Problem/Motivation
MyrestResourceResponseSubscriber::onRequest() subscribes to KernelEvents::REQUEST at priority 10, so it runs for every request the site serves. When count_load.enable is on it reads myrest_count_load from state, updates three counters and writes state back — a read and a write to the shared key-value store on every page view, HTML pages and API requests alike. Two problems follow: a module installed for its API is now in the critical path of every page of the site, and the counter is written non-atomically, so concurrent requests overwrite each other's increments and the number is wrong anyway. It also sets a request attribute on every request whether or not anything reads it.
Proposed resolution
- Count only this module's own requests, which is what the counter is for — it already distinguishes them for its
count_apifigure. - Replace the read-modify-write with something that survives concurrency, or state plainly in the interface that the figure is approximate.
- Set the timing attribute only when the timing display is enabled.
- Assert with a test that a non-API request does no state write, which is the guarantee this issue is really about.
Remaining tasks
Everything. Found while auditing what the module changes outside its own endpoints.
Issue fork myrest-3618260
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #4
sergeydruua commented