Sitelet https://github.com/inventree/InvenTree/pull/12478
Skip to content

[bug] Fix concurrency issues for allocation - #12478

Merged
SchrodingersGat merged 4 commits into
inventree:masterfrom
SchrodingersGat:allocate-stock-bug
Jul 28, 2026
Merged

SchrodingersGat merged 4 commits into
inventree:masterfrom
SchrodingersGat:allocate-stock-bug

Conversation

@SchrodingersGat

@SchrodingersGat SchrodingersGat commented Jul 27, 2026 •

Copy link
Copy Markdown
Member
  • Fixes window for duplicate allocation of stock items via concurrent requests.
  • Adds concurrent regression testing

Issue reported by @nullbenny

Issue Description

unallocated_quantity() is read without a lock, while writes lock only the order row (not the shared StockItem) and insert via bulk_create, so concurrent requests against the same StockItem can all pass validation and all commit — confirmed on POST /api/build/{id}/allocate/, where two concurrent requests each allocating a full 5-unit stock item both returned 201, leaving 10 allocated against 5 (~90% reproduction rate across repeated runs). The same gap exists in the sales-order, serial-based sales-order, and transfer-order allocation paths, and since unallocated_quantity() sums across all three subsystems, over-allocation can occur both within and across them.

@SchrodingersGat SchrodingersGat added this to the 1.5.0 milestone Jul 27, 2026
@SchrodingersGat SchrodingersGat added the bug Identifies a bug which needs to be addressed label Jul 27, 2026
@netlify

netlify Bot commented Jul 27, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for inventree-web-pui-preview canceled.

Name Link
🔨 Latest commit 357dbcc
🔍 Latest deploy log https://app.netlify.com/projects/inventree-web-pui-preview/deploys/6a680777766009000809abc1

@codecov

codecov Bot commented Jul 27, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 31.28492% with 123 lines in your changes missing coverage. Please review.
✅ Project coverage is 86.85%. Comparing base (c1ebe0b) to head (357dbcc).

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #12478      +/-   ##
==========================================
+ Coverage   86.84%   86.85%   +0.01%     
==========================================
  Files        1443     1442       -1     
  Lines       95693    95790      +97     
  Branches    11121    11094      -27     
==========================================
+ Hits        83104    83203      +99     
+ Misses      12525    12522       -3     
- Partials       64       65       +1     
Flag Coverage Δ
backend 90.97% <31.28%> (-0.19%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
Backend Apps 92.43% <31.28%> (-0.24%) ⬇️
Backend General 93.53% <ø> (ø)
Frontend 79.66% <ø> (+0.27%) ⬆️
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@SchrodingersGat
SchrodingersGat marked this pull request as draft July 27, 2026 22:25
@SchrodingersGat SchrodingersGat added order Related to purchase orders / sales orders build Build orders labels Jul 28, 2026
@SchrodingersGat
SchrodingersGat marked this pull request as ready for review July 28, 2026 01:38
@SchrodingersGat
SchrodingersGat merged commit 4a8ee54 into inventree:master Jul 28, 2026
44 checks passed
@SchrodingersGat
SchrodingersGat deleted the allocate-stock-bug branch July 28, 2026 02:37
Lowkey-wizard added a commit to EQUA-AI/InvenTree that referenced this pull request Aug 7, 2026
Upstream inventree#12361/inventree#12478 route all build-allocation validation through the
new StockItem.bulk_allocation_count() and persist via bulk_create, which
bypasses BuildItem.clean(). Add the job-kit domain as the fourth
accumulator so builds cannot consume maintenance-reserved stock, and
teach can_delete() to refuse cleanly on job-kit rows (PROTECT FK)
instead of raising ProtectedError.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Identifies a bug which needs to be addressed build Build orders order Related to purchase orders / sales orders

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant