Files
opensourcepos/tests/Models/ItemQuantityTest.php
objecttothis 29a9b1a7e7 Bugfix: Resolve Race Condition in Rewards and Gift Card Spending (#4640)
* Implement atomic updates for gift card and reward point decrements, enhance error handling for insufficient balances, and add regression tests for concurrency safety.

* Add translations for insufficient gift card balance and reward points error messages across all supported languages.

* Reorder `clear_suspended_sale_detail` call to ensure transactional consistency.

* Reorder `clear_all` call to align with success and error handling logic.

* Ensure soft-deleted gift cards are excluded in balance updates.

* Refactor change_quantity logic with atomic upserts, improve error handling for insufficient stock, and update related tests and constants.

* Added check for NEW_ENTRY

* Added unit tests to test changes.

* Fix class name casing in ItemQuantityTest for consistency.

* Fix Bulgarian translations for insufficient balance error messages in Sales module.

* Fix Greek translations for insufficient balance error messages in Sales module.

* Fix Armenian translations for insufficient balance error messages in Sales module.

* Fix Tamil translations for insufficient balance error messages in Sales module.

* Implement race condition testing for database methods with concurrent process support.

* Fix class name casing in ItemTest for consistency.

* Improve concurrent process handling in race condition tests; add readiness and synchronization barriers.

* Improve handling of process I/O streams and timeout management in race condition tests.

* Add test for decrementing gift card value when marked as deleted

* Add `finally` block to ensure proper cleanup in async database race condition tests

* Improve error handling and timeout management in async database race condition tests.

* Refactor test utilities to use shared `EmployeeFixtureTrait` and `ItemFixtureTrait`.

* Track process exit codes explicitly in race condition tests for improved error detection and debugging.

* Improve error handling in `ConcurrentDbRaceTrait` by adding exceptions for `mysqli_poll` and `mysqli_reap_async_query`.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-20 02:24:23 +04:00

93 lines
2.9 KiB
PHP

<?php
namespace Tests\Models;
use App\Models\Item_quantity;
use CodeIgniter\Test\CIUnitTestCase;
use CodeIgniter\Test\DatabaseTestTrait;
use Config\Database;
use Tests\Support\ConcurrentDbRaceTrait;
use Tests\Support\ItemFixtureTrait;
/**
* Regression tests for GHSA-995p-52qw-5hh2: changeQuantity() must apply
* its write in a single atomic upsert, so that two concurrent sales of the
* same item/location can never both read the same stale quantity and
* oversell stock. Unlike the gift card and reward point spends, there is
* deliberately no floor guard here (see the fix's scope note) — negative
* stock is allowed today and this fix does not change that.
*/
class ItemQuantityTest extends CIUnitTestCase
{
use DatabaseTestTrait;
use ConcurrentDbRaceTrait;
use ItemFixtureTrait;
protected $migrate = true;
protected $migrateOnce = true;
protected $refresh = false;
protected $namespace = null;
private const LOCATION_ID = 1;
public static function setUpBeforeClass(): void
{
$seeder = Database::seeder('tests');
$seeder->call('TestDatabaseBootstrapSeeder');
}
protected function setUp(): void
{
parent::setUp();
}
protected function createItemQuantityRow(int $itemId, float $quantity): void
{
\Config\Database::connect()->table('item_quantities')->insert([
'item_id' => $itemId,
'location_id' => self::LOCATION_ID,
'quantity' => $quantity,
]);
}
public function testDecrementQuantitySucceeds(): void
{
$itemId = $this->createTestItem();
$this->createItemQuantityRow($itemId, 10);
$itemQuantityModel = model(Item_quantity::class);
$result = $itemQuantityModel->changeQuantity($itemId, self::LOCATION_ID, -3);
$this->assertTrue($result);
$this->assertEqualsWithDelta(7.0, $this->getItemQuantity($itemId, self::LOCATION_ID), 0.001);
}
public function testDecrementQuantityAllowsGoingNegative(): void
{
$itemId = $this->createTestItem();
$this->createItemQuantityRow($itemId, 5);
$itemQuantityModel = model(Item_quantity::class);
$result = $itemQuantityModel->changeQuantity($itemId, self::LOCATION_ID, -8);
$this->assertTrue($result);
$this->assertEqualsWithDelta(-3.0, $this->getItemQuantity($itemId, self::LOCATION_ID), 0.001);
}
public function testDecrementQuantityConcurrentDecrementsBothApply(): void
{
$itemId = $this->createTestItem();
$this->createItemQuantityRow($itemId, 10);
[$result1, $result2] = $this->raceTwoProcesses(
'itemQuantity',
[$itemId, self::LOCATION_ID, -3.0],
[$itemId, self::LOCATION_ID, -3.0]
);
$this->assertTrue($result1);
$this->assertTrue($result2);
$this->assertEqualsWithDelta(4.0, $this->getItemQuantity($itemId, self::LOCATION_ID), 0.001);
}
}