PluginProbe
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO / 2.11.0
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO v2.11.0
2.11.0 2.10.0 2.9.0 2.8.0 2.7.0 2.6.0 2.5.0 2.4.0 2.3.0 2.2.0 2.1.1 2.1.0 2.0.2 2.0.1 2.0.0 1.32.0 1.31.0 1.30.0 1.29.0 1.28.0 1.27.0 1.26.0 1.25.0 trunk 1.0.0 All 52 releases
← All changes | includes/seo/class-sitemap-generator.php +2028 -229 2.0.2 → 2.11.0 View file →
@@ -21,8 +21,13 @@
21 21 if ( ! defined( 'ABSPATH' ) ) {
22 22 exit;
23 23 }
24 24
25 +// Filename derivation and web-root removal are shared with the deactivator and
26 +// with uninstall.php, which runs without an autoloader — so they live in a
27 +// plain function file both can require. See includes/cleanup-webroot.php.
28 +require_once __DIR__ . '/../cleanup-webroot.php';
29 +
25 30 /**
26 31 * Sitemap Generator Class
27 32 *
28 33 * Generates and manages XML sitemaps for search engine optimization.
@@ -57,8 +62,25 @@
57 62 'include_tags' => 'tags',
58 63 ];
59 64
60 65 /**
66 + * Child sitemap type -> the object that actually supplies its entries.
67 + *
68 + * A child normally carries its object's own slug, but the sitemap presets UI
69 + * writes a display name for the WooCommerce taxonomy child
70 + * ('product_categories', not 'product_cat'), so a saved child list can name a
71 + * type no post type or taxonomy answers to. Resolving through here lets those
72 + * children take the same generic path as every other custom taxonomy instead
73 + * of needing a case of their own (#690).
74 + *
75 + * @since 2.7.0
76 + * @var array<string, string>
77 + */
78 + private const CHILD_TYPE_ALIASES = [
79 + 'product_categories' => 'product_cat',
80 + ];
81 +
82 + /**
61 83 * Supported sitemap types
62 84 *
63 85 * @since 1.0.0
64 86 * @var array
@@ -71,8 +93,159 @@
71 93 */
72 94 private const ID_WALK_CHUNK = 500;
73 95
74 96 /**
97 + * How long a content or settings change is debounced before the sitemap is
98 + * rebuilt, in seconds. Coalesces bulk edits into a single regeneration.
99 + *
100 + * @since 2.2.1
101 + * @var int
102 + */
103 + private const REGENERATION_DEBOUNCE = 30;
104 +
105 + /**
106 + * How far past its due time the scheduled rebuild may sit before a request
107 + * takes it over, in seconds.
108 + *
109 + * WP-Cron is request-driven, so on a site running DISABLE_WP_CRON, blocking
110 + * loopback requests, or seeing very little traffic the event never fires and
111 + * the sitemap silently stops updating (#629). The grace keeps the fast path
112 + * (cron) in charge under normal conditions.
113 + *
114 + * @since 2.2.1
115 + * @var int
116 + */
117 + private const REGENERATION_TAKEOVER_GRACE = 120;
118 +
119 + /**
120 + * Longest backoff between takeover attempts after a failed rebuild, so a
121 + * persistently failing generation cannot run on every admin request.
122 + *
123 + * @since 2.2.1
124 + * @var int
125 + */
126 + private const REGENERATION_MAX_BACKOFF = 3600;
127 +
128 + /**
129 + * Option holding the rebuild that content/settings changes are still waiting
130 + * on: `since`, `source` ('content'|'settings'), `attempts`, `next_attempt`.
131 + * Absent means the served sitemap is up to date with what triggered it.
132 + *
133 + * @since 2.2.1
134 + * @var string
135 + */
136 + public const REGENERATION_PENDING_OPTION = 'thinkrank_sitemap_regeneration_pending';
137 +
138 + /**
139 + * Option holding the last automatic-regeneration failure (`message`,
140 + * `source`, `time`), so the failure is visible instead of swallowed.
141 + *
142 + * @since 2.2.1
143 + * @var string
144 + */
145 + public const REGENERATION_ERROR_OPTION = 'thinkrank_sitemap_regeneration_error';
146 +
147 + /**
148 + * Delivery modes accepted by the `delivery_mode` setting.
149 + *
150 + * Mirrors LLMs_Txt_Manager::DELIVERY_MODES, which solved the same problem
151 + * for llms.txt. `auto` is the only value a site should normally need.
152 + *
153 + * @since 2.9.0
154 + * @var string[]
155 + */
156 + public const DELIVERY_MODES = ['auto', 'static', 'dynamic'];
157 +
158 + /**
159 + * Cache group for documents rendered on the dynamic path.
160 + *
161 + * @since 2.9.0
162 + * @var string
163 + */
164 + private const DYNAMIC_CACHE_PREFIX = 'thinkrank_sitemap_doc_';
165 +
166 + /**
167 + * How long a dynamically rendered document is cached.
168 + *
169 + * Invalidated by content and settings changes through
170 + * {@see self::flush_dynamic_cache()}, so this is only the backstop for a
171 + * change nothing hooked.
172 + *
173 + * @since 2.9.0
174 + * @var int
175 + */
176 + private const DYNAMIC_CACHE_TTL = 12 * HOUR_IN_SECONDS;
177 +
178 + /**
179 + * How long the render lock is held before it is assumed abandoned.
180 + *
181 + * Long enough for a large site's full build, short enough that a request
182 + * killed mid-build does not lock the endpoint out for meaningfully long.
183 + *
184 + * @since 2.9.0
185 + * @var int
186 + */
187 + private const RENDER_LOCK_TTL = 60;
188 +
189 + /**
190 + * Cached stand-in for "this site does not publish that name".
191 + *
192 + * published_document_names() lists what the configuration *could* produce,
193 + * but a child whose type is excluded produces nothing. Without a negative
194 + * entry those names miss the cache forever, so every request for one
195 + * rebuilt the entire sitemap — the same cost the positive cache exists to
196 + * avoid, on a public endpoint (#754 review).
197 + *
198 + * @since 2.9.0
199 + * @var string
200 + */
201 + private const ABSENT_MARKER = "\0thinkrank-absent";
202 +
203 + /**
204 + * How many times, and how long, a losing request waits for the winner.
205 + *
206 + * Bounded at roughly a second in total: past that, building a second copy
207 + * costs less than making a crawler wait.
208 + *
209 + * @since 2.9.0
210 + * @var int
211 + */
212 + private const RENDER_LOCK_WAIT_ATTEMPTS = 4;
213 +
214 + /**
215 + * @since 2.9.0
216 + * @var int
217 + */
218 + private const RENDER_LOCK_WAIT_MICROSECONDS = 250000;
219 +
220 + /**
221 + * Where generated documents go instead of disk, when set.
222 + *
223 + * Every sitemap document this class produces — segments, the index, the
224 + * single flat file and local-sitemap.xml — is published through the one
225 + * writer, {@see self::save_sitemap_to_file()}. Swapping that writer for a
226 + * collector is therefore all it takes to render the same bytes without a
227 + * filesystem, which is what dynamic delivery needs (#752). Doing it here
228 + * rather than duplicating the build pipeline is deliberate: a second
229 + * pipeline would drift from this one, and the index in particular is
230 + * assembled from whatever the children actually produced.
231 + *
232 + * @since 2.9.0
233 + * @var callable|null
234 + */
235 + private $document_sink = null;
236 +
237 + /**
238 + * Transient guarding against two generations running at once. Shared with
239 + * Sitemap_Endpoint's manual generate route so an automatic rebuild and a
240 + * manual one cannot write the same files concurrently.
241 + *
242 + * @since 2.2.1
243 + * @var string
244 + */
245 + public const GENERATION_LOCK_TRANSIENT = 'thinkrank_sitemap_generation_lock';
246 +
247 + /**
75 248 * How many term IDs to hydrate at a time while walking a taxonomy.
76 249 *
77 250 * @since 2.0.1
78 251 * @var int
@@ -78,8 +251,33 @@
78 251 * @var int
79 252 */
80 253 private const TERM_WALK_CHUNK = 1000;
81 254
255 + /**
256 + * Exception code for an automatic rebuild stopped short of the memory limit.
257 + *
258 + * @since 2.10.1
259 + * @var int
260 + */
261 + private const MEMORY_ABORT_CODE = 4290;
262 +
263 + /**
264 + * Whether the chunked walks should stop before the memory limit. Only on
265 + * for automatic rebuilds, whose failure is recorded and retried.
266 + *
267 + * @since 2.10.1
268 + * @var bool
269 + */
270 + private bool $memory_guard = false;
271 +
272 + /**
273 + * Largest memory cost of one walked chunk in this rebuild, in bytes.
274 + *
275 + * @since 2.10.1
276 + * @var int
277 + */
278 + private int $walk_chunk_cost = 0;
279 +
82 280 private array $sitemap_types = [
83 281 'posts' => [
84 282 'name' => 'Posts',
85 283 'post_types' => ['post'],
@@ -106,25 +304,29 @@
106 304 ]
107 305 ];
108 306
109 307 /**
308 + * The generator the content-change listeners share, built on the first
309 + * change of a request.
310 + *
311 + * @since 2.10.1
312 + * @var self|null
313 + */
314 + private static ?self $listener = null;
315 +
316 + /**
110 317 * Constructor
111 318 *
112 319 * @since 1.0.0
320 + * @since 2.10.1 Registers no hooks, whatever `$register_hooks` says. The
321 + * content-change listeners are registered once, at bootstrap,
322 + * by register_content_listeners().
113 323 *
114 - * @param bool $register_hooks Optional. Whether to register the auto-generation
115 - * hooks. Pass false for a read-only instance built
116 - * solely to query settings — the hooks are bound to
117 - * `$this`, so a second hook-registering instance
118 - * would run `handle_content_change()` twice per save.
324 + * @param bool $register_hooks Unused since 2.10.1; kept so existing callers,
325 + * Pro's included, keep working.
119 326 */
120 327 public function __construct(bool $register_hooks = true) {
121 328 parent::__construct('sitemap');
122 -
123 - // Initialize auto-generation hooks
124 - if ($register_hooks) {
125 - $this->init_auto_generation_hooks();
126 - }
127 329 }
128 330
129 331 /**
130 332 * Filter the args of a sitemap post query.
@@ -168,31 +370,57 @@
168 370 return (array) apply_filters('thinkrank_sitemap_term_query_args', $args);
169 371 }
170 372
171 373 /**
172 - * Initialize WordPress hooks for auto-generation
374 + * Register the content-change listeners that queue an automatic rebuild.
173 375 *
174 - * @since 1.0.0
376 + * Called once per request, at plugin bootstrap, next to the WP-Cron
377 + * listeners that run the rebuild these queue (both in
378 + * Plugin::register_sitemap_cron_listeners(), on plugins_loaded). The
379 + * constructor used to register them, so they existed only in a request
380 + * that happened to build a generator: the REST endpoint, the setup wizard,
381 + * an MCP ability. Block-editor saves go through REST and were heard. A
382 + * scheduled post published by WP-Cron, Quick Edit, the classic editor and
383 + * WP-CLI were not, so the post stayed out of the sitemap with nothing
384 + * pending to recover it (#824). Each instance also added its own set, so
385 + * one REST save ran the handlers once per generator built.
386 + *
387 + * The generator is built on the first change and shared for the rest of
388 + * the request, so a bulk edit does not construct one per post.
389 + *
390 + * @since 2.10.1
175 391 * @return void
176 392 */
177 - private function init_auto_generation_hooks(): void {
178 - // Content change hooks - use priority 20 to run after other plugins
179 - add_action('save_post', [$this, 'handle_content_change'], 20, 2);
180 - add_action('delete_post', [$this, 'handle_content_deletion'], 20);
181 - add_action('wp_trash_post', [$this, 'handle_content_deletion'], 20);
182 - add_action('untrash_post', [$this, 'handle_content_change_by_id'], 20);
393 + public static function register_content_listeners(): void {
394 + // Priority 20, to run after other plugins.
395 + add_action('save_post', static function (int $post_id, \WP_Post $post): void {
396 + self::listener()->handle_content_change($post_id, $post);
397 + }, 20, 2);
398 + add_action('delete_post', static function (int $post_id): void {
399 + self::listener()->handle_content_deletion($post_id);
400 + }, 20);
401 + add_action('wp_trash_post', static function (int $post_id): void {
402 + self::listener()->handle_content_deletion($post_id);
403 + }, 20);
404 + add_action('untrash_post', static function (int $post_id): void {
405 + self::listener()->handle_content_change_by_id($post_id);
406 + }, 20);
183 407
184 - // Taxonomy change hooks
185 - add_action('created_term', [$this, 'handle_taxonomy_change'], 20, 3);
186 - add_action('edited_term', [$this, 'handle_taxonomy_change'], 20, 3);
187 - add_action('delete_term', [$this, 'handle_taxonomy_change'], 20, 3);
408 + foreach (['created_term', 'edited_term', 'delete_term'] as $hook) {
409 + add_action($hook, static function (int $term_id, int $tt_id, string $taxonomy): void {
410 + self::listener()->handle_taxonomy_change($term_id, $tt_id, $taxonomy);
411 + }, 20, 3);
412 + }
413 + }
188 414
189 - // NOTE: the WP-Cron regeneration listeners (thinkrank_regenerate_sitemap
190 - // and thinkrank_regenerate_sitemap_settings) are registered at plugin
191 - // bootstrap (Plugin::register_sitemap_cron_listeners(), on plugins_loaded)
192 - // rather than here. A cron run never builds this class via the REST
193 - // endpoint (no rest_api_init), so registering them in the constructor
194 - // would leave the scheduled events with no listener at cron time.
415 + /**
416 + * The generator the content-change listeners share.
417 + *
418 + * @since 2.10.1
419 + * @return self
420 + */
421 + private static function listener(): self {
422 + return self::$listener ??= new self(false);
195 423 }
196 424
197 425 /**
198 426 * Generate XML sitemap
@@ -204,15 +432,10 @@
204 432 */
205 433 public function generate_sitemap(array $options = []): string {
206 434 $settings = $this->get_settings('site');
207 435
208 - $xml = '<?xml version="1.0" encoding="UTF-8"?>' . "\n";
436 + $xml = $this->xml_prolog($settings, 'sitemap');
209 437
210 - // Add XSL stylesheet only if styling is enabled
211 - if (!empty($settings['enable_styling'])) {
212 - $xml .= '<?xml-stylesheet type="text/xsl" href="' . home_url('/wp-content/plugins/thinkrank/static/xsl/sitemap.xsl') . '"?>' . "\n";
213 - }
214 -
215 438 // Add image namespace if images are enabled
216 439 if (!empty($settings['include_images'])) {
217 440 $xml .= '<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">' . "\n";
218 441 } else {
@@ -374,8 +597,15 @@
374 597 ]
375 598 ],
376 599 'use_sitemap_index' => false,
377 600
601 + // How the sitemap reaches crawlers. 'auto' keeps the historical
602 + // behaviour wherever the web root is writable, and only falls back
603 + // to serving the sitemap from PHP where writing a file is
604 + // impossible — previously a hard failure with nothing served
605 + // (#752).
606 + 'delivery_mode' => 'auto',
607 +
378 608 // General Settings
379 609 'links_per_sitemap' => 1000,
380 610 'include_images' => true,
381 611 'include_featured_images' => false,
@@ -397,8 +627,17 @@
397 627 // Advanced Options
398 628 'enable_styling' => true,
399 629 'custom_url_pattern' => 'sitemap-{type}.xml',
400 630
631 + // Stylesheet branding (#639). Both colours default to empty, not
632 + // to the stock hexes: empty means the stylesheet's own value
633 + // stands, so a site that never opens this screen renders exactly
634 + // as it did before the setting existed.
635 + 'styling_logo' => false,
636 + 'styling_logo_url' => '',
637 + 'styling_color_main' => '',
638 + 'styling_color_accent' => '',
639 +
401 640 // Generation tracking
402 641 'last_generated' => ''
403 642 ];
404 643 }
@@ -403,8 +642,49 @@
403 642 ];
404 643 }
405 644
406 645 /**
646 + * Normalize the stylesheet branding values on the way into the store.
647 + *
648 + * The generic sanitizer only runs `sanitize_text_field()` over a string,
649 + * which happily keeps "red" or "rebeccapurple" as a colour. Nothing
650 + * downstream can use those — {@see Sitemap_Stylesheet::render()} skips any
651 + * value it cannot read as a hex colour — so storing them would report a
652 + * successful save of a setting that changes nothing, and `get-sitemap-
653 + * settings` would hand an agent back a colour the sitemap does not use.
654 + * Reducing here instead keeps the store and the rendering in agreement.
655 + *
656 + * @since 2.7.0
657 + *
658 + * @param array $settings Settings to sanitize.
659 + * @param string $context_type Context the save is for.
660 + * @return array
661 + */
662 + protected function sanitize_settings(array $settings, string $context_type = 'site'): array {
663 + $sanitized = parent::sanitize_settings($settings, $context_type);
664 +
665 + foreach (['styling_color_main', 'styling_color_accent'] as $key) {
666 + if (array_key_exists($key, $sanitized)) {
667 + $sanitized[$key] = Sitemap_Stylesheet::hex($sanitized[$key]);
668 + }
669 + }
670 +
671 + if (array_key_exists('styling_logo_url', $sanitized)) {
672 + $sanitized['styling_logo_url'] = esc_url_raw((string) $sanitized['styling_logo_url']);
673 + }
674 +
675 + // A mode this build cannot act on has to be stored as the fallback
676 + // rather than kept verbatim, or get-sitemap-settings reports a delivery
677 + // mode the site does not actually apply.
678 + if (array_key_exists('delivery_mode', $sanitized)) {
679 + $mode = sanitize_key((string) $sanitized['delivery_mode']);
680 + $sanitized['delivery_mode'] = in_array($mode, self::DELIVERY_MODES, true) ? $mode : 'auto';
681 + }
682 +
683 + return $sanitized;
684 + }
685 +
686 + /**
407 687 * Get settings schema definition (implements interface)
408 688 *
409 689 * @since 1.0.0
410 690 *
@@ -418,8 +698,15 @@
418 698 'title' => 'Enable Sitemap',
419 699 'description' => 'Generate XML sitemap for search engines',
420 700 'default' => true
421 701 ],
702 + 'delivery_mode' => [
703 + 'type' => 'string',
704 + 'title' => 'Sitemap Delivery',
705 + 'description' => 'How the sitemap is served: auto picks static when the WordPress root is writable and dynamic when it is not, static writes files to the web root, dynamic serves the sitemap from WordPress with no files written',
706 + 'enum' => self::DELIVERY_MODES,
707 + 'default' => 'auto'
708 + ],
422 709 'include_posts' => [
423 710 'type' => 'boolean',
424 711 'title' => 'Include Posts',
425 712 'description' => 'Include blog posts in sitemap',
@@ -460,8 +747,32 @@
460 747 'type' => 'string',
461 748 'title' => 'Last Generated',
462 749 'description' => 'Timestamp of last sitemap generation',
463 750 'default' => ''
751 + ],
752 + 'styling_logo' => [
753 + 'type' => 'boolean',
754 + 'title' => 'Show Logo On Sitemap',
755 + 'description' => 'Show a logo above the sitemap heading',
756 + 'default' => false
757 + ],
758 + 'styling_logo_url' => [
759 + 'type' => 'string',
760 + 'title' => 'Sitemap Logo',
761 + 'description' => 'Logo image URL. Empty falls back to the site icon',
762 + 'default' => ''
763 + ],
764 + 'styling_color_main' => [
765 + 'type' => 'string',
766 + 'title' => 'Sitemap Main Color',
767 + 'description' => 'Hex color for the sitemap header, links and table head. Empty keeps the stock palette',
768 + 'default' => ''
769 + ],
770 + 'styling_color_accent' => [
771 + 'type' => 'string',
772 + 'title' => 'Sitemap Accent Color',
773 + 'description' => 'Hex color for the header gradient and link hovers. Empty keeps the stock palette',
774 + 'default' => ''
464 775 ]
465 776 ];
466 777 }
467 778
@@ -478,9 +789,14 @@
478 789 * @return string XML URL entry
479 790 */
480 791 private function generate_url_entry(string $url, string $lastmod, float $priority, string $changefreq, array $images = []): string {
481 792 $xml = " <url>\n";
482 - $xml .= " <loc>" . esc_url($url) . "</loc>\n";
793 + // Every <loc> in every sitemap passes through here, which is why the
794 + // scheme preference is applied at this one point rather than at each
795 + // of the dozen collectors that build URLs (#638). An http sitemap on
796 + // an https site hands search engines the wrong address for the whole
797 + // site at once.
798 + $xml .= " <loc>" . esc_url(Url_Scheme::apply($url)) . "</loc>\n";
483 799 // Omit <lastmod> when unknown (empty) — a fabricated timestamp is worse
484 800 // than no timestamp, and an absent lastmod is valid per the spec.
485 801 if (!empty($lastmod)) {
486 802 $xml .= " <lastmod>" . esc_html($lastmod) . "</lastmod>\n";
@@ -490,9 +806,9 @@
490 806
491 807 // Add image entries if provided
492 808 foreach ($images as $image) {
493 809 $xml .= " <image:image>\n";
494 - $xml .= " <image:loc>" . esc_url($image['url']) . "</image:loc>\n";
810 + $xml .= " <image:loc>" . esc_url(Url_Scheme::apply((string) $image['url'])) . "</image:loc>\n";
495 811
496 812 if (!empty($image['title'])) {
497 813 $xml .= " <image:title>" . esc_html($image['title']) . "</image:title>\n";
498 814 }
@@ -613,8 +929,11 @@
613 929 // well-bounded routine with no ceiling (#402).
614 930 $total = count($all_ids);
615 931
616 932 for ($offset = 0; $offset < $total; $offset += self::ID_WALK_CHUNK) {
933 + $this->assert_memory_headroom();
934 + $chunk_start = memory_get_usage(true);
935 +
617 936 $chunk = array_slice($all_ids, $offset, self::ID_WALK_CHUNK);
618 937
619 938 $posts = get_posts($this->filter_query_args([
620 939 'post_type' => $post_types,
@@ -623,8 +942,12 @@
623 942 'post__in' => $chunk,
624 943 'orderby' => 'post__in', // preserve the resolved order
625 944 ]));
626 945
946 + // get_featured_image() hydrates each featured image under the
947 + // attachment's own ID, which the chunk's post IDs do not reach.
948 + $attachment_ids = [];
949 +
627 950 foreach ($posts as $post) {
628 951 if ($this->should_include_in_sitemap($post, $settings)) {
629 952 /**
630 953 * Filter a sitemap entry's permalink.
@@ -645,14 +968,25 @@
645 968 $priority = $this->calculate_intelligent_priority($post, $post->post_type);
646 969 $changefreq = $this->calculate_change_frequency($post, $post->post_type);
647 970 $images = $this->extract_post_images($post, $settings);
648 971
972 + $thumbnail_id = (int) get_post_thumbnail_id($post);
973 + if ($thumbnail_id > 0) {
974 + $attachment_ids[] = $thumbnail_id;
975 + }
976 +
649 977 yield $this->generate_url_entry($url, $lastmod, $priority, $changefreq, $images);
650 978 }
651 979 }
652 980
653 - // Free the hydrated chunk before loading the next one.
981 + // Free the hydrated chunk before loading the next one — including
982 + // the copies get_posts() left in the runtime object cache.
654 983 unset($posts);
984 + $this->release_walk_memory(
985 + $chunk_start,
986 + $this->chunk_post_cache_groups($post_types),
987 + array_merge($chunk, $attachment_ids)
988 + );
655 989 }
656 990 }
657 991
658 992 /**
@@ -712,8 +1046,11 @@
712 1046 // Same moving window as the post walk above, for the same reason.
713 1047 $total = count($all_ids);
714 1048
715 1049 for ($offset = 0; $offset < $total; $offset += self::TERM_WALK_CHUNK) {
1050 + $this->assert_memory_headroom();
1051 + $chunk_start = memory_get_usage(true);
1052 +
716 1053 $chunk = array_slice($all_ids, $offset, self::TERM_WALK_CHUNK);
717 1054
718 1055 $terms = get_terms($this->filter_term_query_args([
719 1056 'taxonomy' => $taxonomy,
@@ -742,12 +1079,48 @@
742 1079 }
743 1080 }
744 1081
745 1082 unset($terms);
1083 + $this->release_walk_memory($chunk_start, ['terms', 'term_meta'], $chunk);
746 1084 }
747 1085 }
748 1086
749 1087 /**
1088 + * The XML declaration, ownership marker and optional stylesheet every
1089 + * sitemap document opens with.
1090 + *
1091 + * The marker is written unconditionally, and that is the point: removal on
1092 + * deactivate and uninstall deletes a web-root sitemap only when the file
1093 + * says it is ours, and our filenames are the canonical ones another SEO
1094 + * plugin writes too (#515). Tying the proof to `enable_styling` — the one
1095 + * marker older versions left — would mean a site with styling off either
1096 + * kept a shadowing file behind (#510) or had a competitor's deleted.
1097 + *
1098 + * @since 2.1.1
1099 + *
1100 + * The stylesheet URL is served by {@see Sitemap_Stylesheet}, not read off
1101 + * disk by the web server, because a static file cannot carry the site's own
1102 + * logo and colours (#639). It is a fixed URL: the palette is applied per
1103 + * request, so changing a brand colour needs no regeneration and shows up on
1104 + * sitemaps published long before.
1105 + *
1106 + * @param array $settings Sitemap settings (read for `enable_styling`).
1107 + * @param string $variant Stylesheet variant, `sitemap` or `index`.
1108 + * @return string Prolog lines, newline-terminated.
1109 + */
1110 + private function xml_prolog(array $settings, string $variant): string {
1111 + $xml = '<?xml version="1.0" encoding="UTF-8"?>' . "\n";
1112 + $xml .= THINKRANK_SITEMAP_MARKER . "\n";
1113 +
1114 + // The stylesheet is presentation only, so it stays opt-in.
1115 + if (!empty($settings['enable_styling'])) {
1116 + $xml .= '<?xml-stylesheet type="text/xsl" href="' . esc_url(Sitemap_Stylesheet::url($variant)) . '"?>' . "\n";
1117 + }
1118 +
1119 + return $xml;
1120 + }
1121 +
1122 + /**
750 1123 * Wrap a set of <url> entry strings in a complete <urlset> document.
751 1124 *
752 1125 * @since 1.14.0
753 1126 *
@@ -756,14 +1129,10 @@
756 1129 * @param bool $with_image_ns Include the image sitemap namespace
757 1130 * @return string Full sitemap XML
758 1131 */
759 1132 private function wrap_urlset(array $entries, array $settings, bool $with_image_ns): string {
760 - $xml = '<?xml version="1.0" encoding="UTF-8"?>' . "\n";
1133 + $xml = $this->xml_prolog($settings, 'sitemap');
761 1134
762 - if (!empty($settings['enable_styling'])) {
763 - $xml .= '<?xml-stylesheet type="text/xsl" href="' . home_url('/wp-content/plugins/thinkrank/static/xsl/sitemap.xsl') . '"?>' . "\n";
764 - }
765 -
766 1135 if ($with_image_ns && !empty($settings['include_images'])) {
767 1136 $xml .= '<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">' . "\n";
768 1137 } else {
769 1138 $xml .= '<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">' . "\n";
@@ -940,9 +1309,16 @@
940 1309 '_builtin' => false
941 1310 ], 'names');
942 1311
943 1312 foreach ($custom_taxonomies as $taxonomy) {
944 - if ($this->should_include_taxonomy($taxonomy)) {
1313 + if (!$this->should_include_taxonomy($taxonomy)) {
1314 + continue;
1315 + }
1316 +
1317 + // Same as the post-type walk above: an explicit per-taxonomy flag
1318 + // now decides, and an unset flag keeps the previous "included"
1319 + // behaviour (#660).
1320 + if (\ThinkRank\SEO\Content_Type_Settings::is_included_in_sitemap('taxonomy', $taxonomy, $settings)) {
945 1321 $taxonomies[] = $taxonomy;
946 1322 }
947 1323 }
948 1324
@@ -1426,9 +1802,15 @@
1426 1802 if (!empty($settings['include_pages'])) {
1427 1803 $post_types[] = 'page';
1428 1804 }
1429 1805
1430 - // Auto-detect public custom post types that should be included
1806 + // Auto-detect public custom post types that should be included.
1807 + //
1808 + // A custom type's `include_<slug>` / `exclude_<slug>` flag is honoured
1809 + // here (#660). It was previously stored — additional_setting_keys()
1810 + // has always let those keys through — but never read, so a CPT was in
1811 + // the sitemap whatever the setting said. Unset still means included, so
1812 + // a site that never touched the flag is unaffected.
1431 1813 $custom_post_types = get_post_types([
1432 1814 'public' => true,
1433 1815 '_builtin' => false
1434 1816 ], 'names');
@@ -1433,9 +1815,13 @@
1433 1815 '_builtin' => false
1434 1816 ], 'names');
1435 1817
1436 1818 foreach ($custom_post_types as $post_type) {
1437 - if ($this->should_include_post_type($post_type)) {
1819 + if (!$this->should_include_post_type($post_type)) {
1820 + continue;
1821 + }
1822 +
1823 + if (\ThinkRank\SEO\Content_Type_Settings::is_included_in_sitemap('post_type', $post_type, $settings)) {
1438 1824 $post_types[] = $post_type;
1439 1825 }
1440 1826 }
1441 1827
@@ -1456,18 +1842,11 @@
1456 1842 // Templately's internal `templately_library` store — which are template
1457 1843 // records, not standalone indexable URLs. BetterDocs `docs` and
1458 1844 // WooCommerce `product` register exclude_from_search => false, so they
1459 1845 // remain included.
1460 - if (!is_post_type_viewable($post_type)) {
1461 - return false;
1462 - }
1463 -
1464 - $post_type_obj = get_post_type_object($post_type);
1465 - if (!$post_type_obj || !empty($post_type_obj->exclude_from_search)) {
1466 - return false;
1467 - }
1468 -
1469 - return true;
1846 + // The predicate lives in Content_Type_Settings so the matrix can ask
1847 + // the same question before offering a switch for this post type.
1848 + return \ThinkRank\SEO\Content_Type_Settings::sitemap_accepts_post_type($post_type);
1470 1849 }
1471 1850
1472 1851 /**
1473 1852 * Check if taxonomy should trigger regeneration
@@ -1476,11 +1855,13 @@
1476 1855 * @param string $taxonomy Taxonomy slug
1477 1856 * @return bool True if taxonomy should trigger regeneration
1478 1857 */
1479 1858 private function should_include_taxonomy(string $taxonomy): bool {
1480 - // Include all public taxonomies (presets control which sitemaps are created)
1481 - $taxonomy_obj = get_taxonomy($taxonomy);
1482 - return $taxonomy_obj && $taxonomy_obj->public;
1859 + // Public taxonomies only, and only the ones this generator can actually
1860 + // emit — the same predicate the content-type matrix asks before it
1861 + // offers a sitemap switch for one (presets still control which
1862 + // sitemaps are created).
1863 + return \ThinkRank\SEO\Content_Type_Settings::sitemap_accepts_taxonomy($taxonomy);
1483 1864 }
1484 1865
1485 1866 /**
1486 1867 * Schedule debounced sitemap regeneration
@@ -1488,16 +1869,678 @@
1488 1869 * @since 1.0.0
1489 1870 * @return void
1490 1871 */
1491 1872 private function schedule_debounced_regeneration(): void {
1492 - // Clear any existing scheduled regeneration
1493 - wp_clear_scheduled_hook('thinkrank_regenerate_sitemap');
1873 + $this->mark_regeneration_pending('content');
1874 + $this->debounce_event('thinkrank_regenerate_sitemap');
1875 + }
1494 1876
1495 - // Schedule regeneration in 30 seconds to debounce rapid changes
1496 - wp_schedule_single_event(time() + 30, 'thinkrank_regenerate_sitemap');
1877 + /**
1878 + * Schedule (or keep) the debounced single event behind a regeneration hook.
1879 + *
1880 + * An event that is already due is left alone. WP-Cron only runs when a
1881 + * request arrives, so on a site with DISABLE_WP_CRON, a blocked loopback or
1882 + * little traffic an overdue event can sit in the queue for a long time —
1883 + * clearing and re-scheduling it on every save pushed the rebuild
1884 + * permanently 30 seconds into the future and the sitemap never updated
1885 + * (#629). Debouncing only against an event that has not come due yet keeps
1886 + * the bulk-edit coalescing without starving the rebuild.
1887 + *
1888 + * @since 2.2.1
1889 + * @param string $hook Regeneration hook to debounce.
1890 + * @return void
1891 + */
1892 + private function debounce_event(string $hook): void {
1893 + $next = wp_next_scheduled($hook);
1894 +
1895 + if ($next !== false) {
1896 + if ($next <= time()) {
1897 + return;
1898 + }
1899 +
1900 + wp_clear_scheduled_hook($hook);
1901 + }
1902 +
1903 + wp_schedule_single_event(time() + self::REGENERATION_DEBOUNCE, $hook);
1497 1904 }
1498 1905
1499 1906 /**
1907 + * Record that a rebuild is outstanding, so an overdue one can be taken over
1908 + * by a later request and its staleness surfaced in the UI.
1909 + *
1910 + * `since` is the *oldest* outstanding change: it is what the takeover grace
1911 + * and the admin staleness warning are measured from, so successive edits
1912 + * must not push it forward. A settings change outranks a content change —
1913 + * it rebuilds regardless of the auto_generate toggle and handles a sitemap
1914 + * that has just been disabled — so once one is outstanding it stays the
1915 + * recorded source until the rebuild lands.
1916 + *
1917 + * @since 2.2.1
1918 + * @param string $source Either 'content' or 'settings'.
1919 + * @return void
1920 + */
1921 + private function mark_regeneration_pending(string $source): void {
1922 + // Whatever made the static files stale made the rendered ones stale
1923 + // too. Invalidating here rather than only on the rebuild keeps the two
1924 + // delivery modes reacting to exactly the same triggers, which is the
1925 + // only way a dynamic site stays as fresh as a static one (#752).
1926 + $this->flush_dynamic_cache();
1927 +
1928 + $pending = get_option(self::REGENERATION_PENDING_OPTION, []);
1929 + $pending = is_array($pending) ? $pending : [];
1930 +
1931 + $since = !empty($pending['since']) ? (int) $pending['since'] : time();
1932 + $current = isset($pending['source']) ? (string) $pending['source'] : '';
1933 + $source = ($current === 'settings' || $source === 'settings') ? 'settings' : 'content';
1934 +
1935 + // Merged so the bookkeeping a rebuild keeps on the marker (`started`,
1936 + // `memory_limit`) survives an edit made while it is outstanding.
1937 + update_option(
1938 + self::REGENERATION_PENDING_OPTION,
1939 + array_merge($pending, [
1940 + 'since' => $since,
1941 + 'source' => $source,
1942 + 'attempts' => !empty($pending['attempts']) ? (int) $pending['attempts'] : 0,
1943 + 'next_attempt' => !empty($pending['next_attempt'])
1944 + ? (int) $pending['next_attempt']
1945 + : time() + self::REGENERATION_TAKEOVER_GRACE,
1946 + // Bumped on every change so a rebuild can tell whether the edit
1947 + // it started for is still the newest one outstanding.
1948 + 'revision' => (!empty($pending['revision']) ? (int) $pending['revision'] : 0) + 1,
1949 + ]),
1950 + true
1951 + );
1952 + }
1953 +
1954 + /**
1955 + * The revision of the outstanding rebuild, for
1956 + * {@see mark_regeneration_complete()} to compare against once it is done.
1957 + *
1958 + * @since 2.2.1
1959 + * @return int Current revision, 0 when nothing is outstanding.
1960 + */
1961 + private function current_regeneration_revision(): int {
1962 + $pending = get_option(self::REGENERATION_PENDING_OPTION, []);
1963 +
1964 + return (is_array($pending) && !empty($pending['revision'])) ? (int) $pending['revision'] : 0;
1965 + }
1966 +
1967 + /**
1968 + * Clear the outstanding-rebuild marker and any recorded failure.
1969 + *
1970 + * Public because a manual generation satisfies whatever the automatic path
1971 + * was still waiting to write.
1972 + *
1973 + * @since 2.2.1
1974 + * @return void
1975 + */
1976 + public function mark_regeneration_complete(?int $revision = null): void {
1977 + // The write succeeded, so whatever failure was on record is history.
1978 + if (get_option(self::REGENERATION_ERROR_OPTION, null) !== null) {
1979 + delete_option(self::REGENERATION_ERROR_OPTION);
1980 + }
1981 +
1982 + $pending = get_option(self::REGENERATION_PENDING_OPTION, null);
1983 +
1984 + if ($pending === null) {
1985 + return;
1986 + }
1987 +
1988 + // A change that landed while this rebuild was running is not covered by
1989 + // the files it just wrote, so it has to stay outstanding — otherwise, on
1990 + // a site where WP-Cron never fires, clearing the marker would strand it
1991 + // exactly the way #629 stranded everything.
1992 + if (
1993 + $revision !== null
1994 + && is_array($pending)
1995 + && (int) ($pending['revision'] ?? 0) !== $revision
1996 + ) {
1997 + // This attempt succeeded, so drop what it claimed: the newer change
1998 + // waits the grace a fresh edit gets, not a failure backoff it never
1999 + // earned. Not zero: that edit queued its own debounced event, and
2000 + // a marker due at once had the next admin request rebuild in its
2001 + // shutdown and the event rebuild again seconds later.
2002 + unset($pending['started'], $pending['memory_limit']);
2003 + $pending['attempts'] = 0;
2004 + $pending['next_attempt'] = time() + self::REGENERATION_TAKEOVER_GRACE;
2005 +
2006 + update_option(self::REGENERATION_PENDING_OPTION, $pending, true);
2007 + return;
2008 + }
2009 +
2010 + delete_option(self::REGENERATION_PENDING_OPTION);
2011 + }
2012 +
2013 + /**
2014 + * Record the attempt that is about to run before it runs.
2015 + *
2016 + * A PHP fatal — the memory limit or max_execution_time — is not a
2017 + * Throwable, so no catch or finally around the generation runs when the
2018 + * process dies, and a failure recorded afterwards was never recorded at
2019 + * all: `attempts` stayed 0, the backoff never applied, and the next request
2020 + * started the same doomed rebuild again (a fatal every few minutes for as
2021 + * long as an admin was logged in). Claiming the attempt up front makes the
2022 + * backoff hold even when nothing after this line gets to run, and leaves a
2023 + * `started` stamp the next attempt can recognise as an interrupted one.
2024 + *
2025 + * @since 2.10.1
2026 + * @return void
2027 + */
2028 + private function claim_regeneration_attempt(): void {
2029 + $pending = get_option(self::REGENERATION_PENDING_OPTION, null);
2030 +
2031 + // Nothing outstanding (e.g. a manual generation already satisfied it):
2032 + // there is no marker to retry from, so nothing to claim.
2033 + if (!is_array($pending) || empty($pending['since'])) {
2034 + return;
2035 + }
2036 +
2037 + if (!empty($pending['started'])) {
2038 + // The previous attempt claimed itself and never reported back.
2039 + update_option(
2040 + self::REGENERATION_ERROR_OPTION,
2041 + [
2042 + 'message' => __('The previous automatic sitemap rebuild stopped before it finished, most likely because PHP ran out of memory or time. It is retried with a growing delay. If this keeps happening, raise the PHP memory_limit or max_execution_time, or run WP-Cron from a system cron.', 'thinkrank'),
2043 + 'source' => isset($pending['source']) ? (string) $pending['source'] : 'content',
2044 + 'attempts' => !empty($pending['attempts']) ? (int) $pending['attempts'] : 1,
2045 + 'time' => (int) $pending['started'],
2046 + ],
2047 + false
2048 + );
2049 + }
2050 +
2051 + $attempts = (!empty($pending['attempts']) ? (int) $pending['attempts'] : 0) + 1;
2052 +
2053 + $pending['attempts'] = $attempts;
2054 + $pending['next_attempt'] = time() + $this->regeneration_backoff($attempts);
2055 + $pending['started'] = time();
2056 +
2057 + update_option(self::REGENERATION_PENDING_OPTION, $pending, true);
2058 + }
2059 +
2060 + /**
2061 + * Delay before the next takeover after the given number of attempts.
2062 + *
2063 + * @since 2.10.1
2064 + * @param int $attempts Attempts made so far (1 or more).
2065 + * @return int Seconds.
2066 + */
2067 + private function regeneration_backoff(int $attempts): int {
2068 + return (int) min(
2069 + self::REGENERATION_TAKEOVER_GRACE * (2 ** min(max($attempts, 1), 10)),
2070 + self::REGENERATION_MAX_BACKOFF
2071 + );
2072 + }
2073 +
2074 + /**
2075 + * Record a failed regeneration instead of discarding it.
2076 + *
2077 + * Keeps the pending marker in place so the rebuild is retried, but backs the
2078 + * next attempt off exponentially (capped) so a persistently failing
2079 + * generation cannot run on every admin request.
2080 + *
2081 + * @since 2.2.1
2082 + * @since 2.10.1 Accepts the memory limit a rebuild had to stop short of, and
2083 + * does not count an attempt claim_regeneration_attempt()
2084 + * already counted.
2085 + * @param string $message Failure detail.
2086 + * @param string $source Either 'content' or 'settings'.
2087 + * @param int|null $memory_limit Memory limit (bytes) the rebuild stopped
2088 + * short of, when that was the failure.
2089 + * @return void
2090 + */
2091 + private function record_regeneration_failure(string $message, string $source, ?int $memory_limit = null): void {
2092 + $pending = get_option(self::REGENERATION_PENDING_OPTION, []);
2093 + $pending = is_array($pending) ? $pending : [];
2094 + $attempts = !empty($pending['attempts']) ? (int) $pending['attempts'] : 0;
2095 +
2096 + // An attempt that claimed itself up front has already been counted.
2097 + if (empty($pending['started'])) {
2098 + $attempts++;
2099 + }
2100 + $attempts = max($attempts, 1);
2101 +
2102 + $backoff = $this->regeneration_backoff($attempts);
2103 +
2104 + // Same precedence mark_regeneration_pending() enforces: a settings
2105 + // rebuild outranks a content one and must not be downgraded by a failed
2106 + // attempt. Overwriting it routed the retry back through the content
2107 + // path, where should_auto_generate() can be false and the completion
2108 + // marker then discards the settings rebuild entirely. Only the
2109 + // outstanding rebuild is upgraded — the recorded error keeps reporting
2110 + // whichever attempt actually failed.
2111 + $current = isset($pending['source']) ? (string) $pending['source'] : '';
2112 + $pending_source = ($current === 'settings' || $source === 'settings') ? 'settings' : 'content';
2113 +
2114 + $marker = [
2115 + 'since' => !empty($pending['since']) ? (int) $pending['since'] : time(),
2116 + 'source' => $pending_source,
2117 + 'attempts' => $attempts,
2118 + 'next_attempt' => time() + $backoff,
2119 + 'revision' => !empty($pending['revision']) ? (int) $pending['revision'] : 0,
2120 + ];
2121 +
2122 + // Remembered so has_memory_for_retry() can keep requests with no more
2123 + // memory than this from repeating the same attempt.
2124 + if ($memory_limit !== null && $memory_limit > 0) {
2125 + $marker['memory_limit'] = $memory_limit;
2126 + }
2127 +
2128 + update_option(self::REGENERATION_PENDING_OPTION, $marker, true);
2129 +
2130 + update_option(
2131 + self::REGENERATION_ERROR_OPTION,
2132 + [
2133 + 'message' => $message,
2134 + 'source' => $source,
2135 + 'attempts' => $attempts,
2136 + 'time' => time(),
2137 + ],
2138 + false
2139 + );
2140 +
2141 + if (defined('WP_DEBUG') && WP_DEBUG) {
2142 + // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log
2143 + error_log(sprintf('ThinkRank: sitemap %s regeneration failed — %s', $source, $message));
2144 + }
2145 + }
2146 +
2147 + /**
2148 + * Is a rebuild outstanding and past the point where WP-Cron should have run
2149 + * it?
2150 + *
2151 + * Deliberately cheap — one autoloaded option read — because it is consulted
2152 + * on every admin request to decide whether the takeover is needed.
2153 + *
2154 + * @since 2.2.1
2155 + * @return bool True when a request should rebuild the sitemap itself.
2156 + */
2157 + public static function has_overdue_regeneration(): bool {
2158 + $pending = get_option(self::REGENERATION_PENDING_OPTION, []);
2159 +
2160 + if (!is_array($pending) || empty($pending['since'])) {
2161 + return false;
2162 + }
2163 +
2164 + $due = !empty($pending['next_attempt'])
2165 + ? (int) $pending['next_attempt']
2166 + : (int) $pending['since'] + self::REGENERATION_TAKEOVER_GRACE;
2167 +
2168 + return time() >= $due;
2169 + }
2170 +
2171 + /**
2172 + * Rebuild the sitemap in-request when WP-Cron has not delivered.
2173 + *
2174 + * Hooked on `shutdown` for admin, REST and CLI requests only (see
2175 + * Plugin::register_sitemap_cron_listeners()), so the work happens after the
2176 + * response has been sent and never adds latency to a visitor page view.
2177 + *
2178 + * @since 2.2.1
2179 + * @return void
2180 + */
2181 + public function run_overdue_regeneration(): void {
2182 + if (!self::has_overdue_regeneration()) {
2183 + return;
2184 + }
2185 +
2186 + $pending = get_option(self::REGENERATION_PENDING_OPTION, []);
2187 + $pending = is_array($pending) ? $pending : [];
2188 + $source = isset($pending['source']) ? (string) $pending['source'] : 'content';
2189 +
2190 + // Cron is running and its own event for this rebuild is still queued
2191 + // and due: it is about to do exactly this work. Only then — an event
2192 + // that has already been consumed (e.g. it fired while another process
2193 + // held the generation lock) is never re-queued, and returning here
2194 + // unconditionally left the rebuild to requests that could not finish it.
2195 + if (wp_doing_cron()) {
2196 + $hook = $source === 'settings' ? 'thinkrank_regenerate_sitemap_settings' : 'thinkrank_regenerate_sitemap';
2197 + $next = wp_next_scheduled($hook);
2198 +
2199 + if ($next !== false && $next <= time()) {
2200 + return;
2201 + }
2202 + }
2203 +
2204 + // The last attempt had to stop short of this process's memory limit.
2205 + // Retrying at the same (or a lower) limit only repeats that, so leave
2206 + // the rebuild to a process with more room — WP-CLI, a system cron, or a
2207 + // host with a higher limit — instead of burning it on every request.
2208 + if (!$this->has_memory_for_retry($pending)) {
2209 + return;
2210 + }
2211 +
2212 + if ($source === 'settings') {
2213 + $this->regenerate_sitemap_from_settings();
2214 + return;
2215 + }
2216 +
2217 + $this->auto_regenerate_sitemap();
2218 + }
2219 +
2220 + /**
2221 + * Acquire the shared generation lock.
2222 + *
2223 + * @since 2.2.1
2224 + * @return bool True when this process may generate.
2225 + */
2226 + private function acquire_generation_lock(): bool {
2227 + if (get_transient(self::GENERATION_LOCK_TRANSIENT)) {
2228 + return false;
2229 + }
2230 +
2231 + set_transient(self::GENERATION_LOCK_TRANSIENT, time(), 5 * MINUTE_IN_SECONDS);
2232 +
2233 + return true;
2234 + }
2235 +
2236 + /**
2237 + * Release the shared generation lock.
2238 + *
2239 + * @since 2.2.1
2240 + * @return void
2241 + */
2242 + private function release_generation_lock(): void {
2243 + delete_transient(self::GENERATION_LOCK_TRANSIENT);
2244 + }
2245 +
2246 + /**
2247 + * This process's PHP memory limit in bytes.
2248 + *
2249 + * @since 2.10.1
2250 + * @return int Bytes, or -1 when unlimited (or unreadable).
2251 + */
2252 + private function current_memory_limit(): int {
2253 + $limit = (string) ini_get('memory_limit');
2254 +
2255 + if ($limit === '' || $limit === '-1') {
2256 + return -1;
2257 + }
2258 +
2259 + $bytes = (int) wp_convert_hr_to_bytes($limit);
2260 +
2261 + return $bytes > 0 ? $bytes : -1;
2262 + }
2263 +
2264 + /**
2265 + * May this process retry a rebuild that last stopped at the memory limit?
2266 + *
2267 + * Raises the limit the way wp-admin does first, so a request that can get
2268 + * more room than the failed attempt had is still allowed to try.
2269 + *
2270 + * @since 2.10.1
2271 + * @param array $pending The pending marker.
2272 + * @return bool True when there is no recorded memory failure, or this
2273 + * process has more memory than the attempt that failed.
2274 + */
2275 + private function has_memory_for_retry(array $pending): bool {
2276 + if (empty($pending['memory_limit'])) {
2277 + return true;
2278 + }
2279 +
2280 + wp_raise_memory_limit('admin');
2281 +
2282 + $limit = $this->current_memory_limit();
2283 +
2284 + return $limit === -1 || $limit > (int) $pending['memory_limit'];
2285 + }
2286 +
2287 + /**
2288 + * Release what one walked chunk left behind.
2289 + *
2290 + * Hydrating a chunk through get_posts()/get_terms() also stores every
2291 + * object and its meta in the in-process object cache, which nothing
2292 + * empties until the request ends. Unsetting the chunk therefore freed
2293 + * nothing, and the walk grew with the size of the site instead of the size
2294 + * of a chunk — about 1.3 GB on a 45k-post site.
2295 + *
2296 + * A persistent object cache that supports it drops only its in-process
2297 + * copy (`flush_runtime`); the shared store keeps its data. WordPress's
2298 + * default cache has no shared store, and flushing it would empty every
2299 + * group for the rest of the request (options, the queried object, other
2300 + * plugins' data), so there only the chunk's own entries are deleted. A
2301 + * persistent cache without `flush_runtime` is left alone: deleting from it
2302 + * would evict the objects for every other request too.
2303 + *
2304 + * @since 2.10.1
2305 + * @param int $chunk_start memory_get_usage(true) before the chunk was hydrated.
2306 + * @param array $groups Cache groups keyed by the chunk's object IDs.
2307 + * @param int[] $ids The chunk's object IDs, plus any objects it
2308 + * hydrated under their own (featured images).
2309 + * @return void
2310 + * @throws \Error See assert_memory_headroom().
2311 + */
2312 + private function release_walk_memory(int $chunk_start, array $groups, array $ids): void {
2313 + // What one chunk costs before it is released: the margin the next one
2314 + // needs. Measured in the same real allocated size assert_memory_headroom()
2315 + // compares against the limit, so the two are the same unit.
2316 + $this->walk_chunk_cost = max($this->walk_chunk_cost, memory_get_usage(true) - $chunk_start);
2317 +
2318 + if (wp_using_ext_object_cache()) {
2319 + if (
2320 + function_exists('wp_cache_supports')
2321 + && wp_cache_supports('flush_runtime')
2322 + && function_exists('wp_cache_flush_runtime')
2323 + ) {
2324 + wp_cache_flush_runtime();
2325 + }
2326 + } elseif (!empty($ids)) {
2327 + foreach ($groups as $group) {
2328 + wp_cache_delete_multiple($ids, $group);
2329 + }
2330 + }
2331 +
2332 + $this->assert_memory_headroom();
2333 + }
2334 +
2335 + /**
2336 + * Cache groups get_posts() fills per post for the given post types.
2337 + *
2338 + * The post, its meta, and one relationships group per taxonomy the post
2339 + * type uses (update_object_term_cache()). Term objects themselves are
2340 + * bounded by the number of terms, not posts, so they are left cached.
2341 + *
2342 + * @since 2.10.1
2343 + * @param string[] $post_types Post types being walked.
2344 + * @return string[] Cache groups keyed by post ID.
2345 + */
2346 + private function chunk_post_cache_groups(array $post_types): array {
2347 + $groups = ['posts', 'post_meta'];
2348 +
2349 + foreach (get_object_taxonomies($post_types) as $taxonomy) {
2350 + $groups[] = $taxonomy . '_relationships';
2351 + }
2352 +
2353 + return array_values(array_unique($groups));
2354 + }
2355 +
2356 + /**
2357 + * Stop an automatic rebuild before the memory limit rather than at it.
2358 + *
2359 + * A PHP memory fatal skips every catch and finally, so the lock, the
2360 + * failure record and the backoff are all lost with it, while stopping here
2361 + * is an ordinary, fully recorded failure. Checked before each chunk is
2362 + * hydrated, against a margin of at least the largest chunk seen so far.
2363 + *
2364 + * It throws an \Error, not an \Exception, on purpose: the per-segment
2365 + * catch (\Exception) blocks in generate_multiple_sitemaps() would otherwise
2366 + * swallow it and carry on — writing an index without the aborted segments
2367 + * and then pruning their files as orphans. Only the automatic rebuild's
2368 + * catch (\Throwable) is meant to see it.
2369 + *
2370 + * @since 2.10.1
2371 + * @return void
2372 + * @throws \Error When the automatic rebuild is close to the memory limit.
2373 + */
2374 + private function assert_memory_headroom(): void {
2375 + if (!$this->memory_guard) {
2376 + return;
2377 + }
2378 +
2379 + $limit = $this->current_memory_limit();
2380 + if ($limit === -1) {
2381 + return;
2382 + }
2383 +
2384 + // A fifth of the limit (at least 32 MB) for writing the files, or one
2385 + // and a half of the costliest chunk if that is more — and never more
2386 + // than half the limit either way. Without that outer cap a single
2387 + // anomalously expensive chunk (500 posts of serialised page-builder or
2388 + // ACF meta reaches hundreds of megabytes) puts the margin above the
2389 + // limit itself, so every later check aborts at any usage at all, the
2390 + // failure records this process's limit, and has_memory_for_retry()
2391 + // then refuses every process that has the same limit. A site that
2392 + // never actually ran out of memory would stop rebuilding until WP-CLI
2393 + // or a system cron happened to run.
2394 + $headroom = (int) min(
2395 + max(
2396 + min(max($limit * 0.2, 32 * MB_IN_BYTES), $limit * 0.5),
2397 + $this->walk_chunk_cost * 1.5
2398 + ),
2399 + $limit * 0.5
2400 + );
2401 +
2402 + // The real allocated size, which is what PHP enforces memory_limit
2403 + // against; memory_get_usage(false) reports only what is handed out of
2404 + // those allocations and so understates the margin by the allocator's
2405 + // slack.
2406 + $usage = memory_get_usage(true);
2407 +
2408 + if ($usage > $limit - $headroom) {
2409 + throw new \Error(
2410 + sprintf(
2411 + /* translators: 1: memory in use, 2: PHP memory limit. */
2412 + __('The sitemap rebuild was stopped at %1$s of the %2$s PHP memory limit, before PHP would have run out of memory. It will be retried by a process with more memory (WP-CLI or a system cron). To let it finish in the admin, raise the PHP memory_limit.', 'thinkrank'),
2413 + size_format($usage),
2414 + size_format($limit)
2415 + ),
2416 + self::MEMORY_ABORT_CODE
2417 + );
2418 + }
2419 + }
2420 +
2421 + /**
2422 + * Run an automatic rebuild's generation with the fatal-safe bookkeeping.
2423 + *
2424 + * @since 2.10.1
2425 + * @param array $settings Sitemap settings.
2426 + * @return bool Whatever generate_and_save() returned.
2427 + * @throws \Throwable Whatever generation throws, after the memory guard is
2428 + * switched back off.
2429 + */
2430 + private function generate_for_regeneration(array $settings): bool {
2431 + // Same headroom wp-admin gives itself; a no-op when the limit is
2432 + // already higher or unlimited.
2433 + wp_raise_memory_limit('admin');
2434 +
2435 + $this->claim_regeneration_attempt();
2436 + $this->memory_guard = true;
2437 + $this->walk_chunk_cost = 0;
2438 +
2439 + try {
2440 + return $this->generate_and_save($settings);
2441 + } finally {
2442 + $this->memory_guard = false;
2443 + }
2444 + }
2445 +
2446 + /**
2447 + * Record a failure thrown by an automatic rebuild.
2448 + *
2449 + * @since 2.10.1
2450 + * @param \Throwable $e What was thrown.
2451 + * @param string $source Either 'content' or 'settings'.
2452 + * @return void
2453 + */
2454 + private function record_thrown_regeneration_failure(\Throwable $e, string $source): void {
2455 + $memory_limit = null;
2456 +
2457 + if ($e instanceof \Error && $e->getCode() === self::MEMORY_ABORT_CODE) {
2458 + $memory_limit = $this->current_memory_limit();
2459 + $memory_limit = $memory_limit > 0 ? $memory_limit : null;
2460 + }
2461 +
2462 + $this->record_regeneration_failure($e->getMessage(), $source, $memory_limit);
2463 + }
2464 +
2465 + /**
2466 + * Report how automatic regeneration is faring, for the admin UI.
2467 + *
2468 + * The feature used to fail invisibly: `last_generated` simply stopped
2469 + * advancing and nothing drew attention to it (#629).
2470 + *
2471 + * @since 2.2.1
2472 + * @return array Health payload.
2473 + */
2474 + public function get_regeneration_health(): array {
2475 + $settings = $this->get_settings('site');
2476 + $pending = get_option(self::REGENERATION_PENDING_OPTION, []);
2477 + $pending = is_array($pending) ? $pending : [];
2478 + $error = get_option(self::REGENERATION_ERROR_OPTION, []);
2479 + $error = is_array($error) ? $error : [];
2480 +
2481 + $since = !empty($pending['since']) ? (int) $pending['since'] : 0;
2482 +
2483 + $next_scheduled = wp_next_scheduled('thinkrank_regenerate_sitemap');
2484 + if ($next_scheduled === false) {
2485 + $next_scheduled = wp_next_scheduled('thinkrank_regenerate_sitemap_settings');
2486 + }
2487 +
2488 + return [
2489 + 'auto_generate' => !empty($settings['auto_generate']),
2490 + 'last_generated' => $settings['last_generated'] ?? '',
2491 + 'pending_since' => $since ? gmdate('c', $since) : null,
2492 + 'pending_seconds' => $since ? max(0, time() - $since) : 0,
2493 + 'next_scheduled' => $next_scheduled ? gmdate('c', (int) $next_scheduled) : null,
2494 + 'cron_disabled' => defined('DISABLE_WP_CRON') && DISABLE_WP_CRON,
2495 + 'stale' => $this->is_sitemap_stale($settings),
2496 + 'last_error' => !empty($error['message'])
2497 + ? [
2498 + 'message' => (string) $error['message'],
2499 + 'source' => isset($error['source']) ? (string) $error['source'] : 'content',
2500 + 'time' => !empty($error['time']) ? gmdate('c', (int) $error['time']) : null,
2501 + ]
2502 + : null,
2503 + ];
2504 + }
2505 +
2506 + /**
2507 + * Has published content changed since the served sitemap was last written?
2508 + *
2509 + * Uses core's cached last-modified lookup, which only considers published
2510 + * posts — the same content the sitemap covers.
2511 + *
2512 + * @since 2.2.1
2513 + * @param array $settings Sitemap settings.
2514 + * @return bool True when the sitemap is behind the content.
2515 + */
2516 + private function is_sitemap_stale(array $settings): bool {
2517 + if (empty($settings['enabled']) || empty($settings['last_generated'])) {
2518 + // Never generated is already reported separately by the UI.
2519 + return false;
2520 + }
2521 +
2522 + $generated = strtotime((string) $settings['last_generated']);
2523 + if (!$generated) {
2524 + return false;
2525 + }
2526 +
2527 + $modified = get_lastpostmodified('gmt');
2528 + if (!$modified) {
2529 + return false;
2530 + }
2531 +
2532 + $modified = strtotime($modified . ' UTC');
2533 + if (!$modified) {
2534 + return false;
2535 + }
2536 +
2537 + // A minute of slack keeps a rebuild that ran alongside the edit from
2538 + // reporting itself as stale.
2539 + return $modified > ($generated + MINUTE_IN_SECONDS);
2540 + }
2541 +
2542 + /**
1500 2543 * Public entry point to debounce-rebuild the sitemap after a settings change
1501 2544 * (e.g. toggling inclusion rules via REST or the MCP ability), so the served
1502 2545 * file reflects the new settings instead of going stale until a content edit.
1503 2546 *
@@ -1506,10 +2549,10 @@
1506 2549 public function schedule_regeneration(): void {
1507 2550 // Debounce against rapid successive saves, but use the settings-specific
1508 2551 // hook so the rebuild runs regardless of the auto_generate toggle (which
1509 2552 // only governs content-change-triggered regeneration).
1510 - wp_clear_scheduled_hook('thinkrank_regenerate_sitemap_settings');
1511 - wp_schedule_single_event(time() + 30, 'thinkrank_regenerate_sitemap_settings');
2553 + $this->mark_regeneration_pending('settings');
2554 + $this->debounce_event('thinkrank_regenerate_sitemap_settings');
1512 2555 }
1513 2556
1514 2557 /**
1515 2558 * Rebuild the served sitemap after an explicit settings change.
@@ -1518,11 +2561,22 @@
1518 2561 * auto_generate setting: the user deliberately changed inclusion rules and
1519 2562 * expects the served file to reflect them even if content-triggered
1520 2563 * auto-generation is turned off. Still respects the master `enabled` flag.
1521 2564 *
1522 - * @return void
2565 + * @since 2.10.0 Reports whether the served sitemap was actually rebuilt, so
2566 + * a caller can say so rather than assume it (#764). Existing
2567 + * callers that ignore the return are unaffected.
2568 + *
2569 + * @return bool True when the served sitemap now reflects the settings.
1523 2570 */
1524 - public function regenerate_sitemap_from_settings(): void {
2571 + public function regenerate_sitemap_from_settings(): bool {
2572 + if (!$this->acquire_generation_lock()) {
2573 + // A manual generation (or another request's takeover) is already
2574 + // writing the files; the pending marker survives so this rebuild is
2575 + // retried rather than lost.
2576 + return false;
2577 + }
2578 +
1525 2579 try {
1526 2580 $settings = $this->get_settings('site');
1527 2581 if (empty($settings['enabled'])) {
1528 2582 // The sitemap was disabled: remove the previously generated static
@@ -1527,30 +2581,98 @@
1527 2581 if (empty($settings['enabled'])) {
1528 2582 // The sitemap was disabled: remove the previously generated static
1529 2583 // files so the web server stops serving a stale sitemap that
1530 2584 // crawlers would otherwise keep fetching.
1531 - $this->delete_published_sitemaps();
1532 - return;
2585 + //
2586 + // A file that could not be removed is still being served, so
2587 + // this is not a success. Reporting one here would tell a caller
2588 + // the sitemap was gone while the web server kept answering with
2589 + // it, which is the failure this return value exists to prevent
2590 + // (#764).
2591 + $removal = $this->delete_published_sitemaps($settings);
2592 + $stuck = is_array($removal['failed'] ?? null) ? $removal['failed'] : [];
2593 +
2594 + if (!empty($stuck)) {
2595 + $this->record_regeneration_failure(
2596 + $this->stuck_files_message($stuck, true),
2597 + 'settings'
2598 + );
2599 +
2600 + return false;
2601 + }
2602 +
2603 + $this->mark_regeneration_complete();
2604 +
2605 + return true;
1533 2606 }
1534 - $this->generate_and_save($settings);
2607 +
2608 + $revision = $this->current_regeneration_revision();
2609 +
2610 + if ('dynamic' === $this->resolve_delivery_mode($settings)) {
2611 + // Returns false when a static file is stuck in the web root:
2612 + // the server keeps serving that file in preference to WordPress,
2613 + // so the switch has not taken effect (#764).
2614 + return $this->switch_to_dynamic_delivery($settings, $revision, 'settings');
2615 + }
2616 +
2617 + if ($this->generate_for_regeneration($settings)) {
2618 + $this->mark_regeneration_complete($revision);
2619 +
2620 + return true;
2621 + }
2622 +
2623 + $this->record_regeneration_failure(
2624 + $this->write_failure_message(),
2625 + 'settings'
2626 + );
2627 +
2628 + return false;
1535 2629 } catch (\Throwable $e) {
1536 - // Settings-triggered regeneration failed - details in exception.
2630 + $this->record_thrown_regeneration_failure($e, 'settings');
2631 +
2632 + return false;
2633 + } finally {
2634 + $this->release_generation_lock();
1537 2635 }
1538 2636 }
1539 2637
1540 2638 /**
2639 + * When a rebuild has been outstanding since, or 0 when none is.
2640 + *
2641 + * Lets a caller report an honest "saved, but the served file has not caught
2642 + * up yet" instead of a bare success (#764).
2643 + *
2644 + * @since 2.10.0
2645 + * @return int Unix timestamp, or 0 when nothing is pending.
2646 + */
2647 + public static function regeneration_pending_since(): int {
2648 + $pending = get_option(self::REGENERATION_PENDING_OPTION, []);
2649 +
2650 + if (!is_array($pending) || empty($pending['since'])) {
2651 + return 0;
2652 + }
2653 +
2654 + return (int) $pending['since'];
2655 + }
2656 +
2657 + /**
1541 2658 * Remove every static sitemap file ThinkRank publishes to the web root.
1542 2659 *
1543 - * Called when the sitemap feature is disabled, and by the cleanup route, so
1544 - * /sitemap.xml, /sitemap_index.xml, the segmented children (incl. paginated
1545 - * -N pages), and /local-sitemap.xml stop being served. Only ThinkRank's own
1546 - * filenames are targeted; WordPress core's wp-sitemap.xml and any other
1547 - * plugin's sitemap in the web root are left untouched.
2660 + * Called when the sitemap feature is disabled, by the cleanup route, and by
2661 + * both removal paths, so /sitemap.xml, /sitemap_index.xml, the segmented
2662 + * children (incl. paginated -N pages), and /local-sitemap.xml stop being
2663 + * served. Only ThinkRank's own filenames are targeted; WordPress core's
2664 + * wp-sitemap.xml and any other plugin's sitemap in the web root are left
2665 + * untouched.
1548 2666 *
1549 2667 * @since 1.31.0 Returns the filenames removed, and accepts the settings to
1550 2668 * derive them from, so a caller that already read them (and
1551 2669 * needs to report what went) does not have to re-read or
1552 2670 * re-derive the name list.
2671 + * @since 2.1.0 Delegates to thinkrank_webroot_delete_sitemaps(). Uninstall
2672 + * needs the same removal but has no autoloader to reach this
2673 + * class, so the logic moved to includes/cleanup-webroot.php
2674 + * and this stays as the in-plugin entry point.
1553 2675 *
1554 2676 * @param array|null $settings Optional. Sitemap settings; defaults to the
1555 2677 * saved site settings.
1556 2678 * @return array{deleted: string[], failed: string[]} Basenames removed, and
@@ -1556,123 +2678,58 @@
1556 2678 * @return array{deleted: string[], failed: string[]} Basenames removed, and
1557 2679 * those that existed but could not be removed.
1558 2680 */
1559 2681 public function delete_published_sitemaps(?array $settings = null): array {
1560 - $settings = $settings ?? $this->get_settings('site');
1561 - $deleted = [];
1562 - $failed = [];
1563 -
1564 - // Base filenames to remove. Derive the child/index names from the stored
1565 - // sitemap_urls so a custom custom_url_pattern (e.g. seo-{type}.xml) is
1566 - // honored, not just the default sitemap-*.xml naming. Include the current
1567 - // primary + the default names as a safety net.
1568 - $names = [
1569 - 'sitemap.xml',
1570 - 'sitemap_index.xml',
1571 - 'local-sitemap.xml',
1572 - $this->get_primary_sitemap_filename($settings),
1573 - ];
1574 -
1575 - foreach ((is_array($settings['sitemap_urls'] ?? null) ? $settings['sitemap_urls'] : []) as $config) {
1576 - if (empty($config['url'])) {
1577 - continue;
1578 - }
1579 - $name = basename((string) wp_parse_url($config['url'], PHP_URL_PATH));
1580 - if ($name !== '') {
1581 - $names[] = $name;
1582 - }
1583 - }
1584 -
1585 - // Segment names for every type we could have published under the current
1586 - // url pattern, not just the ones stored in sitemap_urls. Two states leave
1587 - // a published child unlisted there: settings that drifted from what is on
1588 - // disk (a single-file entry while an index and its children are live), and
1589 - // a content type that has since been switched off. Deriving the names
1590 - // from the pattern reaches those without falling back to a 'sitemap-*.xml'
1591 - // glob, which would also match another plugin's segments.
1592 - $names = array_merge($names, $this->publishable_segment_filenames($settings));
1593 -
1594 - foreach (array_unique(array_filter($names)) as $name) {
1595 - // Remove the file itself and any paginated -N variants of its stem
1596 - // (e.g. seo-posts.xml plus seo-posts-2.xml, seo-posts-3.xml…).
1597 - $path = ABSPATH . $name;
1598 - if (file_exists($path)) {
1599 - wp_delete_file($path);
1600 - // wp_delete_file() returns nothing, so confirm by re-checking.
1601 - if (file_exists($path)) {
1602 - $failed[] = $name;
1603 - } else {
1604 - $deleted[] = $name;
1605 - }
1606 - }
1607 - if (preg_match('/^(.*)\.xml$/i', $name, $m)) {
1608 - // Pagination pages only — a numeric suffix on this exact stem.
1609 - // Globbing '<stem>-*.xml' matched any name that merely started
1610 - // with the stem, so the default 'sitemap.xml' entry pulled in
1611 - // every sitemap-*.xml in the root, including another plugin's.
1612 - $paged_pattern = '/^' . preg_quote($m[1], '/') . '-\d+\.xml$/i';
1613 -
1614 - foreach (glob(ABSPATH . $m[1] . '-*.xml') ?: [] as $paged) {
1615 - $paged_name = basename($paged);
1616 - if (!preg_match($paged_pattern, $paged_name)) {
1617 - continue;
1618 - }
1619 -
1620 - wp_delete_file($paged);
1621 - if (file_exists($paged)) {
1622 - $failed[] = $paged_name;
1623 - } else {
1624 - $deleted[] = $paged_name;
1625 - }
1626 - }
1627 - }
1628 - }
1629 -
1630 - return [
1631 - 'deleted' => array_values(array_unique($deleted)),
1632 - 'failed' => array_values(array_unique($failed)),
1633 - ];
2682 + return thinkrank_webroot_delete_sitemaps($settings ?? $this->get_settings('site'));
1634 2683 }
1635 2684
1636 2685 /**
1637 2686 * Every child-sitemap filename this site could have published.
1638 2687 *
1639 - * Formats the configured url pattern against each type ThinkRank segments by
1640 - * — the four built-ins plus every public custom post type and public custom
1641 - * taxonomy — ignoring whether that type is currently included. The point is
1642 - * to recognise our own filenames, and a type that was published and later
1643 - * disabled still left a file behind.
1644 - *
1645 2688 * @since 1.31.0
2689 + * @since 2.1.0 Delegates to thinkrank_webroot_segment_filenames().
1646 2690 *
1647 2691 * @param array $settings Sitemap settings (read for `custom_url_pattern`).
1648 2692 * @return string[] Basenames, e.g. ['sitemap-posts.xml', 'sitemap-pages.xml'].
1649 2693 */
1650 2694 private function publishable_segment_filenames(array $settings): array {
1651 - $pattern = (string) ($settings['custom_url_pattern'] ?? 'sitemap-{type}.xml');
1652 - if (strpos($pattern, '{type}') === false) {
1653 - return [];
1654 - }
2695 + return thinkrank_webroot_segment_filenames($settings);
2696 + }
1655 2697
1656 - $types = ['posts', 'pages', 'categories', 'tags'];
1657 -
1658 - foreach (get_post_types(['public' => true, '_builtin' => false], 'names') as $cpt) {
1659 - $types[] = (string) $cpt;
1660 - }
1661 -
1662 - foreach (get_taxonomies(['public' => true, '_builtin' => false], 'names') as $taxonomy) {
1663 - $types[] = (string) $taxonomy;
1664 - }
1665 -
1666 - $names = [];
1667 - foreach (array_unique($types) as $type) {
1668 - $name = basename(str_replace('{type}', $type, $pattern));
1669 - if ($name !== '') {
1670 - $names[] = $name;
1671 - }
1672 - }
1673 -
1674 - return $names;
2698 + /**
2699 + * Can this web-root file be shown to be a sitemap ThinkRank wrote?
2700 + *
2701 + * The generator deletes as often as cleanup does — a segment that dropped
2702 + * out of the set, a pagination page beyond the new count, the local sitemap
2703 + * after the business identity was cleared — and until 2.1.1 it did all
2704 + * three by filename alone. That is the #515 bug on a far more frequent
2705 + * trigger: our names are the canonical ones, so an ordinary regeneration
2706 + * (post save, term change, settings save) destroyed RankMath's
2707 + * `sitemap-tags.xml` and `local-sitemap.xml` with no deactivation involved.
2708 + *
2709 + * Every name the generator derives comes from the current settings — the
2710 + * url pattern, the configured `sitemap_urls`, `local-sitemap.xml` — but the
2711 + * ownership test is still asked with `$name_derived = false`, which switches
2712 + * off the legacy fallback for the whole generator side.
2713 + *
2714 + * The fallback exists to recover a pre-2.1.1 file written with
2715 + * `enable_styling` off, which carries neither marker. That recovery belongs
2716 + * to the once-off cleanup paths. Here it can only do harm: this method runs
2717 + * on every post save, and everything this version writes carries
2718 + * THINKRANK_SITEMAP_MARKER, so after the site's first regeneration an
2719 + * unmarked file at one of our names is by definition somebody else's — and
2720 + * deleting it on an ordinary regeneration is #515 through the more common
2721 + * door. The cost is a stale unmarked segment left on disk until deactivation
2722 + * picks it up, which is the safe direction to fail in.
2723 + *
2724 + * @since 2.1.1
2725 + *
2726 + * @param string $path Absolute path to a file in the web root.
2727 + * @param array $settings Sitemap settings.
2728 + * @return bool True when the file may be deleted.
2729 + */
2730 + private function webroot_sitemap_is_ours(string $path, array $settings): bool {
2731 + return thinkrank_webroot_sitemap_is_ours($path, $settings, false);
1675 2732 }
1676 2733
1677 2734 /**
1678 2735 * Auto-regenerate sitemap (called by scheduled action)
@@ -1680,20 +2737,48 @@
1680 2737 * @since 1.0.0
1681 2738 * @return void
1682 2739 */
1683 2740 public function auto_regenerate_sitemap(): void {
2741 + if (!$this->acquire_generation_lock()) {
2742 + // A manual generation (or another request's takeover) is already
2743 + // writing the files; the pending marker survives so this rebuild is
2744 + // retried rather than lost.
2745 + return;
2746 + }
2747 +
1684 2748 try {
1685 2749 // Double-check that auto-generation is still enabled
1686 2750 if (!$this->should_auto_generate()) {
2751 + // Nothing outstanding can be delivered while the feature is off,
2752 + // so drop the marker rather than let the takeover retry forever.
2753 + $this->mark_regeneration_complete();
1687 2754 return;
1688 2755 }
1689 2756
1690 - $this->generate_and_save($this->get_settings('site'));
2757 + $revision = $this->current_regeneration_revision();
2758 + $settings = $this->get_settings('site');
1691 2759
1692 - // Sitemap auto-regenerated successfully
2760 + // See regenerate_sitemap_from_settings(): nothing to write.
2761 + if ('dynamic' === $this->resolve_delivery_mode($settings)) {
2762 + $this->switch_to_dynamic_delivery($settings, $revision, 'content');
2763 + return;
2764 + }
1693 2765
2766 + if ($this->generate_for_regeneration($settings)) {
2767 + $this->mark_regeneration_complete($revision);
2768 + } else {
2769 + // Previously this returned quietly and last_generated simply
2770 + // stopped advancing, leaving the site owner with no way to learn
2771 + // the sitemap had stopped updating (#629).
2772 + $this->record_regeneration_failure(
2773 + $this->write_failure_message(),
2774 + 'content'
2775 + );
2776 + }
1694 2777 } catch (\Throwable $e) {
1695 - // Sitemap auto-regeneration failed - error details available in exception
2778 + $this->record_thrown_regeneration_failure($e, 'content');
2779 + } finally {
2780 + $this->release_generation_lock();
1696 2781 }
1697 2782 }
1698 2783
1699 2784 /**
@@ -1708,8 +2793,26 @@
1708 2793 * @param array $settings Sitemap settings.
1709 2794 * @return bool True when the sitemap files were written.
1710 2795 */
1711 2796 public function generate_and_save(array $settings): bool {
2797 + // Dynamic delivery publishes no files, so writing them here would put a
2798 + // static copy back in the web root for the server to serve in place of
2799 + // the dynamic route. Guarding at each call site left gaps — the
2800 + // snapshot migrator's post-import regeneration had none — so the rule
2801 + // lives with the writing instead.
2802 + //
2803 + // `is_collecting()` is the exception that makes dynamic delivery work
2804 + // at all: render_document() and collect_documents() reach this same
2805 + // method with the writer swapped for a collector, and that is precisely
2806 + // the dynamic build. Only a real write is skipped.
2807 + if (!$this->is_collecting() && 'dynamic' === $this->resolve_delivery_mode($settings)) {
2808 + // Whatever prompted this call changed the sitemap's content, so the
2809 + // rendered copies must not outlive it.
2810 + $this->flush_dynamic_cache();
2811 +
2812 + return true;
2813 + }
2814 +
1712 2815 // Index mode is driven by the use_sitemap_index toggle (not merely by how
1713 2816 // many sitemap_urls happen to be configured). When the toggle is on but
1714 2817 // no child sitemaps are set up yet, synthesize the per-type segmented set
1715 2818 // so we emit a real <sitemapindex> with paginated children instead of a
@@ -1720,16 +2823,29 @@
1720 2823 $results = $this->generate_multiple_sitemaps($settings);
1721 2824 $written = !empty($results['success']);
1722 2825 } else {
1723 2826 $xml = $this->generate_sitemap($settings);
1724 - $written = $this->save_sitemap_to_file($xml, $this->get_primary_sitemap_filename($settings));
2827 + $primary = $this->get_primary_sitemap_filename($settings);
2828 + $written = $this->save_sitemap_to_file($xml, $primary);
1725 2829
1726 2830 // Local business sitemap is a standalone file, regenerated on the
1727 2831 // single-sitemap path too (this is the default mode).
1728 2832 $this->regenerate_local_sitemap($settings);
2833 +
2834 + // Switching out of index mode leaves sitemap_index.xml and every
2835 + // child on disk, still served and never refreshed again. The index
2836 + // path already prunes what it no longer owns; this path never did,
2837 + // so the site kept serving two sitemap trees (#563). Ownership is
2838 + // still tested per file, so another plugin's sitemap at one of our
2839 + // names is never touched (#515).
2840 + $this->prune_orphaned_segments($settings, [['filename' => basename($primary)]]);
1729 2841 }
1730 2842
1731 - if ($written) {
2843 + // last_generated describes what is on disk. A dynamic render publishes
2844 + // nothing, so advancing it would report a static publication that never
2845 + // happened and would let primary_sitemap_file_exists() callers believe
2846 + // there is a file to serve.
2847 + if ($written && !$this->is_collecting()) {
1732 2848 $settings['last_generated'] = gmdate('c');
1733 2849 $this->save_settings('site', null, $settings);
1734 2850 }
1735 2851
@@ -1736,8 +2852,433 @@
1736 2852 return $written;
1737 2853 }
1738 2854
1739 2855 /**
2856 + * Whether this instance is rendering documents rather than publishing them.
2857 + *
2858 + * @since 2.9.0
2859 + *
2860 + * @return bool
2861 + */
2862 + private function is_collecting(): bool {
2863 + return $this->document_sink !== null;
2864 + }
2865 +
2866 + /**
2867 + * Complete a regeneration that delivers dynamically, retiring stale files.
2868 + *
2869 + * Dynamic delivery renders nothing to disk, but that is only half the job.
2870 + * A web server hands back an existing `/sitemap.xml` without ever loading
2871 + * WordPress, so any file left over from a previous static generation goes on
2872 + * being served forever and {@see \ThinkRank\Frontend\SEO_Manager
2873 + * ::maybe_serve_sitemap()} is never reached. Switching to dynamic while
2874 + * leaving those files in place would therefore appear to do nothing at all.
2875 + *
2876 + * Both transitions matter and they differ:
2877 + *
2878 + * - An explicit switch to `dynamic` happens on a site whose root is usually
2879 + * still writable, so the files can simply be removed.
2880 + * - An `auto` site that becomes read-only cannot remove them, because
2881 + * deleting an entry needs write permission on the directory that holds
2882 + * it. There the stale sitemap really is stuck in front of us, and the
2883 + * honest outcome is a recorded failure naming it rather than a rebuild
2884 + * reported as complete (#754 review).
2885 + *
2886 + * Ownership is tested per file by the shared helper, so another plugin's
2887 + * sitemap at one of our names is never deleted (#515).
2888 + *
2889 + * @since 2.9.0
2890 + *
2891 + * @param array $settings Sitemap settings.
2892 + * @param int $revision Revision this rebuild is completing.
2893 + * @param string $source 'settings' or 'content', for the failure record.
2894 + * @return void
2895 + */
2896 + private function switch_to_dynamic_delivery(array $settings, int $revision, string $source): bool {
2897 + $this->flush_dynamic_cache();
2898 +
2899 + $removal = $this->delete_published_sitemaps($settings);
2900 + $stuck = is_array($removal['failed'] ?? null) ? $removal['failed'] : [];
2901 +
2902 + if (!empty($stuck)) {
2903 + $this->record_regeneration_failure($this->stuck_files_message($stuck), $source);
2904 +
2905 + return false;
2906 + }
2907 +
2908 + $this->mark_regeneration_complete($revision);
2909 +
2910 + return true;
2911 + }
2912 +
2913 + /**
2914 + * Why a stale file left in the web root means the change has not landed.
2915 + *
2916 + * Shared by every path that removes published files, so they cannot
2917 + * describe the same situation differently (#764).
2918 + *
2919 + * The two situations that reach it differ in what WordPress is doing, and
2920 + * the message has to say which. After a switch to dynamic delivery
2921 + * WordPress IS serving the sitemap and the files shadow it. After the
2922 + * sitemap is switched off WordPress serves nothing, so the one message
2923 + * used to tell a site owner who had just disabled the sitemap that it was
2924 + * "being served from WordPress", which is the opposite of what they did.
2925 + *
2926 + * @since 2.10.0
2927 + * @since 2.10.0 Public, so the REST endpoint uses it rather than a copy;
2928 + * takes $sitemap_disabled for the disabled path.
2929 + *
2930 + * @param string[] $stuck Basenames that could not be removed.
2931 + * @param bool $sitemap_disabled True when the files outlived disabling
2932 + * the sitemap rather than a switch to
2933 + * dynamic delivery.
2934 + * @return string
2935 + */
2936 + public function stuck_files_message(array $stuck, bool $sitemap_disabled = false): string {
2937 + if ($sitemap_disabled) {
2938 + return sprintf(
2939 + /* translators: 1: comma-separated file names, 2: absolute path to the WordPress root. */
2940 + __('The sitemap is disabled, but these files are still in the site root and your web server is still serving them: %1$s. They could not be removed because %2$s is not writable. Delete them, or ask your host to make the WordPress root writable.', 'thinkrank'),
2941 + implode(', ', $stuck),
2942 + untrailingslashit(ABSPATH)
2943 + );
2944 + }
2945 +
2946 + return sprintf(
2947 + /* translators: 1: comma-separated file names, 2: absolute path to the WordPress root. */
2948 + __('The sitemap is being served from WordPress, but these files are still in the site root and your web server will keep serving them instead: %1$s. They could not be removed because %2$s is not writable. Delete them, or ask your host to make the WordPress root writable.', 'thinkrank'),
2949 + implode(', ', $stuck),
2950 + untrailingslashit(ABSPATH)
2951 + );
2952 + }
2953 +
2954 + /**
2955 + * What to tell the site owner when publishing the files failed.
2956 + *
2957 + * The old wording stated the symptom and stopped there, so the reported
2958 + * cause was a guess and this reached support as a plugin fault rather than
2959 + * a folder permission (#752, #753). When the root is demonstrably
2960 + * unwritable, say that, and say what to do about it.
2961 + *
2962 + * @since 2.9.0
2963 + *
2964 + * @return string
2965 + */
2966 + private function write_failure_message(): string {
2967 + if (!wp_is_writable(ABSPATH)) {
2968 + return sprintf(
2969 + /* translators: %s: absolute path to the WordPress root. */
2970 + __('The sitemap could not be written because the folder %s is not writable by PHP. Ask your host to make the WordPress root writable, or set Sitemap Delivery to Dynamic to serve the sitemap without writing files.', 'thinkrank'),
2971 + untrailingslashit(ABSPATH)
2972 + );
2973 + }
2974 +
2975 + return __('The sitemap files could not be written to the site root.', 'thinkrank');
2976 + }
2977 +
2978 + /**
2979 + * How this site delivers its sitemap.
2980 + *
2981 + * `auto` is resolved on whether the web root can be written. That is the
2982 + * right signal here (unlike llms.txt, where the question is whether the
2983 + * server applies the .htaccess charset block): a site whose root is
2984 + * read-only cannot publish a sitemap file at all, and before this existed
2985 + * the feature simply failed with "The sitemap files could not be written to
2986 + * the site root." and served nothing (#752).
2987 + *
2988 + * @since 2.9.0
2989 + *
2990 + * @param array|null $settings Sitemap settings (falls back to saved ones).
2991 + * @return string One of 'static' or 'dynamic'. Never 'auto'.
2992 + */
2993 + public function resolve_delivery_mode(?array $settings = null): string {
2994 + $settings = $settings ?? $this->get_settings('site');
2995 + $mode = (string) ($settings['delivery_mode'] ?? 'auto');
2996 +
2997 + if ('static' === $mode || 'dynamic' === $mode) {
2998 + return $mode;
2999 + }
3000 +
3001 + return wp_is_writable(ABSPATH) ? 'static' : 'dynamic';
3002 + }
3003 +
3004 + /**
3005 + * Render one published sitemap document without touching the filesystem.
3006 + *
3007 + * Runs the ordinary build pipeline with the writer swapped for a collector,
3008 + * so the bytes returned here are the bytes the static path would have
3009 + * written. `SitemapDeliveryParityTest` asserts that equivalence rather than
3010 + * trusting it.
3011 + *
3012 + * The whole set is built to answer for one file, because the index can only
3013 + * be assembled from the children that were actually produced. The result is
3014 + * cached per document, so that cost is paid once per change and not once
3015 + * per crawler request.
3016 + *
3017 + * @since 2.9.0
3018 + *
3019 + * @param string $filename Published file name, e.g. 'sitemap.xml'.
3020 + * @param array|null $settings Sitemap settings (falls back to saved ones).
3021 + * @return string|null XML, or null when this site does not publish that name.
3022 + */
3023 + public function render_document(string $filename, ?array $settings = null): ?string {
3024 + $filename = basename($filename);
3025 + $settings = $settings ?? $this->get_settings('site');
3026 +
3027 + if (empty($settings['enabled'])) {
3028 + return null;
3029 + }
3030 +
3031 + $cached = get_transient($this->dynamic_cache_key($filename));
3032 + if (self::ABSENT_MARKER === $cached) {
3033 + return null;
3034 + }
3035 + if (is_string($cached) && '' !== $cached) {
3036 + return $cached;
3037 + }
3038 +
3039 + // A miss builds the whole set, because the index can only be assembled
3040 + // from the children that were actually produced. Caching only the
3041 + // requested document therefore made a crawler walking the index and its
3042 + // children rebuild the entire site's sitemap once per file — every post
3043 + // and taxonomy query repeated N times on a public endpoint (#754
3044 + // review). The set is built once and stored in full.
3045 + return $this->stream_documents($settings, $filename);
3046 + }
3047 +
3048 + /**
3049 + * Build every document, caching each as it is produced, keeping one.
3050 + *
3051 + * A miss has to build the whole set, because the index can only be
3052 + * assembled from the children that were actually produced. It does not have
3053 + * to *hold* the whole set: the static path never keeps more than one page
3054 + * in memory, writing each to disk as it goes, and buffering every
3055 + * document's XML to return one of them undid that on the request path,
3056 + * where a large site's entire sitemap corpus would sit in a single PHP
3057 + * process (#754 review).
3058 + *
3059 + * So the sink writes each document straight to its cache entry and lets it
3060 + * go, retaining only the one this request is answering. Peak retention is
3061 + * one document, whatever the site's size.
3062 + *
3063 + * Concurrency: the first request through takes a short lock and does the
3064 + * work. One that finds the lock held waits a bounded moment for the winner
3065 + * to publish, then builds anyway, because serving a correct sitemap late
3066 + * beats serving none.
3067 + *
3068 + * @since 2.9.0
3069 + *
3070 + * @param array $settings Sitemap settings.
3071 + * @param string $wanted Document this request is answering.
3072 + * @return string|null XML for $wanted, or null when the site does not publish it.
3073 + */
3074 + private function stream_documents(array $settings, string $wanted): ?string {
3075 + $lock = self::DYNAMIC_CACHE_PREFIX . 'lock';
3076 +
3077 + if (!$this->acquire_render_lock($lock)) {
3078 + for ($attempt = 0; $attempt < self::RENDER_LOCK_WAIT_ATTEMPTS; $attempt++) {
3079 + usleep(self::RENDER_LOCK_WAIT_MICROSECONDS);
3080 +
3081 + $cached = get_transient($this->dynamic_cache_key($wanted));
3082 + if (self::ABSENT_MARKER === $cached) {
3083 + return null;
3084 + }
3085 + if (is_string($cached) && '' !== $cached) {
3086 + return $cached;
3087 + }
3088 + }
3089 + }
3090 +
3091 + $kept = null;
3092 + // Names only. Keeping the bodies here would be the very retention this
3093 + // method exists to avoid.
3094 + $produced = [];
3095 +
3096 + $previous = $this->document_sink;
3097 + $this->document_sink = function (string $name, string $xml) use (&$kept, &$produced, $wanted): void {
3098 + $produced[$name] = true;
3099 + set_transient($this->dynamic_cache_key($name), $xml, self::DYNAMIC_CACHE_TTL);
3100 +
3101 + if ($name === $wanted) {
3102 + $kept = $xml;
3103 + }
3104 + };
3105 +
3106 + try {
3107 + $this->generate_and_save($settings);
3108 +
3109 + // Names the configuration lists but this build did not produce get
3110 + // a negative entry, so asking for one again is a cache hit rather
3111 + // than another full rebuild.
3112 + $absent = $this->published_document_names($settings);
3113 +
3114 + // Also the exact name this request asked for: a paginated page past
3115 + // the end of a stem is a legitimate request shape that the base
3116 + // list cannot enumerate, and without an entry it would rebuild on
3117 + // every hit.
3118 + $absent[] = $wanted;
3119 +
3120 + foreach (array_unique($absent) as $name) {
3121 + if (!isset($produced[$name])) {
3122 + set_transient($this->dynamic_cache_key($name), self::ABSENT_MARKER, self::DYNAMIC_CACHE_TTL);
3123 + }
3124 + }
3125 + } finally {
3126 + $this->document_sink = $previous;
3127 + delete_transient($lock);
3128 + }
3129 +
3130 + return $kept;
3131 + }
3132 +
3133 + /**
3134 + * Take the render lock, if it is free.
3135 + *
3136 + * Not atomic across processes, and deliberately so: the fallback for losing
3137 + * a race is duplicated work, never a wrong or missing sitemap, so a
3138 + * heavier primitive would buy nothing here.
3139 + *
3140 + * @since 2.9.0
3141 + *
3142 + * @param string $lock Lock transient name.
3143 + * @return bool True when this request holds the lock.
3144 + */
3145 + private function acquire_render_lock(string $lock): bool {
3146 + if (false !== get_transient($lock)) {
3147 + return false;
3148 + }
3149 +
3150 + set_transient($lock, time(), self::RENDER_LOCK_TTL);
3151 +
3152 + return true;
3153 + }
3154 +
3155 + /**
3156 + * Build every document this site publishes and return them all.
3157 + *
3158 + * Verification and tooling only. This retains the whole set in memory, so
3159 + * it must never be used to answer a request: {@see self::stream_documents()}
3160 + * is the serving path and keeps one document at a time regardless of site
3161 + * size (#754 review). `SitemapDeliveryParityTest` enforces that separation
3162 + * by failing if the request path routes back through here.
3163 + *
3164 + * @since 2.9.0
3165 + *
3166 + * @param array $settings Sitemap settings.
3167 + * @return array<string,string> Filename => XML.
3168 + */
3169 + public function collect_documents(array $settings): array {
3170 + $documents = [];
3171 +
3172 + $previous = $this->document_sink;
3173 + $this->document_sink = static function (string $name, string $xml) use (&$documents): void {
3174 + $documents[$name] = $xml;
3175 + };
3176 +
3177 + try {
3178 + $this->generate_and_save($settings);
3179 + } finally {
3180 + $this->document_sink = $previous;
3181 + }
3182 +
3183 + return $documents;
3184 + }
3185 +
3186 + /**
3187 + * The file names this site publishes, without building their contents.
3188 + *
3189 + * Used by the request router to decide whether a URL is ours before doing
3190 + * any work. Cheap: it reads the configured child list rather than querying
3191 + * for entries.
3192 + *
3193 + * @since 2.9.0
3194 + *
3195 + * @param array|null $settings Sitemap settings (falls back to saved ones).
3196 + * @return string[] File names, including paginated pages that may exist.
3197 + */
3198 + public function published_document_names(?array $settings = null): array {
3199 + $settings = $settings ?? $this->get_settings('site');
3200 + $resolved = $this->maybe_promote_to_index($settings);
3201 +
3202 + $names = [$this->get_primary_sitemap_filename($settings), 'local-sitemap.xml'];
3203 +
3204 + foreach ((array) ($resolved['sitemap_urls'] ?? []) as $child) {
3205 + if (!is_array($child) || empty($child['enabled'])) {
3206 + continue;
3207 + }
3208 +
3209 + $path = (string) wp_parse_url((string) ($child['url'] ?? ''), PHP_URL_PATH);
3210 + if ('' !== $path) {
3211 + $names[] = basename($path);
3212 + }
3213 + }
3214 +
3215 + return array_values(array_unique(array_filter($names)));
3216 + }
3217 +
3218 + /**
3219 + * Does this site publish a document under that name?
3220 + *
3221 + * Not a plain membership test against {@see self::published_document_names()}:
3222 + * that lists the configured children, and a child over the per-file URL cap
3223 + * is split into `<stem>-2.xml`, `<stem>-3.xml` and so on, with every page
3224 + * listed in the index. Gating the request router on the base list alone
3225 + * therefore 404'd exactly the pages the index points at, which is worse than
3226 + * not serving them at all.
3227 + *
3228 + * Page counts are not knowable without building, so the stem is what is
3229 + * matched; a page that does not exist is answered by the build finding
3230 + * nothing for it, and is then cached as absent.
3231 + *
3232 + * @since 2.9.0
3233 + *
3234 + * @param string $name Requested file name.
3235 + * @param array|null $settings Sitemap settings (falls back to saved ones).
3236 + * @return bool
3237 + */
3238 + public function publishes_document_name(string $name, ?array $settings = null): bool {
3239 + $names = $this->published_document_names($settings);
3240 +
3241 + if (in_array($name, $names, true)) {
3242 + return true;
3243 + }
3244 +
3245 + if (!preg_match('/^(.*)-\d+\.xml$/i', $name, $m)) {
3246 + return false;
3247 + }
3248 +
3249 + return in_array($m[1] . '.xml', $names, true);
3250 + }
3251 +
3252 + /**
3253 + * Transient key for a rendered document.
3254 + *
3255 + * @since 2.9.0
3256 + *
3257 + * @param string $filename Published file name.
3258 + * @return string
3259 + */
3260 + private function dynamic_cache_key(string $filename): string {
3261 + return self::DYNAMIC_CACHE_PREFIX . md5($filename);
3262 + }
3263 +
3264 + /**
3265 + * Drop every cached dynamic document.
3266 + *
3267 + * Called from the same places that mark the static files stale, so the two
3268 + * delivery modes invalidate on identical triggers.
3269 + *
3270 + * @since 2.9.0
3271 + *
3272 + * @return void
3273 + */
3274 + public function flush_dynamic_cache(): void {
3275 + foreach ($this->published_document_names() as $name) {
3276 + delete_transient($this->dynamic_cache_key($name));
3277 + }
3278 + }
3279 +
3280 + /**
1740 3281 * Resolve index-vs-single mode, synthesizing child sitemaps when needed.
1741 3282 *
1742 3283 * - When use_sitemap_index is on but no child sitemaps are configured, build
1743 3284 * the per-type segmented set so a real <sitemapindex> is produced (#127).
@@ -1888,26 +3429,9 @@
1888 3429 * @param array $settings Sitemap settings.
1889 3430 * @return string Sitemap filename.
1890 3431 */
1891 3432 public function get_primary_sitemap_filename(array $settings): string {
1892 - $use_index = !empty($settings['use_sitemap_index']);
1893 -
1894 - foreach ((is_array($settings['sitemap_urls'] ?? null) ? $settings['sitemap_urls'] : []) as $config) {
1895 - if (empty($config['enabled']) || empty($config['url'])) {
1896 - continue;
1897 - }
1898 -
1899 - if ($use_index !== (($config['type'] ?? '') === 'index')) {
1900 - continue;
1901 - }
1902 -
1903 - $path = wp_parse_url($config['url'], PHP_URL_PATH);
1904 - if (!empty($path)) {
1905 - return basename($path);
1906 - }
1907 - }
1908 -
1909 - return $use_index ? 'sitemap_index.xml' : 'sitemap.xml';
3433 + return thinkrank_webroot_primary_sitemap_filename($settings);
1910 3434 }
1911 3435
1912 3436 /**
1913 3437 * Public URL of the sitemap the site serves.
@@ -1949,8 +3473,18 @@
1949 3473 // File validation failed - error details available in exception
1950 3474 return false;
1951 3475 }
1952 3476
3477 + // Dynamic delivery: hand the document to the collector instead of the
3478 + // filesystem. Reported as published, because for this run it is — the
3479 + // caller's success/failure bookkeeping and the index assembly both key
3480 + // off this return value.
3481 + if ($this->document_sink !== null) {
3482 + ($this->document_sink)($filename, $sitemap_xml);
3483 +
3484 + return true;
3485 + }
3486 +
1953 3487 $sitemap_path = ABSPATH . $filename;
1954 3488
1955 3489 // Use WordPress filesystem API for better security
1956 3490 global $wp_filesystem;
@@ -1959,9 +3493,22 @@
1959 3493 WP_Filesystem();
1960 3494 }
1961 3495
1962 3496 if ($wp_filesystem) {
1963 - return $wp_filesystem->put_contents($sitemap_path, $sitemap_xml, FS_CHMOD_FILE);
3497 + $written = $wp_filesystem->put_contents($sitemap_path, $sitemap_xml, FS_CHMOD_FILE);
3498 +
3499 + if ($written) {
3500 + // Every sitemap this version writes carries the ownership
3501 + // marker, so once one has been written an unmarked file at one
3502 + // of our names cannot be ours. Recording that retires the
3503 + // legacy fallback for this install — see
3504 + // thinkrank_webroot_sitemap_is_ours().
3505 + if (get_option(THINKRANK_SITEMAP_MARKED_WRITE_OPTION) !== '1') {
3506 + update_option(THINKRANK_SITEMAP_MARKED_WRITE_OPTION, '1', false);
3507 + }
3508 + }
3509 +
3510 + return $written;
1964 3511 }
1965 3512
1966 3513 // WP_Filesystem initialization failed
1967 3514 return false;
@@ -1995,13 +3542,55 @@
1995 3542
1996 3543 // Public custom post types each get a child sitemap (parity with the
1997 3544 // "complete" preset and with Rank Math, which lists every public CPT).
1998 3545 foreach (get_post_types(['public' => true, '_builtin' => false], 'names') as $cpt) {
1999 - if ($this->should_include_post_type($cpt)) {
2000 - $urls[] = $this->build_child_sitemap_entry($cpt, $pattern);
3546 + if (!$this->should_include_post_type($cpt)) {
3547 + continue;
2001 3548 }
3549 +
3550 + // ...and the per-content-type sitemap switch (#660).
3551 + // get_enabled_post_types() already honours it, but this list is what
3552 + // index mode builds its children from — so without the same test a
3553 + // CPT the user had switched off still got its own child sitemap,
3554 + // created and streamed in full. The flags live in $inclusions, which
3555 + // is the settings array these children are derived from.
3556 + if (!\ThinkRank\SEO\Content_Type_Settings::is_included_in_sitemap('post_type', $cpt, $inclusions)) {
3557 + continue;
3558 + }
3559 +
3560 + $urls[] = $this->build_child_sitemap_entry($cpt, $pattern);
2002 3561 }
2003 3562
3563 + // Public custom taxonomies get the same treatment (#690). Flat mode has
3564 + // always walked them through get_enabled_taxonomies(); index mode built
3565 + // its children from the list above and never consulted a taxonomy at
3566 + // all, so every custom-taxonomy archive silently vanished from the
3567 + // sitemap the moment a site switched modes — and the per-taxonomy switch
3568 + // the matrix writes had nothing to act on. Same two tests the post-type
3569 + // walk applies, in the same order.
3570 + $taken = array_column($urls, 'type');
3571 +
3572 + foreach (get_taxonomies(['public' => true, '_builtin' => false], 'names') as $taxonomy) {
3573 + if (!$this->should_include_taxonomy($taxonomy)) {
3574 + continue;
3575 + }
3576 +
3577 + if (!\ThinkRank\SEO\Content_Type_Settings::is_included_in_sitemap('taxonomy', $taxonomy, $inclusions)) {
3578 + continue;
3579 + }
3580 +
3581 + // Post types and taxonomies are separate registries, so a site can
3582 + // hold both a `foo` post type and a `foo` taxonomy. They would
3583 + // resolve to one filename, and stream_type_entries() answers post
3584 + // types first, so the second child would list the first one's file
3585 + // twice in the index rather than adding anything.
3586 + if (in_array($taxonomy, $taken, true)) {
3587 + continue;
3588 + }
3589 +
3590 + $urls[] = $this->build_child_sitemap_entry($taxonomy, $pattern);
3591 + }
3592 +
2004 3593 return $urls;
2005 3594 }
2006 3595
2007 3596 /**
@@ -2148,8 +3737,48 @@
2148 3737 if (post_type_exists($type) && !$this->should_include_post_type($type)) {
2149 3738 continue;
2150 3739 }
2151 3740
3741 + // Same for the matrix switch: a child list saved before the user
3742 + // excluded this content type still names it, and regenerating from
3743 + // that list would rewrite the file they asked not to have. Built-in
3744 + // aggregates ('posts', 'pages', ...) are not post type names, so
3745 + // post_type_exists() keeps this to real custom post types.
3746 + if (post_type_exists($type)
3747 + && !\ThinkRank\SEO\Content_Type_Settings::is_included_in_sitemap('post_type', $type, $settings)) {
3748 + continue;
3749 + }
3750 +
3751 + // The taxonomy counterpart of the two guards above (#690). A child
3752 + // list saved while a taxonomy was still included keeps naming it, so
3753 + // without this, excluding one in the matrix would still rewrite and
3754 + // re-list the file the user asked not to have. The built-in
3755 + // aggregates are named 'categories'/'tags' rather than
3756 + // 'category'/'post_tag', so taxonomy_exists() leaves them to the
3757 + // inclusion-flag check below.
3758 + $child_taxonomy = self::CHILD_TYPE_ALIASES[$type] ?? $type;
3759 + if (taxonomy_exists($child_taxonomy)
3760 + && (!$this->should_include_taxonomy($child_taxonomy)
3761 + || !\ThinkRank\SEO\Content_Type_Settings::is_included_in_sitemap('taxonomy', $child_taxonomy, $settings))) {
3762 + continue;
3763 + }
3764 +
3765 + // The built-in aggregates carry their switch in the inclusion flag
3766 + // rather than under a post type name, and they are the four most
3767 + // people actually use. build_segmented_sitemap_urls() drops a child
3768 + // whose flag is empty; regenerating from a list saved while it was
3769 + // still on has to make the same decision, or turning Posts, Pages,
3770 + // Categories or Tags off in the matrix rewrites and re-lists the
3771 + // very file it was asked to remove.
3772 + // An absent flag means "not configured", which every other reader
3773 + // treats as included; only a flag that is present and off excludes.
3774 + $aggregate_flag = array_search($type, self::INCLUSION_CHILD_TYPES, true);
3775 + if ($aggregate_flag !== false
3776 + && array_key_exists($aggregate_flag, $settings)
3777 + && empty($settings[$aggregate_flag])) {
3778 + continue;
3779 + }
3780 +
2152 3781 try {
2153 3782 // The single "general"/"WordPress" sitemap is one un-paginated file
2154 3783 // (there is no index to reference extra pages); it no longer drops
2155 3784 // overflow URLs.
@@ -2194,9 +3823,9 @@
2194 3823 $this->write_sitemap_page($this->paginate_url($sitemap_config['url'], $page), $this->wrap_urlset($buffer, $settings, $image_ns), $type, count($buffer), $results, $index_children);
2195 3824 }
2196 3825
2197 3826 // Remove pages left over from a previous, larger generation.
2198 - $this->cleanup_stale_pages($sitemap_config['url'], $page);
3827 + $this->cleanup_stale_pages($sitemap_config['url'], $page, $settings);
2199 3828
2200 3829 } catch (\Exception $e) {
2201 3830 $results['errors'][] = "Error generating {$type} sitemap: " . $e->getMessage();
2202 3831 $results['success'] = false;
@@ -2215,10 +3844,16 @@
2215 3844 $results['errors'][] = 'Error generating local sitemap: ' . $e->getMessage();
2216 3845 $results['success'] = false;
2217 3846 }
2218 3847
2219 - // Build the index last, from the child files actually generated.
3848 + // Build the index last, from the child files actually generated, plus the
3849 + // sitemaps other plugins own: those serve their own URLs and write no
3850 + // file here, so they are appended to the index only (#104).
2220 3851 if ($index_config !== null) {
3852 + foreach (self::additional_sitemaps() as $extra) {
3853 + $index_children[] = ['url' => $extra];
3854 + }
3855 +
2221 3856 try {
2222 3857 $index_xml = $this->generate_sitemap_index($index_children, $settings);
2223 3858 $filename = basename(wp_parse_url($index_config['url'], PHP_URL_PATH));
2224 3859
@@ -2263,8 +3898,15 @@
2263 3898 * @param array $generated Entries from $results['sitemaps_generated'].
2264 3899 * @return string[] Basenames removed.
2265 3900 */
2266 3901 private function prune_orphaned_segments(array $settings, array $generated): array {
3902 + // Rendering for a request, not publishing: there is nothing on disk
3903 + // this run owns, and a dynamic render must never delete the files a
3904 + // site's previous static mode left behind.
3905 + if ($this->is_collecting()) {
3906 + return [];
3907 + }
3908 +
2267 3909 $kept = [];
2268 3910 foreach ($generated as $entry) {
2269 3911 if (!empty($entry['filename'])) {
2270 3912 $kept[strtolower((string) $entry['filename'])] = true;
@@ -2270,15 +3912,22 @@
2270 3912 $kept[strtolower((string) $entry['filename'])] = true;
2271 3913 }
2272 3914 }
2273 3915
2274 - // The index and the local business sitemap are written by their own
2275 - // paths and are not segments, so they are never orphans here.
2276 - $kept[strtolower(basename($this->get_primary_sitemap_filename($settings)))] = true;
3916 + // The current mode's primary and the local business sitemap are written
3917 + // by their own paths and are never orphans here.
3918 + $primary = strtolower(basename($this->get_primary_sitemap_filename($settings)));
3919 + $kept[$primary] = true;
2277 3920 $kept['local-sitemap.xml'] = true;
2278 - $kept['sitemap.xml'] = true;
2279 - $kept['sitemap_index.xml'] = true;
2280 3921
3922 + // The OTHER mode's primary is an orphan the moment the mode changes:
3923 + // index mode leaves sitemap.xml behind, flat mode leaves
3924 + // sitemap_index.xml and its children. Both used to be kept
3925 + // unconditionally, so the site served two sitemap trees and only ever
3926 + // refreshed one (#563). The children are already covered by the segment
3927 + // sweep below, which now sees them because the index is no longer kept.
3928 + $stale_primaries = array_diff(['sitemap.xml', 'sitemap_index.xml'], [$primary]);
3929 +
2281 3930 $removed = [];
2282 3931
2283 3932 global $wp_filesystem;
2284 3933 if (!$wp_filesystem) {
@@ -2288,9 +3937,11 @@
2288 3937 if (!$wp_filesystem) {
2289 3938 return $removed;
2290 3939 }
2291 3940
2292 - foreach ($this->publishable_segment_filenames($settings) as $candidate) {
3941 + $candidates = array_merge($this->publishable_segment_filenames($settings), $stale_primaries);
3942 +
3943 + foreach ($candidates as $candidate) {
2293 3944 if (isset($kept[strtolower($candidate)])) {
2294 3945 continue;
2295 3946 }
2296 3947
@@ -2309,8 +3960,13 @@
2309 3960 foreach ($paths as $path) {
2310 3961 if (!file_exists($path)) {
2311 3962 continue;
2312 3963 }
3964 + // A name we could have published is not proof we published
3965 + // this file: RankMath and core write at the same paths (#515).
3966 + if (!$this->webroot_sitemap_is_ours($path, $settings)) {
3967 + continue;
3968 + }
2313 3969 if ($wp_filesystem->delete($path)) {
2314 3970 $removed[] = basename($path);
2315 3971 }
2316 3972 }
@@ -2346,11 +4002,15 @@
2346 4002 $settings = $settings ?? $this->get_settings('site');
2347 4003 $entries = $this->collect_local_entries();
2348 4004
2349 4005 if (empty($entries)) {
2350 - // Business identity was cleared — drop any file left from before.
4006 + // Business identity was cleared — drop the file we left from
4007 + // before, but only ours. `local-sitemap.xml` is the name Rank Math
4008 + // publishes under too (this method mirrors it deliberately), so on
4009 + // a migrated site the file at that path may never have been ours
4010 + // to delete (#515).
2351 4011 $path = ABSPATH . 'local-sitemap.xml';
2352 - if (file_exists($path)) {
4012 + if (!$this->is_collecting() && file_exists($path) && $this->webroot_sitemap_is_ours($path, $settings)) {
2353 4013 wp_delete_file($path);
2354 4014 }
2355 4015 return false;
2356 4016 }
@@ -2372,8 +4032,25 @@
2372 4032 *
2373 4033 * @since 1.15.x
2374 4034 * @return array Zero or one URL entry
2375 4035 */
4036 + /**
4037 + * Does this site publish a local business sitemap right now?
4038 + *
4039 + * The same gate {@see self::regenerate_local_sitemap()} applies, asked
4040 + * without writing anything. Callers that need to know whether the document
4041 + * exists must not test the filesystem: under dynamic delivery it is served
4042 + * from PHP and there is no file, which is how `local-sitemap.xml` came to be
4043 + * dropped from robots.txt on exactly those sites (#752).
4044 + *
4045 + * @since 2.9.0
4046 + *
4047 + * @return bool True when the local sitemap has content to publish.
4048 + */
4049 + public function publishes_local_sitemap(): bool {
4050 + return !empty($this->collect_local_entries());
4051 + }
4052 +
2376 4053 private function collect_local_entries(): array {
2377 4054 if (!class_exists('ThinkRank\\SEO\\Site_Identity_Manager')) {
2378 4055 require_once THINKRANK_PLUGIN_DIR . 'includes/seo/class-site-identity-manager.php';
2379 4056 }
@@ -2445,17 +4122,43 @@
2445 4122 case 'products':
2446 4123 $entries = post_type_exists('product') ? $this->collect_post_entries_iter(['product'], $settings) : [];
2447 4124 return ['entries' => $entries, 'image_ns' => true];
2448 4125
2449 - case 'product_categories':
2450 - $entries = taxonomy_exists('product_cat') ? $this->collect_taxonomy_entries_iter('product_cat', $settings) : [];
2451 - return ['entries' => $entries, 'image_ns' => false];
4126 + default:
4127 + // Resolve a preset's display name to the object it streams, so
4128 + // 'product_categories' is an ordinary taxonomy child rather than
4129 + // a case of its own (#690).
4130 + $alias = self::CHILD_TYPE_ALIASES[$type] ?? null;
4131 + $object = $alias ?? $type;
2452 4132
2453 - default:
2454 4133 $custom_post_types = get_post_types(['public' => true, '_builtin' => false], 'names');
2455 - if (in_array($type, $custom_post_types, true)) {
2456 - return ['entries' => $this->collect_post_entries_iter([$type], $settings), 'image_ns' => true];
4134 + if (in_array($object, $custom_post_types, true)) {
4135 + return ['entries' => $this->collect_post_entries_iter([$object], $settings), 'image_ns' => true];
2457 4136 }
4137 +
4138 + // Custom taxonomies reach index mode here, streamed through the
4139 + // same iterator flat mode uses so the two modes emit identical
4140 + // URLs for the same settings.
4141 + if (taxonomy_exists($object) && $this->should_include_taxonomy($object)) {
4142 + return ['entries' => $this->collect_taxonomy_entries_iter($object, $settings), 'image_ns' => false];
4143 + }
4144 +
4145 + // An aliased child whose object is gone (WooCommerce deactivated)
4146 + // keeps writing the empty file it always wrote. Returning null
4147 + // here would hand it the whole-site fallback instead, dumping
4148 + // every URL on the site into a file named for products.
4149 + //
4150 + // A registered taxonomy this generator will not emit
4151 + // (`post_format`, `nav_menu`, a non-public one) needs the same
4152 + // answer for the same reason. generate_multiple_sitemaps()
4153 + // skips those before they reach here, so nothing takes this
4154 + // path today — but it is the one branch where falling through
4155 + // to null is silently catastrophic rather than merely wrong,
4156 + // and the guard keeping it unreachable lives in another method.
4157 + if ($alias !== null || taxonomy_exists($object)) {
4158 + return ['entries' => [], 'image_ns' => false];
4159 + }
4160 +
2458 4161 return null;
2459 4162 }
2460 4163 }
2461 4164
@@ -2498,13 +4201,23 @@
2498 4201 * which has no -N suffix) is never touched.
2499 4202 *
2500 4203 * @since 1.14.0
2501 4204 *
4205 + * @since 2.1.1 Each candidate must pass the content ownership test — a
4206 + * `-N.xml` page of another plugin's sitemap paginates our
4207 + * stem exactly as ours does (#515).
4208 + *
2502 4209 * @param string $base_url Base (page 1) sitemap URL
2503 4210 * @param int $current_pages Number of pages generated this run
4211 + * @param array $settings Sitemap settings, for the ownership test.
2504 4212 * @return void
2505 4213 */
2506 - private function cleanup_stale_pages(string $base_url, int $current_pages): void {
4214 + private function cleanup_stale_pages(string $base_url, int $current_pages, array $settings): void {
4215 + // See prune_orphaned_segments(): a dynamic render deletes nothing.
4216 + if ($this->is_collecting()) {
4217 + return;
4218 + }
4219 +
2507 4220 $filename = basename(wp_parse_url($base_url, PHP_URL_PATH));
2508 4221 if (!preg_match('/^(.*)\.xml$/i', $filename, $m)) {
2509 4222 return;
2510 4223 }
@@ -2521,9 +4234,11 @@
2521 4234
2522 4235 $candidates = glob(ABSPATH . $stem . '-*.xml') ?: [];
2523 4236 foreach ($candidates as $path) {
2524 4237 // Only delete numeric-suffixed pages beyond the current count.
2525 - if (preg_match('/-(\d+)\.xml$/', basename($path), $mm) && (int) $mm[1] > $current_pages) {
4238 + if (preg_match('/-(\d+)\.xml$/', basename($path), $mm)
4239 + && (int) $mm[1] > $current_pages
4240 + && $this->webroot_sitemap_is_ours($path, $settings)) {
2526 4241 $wp_filesystem->delete($path);
2527 4242 }
2528 4243 }
2529 4244 }
@@ -2528,8 +4243,97 @@
2528 4243 }
2529 4244 }
2530 4245
2531 4246 /**
4247 + * Sitemap URLs contributed by other plugins.
4248 + *
4249 + * ThinkRank owns the sitemap index and the robots.txt `Sitemap:` lines, so a
4250 + * companion plugin that serves its own sitemap — Pro's news and video
4251 + * sitemaps, for instance — had no way to be discovered: it appeared in
4252 + * neither, leaving manual Search Console submission as the only route in
4253 + * (#104). Registering here puts a sitemap in the index when one exists, and
4254 + * in robots.txt when it does not.
4255 + *
4256 + * Callers get root-relative paths. Entries are normalised to a leading
4257 + * slash, de-duplicated, and anything that is not a non-empty string is
4258 + * dropped, so one badly-behaved callback cannot produce a malformed index.
4259 + *
4260 + * @since 2.3.1
4261 + *
4262 + * @return string[] Root-relative sitemap paths, e.g. ['/news-sitemap.xml'].
4263 + */
4264 + public static function additional_sitemaps(): array {
4265 + /**
4266 + * Filters the sitemaps contributed by other plugins.
4267 + *
4268 + * @since 2.3.1
4269 + *
4270 + * @param string[] $sitemaps Root-relative sitemap paths.
4271 + */
4272 + $sitemaps = apply_filters('thinkrank_additional_sitemaps', []);
4273 +
4274 + if (!is_array($sitemaps)) {
4275 + return [];
4276 + }
4277 +
4278 + // Both consumers resolve an entry with home_url(), which prefixes the
4279 + // install's own directory. Everything below is measured against that so
4280 + // an absolute URL is reduced to what home_url() will put back.
4281 + $home = wp_parse_url(home_url('/'));
4282 + $home_host = strtolower((string) ($home['host'] ?? ''));
4283 + $home_path = '/' . trim((string) ($home['path'] ?? ''), '/');
4284 +
4285 + $clean = [];
4286 + foreach ($sitemaps as $sitemap) {
4287 + if (!is_string($sitemap)) {
4288 + continue;
4289 + }
4290 +
4291 + $sitemap = trim($sitemap);
4292 + if ('' === $sitemap) {
4293 + continue;
4294 + }
4295 +
4296 + // A full URL on this site is accepted and reduced to the part
4297 + // home_url() does not already supply, so a caller that reached for
4298 + // home_url() still lands in the right place — including on a
4299 + // subdirectory install, where keeping the whole path would repeat
4300 + // the directory. A URL on another host is dropped rather than
4301 + // rewritten: the sitemaps protocol will not accept a cross-host
4302 + // child anyway, and reusing its path would advertise a URL on this
4303 + // site that does not exist.
4304 + if (preg_match('#^(https?:)?//#i', $sitemap)) {
4305 + $parts = wp_parse_url('//' === substr($sitemap, 0, 2) ? 'https:' . $sitemap : $sitemap);
4306 + if (!is_array($parts)) {
4307 + continue;
4308 + }
4309 +
4310 + if (strtolower((string) ($parts['host'] ?? '')) !== $home_host) {
4311 + continue;
4312 + }
4313 +
4314 + $path = (string) ($parts['path'] ?? '');
4315 + if ('' === $path) {
4316 + continue;
4317 + }
4318 +
4319 + if ('/' !== $home_path && ($path === $home_path || 0 === strpos($path, $home_path . '/'))) {
4320 + $path = substr($path, strlen($home_path));
4321 + }
4322 +
4323 + // A sitemap served from a query string keeps it; dropping the
4324 + // query would point at a different document.
4325 + $query = (string) ($parts['query'] ?? '');
4326 + $sitemap = $path . ('' !== $query ? '?' . $query : '');
4327 + }
4328 +
4329 + $clean[] = '/' . ltrim($sitemap, '/');
4330 + }
4331 +
4332 + return array_values(array_unique($clean));
4333 + }
4334 +
4335 + /**
2532 4336 * Generate sitemap index XML from the list of child sitemap files produced
2533 4337 * during generation (each already resolved to its final, possibly paginated,
2534 4338 * URL).
2535 4339 *
@@ -2538,14 +4342,9 @@
2538 4342 * @param array $settings Sitemap settings
2539 4343 * @return string Sitemap index XML
2540 4344 */
2541 4345 private function generate_sitemap_index(array $children, array $settings): string {
2542 - $xml = '<?xml version="1.0" encoding="UTF-8"?>' . "\n";
2543 -
2544 - // Add XSL stylesheet only if styling is enabled
2545 - if (!empty($settings['enable_styling'])) {
2546 - $xml .= '<?xml-stylesheet type="text/xsl" href="' . home_url('/wp-content/plugins/thinkrank/static/xsl/sitemap-index.xsl') . '"?>' . "\n";
2547 - }
4346 + $xml = $this->xml_prolog($settings, 'index');
2548 4347 $xml .= '<sitemapindex xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">' . "\n";
2549 4348
2550 4349 $site_url = home_url();
2551 4350
@@ -2558,9 +4357,9 @@
2558 4357 $sitemap_url = $site_url . $sitemap_url;
2559 4358 }
2560 4359
2561 4360 $xml .= " <sitemap>\n";
2562 - $xml .= " <loc>" . esc_url($sitemap_url) . "</loc>\n";
4361 + $xml .= " <loc>" . esc_url(Url_Scheme::apply($sitemap_url)) . "</loc>\n";
2563 4362 $xml .= " <lastmod>" . gmdate('c') . "</lastmod>\n";
2564 4363 $xml .= " </sitemap>\n";
2565 4364 }
2566 4365