Repository navigation
[Fix] Changing a site's branch no longer checks out the live release under modern deployment - #1263
Conversation
…under modern deployment With modern deployment enabled, a site's path is `<base>/current`, which points at the active release. UpdateBranch ran `git fetch origin` and `git checkout -f <branch>` in that path, so saving a new branch swapped the code of the live release in place, with no build, no pre-flight and no migrations. The forced checkout also restored tracked files over the shared resources, replacing the `storage` symlink with a plain directory in that release. The branch is now switched in `<base>/source`, the checkout that holds the shared resources and is pulled on every deployment. The next deployment clones the new branch into a fresh release as usual. Sites without modern deployment keep their current behaviour.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: vitodeploy/vito/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughBranch updates now run Git fetch and checkout operations in the source directory for modern deployments. Git operations accept an optional path and retain the site path as the default. ChangesBranch update path
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to Modern-deployment branch changes now target the source checkout rather than the live release, while other deployments retain their existing behavior. The change is ready to merge subject to normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The change prevents checkout from directly rewriting the active release. However, the replacement directory also backs resources shared by running releases. Where shared resources overlap Git-tracked files, forced checkout can still change live configuration or data before deployment, and switching back to an older release would not restore those resources. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What happens
On a site with Modern Deployment enabled, changing the branch under Site → Settings → Branch rewrites the code of the live release in place.
UpdateBranchrunsgit fetch originandgit checkout -f <branch>in$site->path. With modern deployment,$site->pathis<base>/current, the symlink to the active release, so:column ... does not exist) until a deployment ran the migrations.git checkout -frestores tracked files over the shared resources, sostoragein that release turns into a plain directory instead of the symlink to<base>/source/storage. Uploads, logs and cache written by that release no longer reach shared storage.<base>/sourcestays on the old branch, so the next deployment'sgit pull origin <new-branch>there moves the old local branch onto the new one.Steps to reproduce
.env,storage) and deploy.git -C <base>/current reflog -1showscheckout: moving from <old> to <new>, and<base>/current/storageis a directory.Fix
When modern deployment is enabled,
UpdateBranchruns the fetch and the checkout in<base>/sourceinstead.Git::checkout()andGit::fetchOrigin()take an optional path, the wayGit::clone()already does. The live release is left alone, and the next deployment clones the new branch into a fresh release as usual. Sites without modern deployment behave as before.Tests
tests/Feature/SitesTest.php: with modern deployment enabled, changing the branch runs in<base>/sourceand nevercds into<base>/current. It fails on4.xwithout the fix.661e497cplus this patch): after changing the branch twice, the active release'sHEADand reflog were untouched, itsstoragewas still a symlink, andsourceswitched branches.