Skip to content

Add DDM custom activations schema - #50133

Merged
raju249 merged 1 commit into
mainfrom
49966-ddm-custom-activations-migration
Jul 31, 2026
Merged

Add DDM custom activations schema#50133
raju249 merged 1 commit into
mainfrom
49966-ddm-custom-activations-migration

Conversation

@raju249

@raju249 raju249 commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Related issue: Resolves #49966

Adds the schema for custom DDM activations (parent story #48222).

  • Creates mdm_apple_ddm_activations — stores the activation JSON as-is (mediumtext, so the generated token column hashes the exact stored bytes) with a declaration_uuid FK to mdm_apple_declarations that cascades on delete.
  • Extends mdm_configuration_profile_variables with apple_ddm_activation_uuid so activations can carry Fleet variables (needed by CADDM: Validation + Upload API #49970).
  • Adds activation_updated_at to host_mdm_apple_declarations so a changed activation regenerates the declaration's effective token, mirroring variables_updated_at / assets_updated_at.
  • Drops mdm_apple_declaration_activation_references — created with the original DDM tables in 20240327115530_AddDDMTables.go, never written to by any code path, so it is empty in every deployment.

Deviations from the SQL in #49966

The declaration_uuid FK is the one addition, confirmed with @MagnusHJensen: it keeps the 1:1 lifecycle enforced by the database rather than requiring cleanup in every delete path. configuration_identifier is kept alongside it for validation and DDM serving. Its unique key doubles as the FK's backing index.

The rest are corrections needed for the specced SQL to work, all following the precedent in 20260409153715_AddDDMVariablesSupport.go:

  • ck_mdm_configuration_profile_variables_exactly_one is dropped and re-added to count the new column. That constraint requires exactly one owner column to be non-null; adding a seventh without updating it means any row setting apple_ddm_activation_uuid sums to 0, fails the check, and is rejected.
  • UNIQUE (apple_ddm_activation_uuid, fleet_variable_id) added to match the six existing owner columns. That table's write path is INSERT ... ON DUPLICATE KEY UPDATE, which needs a unique key to collide on.
  • activation_updated_at is DATETIME(6), not TIMESTAMP(6) — its siblings are datetime(6) and EffectiveDDMToken formats them into the token string, so TIMESTAMP's session-timezone conversion on read would change tokens and re-push declarations to every host.
  • team_id gets DEFAULT '0' to match mdm_apple_declarations, where 0 is Unassigned.

Note for #49970

declaration_uuid is NOT NULL, so the upload path must populate it in addition to configuration_identifier. The declaration UUID prefix has no separator (MDMAppleDeclarationUUIDPrefix = "d", 1 char + 36-char UUID = the full varchar(37)).

Checklist for submitter

  • Input data is properly validated, SELECT * is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters.

No changes file: this sub-task adds schema only and ships no user-visible behavior.

Testing

  • Added/updated automated tests
  • QA'd all new/changed functionality manually

TestUp_20260729115013 covers: the stale table is present before and gone after; pre-existing mdm_configuration_profile_variables rows survive the check constraint replacement (that ADD CONSTRAINT revalidates every existing row); an activation attaches to a declaration and gets its generated token; the 1:1 unique key and the FK both reject bad inserts; a variable row binds to an activation (the case the old constraint would have rejected); the constraint still rejects two-owner and zero-owner rows; and deleting the declaration cascades to the activation and through it to the activation's variable rows.

Also ran the full migrations suite (MYSQL_TEST=1 go test ./server/datastore/mysql/migrations/...) to confirm no other migration is disturbed, and verified the regenerated schema.sql diff contains only changes from this migration.

Database migrations

  • Checked schema for all modified table for columns that will auto-update timestamps during migration.
  • Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects.
  • Ensured the correct collation is explicitly set for character columns (COLLATE utf8mb4_unicode_ci).

Neither modified table has an ON UPDATE CURRENT_TIMESTAMP column, so no rows have their timestamps touched.

Summary by CodeRabbit

  • New Features

    • Added support for Apple DDM custom activations.
    • Added activation-specific tokens and timestamps to support reliable declaration updates.
    • Enabled configuration variables to be associated with a specific activation.
    • Added validation to prevent duplicate or invalid activation associations.
    • Activations and related settings are now automatically removed when their declaration is deleted.
  • Tests

    • Added coverage for activation creation, uniqueness, validation, associations, token generation, and cascading cleanup.

@raju249
raju249 requested a review from a team as a code owner July 29, 2026 12:11
@raju249
raju249 requested a review from MagnusHJensen July 29, 2026 12:12
@raju249 raju249 self-assigned this Jul 29, 2026
@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 9f82bbae-3d07-476a-b65c-016f7898edbd

📥 Commits

Reviewing files that changed from the base of the PR and between f5ca4b5 and 4157305.

📒 Files selected for processing (3)
  • server/datastore/mysql/migrations/tables/20260729115013_AddDDMCustomActivations.go
  • server/datastore/mysql/migrations/tables/20260729115013_AddDDMCustomActivations_test.go
  • server/datastore/mysql/schema.sql

Walkthrough

Adds the mdm_apple_ddm_activations table and removes the stale activation references table. Extends configuration profile variables with activation ownership and constraints, adds host activation timestamps, and updates migration status data. Registers the migration with a no-op rollback. Adds regression tests covering schema changes, token generation, uniqueness, foreign keys, constraint enforcement, data preservation, and cascading deletes.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise and accurately describes the main change: adding DDM custom activation schema.
Description check ✅ Passed The description covers the related issue, checklist items, testing, and database migration notes required by the template.
Linked Issues check ✅ Passed The migration satisfies #49966 by creating the activation table, updating variable association, dropping the stale table, adding tests, and regenerating schema.sql.
Out of Scope Changes check ✅ Passed The changes appear limited to the requested migration, schema update, and test coverage; no unrelated edits are evident.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 49966-ddm-custom-activations-migration

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Jul 29, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 81.48148% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 68.17%. Comparing base (ccfcc65) to head (04216e4).
⚠️ Report is 2 commits behind head on main.

Files with missing lines Patch % Lines
...s/tables/20260729115013_AddDDMCustomActivations.go 81.48% 6 Missing and 4 partials ⚠️
Additional details and impacted files
@@           Coverage Diff           @@
##             main   #50133   +/-   ##
=======================================
  Coverage   68.17%   68.17%           
=======================================
  Files        3934     3935    +1     
  Lines      250983   251037   +54     
  Branches    13440    13440           
=======================================
+ Hits       171098   171142   +44     
- Misses      64551    64557    +6     
- Partials    15334    15338    +4     
Flag Coverage Δ
backend 69.46% <81.48%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

MagnusHJensen
MagnusHJensen previously approved these changes Jul 31, 2026

@MagnusHJensen MagnusHJensen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merge conflict, if you can re-generate the schema that would be great. (Maybe you need to bump this migration timestamp)

Adds the schema for custom DDM activations, letting admins override the
activation Fleet generates for a configuration declaration.

- Creates mdm_apple_ddm_activations, storing the activation JSON as-is with
  a generated token column, linked 1:1 to its configuration declaration by a
  declaration_uuid foreign key that cascades on delete.
- Extends mdm_configuration_profile_variables with apple_ddm_activation_uuid
  so activations can carry Fleet variables, including the unique key its
  upsert path relies on and a replacement check constraint that counts the
  new column.
- Adds activation_updated_at to host_mdm_apple_declarations so a changed
  activation regenerates the declaration's effective token, mirroring
  variables_updated_at and assets_updated_at.
- Drops mdm_apple_declaration_activation_references, which was created with
  the original DDM tables and never written to by any code path.
@raju249
raju249 force-pushed the 49966-ddm-custom-activations-migration branch from 4157305 to 04216e4 Compare July 31, 2026 09:02
@raju249

raju249 commented Jul 31, 2026

Copy link
Copy Markdown
Contributor Author

@MagnusHJensen - For your review! Rebased and conflicts fixed.

@raju249
raju249 merged commit 9d0f510 into main Jul 31, 2026
30 checks passed
@raju249
raju249 deleted the 49966-ddm-custom-activations-migration branch July 31, 2026 09:06
raju249 added a commit that referenced this pull request Aug 12, 2026
**Related issue:** Resolves #50627

# Checklist for submitter

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

## Database migrations

- [x] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [x] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [x] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## Details

Schema groundwork for `.ipa` setup experience (#33995):

- `in_house_apps.install_during_setup` (`TINYINT(1) NOT NULL DEFAULT 0`)
— mirrors `software_installers.install_during_setup` and
`vpp_apps_teams.install_during_setup`. Since one `.ipa` upload creates
one row per platform, the flag is already per-platform and per-team.
- `setup_experience_status_results.in_house_app_id` (`INT UNSIGNED
NULL`, FK to `in_house_apps.id` `ON DELETE CASCADE`) — mirrors the
existing `fk_setup_experience_status_results_va_id` constraint. The
cascade is a backstop only; a later sub-task blocks deleting an app that
is still assigned.
- No new column for the MDM command UUID: the existing
`nano_command_uuid` column carries it, same as VPP installs.

New columns are numeric, so no collation applies. `ALTER TABLE ... ADD
COLUMN` does not touch `in_house_apps.updated_at` values for existing
rows.

Migration test covers the `0` default for pre-existing rows and the FK
cascade. `changes/` entry intentionally omitted, matching the
schema-only PR pattern from #50133; the user-visible entry lands with
the final sub-task.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added support for configuring whether in-house apps install during
device setup.
* Setup experience results can now be associated with a specific
in-house app.
* Associated setup results are automatically removed when the app is
deleted.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CADDM: Migration

2 participants