Skip to content

Reconcile upstream v3.2.1 and preserve PSF fork history - #7

Open
JacobCoffee wants to merge 627 commits into
v3.0.1-psffrom
sync/v3.2.1-psf
Open

JacobCoffee wants to merge 627 commits into
v3.0.1-psffrom
sync/v3.2.1-psf

Conversation

@JacobCoffee

@JacobCoffee JacobCoffee commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Changes

Reconcile the PSF fork with the latest published upstream CE release, v3.2.1, and prepare the operator-owned deployment-branch transition from v3.0.1-psf to v3.2.1-psf.

Merge with a merge commit, not squash/rebase. The repository currently permits only squash merges. An administrator must enable merge commits before merging this PR; no repository settings have been changed by this work.

  • Restore ancestry lost by PR Sync with upstream plausible/analytics #2's squash merge. Original merge ec3f81de488b7aa9a6dcffc03cb9b33bcb53cda1 and squash commit 2d3391215fd26fe3a4a2e54c083e4ffb5ebe7b60 have identical trees. The ancestry-repair commit introduces no file-content changes.
  • Incorporate upstream tag v3.2.1 while retaining imported master snapshot dc51b4cc9c7107d9bed63fbe594c7c81fe702238. This is not a reset to stock v3.2.1; the versioned branch names the latest incorporated CE release and retains the already-imported later changes.
  • Keep all application/runtime content identical to security-fix baseline c4659937df40ab35a8c0aa2ba2f8dc6e8b88fa18. Only workflows, README, and changelog differ.
  • Reconcile upstream action updates without reintroducing Blacksmith runners. Preserve GitHub-hosted runners, unit-test partitions, four E2E shards, and the MinIO source-build repair.
  • Run ordinary CI on v*-psf branches; compare Credo/tracker changes against the PR base rather than the stale upstream master mirror. Do not broaden inherited publishing or Terraform deployment triggers.
  • Document release-tag synchronization, the retained upstream snapshot, and the manual branch cutover.

Preserved PSF behavior

  • Landing page, controller, and public dashboard links.
  • Cabotage Unix socket support, Dockerfile, and Procfile.
  • Existing PostgreSQL and ClickHouse migration history, PSF replication topology adjustments.
  • Google API/GA4 import changes.
  • Storybook security removal and the MinIO CI repair.

Verification

  • Original merge and squash trees match; ancestry-repair tree exactly matches its first parent.
  • Both upstream v3.2.1 and the previously imported master snapshot are ancestors of this branch.
  • All files outside .github/workflows/, README.md, and CHANGELOG.md are unchanged from c4659937df.
  • Production Docker image build passed as psf-plausible:reconcile-v3.2.1 (existing runtime build layers reused).
  • Network-isolated compiled-release smoke: all four Storybook paths resolve only to the normal dashboard fallback, and Storybook module/dependency are absent.
  • Compiled PSF landing action returns packaged HTML with status 200; HTTPS_UDS selects the configured Unix socket and port 0.
  • actionlint v1.7.7 passed for all workflows (embedded shell/Python lint disabled).
  • GitHub CI results pending after opening this PR.

These release checks exercise compiled routing, the landing action, and runtime configuration; they are not live HTTP or database-backed integration tests.

Operator-owned merge and cutover

This PR does not change the default branch, branch rules, Cabotage settings, production workloads, or credentials. The review branch is sync/v3.2.1-psf, leaving the intended deployment name available for the eventual rename.

  • Wait for CI and review; enable merge commits in repository settings.
  • Coordinate auto-deploy before merging: Cabotage still tracks v3.0.1-psf, so merging there can trigger its existing deployment automation.
  • Merge this PR with a merge commit, not squash/rebase.
  • Rename the reviewed deployment branch to v3.2.1-psf; update default branch, branch rules, and Cabotage's tracked branch together.
  • Verify the deployed source commit/image digest and application health.

No database-backed migration rehearsal is claimed: this PR changes no migration or application code. Credential remediation from ENG-14 remains separate from this reconciliation.

Gen by 🤖

zoldar and others added 30 commits October 23, 2025 07:28
…5809)

* Add tests for query timezones

* Test timezones at controller level

* Remove v1 controller tests for ambigous times

* Add tests for legacy_time_on_page_cutoff

* Add test for generic cutoff timezone behaviour without gaps
* add module name to service_error when check times out

Otherwise, it can sometimes remain unclear in the diagnostics, whether
it was InstallationV2 or InstallationV2CacheBust that timed out.

* Remove duplicate timeout logic

The current production logs show two types of verification timeouts:

* service_error: "Unhandled Browserless response status: 408" (vast
  majority of cases)
* service_error: :timeout (only a few cases)

The latter happens when we hit the Req receive_timeout
(endpoint_timeout + 2s). I've seen Browserless not respect the timeout
param from time to time, so it's better to keep the timeout logic
"in-house" only.

* make service_error into a map with code and extra

* interpret temporary service errors

...but still consider them "unhandled" for telemetry, also notifying Sentry
and logging the warning.

* separate sentry messages (verification)

* make Verification.ChecksTest more DRY

* organize tests into describe blocks

* test verification telemetry and logging

* fix codespell

* pass timeout as query param to Browserless too
* add module name to service_error when check times out

Otherwise, it can sometimes remain unclear in the diagnostics, whether
it was InstallationV2 or InstallationV2CacheBust that timed out.

* Remove duplicate timeout logic

The current production logs show two types of verification timeouts:

* service_error: "Unhandled Browserless response status: 408" (vast
  majority of cases)
* service_error: :timeout (only a few cases)

The latter happens when we hit the Req receive_timeout
(endpoint_timeout + 2s). I've seen Browserless not respect the timeout
param from time to time, so it's better to keep the timeout logic
"in-house" only.

* make service_error into a map with code and extra

* interpret temporary service errors

...but still consider them "unhandled" for telemetry, also notifying Sentry
and logging the warning.

* separate sentry messages (verification)

* make Verification.ChecksTest more DRY

* organize tests into describe blocks

* test verification telemetry and logging

* fix codespell

* get rid of legacy verification

* rename Checks.InstallationV2 -> Checks.VerifyInstallation

* delete Live.Installation and rename Live.InstallationV2 -> Live.Installation

* rename installationv2 (live) files as well

* delete old change-domain routes

Also rename current liveview modules and routes, removing the v2 suffix

* rename domain_change_v2 files, removing v2 suffix

* remove legacy JS verifier code

Also fix dockerignore and elixir.yml referencing a wrong priv path

* rename verification_v2_test -> verification_test

* remove v2 prefix from logs and sentry messages

* clean up duplicate external_sites_controller_test.exs tests

* remove flag

* fix typespec

* pass timeout as query param to Browserless too

* Fixup external sites controller test module (plausible#5826)

* fix test description

---------

Co-authored-by: Artur Pata <artur.pata@gmail.com>
* add module name to service_error when check times out

Otherwise, it can sometimes remain unclear in the diagnostics, whether
it was InstallationV2 or InstallationV2CacheBust that timed out.

* Remove duplicate timeout logic

The current production logs show two types of verification timeouts:

* service_error: "Unhandled Browserless response status: 408" (vast
  majority of cases)
* service_error: :timeout (only a few cases)

The latter happens when we hit the Req receive_timeout
(endpoint_timeout + 2s). I've seen Browserless not respect the timeout
param from time to time, so it's better to keep the timeout logic
"in-house" only.

* make service_error into a map with code and extra

* interpret temporary service errors

...but still consider them "unhandled" for telemetry, also notifying Sentry
and logging the warning.

* separate sentry messages (verification)

* make Verification.ChecksTest more DRY

* organize tests into describe blocks

* test verification telemetry and logging

* fix codespell

* get rid of legacy verification

* rename Checks.InstallationV2 -> Checks.VerifyInstallation

* delete Live.Installation and rename Live.InstallationV2 -> Live.Installation

* rename installationv2 (live) files as well

* delete old change-domain routes

Also rename current liveview modules and routes, removing the v2 suffix

* rename domain_change_v2 files, removing v2 suffix

* remove legacy JS verifier code

Also fix dockerignore and elixir.yml referencing a wrong priv path

* rename verification_v2_test -> verification_test

* remove v2 prefix from logs and sentry messages

* clean up duplicate external_sites_controller_test.exs tests

* remove flag

* fix typespec

* pass timeout as query param to Browserless too

* Fixup external sites controller test module (plausible#5826)

* fix test description

* clean up detection sentry events + tests

* improve naming

---------

Co-authored-by: Artur Pata <artur.pata@gmail.com>
* Broadcast tracker script config updates

* Fix broadcast_put typespec

* Preload site association on CE

* Stop preloading uselessly

* Reload tracker_script_config on CE only
* Crop big consolidated views

* number format
…ible#5834)

* Set Consolidated View's timezone to what majority of sites has

* clean up
* Display 24h charts in CRM

* Move New Custom Plan button to the top of the page

* Allow custom plan deletion

* Add managed proxy price modifier to custom plan estimation
* make timeout configurable for a check via check_opts

* add an internal_check_timeout test case to verification/checks_test.exs

* move verification observability tests to a separate file

... make it sync and test capturing Sentry events too

* separate detection observability checks too

* test sentry events in detection

* consider internal check timeouts browserless issues in detection too

* test util function defs to ee_only
* Improve dark mode

- Switch from `slate` to `zinc` for the gray color palette
- Darken overall dark mode UI
- Switch from `green` to `emerald` for the green color palette
- Update a few previously missed instances of title case to sentence case
- Consolidate button styles and change naming from `bright` to `secondary`
- Update button disabled styles
- Fix tooltip not adjusting to content width
- Update graph tooltip layout and typography
- Add transition effects to hover states
- Reduce footer logo size

* Fix oversights

- Update funnel graph colors
- Update graph grid colors
- Improve focus styles
- Improve disabled input styles

* Fix more oversights in relation to dashboard filtering

- Improve consistency of input, button, combobox and modal components in relation to settings area
- Fix segment tooltip color

* Fix search input style in funnel and segments dropdowns

* Add white background to favicon images in dark mode

- The GitHub and ChatGPT favicons are hard to see in dark mode, so we add a white background to them.

* Fix tooltip color to fit all backgrounds in dark mode

* Fix tests

* Fixed more tests

* Extract SourceFavicon component to eliminate favicon duplication

* Fix regression on installation page after rebase

* Fix formatting issues

* Fix favicon test failure in CI by reading placeholder icon at compile time

* Undo previous commit
* Update playwright to 1.56.1

* chore: Bump tracker_script_version to 33

* Run audit fix for /assets

---------

Co-authored-by: apata <apata@users.noreply.github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 5.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v5)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 5 to 6.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v5...v6)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Added dark mode change to CHANGELOG.md
- Fixed broken `WithImportedSwitch` icon focus outline
- Updated comments in `app.css` referencing old color scheme
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 5 to 6.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Cenk Kücük <cenk@plausible.io>
- Update tab component visually for extra affordance
…le#5838)

* Update site switcher UI to accommodate for consolidated view

* Implement logic to display consolidated view in site picker

* Fix "All sites" selected state in site switcher

* Fixup tests

* Include consolidated view assigns in shared links

* Format

* Extract `ConsolidatedView.ok_to_display?/2`

* Format

* I'll pretend no one saw this

* Skip unnecessary `on_ee`

* oops

---------

Co-authored-by: Adam Rutkowski <hq@mtod.org>
* add opts to Check.perform signature

* increase domain change detection timeout to 11s

* same footer after submit + docs link

* domain change flow improvements

* fix for CE

* fix link

* rename to @plausible-analytics/tracker

* change icon
* Update site_setup_help_email.html.heex

* Update welcome_email.html.heex

* Update create_site_email.html.heex

* Fix formatting

* Fix flakiness due to sync persistor tests not cleaning up

* Update tests

* Fix CE tests

---------

Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>
* Enhance TypeScript definitions for Plausible tracking library

Updated the plausible.d.ts file to improve documentation by adding JSDoc comments for all functions and properties. This enhances clarity and usability for developers integrating the tracking library.

* Update CHANGELOG.md to reflect changes in TypeScript definition comments for improved IDE integration

* Format

* Remove subtitle from changelog

---------

Co-authored-by: Ahmed Hassanein <eng.a7mad.gamal@gmail.com>
metmarkosaric and others added 28 commits March 16, 2026 11:17
* Changing the note on top of a new dashboard

Changing the note on top of a new dashboard and adding a custom event to track clicks

* Update first_dashboard_launch_banner.ex

* Fix formatting and use route helper instead of URL string

---------

Co-authored-by: Adrian Gruntkowski <github@todo.computer>
…le#6153)

* fix

* Revert "fix"

This reverts commit 24c1b0d.

* Reapply "fix"

This reverts commit 98298f3.

* Test

* Remove unused import

* await lv

* err

* Fix e2e regressiont test

---------

Co-authored-by: Adrian Gruntkowski <github@todo.computer>
* Remove Sites.list() in favour of Sites.Index

* Implement basic sort options widget

@sanne-san pls review 🙏

* Attempt to indicate pinned sites

cc @sanne-san

* Remove Scrivener

* Format

* Update mix.lock

* Tweak sorting and pinning UI

- Moved sorting dropdown to the right of the top bar
- Changed pin icon behaviour to be a quick action button to unpin, and leaving the ellipsis menu always visible

* Add sorting loading state

* Fix pinning tests

* Make CI pass

* Move pin icon to `Icons` module

* Indicate pinned status in CRM

* Store user sort preference; migration to be extracted

* Move @sort_options if we intend to keep it as a module attribute

* Implement feedback

- Change "Most visitors" to "Visitors, high to low" and "Fewest visitors" to "Visitors, low to high" in the sort dropdown.
- Add dedicated styles to Prima dropdown, rather than using button styles directly, as they diverge from button styles in a few ways.
- Add data-sort-trigger attribute to sort dropdown so that loading state only applies to sorting, not to pinning/unpinning.
- Add padding to search form to ensure consistent height with other form elements.
- Ensure dropdown menu is always at least as wide as the trigger button.
- Changed site card hover effect to shadow-md instead of shadow-lg.

* Revert removal of unused css

- These changes weren't supposed to go into this PR

* Fixup tests

* Test no sort order persistence for guests (there's nowhere to store it)

* Update changelog

* Migration: store one map per membership wrt sort preferences

* Use unified sorting preferences object

* Cosmetics

* Lose track of `filter_by_domain` in `Sites.Index`

It's irrelevant to carry over

* Rework index build/pagination options

* Fix typespecs

* Remove unused uri argument

* Avoid passing URI around, maintain uri params instead

* Remove unused assigns

* Use prima's match_trigger_width instead of custom JS override

- Upgrade prima to 0.2.6 and replace the custom Dropdown hook that manually set min-width with the built-in match_trigger_width={true}.

* Skip an iteration

* Update lib/plausible_web/live/sites.ex

Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>

* Keep `filter_text` socket assign after all

* Turn sort_options into a list again to avoid undefined ordering

* Use path helpers for :stats

* Fix compilation error

* Use PlausibleWeb.Endpoint to enable path helpers

* Use an embed to store sort preferences

* Restructure index user preference

* Remove unused component attrs

* Remove validate_inclusions covered by Ecto.Enum type

---------

Co-authored-by: Sanne de Vries <sannedv@protonmail.com>
Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>
* fix graph crashing

* do not attempt to link to __blank__ period
)

* Bring back trigger showing first dashboard launch banner

* Use CSS class instead of onclick event
* Update welcome_email.html.heex

* Update site_setup_success_email.html.heex

* Update site_setup_help_email.html.heex

* Update create_site_email.html.heex

* Update check_stats_email.html.heex

* Update trial_one_week_reminder.html.heex

* Update trial_over_email.html.heex

* Create trial_ending_tomorrow.html.heex

* Update trial_ending_tomorrow.html.heex

* Create trial_ending_today.html.heex

* Update email.ex

* Update send_trial_notifications.ex

* Update send_trial_notifications.ex

* Update email.ex

* Apply formatting

* Remove unused argument from one of email functions

* Make tests account for new phrasing of emails

---------

Co-authored-by: Adrian Gruntkowski <github@todo.computer>
Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>
* API v2: fix returning buckets outside of queried range

* For time:hour and time:minute, sessions are smeared using time_slots.
  The fix is to filter out time_slots that fall outside of the utc boundaries

* For any other time dimension, there's no session smearing, but since
  sessions are put into time buckets by the last event timestamps, the
  query might return buckets that are outside of the query time range.
  The fix is to clamp those sessions into the last bucket instead.

* allow time dimensions when querying views_per_visit

* update changelog

* stop generating bad timeslots instead
* Move subscription settings page content into a LiveView

Prepares the page to host the choose_plan modal as a LiveComponent in a follow-up PR. Pure refactor, no UX changes.
- Extract subscription page content into a new SubscriptionSettings LiveView
- Move data loading out of the controller and into the LiveView
- Embed the LiveView in the existing settings layout via live_render

* Incorporate feedback

- Render SubscriptionSettings LiveView directly from the router instead of via a controller action and template
- Update the shared settings layout to work without a request object
- Move view helpers from SettingsView to the billing components module

* Fix Alpine.js attribute warnings in settings templates

* Update lib/plausible_web/live/components/form.ex

Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>

* Update lib/plausible_web/live/components/form.ex

Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>

* Update lib/plausible_web/live/subscription_settings.ex

Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>

* Update lib/plausible_web/templates/layout/settings.html.heex

Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>

* Incorporate more feedback

- Move billing helpers to a dedicated Helpers module
- Add a CurrentPath plug to the settings pipeline so we can avoid all the branching in the layout template
- Remove conn dependency from the settings layout

* Address remaining PR review feedback

- Use `conn.request_path` instead of `Path.join` in CurrentPath plug
- Remove unused `%Plug.Conn{}` clause from `account_settings_sidebar`
- Use dot notation for always-present assigns in `account_settings_sidebar`

* Add SettingsContext on_mount hook for settings LiveViews

---------

Co-authored-by: Adrian Gruntkowski <adrian.gruntkowski@gmail.com>
* Fix flaky test

* Another one

* Fixup
* Update ua_inspector

* use upstream again

* Add test against regression

---------

Co-authored-by: Adam Rutkowski <hq@mtod.org>
* Escape goal name in the funnel tooltip to prevent XSS

* Remove unnecessary use of String()

---------

Co-authored-by: Adam Rutkowski <hq@mtod.org>
* Export BEAM processes to OTLP metrics endpoint

* fix max nesting

* update mix.lock

* switch to Enum.map insted
The original merge ec3f81d has the same tree as squash commit 2d33912. Record it as a parent while preserving every file from the current patched PSF branch.
Retain the already-imported master snapshot and all runtime behavior from c465993. Incorporate upstream release ancestry and compatible action updates; prepare versioned deployment-branch CI and document the operator-owned cutover. This PR must be merged with a merge commit, not squashed.
@JacobCoffee

Copy link
Copy Markdown
Member Author

ooh all green - scary

@JacobCoffee

Copy link
Copy Markdown
Member Author

will review tmrw morning

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants