UPSTREAM FIX

magento2-40217: Batches EAV collection attribute value setting to cut loop iterations

Community fix magento2-40217 merged into magento/magento2 on 2025-11-20, released in 2.4.9.

Batches EAV collection attribute value setting to cut loop iterations edited

Pull request title
Time complexity of _loadAttributes in Eav\Model\Entity\Collection\AbstractCollection increases with number of products in cart and attributes
Pull request
magento/magento2#40217
Issues
#40216 human
Author
@senthilengg
Merged
2025-11-20
Fixed in
2.4.9
Reported on
—
Categories
Catalog/Product
Components
magento/module-eav

Labels

Area
Catalog
Component
Eav
Priority
P2
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Description

Iterates per attribute per product which increases the time complexity to multifold

Steps to reproduce

1. Review https://github.com/magento/magento2/blob/2.4-develop/app/code/Magento/Catalog/Model/AbstractModel.php#L180 and there is a nested for in https://github.com/magento/magento2/blob/2.4-develop/app/code/Magento/Eav/Model/Entity/Collection/AbstractCollection.php#L1236 and it calls _setItemAttributeValue once per attribute and _setItemAttributeValue iterates all products and set the value which is **O(n*m) [50 products in cart & 50 attributes leads to 2500 iterations]**
n = number of attributes
m= numbers of products
Profiler Output

<img width="1590" height="608" alt="Image" src="https://github.com/user-attachments/assets/04e7110c-4994-46bf-9651-4d8cd62e8151" />


2. In addition setData function in https://github.com/magento/magento2/blob/2.4-develop/app/code/Magento/Catalog/Model/AbstractModel.php#L180 does the same validation for all products instead it should be done once per attribute per collection given it doesn't change per product or per entityValue

Expected result

Iterates the number of rows from select query and then set once per product

Actual result

Iterates per attribute per product which increases the time complexity to multifold

Taken from the upstream issue.

Error signatures

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 conflict 2.4.6-p1 conflict 2.4.6-p2 conflict 2.4.6-p3 conflict 2.4.6-p4 conflict 2.4.6-p5 conflict 2.4.6-p6 conflict 2.4.6-p7 conflict 2.4.6-p8 conflict 2.4.6-p9 conflict 2.4.6-p10 conflict 2.4.6-p11 conflict 2.4.6-p12 conflict 2.4.6-p13 conflict 2.4.6-p14 conflict 2.4.6-p15 conflict
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 conflict 2.4.7-p1 conflict 2.4.7-p2 conflict 2.4.7-p3 conflict 2.4.7-p4 conflict 2.4.7-p5 conflict 2.4.7-p6 conflict 2.4.7-p7 conflict 2.4.7-p8 conflict 2.4.7-p9 conflict 2.4.7-p10 conflict
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 conflict 2.4.8-p1 conflict 2.4.8-p2 conflict 2.4.8-p3 conflict 2.4.8-p4 conflict 2.4.8-p5 conflict
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 69.2%. Probability it is security relevant: 0.6%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindrefactorrefactor 51.2%, bugfix 45.5%, feature 1.4%, tests_only 0.7%, dependency 0.7%, docs_only 0.5%36.3%
Areacatalogcatalog 77.0%, framework 9.6%, other 4.0%55.1%
Reported versionunspecifiedunspecified 34.4%, 2.4.8 2.4%, 2.4.8-p2 2.1%11.4%
Scope0.84 of 21 38.9%, 0 38.5%, 2 22.6%2.6%
Risk1.05 of 21 49.4%, 2 28.0%, 0 22.6%6.0%
Worth backporting1.10 of 21 42.0%, 2 34.1%, 0 23.9%2.4%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40217/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

No checked release lacks this fix with a clean code match, so no bundle is offered.

Bundle README (what the ZIP ships)
# magento2-40217

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40217
Issue: https://github.com/magento/magento2/issues/40216
Author: @senthilengg
Source commit: 7a4f0b73ddc1ee2abc017aef426c4714e64b0724
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.