleCanMigrateANewSystemDatabase: an administrator creates the database, a login role and the DBOS schema, and grants the role only USAGE, CREATE on that schema. The role then migrates the new system database, and every expected table exists. With the statement restored, the test fails with the error above. It is skipped on CockroachDB, whose privilege model differs.

MigrationManagerTest passes on Postgres (24/24). Not run locally: CockroachDB.

Parity. Python dropped the statement in 3.0.0 (py#853, closing py#852), and TypeScript in 5.0 (ts#1362). Go never had it.

Closes #576

🤖 Generated with Claude Code

Migration 1 ran CREATE EXTENSION IF NOT EXISTS "uuid-ossp". Nothing in the
schema uses it: every generated UUID comes from the built-in gen_random_uuid().
CREATE EXTENSION needs CREATE on the database, even for a trusted extension, so
a role granted only USAGE and CREATE on a pre-created DBOS schema could not
migrate a new system database:

  permission denied to create extension "uuid-ossp"

Python dropped the statement in 3.0.0 (py#853) and TypeScript in 5.0
(ts#1362); Go never had it. Databases that already ran migration 1 keep the
extension; nothing drops it.

MigrationManagerTest gains a test that migrates a new system database as such a
role, which fails with the error above when the statement is present. The
historical migration 1 copy in that test keeps the statement, since it stands
for a database an older release created.

Closes #576
@devhawk
devhawk requested review from kraftp, maxdml and qianl15 and a lite review from Copilot September 25, 2026 22:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

What changed in this PR

Removes the unused uuid-ossp installation from migration 1 and adds regression coverage for schema-scoped migration roles.

Changes:

  • Removes the unnecessary extension creation.
  • Adds a least-privilege PostgreSQL migration test.
  • Preserves the historical migration fixture.
File Description
transact/​src/​test/​java/​dev/​dbos/​transact/​migrations/​MigrationManagerTest.java Adds schema-scoped role migration coverage.
transact/​src/​main/​java/​dev/​dbos/​transact/​migrations/​MigrationManager.java Removes uuid-ossp installation from migration 1.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@devhawk
devhawk merged commit 7953fa2 into main Sep 25, 2026
13 checks passed
@devhawk
devhawk deleted the drop-uuid-ossp branch September 25, 2026 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migration 1 installs uuid-ossp, which nothing uses and which needs CREATE on the database

3 participants