fix(deploy): sync rooms Prisma types and harden checkout against stale host files
Local Build and Deploy / deploy (push) Failing after 1m19s

next build failed on host-local rooms.ts using Prisma without import while tsc incremental passed; force non-incremental typecheck and verify src matches HEAD.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-18 20:06:34 +02:00
1 parent c053b8de87
commit 1abbf3fde7
4 files changed
+31 -14

No files matched your search

+19 -12
View File
@@ -37,8 +37,7 @@ jobs:
DEPLOY_GROUP="$(id -gn)" DEPLOY_GROUP="$(id -gn)"
# CRITICAL: last deploy chowns the tree to www-data. Reclaim ownership # CRITICAL: last deploy chowns the tree to www-data. Reclaim ownership
# BEFORE git reset, otherwise stale sources (e.g. old nitro editor with # BEFORE git reset, otherwise stale sources can survive and break builds.
# a removed Json type) can survive and break typecheck.
sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/ sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/
# CRITICAL: Prevent Git permission blocks caused by the www-data ownership change # CRITICAL: Prevent Git permission blocks caused by the www-data ownership change
@@ -49,26 +48,36 @@ jobs:
# 3. Fetch and update code # 3. Fetch and update code
git fetch origin --prune git fetch origin --prune
# Clear bits that can pin host-local stale copies over origin/main.
git ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' | while IFS= read -r f; do
[ -n "$f" ] || continue
git update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true
done
git reset --hard origin/main git reset --hard origin/main
# Drop stray untracked sources left on the host (keep secrets/env). # Drop stray untracked sources left on the host (keep secrets/env).
git clean -fd -e .env -e .env.local -e .env.production -e .env*.local -- src git clean -fd -e .env -e .env.local -e .env.production -e .env*.local -- src
# Force-refresh sources after reclaiming ownership (belt-and-suspenders).
git checkout -f HEAD -- src git checkout -f HEAD -- src
# Working tree under src/ must match HEAD exactly (catches sticky host edits).
if ! git diff --exit-code -- src >/dev/null; then
echo "ERROR: src/ still differs from HEAD after reset/checkout:" >&2
git diff --stat -- src >&2 || true
git checkout -f HEAD -- src
git diff --exit-code -- src
fi
# Drop incremental TS caches that can hide real type errors.
rm -f tsconfig.tsbuildinfo .tsbuildinfo
find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true
# Preserve .next/cache so Next.js can reuse its incremental build cache. # Preserve .next/cache so Next.js can reuse its incremental build cache.
rm -rf .output dist rm -rf .output dist .next/types .next/dev
# Release tag for Sentry / logs (short git sha) # Release tag for Sentry / logs (short git sha)
export APP_VERSION="$(git rev-parse --short HEAD)" export APP_VERSION="$(git rev-parse --short HEAD)"
export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}" export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}"
echo "APP_VERSION=${APP_VERSION}" echo "APP_VERSION=${APP_VERSION}"
# Fail fast if a host-local stale copy still has the removed Json type.
if grep -nE ':\s*Json\b|Json\s*\|' src/app/admin/import/furni/nitro-editor-dialog.tsx; then
echo "ERROR: nitro-editor-dialog.tsx still contains a Json type after checkout" >&2
exit 1
fi
# 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml # 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml
# (do not set a PNPM only-built-deps env override here). # (do not set a PNPM only-built-deps env override here).
pnpm install --frozen-lockfile pnpm install --frozen-lockfile
@@ -83,8 +92,6 @@ jobs:
# 7. Next.js Build # 7. Next.js Build
# Skip env refine during compile/page-data; runtime still validates via env.ts. # Skip env refine during compile/page-data; runtime still validates via env.ts.
# Drop stale generated types that can diverge from source after incremental builds.
rm -rf .next/types .next/dev
export SKIP_ENV_VALIDATION=1 export SKIP_ENV_VALIDATION=1
pnpm build pnpm build
+1 -1
View File
@@ -11,7 +11,7 @@
"build": "next build", "build": "next build",
"start": "next start", "start": "next start",
"prisma:generate": "prisma generate", "prisma:generate": "prisma generate",
"typecheck": "tsc --noEmit", "typecheck": "tsc --noEmit --incremental false",
"biome:check": "biome check --write .", "biome:check": "biome check --write .",
"biome:lint": "biome lint .", "biome:lint": "biome lint .",
"biome:format": "biome format --write .", "biome:format": "biome format --write .",
+5 -1
View File
@@ -1,6 +1,7 @@
"use server"; "use server";
import { revalidatePath } from "next/cache"; import { revalidatePath } from "next/cache";
import type { Prisma } from "@/generated/prisma/client";
import { requirePermission } from "@/lib/admin/guard"; import { requirePermission } from "@/lib/admin/guard";
import { PERMS } from "@/lib/permissions"; import { PERMS } from "@/lib/permissions";
import { prisma } from "@/lib/prisma"; import { prisma } from "@/lib/prisma";
@@ -105,7 +106,10 @@ export async function updateRoom({
usersMax?: number; usersMax?: number;
}) { }) {
const staff = await requirePermission(PERMS.ROOMS_EDIT); const staff = await requirePermission(PERMS.ROOMS_EDIT);
await prisma.rooms.update({ where: { id }, data: data as any }); await prisma.rooms.update({
where: { id },
data: data as Prisma.RoomsUpdateInput,
});
await logStaffActivity({ await logStaffActivity({
staffId: staff.id, staffId: staff.id,
action: "room_update", action: "room_update",
+6
View File
@@ -25,6 +25,12 @@ describe("production deploy workflow", () => {
expect(resetAt).toBeGreaterThan(reclaimAt); expect(resetAt).toBeGreaterThan(reclaimAt);
}); });
it("verifies src/ matches HEAD and clears tsbuildinfo before typecheck", () => {
expect(workflow).toContain("git diff --exit-code -- src");
expect(workflow).toContain("*.tsbuildinfo");
expect(workflow).toContain("pnpm typecheck");
});
it("does not override onlyBuiltDependencies (uses pnpm-workspace.yaml)", () => { it("does not override onlyBuiltDependencies (uses pnpm-workspace.yaml)", () => {
expect(workflow).not.toContain("PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES"); expect(workflow).not.toContain("PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES");
}); });