Repository navigation
The host runs Composer 0.26.0: one config file, no prisma-composer binary (8.0.0-rc.20) - #330
Conversation
Composer 0.26.0 moves its configuration into the composer section of prisma.config.ts and drops the prisma-composer binary. Until it is on the registry, both manifests pin the preview of prisma/composer#331. The preview's composer-cli depends on @prisma/composer by URL, which pnpm refuses in subdependencies unless blockExoticSubdeps is off. Both go back to 0.26.0 before this merges. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
Composer 0.26.0 peers @prisma/cli-engine 0.6.2, the version the shell ships, so the tarball check no longer needs to excuse a mismatch. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
…es it A composer section that still names a config file is now refused by Composer's section validator before any handler runs: the result is CLI.CONFIG_SECTION_INVALID carrying CONFIG.FIELD_RETIRED, exit 2, on every platform, so the Windows variant of the test goes away. A second fixture builds a valid section with defineConfig from @prisma/composer/config and nodeBuild(), and shows dev accepting it and reaching its handler. Its state descriptor is written by hand: the Prisma Cloud control entry would bring the whole cloud target and the ORM toolchain into the host's dev dependencies. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
prisma init installs this skill into every new project, and it still said dev and deploy need a separate prisma-composer.config.ts. With Composer 0.26.0 that file is refused; the skill now shows the composer section and the three CONFIG codes the way Composer's own skill does. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
The configPath test now checks the headline summary, which names the section and the file, and the diagnostic's severity. The valid-section test checks that the handler's failure names the entry the host passed, so it shows the argv reached composer's dev rather than only that some composer code came back. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
A new project with no composer section gets CONFIG.SECTION_MISSING and has no old file to move, so the skill now says to write the section in that case and to move the old contents only for the other two codes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
Composer 0.26.0 is on latest, so both manifests pin it in place of the pkg.pr.new preview, and the workspace stops allowing URL dependencies below the top level, which only the preview needed. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
Merging publishes prisma@latest pinning Composer 0.26.0, whose configuration is the composer section of prisma.config.ts. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (13)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughPackage and workspace versions advance to 8.0.0-rc.20, and Composer CLI dependencies advance to 0.26.0. CLI tests and skill documentation describe a single Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to This change updates package versions and Composer configuration guidance and tests. No concrete merge-blocking issue was found, so it appears ready to merge after normal CI checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The configuration contract changes, but the host retains validation before command execution. No introduced security issue was established. Composer 0.26.0’s internal state-management and recovery behavior could not be independently verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
commit: |
``` $ git diff --stat main...HEAD | tail -1 25 files changed, 1 insertion(+), 2833 deletions(-) ``` This closes the one-config-file project. It deletes the project's working folder, `projects/one-config-file/`, and fixes one duplicate number in the failure-mode catalogue. Linear: TML-3340. The project moved Prisma Composer's configuration out of its own `prisma-composer.config.ts` into the `composer` section of `prisma.config.ts`, and deleted Composer's standalone `prisma-composer` binary. Prisma 8 now has one CLI and one config file. The rest of this description is the close-out record the Drive process asks for: what was checked, where each decision now lives, and where each unfinished item is tracked. ## What was delivered | PR | What it did | | --- | --- | | prisma/composer#328 | Composer's configuration is the `composer` section of `prisma.config.ts`. The old file and `configPath` are refused. | | prisma/composer#331 | The `prisma-composer` binary is gone. Docs, examples and the shipped skill say `prisma deploy` and `prisma dev`. Released as Composer 0.26.0. | | prisma/prisma-cli#330 | The `prisma` host runs Composer 0.26.0. Released as `prisma@8.0.0-rc.20`. | | prisma/web#8387 | The public Composer docs describe the `composer` section. | | prisma/composer#332 | Found during testing: `prisma dev` and `prisma deploy` failed in pnpm projects. Merged, not yet released (TML-3520). | | prisma/composer#333 | An emulator test race that made CI flaky, plus `PRISMA_COMPOSER_EMULATORS_DIR`. | Three more PRs came out of this close-out and are open: - prisma/composer#347 writes ADR-0050, which records the binary's retirement. Without it the close-out failed the ADR audit, and four older ADRs still described `prisma-composer` as the entry point. - prisma/web#8415 fixes a tutorial page that still told readers to write `prisma-composer.config.ts`. - prisma/pdp-control-plane#5608 makes the platform's Compute import flow write the `composer` section into `prisma.config.ts`, and recognise repositories that already have it. Until now it wrote `prisma-composer.config.mjs` and pinned Composer 0.25.0, so imported repositories broke on upgrading to 0.26.0. ## Definition of Done | Item | Verdict | Evidence | | --- | --- | --- | | orm-demo has one config file, and `prisma deploy` and `prisma dev` run against it from the host | Met, with deviations | `examples/orm-demo` has only `prisma.config.ts`. `prisma dev` from the host build reached ready (slice 3 QA). A real `prisma deploy` of orm-demo succeeds in Composer's e2e workflow on `main`, using the published host with the workspace family. No deploy ran from the host build itself, because no service token was available. | | The old file and `configPath` get their diagnostics | Met, with a deviation | `CONFIG.FILE_RETIRED` and `CONFIG.FIELD_RETIRED`, exit 2, from the host binary. Shown with `prisma dev`, because `deploy` checks credentials before reading the config. Both commands use the same validator. | | A broken `effect` install fails with `CLI.CONFIG_UNREADABLE`, and `prisma --version` still works | Met, with the same deviation | Slice 3 QA, step 5. | | Published packages have no `bin` and no stale name | Met | `@prisma/composer-cli` and `@prisma/composer` 0.28.0 declare no `bin`. Their unpacked tarballs name the old file only in the messages that refuse it. | | A CI check keeps the old name out | Met | `pnpm lint:retired-binary-name` runs in CI. Its test plants a mention and expects a failure. | | TML-3340 Done, web pages updated | Met | TML-3340 is Done with a closing comment. One page missed by #8387 is fixed in prisma/web#8415. | | The consolidation plan says `deploy` and `dev` stay bare | Met | `projects/consolidate-clis/cli-consolidation-plan.md`, and now ADR-0050 in prisma/composer. | | Retro run, ADR merged, folder deleted | Met once #347 and this PR merge | The retro's lesson is failure mode F42. ADR-0049 is merged. ADR-0050 is in #347. | | Repository references to the folder removed | Met | Nothing outside the folder links to it. | | Manual QA for each user-facing slice | Met, with a deviation | Slice 3 has a QA transcript. Slices 1 and 2 recorded their manual QA in the Verification sections of #328 and #331. | ## Where each decision lives now Every decision recorded in the deleted spec and design notes has a home outside the folder: - **Composer's configuration is the `composer` section, validated by the section, with the old file and field refused:** ADR-0049, and the `CONFIG` code list in ADR-0044. - **The `effect` version pre-flight is deleted; a broken tree fails with the engine's error:** ADR-0049. #347 adds the four rejected alternatives, which until now were only in #328's description. - **The binary is retired, and `destroy` and `log` stay programmatic:** ADR-0050 in #347. - **`deploy` and `dev` stay bare commands; `destroy` is not mounted:** ADR-0050, and the consolidation plan. - **The examples' `destroy` scripts keep `--production` and `--stage`:** ADR-0050 records this as a repository-internal script grammar, not a public command. - **Examples and CI run the published host with a workspace override:** `gotchas.md` and `scripts/check-cli-engine-pin*.mjs` in prisma/composer, which enforce it. - **Composer runs the `alchemy` installed beside `@prisma/composer`:** ADR-0007's amendment and `docs/design/10-domains/deploy-cli.md` in prisma/composer. ## Deferred items and their tickets | Ticket | Item | | --- | --- | | TML-3520 | Release Composer 0.29.0 and pin it in the host, so `prisma@latest` gets the pnpm fix. | | TML-3521 | Teardown and logs have no `prisma` command. | | TML-3522 | Two checkouts of one app still share a local Postgres server. | | TML-3523 | A compute emulator test is too tight on time and flakes under load. | | TML-3524 | Composer's examples pin an older `prisma` host than `latest`. | | TML-3525 | Drop the exact `effect` pin once `effect` 4 is stable or Alchemy pins its peer. | | TML-3526 | dependency-cruiser skips the examples' `prisma.config.ts`. | | TML-3527 | Edge cases in how Composer starts Alchemy. | | TML-3528 | prisma/asks and prisma/streams still use the retired config or command. | Two smaller review notes are accepted without tickets. The prisma-cli conformance check needs a new exception on each joint engine release, which is visible when it happens. Windows edge cases are out of scope, because Windows is documented as unsupported for local tooling. ## What this PR deletes Every file under `projects/one-config-file/` is transient under `drive/project/README.md`: the spec, plan, design notes, retro log, README, and each slice's spec, plan, grounding notes, reviews and QA transcript. None is methodology to migrate. The decisions are mapped above. The full files stay readable in the history of prisma/orm#30536. ## The failure-mode number The retro added its lesson to `drive/calibration/failure-modes.md` as F39. prisma/orm#30613 had already used F39 two days earlier. This PR renumbers ours to F42, the next free number. Agent: saruman-38 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Slice 3 of the one-config-file project (prisma/orm#30536). Composer 0.26.0 published the merged config (prisma/composer#328) and dropped the
prisma-composerbinary (prisma/composer#331); this PR makes the host carry it. Merging publishesprisma@8.0.0-rc.20.From a Composer project outside any workspace, with this branch's
prismaand Composer 0.26.0 from the registry:The decision
@prisma/cliandprismapin@prisma/composer-cliand@prisma/composerat 0.26.0 and the version advances to 8.0.0-rc.20, soprisma@latestruns Composer's family with thecomposersection ofprisma.config.tsas its configuration. The automatic pin-bump workflow did not fire (Composer's publish could not notify this repository), so this PR carries the bump.What the bump changes in the host
composer: { configPath }now proves the retirement:dev --configagainst it fails with the engine'sCLI.CONFIG_SECTION_INVALIDheadline and Composer'sCONFIG.FIELD_RETIREDdiagnostic, exit 2, on every platform, since validation now fails before the handler runs. A second fixture holds a valid section built withdefineConfig as composerfrom@prisma/composer/configand proves the handler runs against it.scripts/conformance.tsis removed, as its own note said this bump would do. The suite reports nothing.skills/prisma-platform-core-concepts/SKILL.mdno longer saysprisma-composer.config.tsis mandatory or thatdevfails withCONFIG.FILE_MISSING. It describes thecomposersection and the three retirement codes in the same terms as Composer's own skill, with the fix for each.composer-isolation.test.tspasses unchanged: mounting the 0.26.0 family still loads neither Alchemy noreffecton an unrelated command.Verification
test:scripts,check:skill-packaging,manifest-pins,composer-isolation, andcheck:conformancewith zero failing and zero allowed.--version,deploy --help,dev --helpexit 0 and list neitherdestroynorlog; the retired file givesCONFIG.FILE_RETIRED; the retired field givesCONFIG.FIELD_RETIRED; aneffectforced to 4.0.0-rc.118 givesCLI.CONFIG_UNREADABLEnaming the missing module while--versionstill exits 0.prisma devto ready still needsalchemyas a direct dependency in a plain pnpm project; that is a Composer defect fixed in prisma/composer#332, not a host matter, and will ship in Composer's next release.Not in this PR
destroyandlogremain operations on@prisma/composer/control; their command-line form is a separate grammar project.latest.Agent: columbo-17
🤖 Generated with Claude Code