Low-severity follow-ups found while reviewing the tenancy-adoption stack (#385–#395).
- The permission editor drops a role's code-mapped permissions until restart.
modules/permissions/permissions/service.py:~117-118 pops _role_map[role] and re-maps only the DB keys.
- The branding reaper deletes the bytes before its own commit.
FileStorageService.delete flushes the soft-delete and deletes the backend object, and only then does branding/reaper.py commit.
- If that commit fails, the row stays live with no bytes.
- Fix: commit the soft-delete first, then delete the object, or leave orphaned objects to a janitor.
branding/tenant_branding.py _INFLIGHT is module-global, shared across app instances in one process. In tests, a failed read that every waiter cancelled can log "exception never retrieved".
Low-severity follow-ups found while reviewing the tenancy-adoption stack (#385–#395).
modules/permissions/permissions/service.py:~117-118pops_role_map[role]and re-maps only the DB keys.userrole in the editor drops the code-mapped grants:users.self_profile, file_storage's grants, and, on single-tenant installs,dashboard.view(dashboard: platform-wide stats cache and unscoped User counts need a tenant decision #374).FileStorageService.deleteflushes the soft-delete and deletes the backend object, and only then doesbranding/reaper.pycommit.branding/tenant_branding.py_INFLIGHTis module-global, shared across app instances in one process. In tests, a failed read that every waiter cancelled can log "exception never retrieved".