Skip to content

Tests: Isolate user fixtures from randomized execution - #13187

Closed
sirreal wants to merge 4 commits into
WordPress:trunkfrom
sirreal:agent/test-order-user-isolation
Closed

sirreal wants to merge 4 commits into
WordPress:trunkfrom
sirreal:agent/test-order-user-isolation

Conversation

@sirreal

@sirreal sirreal commented Aug 20, 2026 •

Copy link
Copy Markdown
Member

Avoid mutating shared user IDs, refresh the shared capability fixture, and isolate the capability test that defines DISALLOW_UNFILTERED_HTML. Also restrict the INFORMATION_SCHEMA lookup to the active database so it cannot read another test database's auto-increment value.

The constant test has its own file and class, Tests_User_MapMetaCapDisallowUnfilteredHtml, so PHPUnit discovers it when invoked by file. A separate process prevents the constant from affecting later tests. A separate class prevents the child process's class teardown from deleting fixtures still needed by Tests_User_MapMetaCap in the parent process. The isolated test creates its own administrator and grants super-admin privileges on multisite; test teardown rolls back that grant.

Verified locally on 2026-09-14 with PHP 8.5.10 and PHPUnit 9.6.36:

  • Both capability files pass when invoked individually on single site and multisite: the isolated file runs 1 test with 5 assertions; the original runs 35 tests with 95 assertions on single site and 96 on multisite.
  • Randomized user group with seed 1789039001: 1,344 tests / 4,534 assertions on single site and 1,403 / 5,000 on multisite. Both exit 0 with five existing PHPUnit deprecation warnings; single site also has one skip.
  • PHPCS passes on both files changed by the split. git diff --check passes.

Trac: https://core.trac.wordpress.org/ticket/65893

@lancewillett

Copy link
Copy Markdown
Member

Updated with 38efccb after merging current trunk.

The separate-process capability test previously passed user ID 0 to map_meta_cap(). On multisite, that user is not a super admin, so file-management capabilities map to do_not_allow instead of the test’s original expected primitive capabilities. The test now creates an administrator fixture, grants it super-admin privileges on multisite, and revokes those privileges in finally.

Validation:

  • PHPCS: all four changed user test files
  • Multisite mapMetaCap.php: 35 tests, 96 assertions
  • Multisite randomized replay of the four changed user test files (seed 65893): 763 tests, 3,136 assertions
  • Single-site randomized replay of the same files (seed 65894): 753 tests, 2,903 assertions
  • PHP syntax checks and git diff --check

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

@lancewillett
lancewillett marked this pull request as ready for review September 7, 2026 21:51
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props jonsurrell, lancewillett.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@sirreal
sirreal force-pushed the agent/test-order-user-isolation branch from 38efccb to 8c81776 Compare September 9, 2026 12:21
Comment thread tests/phpunit/tests/user/mapMetaCap.php Outdated
@sirreal
sirreal marked this pull request as draft September 9, 2026 12:26
Name the class and file for the condition under test so direct PHPUnit
file execution discovers it. Explain why the test needs both process
isolation and a separate class from Tests_User_MapMetaCap.

Remove the redundant super-admin cleanup; test teardown rolls back the
site option before the isolated process exits.
@sirreal
sirreal marked this pull request as ready for review September 14, 2026 10:49
wporg-sync pushed a commit that referenced this pull request Sep 14, 2026
Keep temporary user IDs out of shared query fixtures and refresh the shared administrator object so capability changes are cleaned up on the instance used by later tests.

Move the `DISALLOW_UNFILTERED_HTML` test into its own file and process, with an administrator fixture and super-admin privileges on multisite. This contains the constant and prevents child-process teardown from deleting another class's fixtures.

Restrict the auto-increment lookup to the active database.

Developed in: #13187

Props jonsurrell.
See #65893.


git-svn-id: https://develop.svn.wordpress.org/trunk@63614 602fd350-edb4-49c9-b593-d223f7449a82
@lancewillett

Copy link
Copy Markdown
Member

wporg-sync pushed a commit to WordPress/WordPress that referenced this pull request Sep 14, 2026
Keep temporary user IDs out of shared query fixtures and refresh the shared administrator object so capability changes are cleaned up on the instance used by later tests.

Move the `DISALLOW_UNFILTERED_HTML` test into its own file and process, with an administrator fixture and super-admin privileges on multisite. This contains the constant and prevents child-process teardown from deleting another class's fixtures.

Restrict the auto-increment lookup to the active database.

Developed in: WordPress/wordpress-develop#13187

Props jonsurrell.
See #65893.

Built from https://develop.svn.wordpress.org/trunk@63614


git-svn-id: http://core.svn.wordpress.org/trunk@62790 1a063a9b-81f0-0310-95a4-ce76da25c4cd
@sirreal
sirreal deleted the agent/test-order-user-isolation branch September 14, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

2 participants