Schema Update Rollback Safety for Drupal hook_update_N
29.3K reputation · 16 Dec 2024, 04:29 UTC
Schema Update Rollback Safety for Drupal hook_update_N
The goal is to guarantee that a schema change made inside a hook_update_N implementation can be automatically reverted if a subsequent update fails, leaving the database in its pre‑update state.
Currently Drupal core runs updates sequentially but does not wrap DDL statements in a transaction that can be rolled back, and the only safety net is the configuration management system, which does not cover raw table alterations.
Permission to execute update.php is limited to users with the "administer site configuration" permission, yet there is no extra guard to stop a partially failed schema update from being left applied.
An unresolved decision is whether core should adopt a declarative schema migration layer with built‑in undo capability, similar to Doctrine Migrations, to provide reliable rollback for schema changes.
Should Drupal core add automatic transaction rollback for DDL statements inside hook_update_N? Is a declarative schema migration layer with undo mechanism needed to ensure safe schema updates? What additional permission or execution safeguards should prevent leaving a partial schema change in place after a failed update?