Problem/Motivation
After upgrading to Drupal 10, some permissions on my roles were removed by user_update_10000, the resulting config object had numeric keys on the permissions array causing the config export diff to look something like this:
Update hook was migrated from a post update in #3319845: user_post_update_update_migrated_roles_followup() needs to be a hook_update_N
$ git diff
diff --git a/config-export/user.role.authenticated.yml b/config-export/user.role.authenticated.yml
index f32cd7f0..201966e7 100644
--- a/config-export/user.role.authenticated.yml
+++ b/config-export/user.role.authenticated.yml
@@ -15,12 +15,12 @@ label: 'Authenticated user'
weight: 1
is_admin: false
permissions:
- - 'access content'
- - 'cancel account'
- - 'execute default arbitrary graphql requests'
- - 'flag learning_page_read'
- - 'view media'
+ 0: 'access content'
+ 1: 'cancel account'
+ 2: 'execute default arbitrary graphql requests'
+ 3: 'flag learning_page_read'
+ 4: 'view media'
Steps to reproduce
- Have roles with non existent permissions
- Upgrade to D10 and run db updates
- Export config
Proposed resolution
Wrap $permissions in array_values
Comments
Comment #3
acbramley commentedNot sure if this is testable, but this fixes it for me.
Comment #4
catchBumping this to critical, it's probably not data-loss as such, but it makes it a lot harder to review the config changes as a result of the update.
Comment #5
acbramley commentedPretty janky test coverage but it fails without the fix
Comment #6
catchI don't have any better ideas on the test coverage, better janky than nothing, especially when it's only got to last (but do it's job very well in the meantime) until Drupal 11.
Comment #7
alexpottThere is a much better fix for this. This is a duplicate of #3039499: Role permissions not sorted in config export and that issue has a better fix that results in this being fixed in more siutations.
Comment #8
acbramley commentedThanks @alexpott I didn't even think of that approach.