media store: a failed write gives its budget reservation back (V-584)
Put and PutFile added the blob size to s.total before writing, and only the writeFile and os.Rename failure paths released it. A writeMeta failure in either, and a chmod failure on the spool in PutFile, kept the size, so a store that hit a full disk over-counted itself and could answer ErrStoreFull while the disk had room until the next Open re-measured. One defer per function now owns the release, disarmed on the success return, so a future early return cannot reintroduce the leak. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -287,6 +287,73 @@ func TestPutLeavesNothingWhenTheBytesCannotBeWritten(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// An over-counted store answers ErrStoreFull while the disk has room, and only
|
||||
// the next Open corrects it. So every failed write has to give its reservation
|
||||
// back, not just the one that remembered to.
|
||||
func TestPutReleasesTheBudgetWhenTheSidecarCannotBeWritten(t *testing.T) {
|
||||
s := testStore(t)
|
||||
data := []byte("no sidecar for this")
|
||||
blockSidecar(t, s, KindImage, data)
|
||||
if _, err := s.Put(KindImage, "image/png", "web:upload", data); err == nil {
|
||||
t.Fatal("put must fail")
|
||||
}
|
||||
if s.Total() != 0 {
|
||||
t.Errorf("total = %d, want the failed put not counted", s.Total())
|
||||
}
|
||||
}
|
||||
|
||||
func TestPutFileReleasesTheBudgetWhenTheSidecarCannotBeWritten(t *testing.T) {
|
||||
s := testStore(t)
|
||||
data := []byte("no sidecar for this either")
|
||||
blockSidecar(t, s, KindAudio, data)
|
||||
src := filepath.Join(t.TempDir(), "capture.wav")
|
||||
if err := os.WriteFile(src, data, 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := s.PutFile(KindAudio, "audio/wav", "meeting", src); err == nil {
|
||||
t.Fatal("put file must fail")
|
||||
}
|
||||
if s.Total() != 0 {
|
||||
t.Errorf("total = %d, want the failed put not counted", s.Total())
|
||||
}
|
||||
}
|
||||
|
||||
// The chmod arm is PutFile's alone: Put never touches a spool file.
|
||||
func TestPutFileReleasesTheBudgetWhenTheSpoolCannotBeChmodded(t *testing.T) {
|
||||
if os.Geteuid() == 0 {
|
||||
t.Skip("root can chmod a file it does not own")
|
||||
}
|
||||
// A symlink to a file owned by somebody else. Stat and the hash follow it
|
||||
// and succeed; chmod follows it too and is refused.
|
||||
src := filepath.Join(t.TempDir(), "capture.wav")
|
||||
if err := os.Symlink("/etc/hosts", src); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
info, err := os.Stat(src)
|
||||
if err != nil || info.Size() == 0 {
|
||||
t.Skip("no readable /etc/hosts to point at")
|
||||
}
|
||||
s := testStore(t)
|
||||
if _, err := s.PutFile(KindAudio, "audio/wav", "meeting", src); err == nil {
|
||||
t.Fatal("put file must fail")
|
||||
}
|
||||
if s.Total() != 0 {
|
||||
t.Errorf("total = %d, want the failed put not counted", s.Total())
|
||||
}
|
||||
}
|
||||
|
||||
// blockSidecar puts a directory where the sidecar for data has to go, so
|
||||
// writeMeta fails while the blob path is still free.
|
||||
func blockSidecar(t *testing.T, s *Store, kind Kind, data []byte) {
|
||||
t.Helper()
|
||||
sum := sha256.Sum256(data)
|
||||
id := hex.EncodeToString(sum[:])
|
||||
bucket := filepath.Join(s.dir, string(kind), id[:2])
|
||||
if err := os.MkdirAll(filepath.Join(bucket, id+".json"), 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
// The per-blob cap bounds one call and nothing bounded their sum. 64 MiB per
|
||||
// call times unlimited calls inside a seven-day window fills the disk mavend's
|
||||
// database lives on.
|
||||
|
||||
Reference in New Issue
Block a user