Skip to content

trunk-merge/pr-106919/e81f332e-8631-4e00-abd0-a2d8ef22027f - #108907

Closed
trunk-io[bot] wants to merge 44 commits into
masterfrom
trunk-merge/pr-106919/e81f332e-8631-4e00-abd0-a2d8ef22027f
Closed

trunk-io[bot] wants to merge 44 commits into
masterfrom
trunk-merge/pr-106919/e81f332e-8631-4e00-abd0-a2d8ef22027f

Conversation

@trunk-io

@trunk-io trunk-io Bot commented Sep 30, 2026

Copy link
Copy Markdown
Trunk Merge Pull Request Banner

This pull request was created and is being managed by Trunk Merge.

This pull request is based on the master branch at SHA 1c66a26fd9f969905a64bc564e302f70bee1736d.

See more details about each PR in the batch here:

When CI completes, this pull request will be closed automatically.

Pull Requests Being Tested

This pull request is testing a batch with the changes from pull requests 106919, 108809, 106380, and 106274 - batching documentation.

Pull request 106919 is stacked on pull request 106900, whose changes are included here and will be merged with it.

aspicer and others added 30 commits September 24, 2026 13:11
A query can now choose the native JSON events table or the legacy one
without flipping the instance settings. When the modifier is unset, the
settings decide as before.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A funnel correlation query has no modifiers of its own, and neither does
the persons modal options query, so both ran with team defaults and could
read a different events table than the insight they came from.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Forwarding *args alongside extract_modifiers could pass that argument twice.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A test outside the product must not run its query runners.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The project settings API drops the key from any modifiers update, so a
customer cannot set or clear it and an echoed settings page save keeps
the value staff set in Django admin.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Canvas comment access now follows the space of the canvas. A task id on a canvas comment is optional metadata, and the API checks it only when a comment sets a new one.

Comment activity rows can exist without a task, so the canvas owner and mentioned users get notified. Agents read all threads on a canvas through two new endpoints and MCP tools behind the canvas-comments-mcp flag.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
Rename the base queryset parameter so it does not share a name with the list of thread entries, and look up an artifact owner only when the comment has a task.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
The canvas comment tools add the canvas-comments-mcp flag, so the list of flags that tool definitions use grows to 37.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
- Skills ship to every MCP client, so they no longer name the flag-gated canvas comment tools. The tool descriptions carry that guidance while the flag is on.
- A truncated comment body ends its chunk on a UTF-8 character boundary, so the next chunk does not lose a multibyte character.
- The Slack DM path does not load a task for a canvas comment, because it never reads it.
- The two new canvas comment tests have return annotations.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
Canvas comments now use the scope "canvas". A data migration moves existing "desktop_canvas" rows to the new name, and its reverse moves them back.

Desktop builds that predate the rename still send "desktop_canvas", and pods on the previous release can write it during a deploy. The API accepts that name on input, normalizes it to "canvas", reads rows with either name, and returns "canvas".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
The list filter already accepts both scope names, so it does not convert the query value. Analytics and thread-event payloads only see comments the new code wrote, which already carry "canvas". Desktop converts the activity feed scope itself, so the facade passes the stored value through. The scope names are inlined into the one set and one function that use them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
Pods on the previous release treat "canvas" as an ordinary comment scope: they skip the space check and list those rows in unscoped queries. So this release protects both names but keeps storing "desktop_canvas". The rename of stored rows moves to a follow-up that lands after every pod protects both names.

Canvas comments no longer write activity log rows, because the activity log cannot check the canvas's space. Rows written before this are hidden by the same visibility rule the ticket comment rows use.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
An edit skipped the canvas-to-task check when the stored taskId was unchanged, even if item_id moved the comment to another canvas, and it skipped the check for every reply. Now only a new reply, which takes its link from the root, and an edit that keeps both the stored task and the canvas skip it.

Completing or reopening a canvas comment task no longer writes an activity log row, and the visibility rule hides the rows written before this.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
The comment list looked up Slack mirrors by the requested scope only, so a canvas thread mirrored under the other scope name lost its Slack link in the response. The lookup now matches both canvas scope names, like the comment filter does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
The task comment list and detail endpoints included canvas comments by their taskId and did not check the canvas's space, so a caller who could see the task but not that space could read the comments. Both now include a canvas comment only when the requester can see its canvas. The facade's activity feed uses the same visible-canvas query.

Migration canvas.0021 masks the text of activity log rows written for canvas comments and their replies before comments stopped writing them. Reply rows have the scope "Comment", so the visibility rule could not hide them. The migration finds them per team through the canvas comment roots.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
Regenerated after the rebase onto master. The shared task_id help text now names the canvas scope, and the shorter string fits on one line.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
A canvas comment without a task is checked only against the canvas's space. For a sandbox token that used the user's full channel access, so a task sandbox could read or write comments on a teammate's canvas in a private space the user belongs to. The canvas API gives sandbox tokens only public canvases and canvases the user created. The comment checks now apply the same limit to sandbox requests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
Behind the posthog-desktop-canvas-comments flag, the Comments tab, the breadcrumb button and the text-selection action work on a canvas that no agent task backs. Canvas comment focus is keyed by the canvas, not by a task, and the activity feed accepts rows without a task id.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
The freeform view, the grid view and the breadcrumb now read "comments on" from useCanvasCommentsEnabled instead of three copies of the flag check. The text-selection comment action no longer takes an enabled prop, because the freeform view does not render it when comments are off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
Desktop now sends and reads the scope "canvas" for canvas comments. commentScopeFromWire reads the old name "desktop_canvas" as "canvas", so older task timeline events and deep links still open their canvas thread.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
The activity row wrote comment focus under the canvas key before it knew where activation would go, so the Activity rail, which opens the task, lost the thread. Each activation path now writes focus where its target reads it. The rail opens a canvas comment row that no task backs on the canvas, not on an empty selection.

Canvas comment lists no longer key on the task id, which the backend ignores for canvas threads. TaskCommentsList passes the task id to task-keyed stores and uses the canvas key only for comment focus. The comment scope list is defined once.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
Opening a canvas thread from a task's comment list, or from its timeline through that list, wrote the focus under the task key and then opened the canvas. The canvas reads focus under its own key, so it did not reveal the thread. The list now writes the focus under the canvas key when it opens the canvas.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
The comment list's send-to-agent actions need a task id, and a canvas comment list can now have none. The composer and thread replies offer the action only when a task exists, as the selected-text action already does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b496dfaa-ef83-402b-8d41-4579119729f5
aspicer and others added 13 commits September 29, 2026 15:02
HogQL picks the events table once per query from the context, so the
subquery, person-join and grouped-property cases read the same table
the trends and events-query cases already prove.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- skip heading-like lines inside fenced code when placing page edits
- normalize blank lines only at edit boundaries
- bound llm retries by one caller deadline
- match content boundaries by path segment in both filters
- follow same-site sitemap redirects and keep custom-port pages
- cap the opportunities refresh response
- give CONTENT_AUTOPILOT_MODEL its own default and drop the unused safety model setting

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…t edits

Match fence openers and closers separately, so an info-string fence line
inside a code block no longer closes it and a backtick info string no
longer opens one. Return a named section from _find_section for the
tuple-return semgrep rule, and give the fake client in the call_json
test a type mypy can resolve.
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

🤖 CI report

⚠️ Django migration SQL — 2 new migrations to review

We've detected new migrations on this PR. Review the SQL output for each migration:

products/canvas/backend/migrations/0021_mask_canvas_comment_activity.py

/opt/hostedtoolcache/Python/3.14.7/x64/lib/python3.14/site-packages/anyio/from_thread.py:119: SyntaxWarning: 'return' in a 'finally' block
  return result
/opt/hostedtoolcache/Python/3.14.7/x64/lib/python3.14/site-packages/structlog/stdlib.py:1166: UserWarning: Remove `format_exc_info` from your processor chain if you want pretty exceptions.
  ed = p(logger, meth_name, ed)  # type: ignore[arg-type]
2026-09-30T05:20:01.218827Z [error    ] Path must be a valid database or directory containing databases. [posthog.exceptions_capture] pid=7941 tid=140470999608192
Traceback (most recent call last):
  File "/home/runner/work/posthog/posthog/posthog/geoip.py", line 15, in <module>
    geoip: Optional[GeoIP2] = GeoIP2(cache=8)
                              ~~~~~~^^^^^^^^^
  File "/opt/hostedtoolcache/Python/3.14.7/x64/lib/python3.14/site-packages/django/contrib/gis/geoip2.py", line 116, in __init__
    raise GeoIP2Exception(
        "Path must be a valid database or directory containing databases."
    )
django.contrib.gis.geoip2.GeoIP2Exception: Path must be a valid database or directory containing databases.
/opt/hostedtoolcache/Python/3.14.7/x64/lib/python3.14/site-packages/sshtunnel.py:1040: SyntaxWarning: 'return' in a 'finally' block
  return (ssh_host,
/opt/hostedtoolcache/Python/3.14.7/x64/lib/python3.14/site-packages/langchain_core/_api/deprecation.py:27: UserWarning: Core Pydantic V1 functionality isn't compatible with Python 3.14 or greater.
  from pydantic.v1.fields import FieldInfo as FieldInfoV1
System check identified some issues:

WARNINGS:
?: (axes.W001) You are using the django-axes cache handler for login attempt tracking. Your cache configuration is however invalid and will not work correctly with django-axes. This can leave security holes in your login systems as attempts are not tracked correctly. Reconfigure settings.AXES_CACHE and settings.CACHES per django-axes configuration documentation.
?: (staticfiles.W004) The directory '/home/runner/work/posthog/posthog/frontend/dist' in the STATICFILES_DIRS setting does not exist.
BEGIN;
--
-- Raw Python operation
--
-- THIS OPERATION CANNOT BE WRITTEN AS SQL
COMMIT;

products/tasks/backend/migrations/0133_task_comment_activity_optional_task.py

/opt/hostedtoolcache/Python/3.14.7/x64/lib/python3.14/site-packages/structlog/stdlib.py:1166: UserWarning: Remove `format_exc_info` from your processor chain if you want pretty exceptions.
  ed = p(logger, meth_name, ed)  # type: ignore[arg-type]
2026-09-30T05:20:28.639165Z [error    ] Path must be a valid database or directory containing databases. [posthog.exceptions_capture] pid=8787 tid=139921061690240
Traceback (most recent call last):
  File "/home/runner/work/posthog/posthog/posthog/geoip.py", line 15, in <module>
    geoip: Optional[GeoIP2] = GeoIP2(cache=8)
                              ~~~~~~^^^^^^^^^
  File "/opt/hostedtoolcache/Python/3.14.7/x64/lib/python3.14/site-packages/django/contrib/gis/geoip2.py", line 116, in __init__
    raise GeoIP2Exception(
        "Path must be a valid database or directory containing databases."
    )
django.contrib.gis.geoip2.GeoIP2Exception: Path must be a valid database or directory containing databases.
/opt/hostedtoolcache/Python/3.14.7/x64/lib/python3.14/site-packages/langchain_core/_api/deprecation.py:27: UserWarning: Core Pydantic V1 functionality isn't compatible with Python 3.14 or greater.
  from pydantic.v1.fields import FieldInfo as FieldInfoV1
System check identified some issues:

WARNINGS:
?: (axes.W001) You are using the django-axes cache handler for login attempt tracking. Your cache configuration is however invalid and will not work correctly with django-axes. This can leave security holes in your login systems as attempts are not tracked correctly. Reconfigure settings.AXES_CACHE and settings.CACHES per django-axes configuration documentation.
?: (staticfiles.W004) The directory '/home/runner/work/posthog/posthog/frontend/dist' in the STATICFILES_DIRS setting does not exist.
BEGIN;
--
-- Custom state/database change combination
--
ALTER TABLE "posthog_task_comment_activity" ALTER COLUMN "task_id" DROP NOT NULL;
COMMIT;

Last updated: 2026-09-30 05:20 UTC (7c55c17)

✅ Django migration risk — migration analysis complete

We've analyzed your migrations for potential risks.

Summary: 0 Safe | 2 Needs Review | 0 Blocked

⚠️ Needs Review

May have performance impact

canvas.0021_mask_canvas_comment_activity
  └─ #1 ⚠️ RunPython: RunPython data migration needs review for performance
tasks.0133_task_comment_activity_optional_task
  └─ #1 ✅ SeparateDatabaseAndState
     Wrapper operation - see nested operations for risk: RunSQL
     database_operations: RunSQL
     └─ #2 ⚠️ RunSQL: RunSQL with ALTER may cause locks

📚 How to Deploy These Changes Safely

RunPython:

Use batching for large data migrations:

  • Use .iterator() to avoid loading all rows into memory
  • Use .bulk_update() instead of saving individual objects
  • Batch size: 1,000-10,000 rows per batch
  • Add pauses between batches
  • Consider background jobs for very large updates (millions of rows)

See the migration safety guide

Last updated: 2026-09-30 05:21 UTC (7c55c17)

@trunk-io trunk-io Bot closed this Sep 30, 2026
@trunk-io
trunk-io Bot deleted the trunk-merge/pr-106919/e81f332e-8631-4e00-abd0-a2d8ef22027f branch September 30, 2026 05:22
@trunk-io

trunk-io Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Author

Static Badge   Static Badge   Static Badge

Failed Test Failure Summary Logs
Scenes-App/Feature Flags NewRemoteConfigFlagPayloadError play-test Logs ↗︎
Scenes-App/SidePanels SidePanelNotebooks smoke-test The test timed out while waiting for a loading indicator or spinner to disappear. Logs ↗︎
Layout/Products and files Chat play-test Logs ↗︎

View Full Report ↗︎ ⋅ Docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants