From 1abbf3fde751c841100b4a3ecbe3a9310a3e3015 Mon Sep 17 00:00:00 2001 From: simoleo89 Date: Sat, 18 Jul 2026 20:06:34 +0200 Subject: [PATCH] fix(deploy): sync rooms Prisma types and harden checkout against stale host files next build failed on host-local rooms.ts using Prisma without import while tsc incremental passed; force non-incremental typecheck and verify src matches HEAD. Co-authored-by: Cursor --- .gitea/workflows/deploy.yaml | 31 +++++++++++++++--------- package.json | 2 +- src/actions/rooms.ts | 6 ++++- src/lib/deploy-workflow-contract.test.ts | 6 +++++ 4 files changed, 31 insertions(+), 14 deletions(-) diff --git a/.gitea/workflows/deploy.yaml b/.gitea/workflows/deploy.yaml index 33805c4c..776ed5ad 100644 --- a/.gitea/workflows/deploy.yaml +++ b/.gitea/workflows/deploy.yaml @@ -37,8 +37,7 @@ jobs: DEPLOY_GROUP="$(id -gn)" # CRITICAL: last deploy chowns the tree to www-data. Reclaim ownership - # BEFORE git reset, otherwise stale sources (e.g. old nitro editor with - # a removed Json type) can survive and break typecheck. + # BEFORE git reset, otherwise stale sources can survive and break builds. sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/ # CRITICAL: Prevent Git permission blocks caused by the www-data ownership change @@ -49,26 +48,36 @@ jobs: # 3. Fetch and update code git fetch origin --prune + # Clear bits that can pin host-local stale copies over origin/main. + git ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' | while IFS= read -r f; do + [ -n "$f" ] || continue + git update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true + done git reset --hard origin/main # Drop stray untracked sources left on the host (keep secrets/env). git clean -fd -e .env -e .env.local -e .env.production -e .env*.local -- src - # Force-refresh sources after reclaiming ownership (belt-and-suspenders). git checkout -f HEAD -- src + # Working tree under src/ must match HEAD exactly (catches sticky host edits). + if ! git diff --exit-code -- src >/dev/null; then + echo "ERROR: src/ still differs from HEAD after reset/checkout:" >&2 + git diff --stat -- src >&2 || true + git checkout -f HEAD -- src + git diff --exit-code -- src + fi + + # Drop incremental TS caches that can hide real type errors. + rm -f tsconfig.tsbuildinfo .tsbuildinfo + find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true + # Preserve .next/cache so Next.js can reuse its incremental build cache. - rm -rf .output dist + rm -rf .output dist .next/types .next/dev # Release tag for Sentry / logs (short git sha) export APP_VERSION="$(git rev-parse --short HEAD)" export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}" echo "APP_VERSION=${APP_VERSION}" - # Fail fast if a host-local stale copy still has the removed Json type. - if grep -nE ':\s*Json\b|Json\s*\|' src/app/admin/import/furni/nitro-editor-dialog.tsx; then - echo "ERROR: nitro-editor-dialog.tsx still contains a Json type after checkout" >&2 - exit 1 - fi - # 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml # (do not set a PNPM only-built-deps env override here). pnpm install --frozen-lockfile @@ -83,8 +92,6 @@ jobs: # 7. Next.js Build # Skip env refine during compile/page-data; runtime still validates via env.ts. - # Drop stale generated types that can diverge from source after incremental builds. - rm -rf .next/types .next/dev export SKIP_ENV_VALIDATION=1 pnpm build diff --git a/package.json b/package.json index 2cb2c579..7ab6e011 100644 --- a/package.json +++ b/package.json @@ -11,7 +11,7 @@ "build": "next build", "start": "next start", "prisma:generate": "prisma generate", - "typecheck": "tsc --noEmit", + "typecheck": "tsc --noEmit --incremental false", "biome:check": "biome check --write .", "biome:lint": "biome lint .", "biome:format": "biome format --write .", diff --git a/src/actions/rooms.ts b/src/actions/rooms.ts index 8e44d43a..487e87d9 100644 --- a/src/actions/rooms.ts +++ b/src/actions/rooms.ts @@ -1,6 +1,7 @@ "use server"; import { revalidatePath } from "next/cache"; +import type { Prisma } from "@/generated/prisma/client"; import { requirePermission } from "@/lib/admin/guard"; import { PERMS } from "@/lib/permissions"; import { prisma } from "@/lib/prisma"; @@ -105,7 +106,10 @@ export async function updateRoom({ usersMax?: number; }) { const staff = await requirePermission(PERMS.ROOMS_EDIT); - await prisma.rooms.update({ where: { id }, data: data as any }); + await prisma.rooms.update({ + where: { id }, + data: data as Prisma.RoomsUpdateInput, + }); await logStaffActivity({ staffId: staff.id, action: "room_update", diff --git a/src/lib/deploy-workflow-contract.test.ts b/src/lib/deploy-workflow-contract.test.ts index 32593a96..1e3060d6 100644 --- a/src/lib/deploy-workflow-contract.test.ts +++ b/src/lib/deploy-workflow-contract.test.ts @@ -25,6 +25,12 @@ describe("production deploy workflow", () => { expect(resetAt).toBeGreaterThan(reclaimAt); }); + it("verifies src/ matches HEAD and clears tsbuildinfo before typecheck", () => { + expect(workflow).toContain("git diff --exit-code -- src"); + expect(workflow).toContain("*.tsbuildinfo"); + expect(workflow).toContain("pnpm typecheck"); + }); + it("does not override onlyBuiltDependencies (uses pnpm-workspace.yaml)", () => { expect(workflow).not.toContain("PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES"); });