Skip to content

fix(packages): run composer as a separate process and roll back failed installs - #2485

Merged
Seiger merged 3 commits into
evolution-cms:3.5.xfrom
elcreator:composer-out-of-process
Sep 30, 2026
Merged

Seiger merged 3 commits into
evolution-cms:3.5.xfrom
elcreator:composer-out-of-process

Conversation

@elcreator

Copy link
Copy Markdown

package:installrequire ran Composer inside the artisan process. Composer then replaced the vendor files that process was loading classes from; a class loaded lazily halfway through the update was already gone, every remaining operation failed and the site was left with a broken vendor directory.

  • Run Composer through ExecWithFallback as a separate process, found the same way the core updater finds it (shared RunsComposerShell trait). The in-process run stays only for hosts where no process can be started.
  • On failure, or when the site no longer boots afterwards, restore custom/composer.json and composer.lock and reinstall from the old lock.
  • Pass --minimal-changes where Composer supports it, so shared dependencies move only as far as the new package needs.
  • package:installautoload rebuilds the autoloader instead of updating every package.
  • Store "Install by file" recognises a Composer package archive, keeps it in a local artifact repository and queues a console install for it, which works offline when its dependencies are installed. An archive shaped like a Composer package with an unusable composer.json is refused instead of being copied into the web root.
  • cli-install reports a failed composer update instead of passing over it.

elcreator and others added 3 commits September 30, 2026 02:05
…d installs

package:installrequire ran Composer inside the artisan process. Composer then
replaced the vendor files that process was loading classes from; a class
loaded lazily halfway through the update was already gone, every remaining
operation failed and the site was left with a broken vendor directory.

- Run Composer through ExecWithFallback as a separate process, found the same
  way the core updater finds it (shared RunsComposerShell trait). The
  in-process run stays only for hosts where no process can be started.
- On failure, or when the site no longer boots afterwards, restore
  custom/composer.json and composer.lock and reinstall from the old lock.
- Pass --minimal-changes where Composer supports it, so shared dependencies
  move only as far as the new package needs.
- package:installautoload rebuilds the autoloader instead of updating
  every package.
- Store "Install by file" recognises a Composer package archive, keeps it
  in a local artifact repository and queues a console install for it, which
  works offline when its dependencies are installed. An archive shaped like
  a Composer package with an unusable composer.json is refused instead of
  being copied into the web root.
- cli-install reports a failed composer update instead of passing over it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Store module shipped 6 of the 22 manager languages, and loaded only the
manager language's file, so a key missing from a translation showed nothing.
English is now loaded first and the manager language on top of it, and the
Composer archive messages are translated into all 22 languages.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Only sk and uk defined it and nothing reads it; the author label comes from
popup_author. A test now keeps translations from carrying keys en lacks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Seiger
Seiger merged commit c0ff431 into evolution-cms:3.5.x Sep 30, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants