Repository navigation
fix(posix): restore revisions atomically and guard upload rollback - #839
Open
Mortimer-RR wants to merge 1 commit into
Open
Mortimer-RR wants to merge 1 commit into
Mortimer-RR wants to merge 1 commit into
Conversation
RestoreRevision in the posix tree truncated the live file and copied the revision into it in place. Concurrent readers could see an empty or partially restored file, and a failed copy left the file truncated while its xattrs still described the previous content. The posix RestoreRevision now copies the revision into a temp file in the space's .oc-tmp directory, fsyncs it, carries over the target's oc xattrs, mode and owner, applies the revision's checksum, blob id, blob size and mtime, and renames it over the target, like the blobstore does for uploads. Separately, rolling back an aborted upload (Cleanup with a versionID) doesn't check that the session still owns the node. An older upload whose postprocessing fails after a newer upload has finished therefore reverts the node to the old version, replacing the newer content. Cleanup now locks the node, checks that it is still processing this session, and only then calls RevertUpload, under the same lock (the metadata lock is re-entrant for the node object). Otherwise it keeps the node and leaves the revision as an ordinary version. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Mortimer-RR
force-pushed
the
fix/atomic-restore-revision
branch
from
October 3, 2026 02:28
3c8a465 to
e21625a
Compare
Author
|
Resolved the merge conflict |
Member
|
I approved the CI run. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #838
Changes
pkg/storage/fs/posix/tree/revisions.goRestoreRevision: copies the revision into atemp file in the space's
.oc-tmpdirectory, fsyncs it, carries over the target'suser.oc.*xattrs, mode and owner (a failed chown is logged, not fatal), applies therevision's checksum, blob id, blob size and type attributes and the mtime, and
rename()s it over the target, likeblobstore.Uploaddoes for uploads. The mtime is thenset through the metadata backend so its cache picks up the new attributes. The "current"
copy for
EnableFSRevisionsis unchanged.pkg/storage/pkg/decomposedfs/upload/upload.goCleanup(versionIDbranch): takes thenode's metadata lock and re-reads the status through the metadata backend (bypassing the
node's attribute cache). It only restores when the node is still
processing:<this session>. Otherwise it logs, keeps the node, and leaves the revision as an ordinaryversion. The lock is released before the rest of
Cleanup, whoseUnmarkProcessinglocks again through a different node object.
Tests
pkg/storage/fs/posix/tree/revisions_test.go:main: target truncated to 0 bytes);main: 3831 of3841 reads saw partial content).
pkg/storage/pkg/decomposedfs/upload_async_test.go, "two uploads overwrite an existingfile in parallel": the older upload fails after the newer one succeeded; the newer content
and the original version must survive (fails on
main: the file is rolled back from 20to 10 bytes).
go test -raceclean onpkg/storage/fs/posix/tree,pkg/storage/pkg/decomposedfsandits
uploadpackage.pkg/storage/...passes.(upstream: 50 of 50 bad); aborting the older upload keeps the newer content (upstream:
rolled back).
Note: downloads still don't take the node lock; with the atomic rename they don't need it
for consistent bytes (an open file descriptor keeps the old inode).
🤖 Generated with Claude Code