# Reproduce the wpmgr measurements

Recorded on September 28, 2026 with Atlas CE v1.3.0, ptah-compat 0.10.0 and
PostgreSQL 16.15. PostgreSQL ran on Docker context `remote-dev-container`, and
both CLIs connected through an SSH forward.

wpmgr is licensed under AGPL-3.0. This directory holds no copy of its files:
it holds the commands, the two SQL inputs written for this post, and what the
commands printed. `commands.json` records the working directory, the argument
list, the names of the environment variables each command set, the exit code
and the time of every step.

## Inputs

| What | Where |
| --- | --- |
| wpmgr before the fixes | `mosamlife/wpmgr` at `2c471d2e490f3724af5d8775684d31850352a85f` |
| wpmgr after #762 | `mosamlife/wpmgr` at `8b81b3e334b8f68a66005acf5a74e610ed1c348b` |
| The #760 proposal | `stokaro/showcase-wpmgr` at `bc7fc30101ed89adeb67c68a3c34be8657334c78` |
| ptah-compat 0.10.0 | `ptah_0.10.0_darwin_arm64.tar.gz` from the stokaro/ptah release, checked against its `checksums.txt` |
| Atlas CE v1.3.0 | built from the `v1.3.0` tag of ariga/atlas, the build stokaro/ptah-atlas-conformance pins |

`go install ptah.run/cmd/ptah-compat@v0.10.0`, the install command in the post's
last section, was checked with Go 1.27.1 and built a binary that reports
`v0.10.0` (`measured/27-go-install.txt`).

The Atlas binary reports `atlas community version v1.3.0`. Because it was
built from source rather than downloaded, its version output also carries
Atlas's pointer to the official downloads.

Run the commands from `apps/api` of the matching checkout, with a throwaway
PostgreSQL 16 server. `ATLAS_DEV_URL` names a dev database on it; the Atlas
runs and the ptah-compat runs used different databases on the same server.
The migrations create roles in `DO` blocks, so the ptah-compat runs also set
`PTAH_DEV_SERVER_DISPOSABLE=1`, which declares the whole server throwaway.
Never point it at a server that holds anything you want to keep.

## Before the fixes, at 2c471d2

```console
atlas migrate diff probe --env local
atlas migrate hash --dir file://migrations
atlas migrate diff probe --env local
```

The first run stops on the checksum (`measured/03-main-atlas-diff.txt`). After
the hash, the second fails to load `db/schema.sql`, because a policy on `sites`
reads `site_shares` before the file creates it
(`measured/05-main-atlas-diff-after-hash.txt`).

```console
atlas migrate apply --dir file://migrations --url "$REPLAY_URL"
```

`REPLAY_URL` is another empty database. `measured/07-replay-counts.txt` counts
the tables and policies in `public` after the 145 migrations. Steps 08 to 11
count `CREATE TABLE` and `CREATE POLICY` lines in `db/schema.sql` at both
commits with `grep -c`.

Steps 12 and 13 take the `getBackupScheduleForSite` query from
`internal/db/sqlc/backups.sql.go` at each commit and run `PREPARE` on the
migrated database. The query sqlc generated at `2c471d2` names a dropped
column; the one at `8b81b3e` prepares.

## After #762, at 8b81b3e

```console
atlas migrate validate --env local
atlas migrate diff probe --env local
ptah-compat migrate diff probe --env local
```

All three exit 0, and both diffs report the directory synced.

Append `site-scope-policy.sql` to `db/schema.sql`, then:

```console
atlas migrate diff site_scope --env local
ptah-compat migrate diff site_scope --env local
ptah-compat migrate diff site_scope_again --env local
atlas migrate validate --env local
```

Atlas reports synced and `git status --porcelain -- migrations` stays empty
(steps 17 and 18). ptah-compat writes a migration and updates `atlas.sum`
(steps 19 and 20); `measured/21-policy-migration.sql` is the file it wrote. Its
second run reports synced, and Atlas validates the directory with the new file
in it.

## The #760 drift check, at bc7fc30

From the repository root:

```console
bash scripts/check-schema-drift.sh
```

`WPMGR_PTAH_COMPAT` names the ptah-compat binary. The check passes
(`measured/24-guard-in-sync.txt`). Then copy `drift-probe.sql` to
`apps/api/migrations/20261001000000_drift_probe.sql`, re-hash with
`ptah-compat migrate hash --dir file://migrations` from `apps/api` so the
checksum is not what fails, and run the check again. It exits 1 and prints the
difference (`measured/26-guard-drift.txt`).

## Scope and normalization

These are two wpmgr commits, one proposal branch, one added policy and one
PostgreSQL version. No paid Atlas edition was run.

`site-scope-policy.sql` was written for this post with the predicate wpmgr's
m132 migration uses for the tables it already covers.

Captured output has trailing whitespace removed. Checkout paths read as
`/wpmgr@<commit>`, the macOS temporary directory as `$TMPDIR/`, and the
disposable database password as `[REDACTED]`. `verified.json` keeps the
SHA-256 of each file before normalization when normalization changed it.
Remove the disposable databases and containers when finished.
