Problem/Motivation

After upgrading to Drupal 10, some permissions on my roles were removed by user_update_10000, the resulting config object had numeric keys on the permissions array causing the config export diff to look something like this:

Update hook was migrated from a post update in #3319845: user_post_update_update_migrated_roles_followup() needs to be a hook_update_N

$ git diff
diff --git a/config-export/user.role.authenticated.yml b/config-export/user.role.authenticated.yml
index f32cd7f0..201966e7 100644
--- a/config-export/user.role.authenticated.yml
+++ b/config-export/user.role.authenticated.yml
@@ -15,12 +15,12 @@ label: 'Authenticated user'
 weight: 1
 is_admin: false
 permissions:
-  - 'access content'
-  - 'cancel account'
-  - 'execute default arbitrary graphql requests'
-  - 'flag learning_page_read'
-  - 'view media'
+  0: 'access content'
+  1: 'cancel account'
+  2: 'execute default arbitrary graphql requests'
+  3: 'flag learning_page_read'
+  4: 'view media'

Steps to reproduce

  1. Have roles with non existent permissions
  2. Upgrade to D10 and run db updates
  3. Export config

Proposed resolution

Wrap $permissions in array_values

Issue fork drupal-3341431

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

acbramley created an issue. See original summary.

acbramley’s picture

Status: Active » Needs review

Not sure if this is testable, but this fixes it for me.

catch’s picture

Priority: Normal » Critical
Issue tags: +D10 upgrade path

Bumping this to critical, it's probably not data-loss as such, but it makes it a lot harder to review the config changes as a result of the update.

acbramley’s picture

Pretty janky test coverage but it fails without the fix

1) Drupal\Tests\user\Functional\Update\UserUpdateRoleMigrateTest::testRolePermissions
Failed asserting that two arrays are equal.
--- Expected
+++ Actual
@@ @@
 Array (
     0 => 0
     1 => 1
-    2 => 2
-    3 => 3
-    4 => 4
-    5 => 5
-    6 => 6
+    2 => 3
+    3 => 4
+    4 => 5
+    5 => 6
+    6 => 7
 )
catch’s picture

Status: Needs review » Reviewed & tested by the community

I don't have any better ideas on the test coverage, better janky than nothing, especially when it's only got to last (but do it's job very well in the meantime) until Drupal 11.

alexpott’s picture

Status: Reviewed & tested by the community » Closed (duplicate)

There is a much better fix for this. This is a duplicate of #3039499: Role permissions not sorted in config export and that issue has a better fix that results in this being fixed in more siutations.

acbramley’s picture

Thanks @alexpott I didn't even think of that approach.