From defe4883915ea8bb3f707a3d1b261d9a05b0e5ef Mon Sep 17 00:00:00 2001 From: denkfabrik-li <274324701+denkfabrik-li@users.noreply.github.com> Date: Fri, 28 Aug 2026 04:42:00 +0200 Subject: [PATCH] Ask about the zips queue on every path that could answer it ensure_worker_watches_zips() exists because a worker unit written before zip downloads had their own queue watches 'default' only, and a zip enqueued to 'zips' then waits forever with nothing saying why. It is called from exactly one place: inside the branch that reloads PHP-FPM, nested inside the branch that found a worker unit. So it runs only when a PHP-FPM unit was detected. Driving the restart block through four host shapes, with everything it touches stubbed: systemd + fpm + worker reached, restarted systemd + worker, no fpm silent --no-restart silent no systemd at all silent The second line is the one that matters. A worker unit is a different service from PHP-FPM, and not finding one says nothing about the other: a host running mod_php, or one whose FPM unit is named in a way this script does not recognise, can still have a systemd worker that predates the zips queue. That host gets no check and no mention. The check now runs in the else branch too, where it costs nothing -- its own first line returns immediately unless systemd and a worker unit are both present -- and the worker is restarted after it, paired exactly as the FPM branch pairs them. That pairing is the point rather than a flourish: the new --queue argument reaches the worker only when systemd next starts it from ExecStart. The queue:restart that projectsend:update signals cannot deliver it, because that makes a worker pick up new *code* and it has already run by the time this block is reached, so the worker came back on the old command line. Editing the unit without the restart would leave the operator told that zip downloads were fixed while they still could not finish -- worse than the silence it replaces, since silence sends somebody looking. Under --no-restart it is said rather than done: editing a unit file is exactly what that flag asks us not to do, but a worker that cannot finish a zip is broken whether or not we are allowed to touch it, and this is the only place that knows to mention it. Same four shapes afterwards: systemd + fpm + worker reached, restarted systemd + worker, no fpm reached, restarted --no-restart not reached, but said so no systemd at all reached, no restart (returns immediately) No test: the suite cannot drive a shell script that restarts services. bash -n parses, and the harness above is the evidence. --- update.sh | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/update.sh b/update.sh index 6f15f6af..d5850105 100755 --- a/update.sh +++ b/update.sh @@ -669,6 +669,11 @@ Then reload PHP-FPM, and bring the site back with: php artisan up" if [[ "$NO_RESTART" == "1" ]]; then warn "Not touching systemd, as asked." warn "PHP is still running the old code until you reload it — ProjectSend will keep telling your staff so." + # Said rather than done: the check below edits a unit file, which is + # exactly what --no-restart asks us not to do. But a worker that + # predates the zips queue is broken whether or not we are allowed to + # touch it, and this is the only place that knows to mention it. + warn "Your worker's queues were not checked either. If it predates the zips queue, zip downloads never finish — run without --no-restart, or add 'zips' to its --queue list yourself." elif [[ "${SYSTEMD:-0}" == "1" && -n "${FPM_SERVICE:-}" ]]; then say "Reloading $FPM_SERVICE" systemctl reload "$FPM_SERVICE" 2>/dev/null || systemctl restart "$FPM_SERVICE" \ @@ -684,6 +689,29 @@ Then reload PHP-FPM, and bring the site back with: php artisan up" fi else warn "No PHP-FPM service was found to reload. Reload PHP yourself now, or it keeps serving the old code." + + # The worker is a different unit from PHP-FPM, and not finding one + # says nothing about the other: a host running mod_php, or one where + # the FPM unit is named in a way this script does not recognise, can + # still have a systemd worker that predates the zips queue. The + # function returns immediately unless systemd and a worker unit are + # both there, so reaching it from here costs nothing and stops this + # branch being the one place the queue is never mentioned. + ensure_worker_watches_zips + + # Paired with the edit, exactly as the FPM branch above pairs them, + # and for the reason its comment gives: the new --queue argument + # only reaches the worker when systemd next starts it from + # ExecStart. projectsend:update's queue:restart cannot deliver it — + # that makes a worker pick up new *code*, and it has already run by + # the time we get here, so the worker came back on the old command + # line. Without this, the unit is edited, the operator is told so, + # and zips still never finish: a false completion, which is worse + # than the silence this branch used to keep. + if [[ "${SYSTEMD:-0}" == "1" && -n "${WORKER_SERVICE:-}" ]]; then + say "Restarting $WORKER_SERVICE" + systemctl restart "$WORKER_SERVICE" || warn "Could not restart $WORKER_SERVICE." + fi fi say "Bringing the site back up"