UPSTREAM FIX

magento2-33161: Removes invalid preferences from Catalog and RemoteStorage di.xml

Community fix magento2-33161 merged into magento/magento2 on 2024-11-12, released in 2.4.8; applies cleanly to 27 releases from 2.4.6 to 2.4.7-p10.

Removes invalid preferences from Catalog and RemoteStorage di.xml edited

Pull request title
Allow only valid preferences during setup:di:compile
Pull request
magento/magento2#33161
Issues
#38517 pr-derived
Author
@fredden
Merged
2024-11-12
Fixed in
2.4.8
Reported on
—
Categories
—
Components
magento/module-catalog, magento/module-remote-storage

Labels

Area
Framework
Component
Setup
Priority
P3
Severity
—
Reported on (labels)
—

Issue

Title and steps come from the upstream issue and pull request.

Description

The setup:di:compile command has exclude lists to avoid loading / compiling dependency injection for 'test' classes. When preferences exist for these excluded classes, any plugins associated with the original classes are (potentially) rendered useless. This is because the child class (preference) can call the original class in a way which does not use Magento's plugin system (ie, parent::methodName()). And it's impossible to plugin a class that does not go through Magento's compilation process (to have interceptors created, etc). See https://github.com/magento/security-package/issues/296 for a real-world example of this problem in action.

Steps to reproduce

1. Create a preference for a class which does not exist. The "for" class can exist or not; the "type" class should not exist.
1. Create a preference for a class which is specifically excluded (like a "test" class). The "for" class can exist or not; the "type" class should exist, but not be eligible for dependency compilation - for example if the path includes Test.

Before this pull request, these would silently fail; after this pull request, an error is shown.

Taken from the upstream pull request.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: passes before (after: error)unit: passes before, could not run after
2.4.8
2.4.8 conflictcontains the fix 2.4.8-p1 conflictcontains the fix 2.4.8-p2 conflictcontains the fix 2.4.8-p3 conflictcontains the fix 2.4.8-p4 conflictcontains the fix 2.4.8-p5 conflictcontains the fix
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 78.3%. Probability it is security relevant: 10.5%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 85.2%, feature 8.3%, refactor 3.9%, dependency 1.1%, tests_only 1.1%, docs_only 0.4%68.2%
Areaframeworkframework 97.1%, admin 0.9%, other 0.5%93.6%
Reported versionunspecifiedunspecified 18.4%, 2.4.6 2.3%, 2.4.9 2.3%3.2%
Scope1.24 of 21 57.7%, 2 33.4%, 0 8.9%17.8%
Risk0.68 of 20 44.0%, 1 43.6%, 2 12.4%9.8%
Worth backporting1.24 of 22 44.6%, 1 34.8%, 0 20.6%4.4%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-33161/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (2): magento/module-catalog, magento/module-remote-storage
Bundle README (what the ZIP ships)
# magento2-33161

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/33161
Issue: https://github.com/magento/magento2/issues/38517
Author: @fredden
Source commit: 59e9ddd03fec3e42804e3ad514d78a551f0c1ad2
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.