Add DDM custom activations schema - #50133
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
WalkthroughAdds the 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #50133 +/- ##
=======================================
Coverage 68.17% 68.17%
=======================================
Files 3934 3935 +1
Lines 250983 251037 +54
Branches 13440 13440
=======================================
+ Hits 171098 171142 +44
- Misses 64551 64557 +6
- Partials 15334 15338 +4
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
MagnusHJensen
left a comment
There was a problem hiding this comment.
Merge conflict, if you can re-generate the schema that would be great. (Maybe you need to bump this migration timestamp)
Adds the schema for custom DDM activations, letting admins override the activation Fleet generates for a configuration declaration. - Creates mdm_apple_ddm_activations, storing the activation JSON as-is with a generated token column, linked 1:1 to its configuration declaration by a declaration_uuid foreign key that cascades on delete. - Extends mdm_configuration_profile_variables with apple_ddm_activation_uuid so activations can carry Fleet variables, including the unique key its upsert path relies on and a replacement check constraint that counts the new column. - Adds activation_updated_at to host_mdm_apple_declarations so a changed activation regenerates the declaration's effective token, mirroring variables_updated_at and assets_updated_at. - Drops mdm_apple_declaration_activation_references, which was created with the original DDM tables and never written to by any code path.
4157305 to
04216e4
Compare
|
@MagnusHJensen - For your review! Rebased and conflicts fixed. |
**Related issue:** Resolves #50627 # Checklist for submitter - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually ## Database migrations - [x] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [x] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [x] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). ## Details Schema groundwork for `.ipa` setup experience (#33995): - `in_house_apps.install_during_setup` (`TINYINT(1) NOT NULL DEFAULT 0`) — mirrors `software_installers.install_during_setup` and `vpp_apps_teams.install_during_setup`. Since one `.ipa` upload creates one row per platform, the flag is already per-platform and per-team. - `setup_experience_status_results.in_house_app_id` (`INT UNSIGNED NULL`, FK to `in_house_apps.id` `ON DELETE CASCADE`) — mirrors the existing `fk_setup_experience_status_results_va_id` constraint. The cascade is a backstop only; a later sub-task blocks deleting an app that is still assigned. - No new column for the MDM command UUID: the existing `nano_command_uuid` column carries it, same as VPP installs. New columns are numeric, so no collation applies. `ALTER TABLE ... ADD COLUMN` does not touch `in_house_apps.updated_at` values for existing rows. Migration test covers the `0` default for pre-existing rows and the FK cascade. `changes/` entry intentionally omitted, matching the schema-only PR pattern from #50133; the user-visible entry lands with the final sub-task. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for configuring whether in-house apps install during device setup. * Setup experience results can now be associated with a specific in-house app. * Associated setup results are automatically removed when the app is deleted. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Related issue: Resolves #49966
Adds the schema for custom DDM activations (parent story #48222).
mdm_apple_ddm_activations— stores the activation JSON as-is (mediumtext, so the generatedtokencolumn hashes the exact stored bytes) with adeclaration_uuidFK tomdm_apple_declarationsthat cascades on delete.mdm_configuration_profile_variableswithapple_ddm_activation_uuidso activations can carry Fleet variables (needed by CADDM: Validation + Upload API #49970).activation_updated_attohost_mdm_apple_declarationsso a changed activation regenerates the declaration's effective token, mirroringvariables_updated_at/assets_updated_at.mdm_apple_declaration_activation_references— created with the original DDM tables in20240327115530_AddDDMTables.go, never written to by any code path, so it is empty in every deployment.Deviations from the SQL in #49966
The
declaration_uuidFK is the one addition, confirmed with @MagnusHJensen: it keeps the 1:1 lifecycle enforced by the database rather than requiring cleanup in every delete path.configuration_identifieris kept alongside it for validation and DDM serving. Its unique key doubles as the FK's backing index.The rest are corrections needed for the specced SQL to work, all following the precedent in
20260409153715_AddDDMVariablesSupport.go:ck_mdm_configuration_profile_variables_exactly_oneis dropped and re-added to count the new column. That constraint requires exactly one owner column to be non-null; adding a seventh without updating it means any row settingapple_ddm_activation_uuidsums to 0, fails the check, and is rejected.UNIQUE (apple_ddm_activation_uuid, fleet_variable_id)added to match the six existing owner columns. That table's write path isINSERT ... ON DUPLICATE KEY UPDATE, which needs a unique key to collide on.activation_updated_atisDATETIME(6), notTIMESTAMP(6)— its siblings aredatetime(6)andEffectiveDDMTokenformats them into the token string, soTIMESTAMP's session-timezone conversion on read would change tokens and re-push declarations to every host.team_idgetsDEFAULT '0'to matchmdm_apple_declarations, where 0 is Unassigned.Note for #49970
declaration_uuidisNOT NULL, so the upload path must populate it in addition toconfiguration_identifier. The declaration UUID prefix has no separator (MDMAppleDeclarationUUIDPrefix = "d", 1 char + 36-char UUID = the fullvarchar(37)).Checklist for submitter
SELECT *is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters.No changes file: this sub-task adds schema only and ships no user-visible behavior.
Testing
TestUp_20260729115013covers: the stale table is present before and gone after; pre-existingmdm_configuration_profile_variablesrows survive the check constraint replacement (thatADD CONSTRAINTrevalidates every existing row); an activation attaches to a declaration and gets its generated token; the 1:1 unique key and the FK both reject bad inserts; a variable row binds to an activation (the case the old constraint would have rejected); the constraint still rejects two-owner and zero-owner rows; and deleting the declaration cascades to the activation and through it to the activation's variable rows.Also ran the full migrations suite (
MYSQL_TEST=1 go test ./server/datastore/mysql/migrations/...) to confirm no other migration is disturbed, and verified the regeneratedschema.sqldiff contains only changes from this migration.Database migrations
COLLATE utf8mb4_unicode_ci).Neither modified table has an
ON UPDATE CURRENT_TIMESTAMPcolumn, so no rows have their timestamps touched.Summary by CodeRabbit
New Features
Tests