[4.x] Revert to the previous context when a runForMultiple() or central() callback throws - #1488
GautierDele wants to merge 1 commit into
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthrough
ChangesTenancy cleanup
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The tenancy-restoration change is ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change reduces the risk of work continuing under the wrong tenant after a callback fails. Restoration still depends on tenancy cleanup completing successfully, and the behavior of production callers and listeners has not been fully established. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the tenant trail, Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #1488 +/- ##
============================================
- Coverage 86.89% 86.88% -0.01%
Complexity 1252 1252
============================================
Files 186 186
Lines 3654 3653 -1
============================================
- Hits 3175 3174 -1
Misses 479 479 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
|
Hello @stancl,
Also, do you have any release date estimation for v4 ? Quite interested by it ! |
Tenancy::run()reverts to the previous context in afinallysince b9cc63f, butrunForMultiple()andcentral()still restore it only after the callback returns. When the callback throws:runForMultiple()stays initialized for the tenant whose callback threw, instead of returning to the original tenant or to the central context.central()stays in the central context instead of re-initializing the previous tenant, although its docblock says it is atomic and safely reverts to the previous context.This reaches beyond user code:
UpdateOrCreateSyncedResource,DeleteResourcesInTenantsandRestoreResourcesInTenantsall walk the tenants withrunForMultiple(). A write refused in one tenant's database (a NOT NULL or unique constraint, for instance) leaves the rest of the request or job running against that tenant's connection, cache and filesystem.This PR wraps both in
try/finally, the wayrun()already does. When the callback returns normally nothing changes, including the valuecentral()returns.Tests:
runForMultiple reverts to the original context when the closure throws, starting from the central context and from a tenant contextcentral helper reverts back to tenant context when the callback throwsAll three cases fail on
masterand pass with the change. PHPStan reports no errors onsrc/Tenancy.php.3.x has the same defect, and
Tenant::run()there has nofinallyeither. A backport covering all three follows.Summary by CodeRabbit