Repository navigation
Conversation
Ported from owncloud#550 (8935224). The upstream commit also patched pkg/storage/fs/posix/blobstore, which we rewrote in f6ca1ec and f60de0e to use rename plus periodic fdatasync, so that hunk does not apply here.
Upload only copies when renaming the source into the blobstore fails, so the existing specs never ran the code path that leaked the blob file descriptor. They now use a source on a second device to force the EXDEV rename failure, and assert via /proc/self/fd that no descriptor is left pointing at the blob, both for a successful copy and for a copy that breaks midway.
The decomposed driver has its own copy of the filesystem blobstore, which had the same missing Close() and Sync() as the ocis one fixed in owncloud#550: every upload that could not be renamed into place leaked the descriptor of the blob file, and the blob was not flushed to disk before the node was updated.
The copy fallback of the posix blobstore only closed the temp file on the success path, so a copy that broke midway leaked its descriptor. Also stop swallowing the final Sync() error: a blob that could not be flushed to disk should not look like a successful upload.
The deferred Close() added with owncloud#550 assigns the close error to err, but Upload's result was unnamed, so that assignment was discarded and a failing close returned success. On NFS, where close() is the point at which the client flushes dirty pages, that means a truncated or missing blob gets committed without anyone noticing. Naming the result makes the guard do what it reads like: report a close failure only when nothing else failed.
aduffeck
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix a few fildescriptor leaks on errors