fix(packages): run composer as a separate process and roll back failed installs - #2485
Merged
Merged
Conversation
…d installs package:installrequire ran Composer inside the artisan process. Composer then replaced the vendor files that process was loading classes from; a class loaded lazily halfway through the update was already gone, every remaining operation failed and the site was left with a broken vendor directory. - Run Composer through ExecWithFallback as a separate process, found the same way the core updater finds it (shared RunsComposerShell trait). The in-process run stays only for hosts where no process can be started. - On failure, or when the site no longer boots afterwards, restore custom/composer.json and composer.lock and reinstall from the old lock. - Pass --minimal-changes where Composer supports it, so shared dependencies move only as far as the new package needs. - package:installautoload rebuilds the autoloader instead of updating every package. - Store "Install by file" recognises a Composer package archive, keeps it in a local artifact repository and queues a console install for it, which works offline when its dependencies are installed. An archive shaped like a Composer package with an unusable composer.json is refused instead of being copied into the web root. - cli-install reports a failed composer update instead of passing over it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Store module shipped 6 of the 22 manager languages, and loaded only the manager language's file, so a key missing from a translation showed nothing. English is now loaded first and the manager language on top of it, and the Composer archive messages are translated into all 22 languages. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Only sk and uk defined it and nothing reads it; the author label comes from popup_author. A test now keeps translations from carrying keys en lacks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
package:installrequire ran Composer inside the artisan process. Composer then replaced the vendor files that process was loading classes from; a class loaded lazily halfway through the update was already gone, every remaining operation failed and the site was left with a broken vendor directory.