magento2-40080: Exceptions for a negative ?p= value on category and search result pages
Community fix magento2-40080 merged into magento/magento2 on 2025-11-19, released in 2.4.9.
Fixes exceptions for a negative ?p= value on category and search result pages edited
- Pull request title
- Negative `?p=` query string causes ElasticSearch exception
- Pull request
- magento/magento2#40080
- Issues
- #40079 human
- Author
- @lbajsarowicz
- Merged
- 2025-11-19
- Fixed in
- 2.4.9
- Reported on
- 2.4.7-p6
- Categories
- Catalog/Product
- Components
- magento/module-catalog, magento/module-catalog-search
Labels
- Area
- Catalog
- Component
- Catalog
- Priority
- P2
- Severity
- —
- Reported on (labels)
- 2.4.7-p6
Issue
Title and steps come from the upstream issue and pull request.
Description
2. Exception log
[2025-07-18T08:51:57.205541+00:00] .CRITICAL: Elasticsearch\Common\Exceptions\BadRequest400Exception: {"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"numHits must be > 0; please use TotalHitCountCollector if you just need the total hit count"}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[{"shard":0,"index":"local__product_1_v3","node":"6QGS43UJRPuMWbWoEdD4vA","reason":{"type":"illegal_argument_exception","reason":"numHits must be > 0; please use TotalHitCountCollector if you just need the total hit count"}}],"caused_by":{"type":"illegal_argument_exception","reason":"numHits must be > 0; please use TotalHitCountCollector if you just need the total hit count","caused_by":{"type":"illegal_argument_exception","reason":"numHits must be > 0; please use TotalHitCountCollector if you just need the total hit count"}}},"status":400} in /var/www/html/vendor/elasticsearch/elasticsearch/src/Elasticsearch/Connections/Connection.php:693
Steps to reproduce
2. Change
?p=2 to ?p=-2Expected result
2. Expected to not see the Exception Log entry related to the occurrence (it's not application error, but User Input is out of supported range)
Actual result
2. Exception log
[2025-07-18T08:51:57.205541+00:00] .CRITICAL: Elasticsearch\Common\Exceptions\BadRequest400Exception: {"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"numHits must be > 0; please use TotalHitCountCollector if you just need the total hit count"}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[{"shard":0,"index":"local__product_1_v3","node":"6QGS43UJRPuMWbWoEdD4vA","reason":{"type":"illegal_argument_exception","reason":"numHits must be > 0; please use TotalHitCountCollector if you just need the total hit count"}}],"caused_by":{"type":"illegal_argument_exception","reason":"numHits must be > 0; please use TotalHitCountCollector if you just need the total hit count","caused_by":{"type":"illegal_argument_exception","reason":"numHits must be > 0; please use TotalHitCountCollector if you just need the total hit count"}}},"status":400} in /var/www/html/vendor/elasticsearch/elasticsearch/src/Elasticsearch/Connections/Connection.php:693
Taken from the upstream issue.
Error signatures
- 2. Expected to **not** see the Exception Log entry related to the occurrence (it's not application error, but User Input is out of supported range)
- 2. Exception log
- [2025-07-18T08:51:57.205541+00:00] .CRITICAL: Elasticsearch\Common\Exceptions\BadRequest400Exception: {"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"numHits must be > 0; please
Code match per tag
Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.
| Line | Code match per tag | Tests |
|---|---|---|
| 2.4.6 | 2.4.6 conflict 2.4.6-p1 conflict 2.4.6-p2 conflict 2.4.6-p3 conflict 2.4.6-p4 conflict 2.4.6-p5 conflict 2.4.6-p6 conflict 2.4.6-p7 conflict 2.4.6-p8 conflict 2.4.6-p9 conflict 2.4.6-p10 conflict 2.4.6-p11 conflict 2.4.6-p12 conflict 2.4.6-p13 conflict 2.4.6-p14 conflict 2.4.6-p15 conflict | 2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data |
| 2.4.7 | 2.4.7 conflict 2.4.7-p1 conflict 2.4.7-p2 conflict 2.4.7-p3 conflict 2.4.7-p4 conflict 2.4.7-p5 conflict 2.4.7-p6 conflict 2.4.7-p7 conflict 2.4.7-p8 conflict 2.4.7-p9 conflict 2.4.7-p10 conflict | 2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data |
| 2.4.8 | 2.4.8 conflict 2.4.8-p1 conflict 2.4.8-p2 conflict 2.4.8-p3 conflict 2.4.8-p4 conflict 2.4.8-p5 conflict | 2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data |
| 2.4.9 | 2.4.9 conflictcontains the fix | 2.4.9: no test data |
Triage
Model @cf/cloudflare/clef. Probability this is a bug fix: 97.8%. Probability it is security relevant: 1.0%.
Show the model's answers and probabilities
| Question | Answer | Probabilities | Confidence |
|---|---|---|---|
| Change kind | bugfix | bugfix 95.3%, refactor 1.8%, tests_only 1.0%, feature 0.9%, dependency 0.5%, docs_only 0.4% | 89.1% |
| Area | catalog | catalog 87.2%, frontend 3.2%, other 2.4% | 73.0% |
| Reported version | 2.4.7-p6 | 2.4.7-p6 59.9%, 2.4.7 6.8%, 2.4.7-p7 2.0% | 35.7% |
| Scope | 1.22 of 2 | 1 45.1%, 2 38.5%, 0 16.4% | 6.7% |
| Risk | 0.67 of 2 | 1 46.6%, 0 43.1%, 2 10.3% | 12.0% |
| Worth backporting | 1.62 of 2 | 2 68.7%, 1 24.5%, 0 6.8% | 30.5% |
Download
For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40080/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.
No checked release lacks this fix with a clean code match, so no bundle is offered.
Bundle README (what the ZIP ships)
# magento2-40080 Community fix merged upstream into magento/magento2, adapted by magento.watch. This is not a patch published by Adobe. Pull request: https://github.com/magento/magento2/pull/40080 Issue: https://github.com/magento/magento2/issues/40079 Author: @lbajsarowicz Source commit: 110579b6698d6a280b12636bcb8307d59e60ffdc Modifications: test files and documentation removed, paths rewritten relative to each Composer package. Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code. Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)
Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.
