Skip to content

Preserve upgrades with stable signed application caches - #6

Merged
brianvarskonst merged 2 commits into
mainfrom
codex/review-followup-20261003
Oct 3, 2026
Merged

brianvarskonst merged 2 commits into
mainfrom
codex/review-followup-20261003

Conversation

@brianvarskonst

Copy link
Copy Markdown
Member

Sites with missing or short APP_SECRET now keep booting after a patch upgrade while WordPress and Symfony application caches use request memory. Strong secrets enable signed persistence across all configured application backends; unsigned or modified existing values are discarded before deserialization.

SYMPRESS_PROJECT_DIR supplies a literal stable cache identity across numbered releases, while code/config discovery stays on the actual release. Custom object classes can be explicitly allowlisted.

Validation: full QA, 66 tests/334 assertions; complete live Redis/Memcached/APCu suite, 66/387 with zero skips. Real containers using the prior Kernel 1.1.3 cover missing/short/strong keys, cache.app and named pools, persistence boundaries and tampered payloads.

@brianvarskonst
brianvarskonst merged commit d81870c into main Oct 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant