fix(create): roll back only the database and user this create made - #115
Merged
mrrobot47 merged 2 commits intoSep 28, 2026
Merged
Conversation
`ee site create --type=php --with-db` dropped another site's database or user when its create failed: `--dbname=<existing db>` (even `--dbname=mysql`), `--dbuser=<existing user>`, or the default name `str_replace(['.','-'],'_',site)` colliding (`a-b.test`, `a.b.test`, `a_b.test`). A failed `--ssl=custom` check also removed a pre-existing webroot. - The rollback (`catch_clean()` and the signal handler) now drops the database and user only when this run created them on the global db. - The global db names go through site-command's `reserve_global_db_names()` before anything is created: a taken `--dbname`/`--dbuser` is refused, a taken default name gets a numeric suffix, and the default is cut to 64 characters. - `check_site_name_conflicts()` refuses a site whose webroot already exists or whose docker volumes or compose project another site uses, before the database step. - Level 0 lasts until the webroot exists, so an early failure keeps a directory this run did not create. Needs the site-command functions of the same change.
…ignal interrupts a step Signals are handled only between statements of the site-type file, never inside the site-command helpers it calls. So a signal during `create_user_in_db()` was handled before `$this->created_global_db = true` ran, and the rollback left the new database and user behind. The flag is now set in the same statement as the call. For the same reason the level is raised to 1 just before `create_site_root()`, not after it. At level 0 an interrupted create, or a failed `chown` inside it, would keep the webroot it had just made, and every retry would then be refused with "Webroot directory already exists".
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on EasyEngine/site-command#503 and must be merged after it: this uses its new
reserve_global_db_names()andcheck_site_name_conflicts().This is a guard against rare name collisions and mistakes, not something a normal
ee site create --type=phpruns into. It only matters with--with-dbwhen two site names map to the same database name or docker volume prefix, or when--dbname/--dbusernames a database or user that already exists. In those cases a failed create's rollback could drop the other site's database or user, or the new site could end up on the other site's volumes and containers.When it happens
a-b.test,a.b.testanda_b.testall map toa_b_test, so the second create fails and its rollback drops the first site's database.--dbnameor--dbuser: the create fails and the rollback drops that database or user.a-b.test/ab.test,blog.example.com/blogexample.com): the second site mounted the first site's volumes and recreated its containers.--ssl=customcheck also removed asites/<site>directory that already existed.What changes
catch_clean()and the signal handler) drops the database and user only when this run created them on the global DB.reserve_global_db_names()before anything is created.check_site_name_conflicts()refuses a site whose webroot already exists or whose volumes or compose project another site uses, before the database step.Behaviour changes
--dbnameor--dbuseris refused with a clear error. Such a create never succeeded before either._2(then_3, …) suffix, stored in the site row as before. Default names are cut to 64 characters.Testing
developand passes with the fix.--with-dbcreate and delete works as before.