Skip to content

Escape LIKE metacharacters in queue prefixes - #811

Open
afurm wants to merge 2 commits into
rails:mainfrom
afurm:escape-queue-prefix-like-wildcards
Open

afurm wants to merge 2 commits into
rails:mainfrom
afurm:escape-queue-prefix-like-wildcards

Conversation

@afurm

@afurm afurm commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

What

QueueSelector turns a worker prefix such as mail_* into a SQL LIKE pattern. _ and % in that prefix were left unescaped, so LIKE 'mail_%' also matched mailbox or mail-ops. * is still the only wildcard.

When that false match was the only row, in_raw_order returned it immediately because queues.one? skipped the literal start_with? filter. The worker then claimed jobs from a queue it was not configured to run.

Why

_ and % are escaped (via sanitize_sql_like) before * is replaced with %, and the LIKE clause sets ESCAPE '\' so the escape works on SQLite as well as MySQL and PostgreSQL. Prefix matches always go through the literal filter, including when only one name comes back, so a false LIKE hit is not claimed.

A regression test covers a prefix that is the only LIKE hit but not a literal match, and a real mail_* / 100%_* queue that should still be claimed.

afurm added 2 commits October 3, 2026 08:39
A worker prefix such as mail_* became LIKE 'mail_%', so _ and % matched
any character. When that false match was the only row, the selector
returned it without the literal prefix check and the worker claimed a
queue it was not configured to run.
ESCAPE '\' is a valid string on SQLite and PostgreSQL, but MySQL treats
the backslash as an escape and rejects the clause. MySQL needs the same
one-character escape written as '\\'.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant