feat(store): api/reaper/offsite/migrate 按版本集合校验 schema,库比二进制新时拒绝启动;bootstrap 迁移前失败回滚宿主二进制

This commit is contained in:
Lemon-miaow committed 2026-09-25 01:46:33 +08:00
1 parent b1678f78c8
commit 3ed6603201
17 files changed
+390 -38

No files matched your search

+8 -1
View File
@@ -84,7 +84,8 @@ func LoadMigrations() ([]Migration, error) {
// Up applies every pending migration in ascending order, exactly once, under
// the advisory lock. It is safe to run concurrently from multiple replicas: the
// lock serializes them and AppliedVersions makes the work idempotent.
// lock serializes them and AppliedVersions makes the work idempotent. It refuses
// (ErrSchemaNewer) a database that records a version this build does not embed.
func Up(ctx context.Context, d Driver, migrations []Migration) (applied []int, err error) {
if err := d.Lock(ctx); err != nil {
return nil, fmt.Errorf("acquire migration lock: %w", err)
@@ -102,6 +103,12 @@ func Up(ctx context.Context, d Driver, migrations []Migration) (applied []int, e
if err != nil {
return nil, fmt.Errorf("read applied versions: %w", err)
}
// A version this build does not embed means a newer release migrated the database.
// Applying the older build's remaining steps on top would be a guess about a schema
// it never saw, so nothing runs.
if err := CompareSchema(done, migrations).Newer(); err != nil {
return nil, err
}
ordered := append([]Migration(nil), migrations...)
sort.Slice(ordered, func(i, j int) bool { return ordered[i].Version < ordered[j].Version })