mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-06 14:31:57 +02:00
* volume: compact an oversized .ecj at mount, safely (Rust + Go) Restore the mount-time compaction dropped from #11408, Rust + Go parity. A journal already bloated by repeated shard copies is folded down to the id set it encodes. - Trigger after load when file_records > max(threshold, 4x distinct), with a 1 MiB floor so small journals are never rewritten. The set is written to .ecj.compact.tmp + fsync, the handle dropped, renamed, the directory fsynced and the append handle reopened. A failure before the rename keeps the original journal and handle; a failure after it fails the mount. - Go never compacts after a failed journal load; the set would be partial and the rewrite would drop the unread records. - A per-path registry (ecj_registry.rs / ecj_registry.go) counts EcVolume holders and out-of-band writers of each .ecj. Compaction runs only when this volume is the sole holder and no copy is writing; holders and writers wait while one runs. This covers shared -dir.idx journals and cross-disk reconcile, where another EcVolume may hold the same journal. - VolumeEcShardsCopy and EC index recovery register as writers around their .ecj append and partial-file cleanup. - Under the reservation, re-check that the file on disk is still the inode and size that was loaded. - Publish errors are classified where they happen; a failed rename plus a failed restore reports both errors. - Compaction runs after the .vif / bitrot checks, so a refused mount leaves the journal untouched. - The tmp is opened like other volume files, removed at mount if a crash left it, and listed in every EC index cleanup path. Failure paths are tested through the real mount via injectable fs steps (open_with / newEcVolumeWith), plus sibling holders, active copies, changed-after-load, stale tmp cleanup, refused mounts and the Go load-error guard. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * volume: fail the mount when the compacted .ecj's directory cannot be synced The Rust mount synced the journal's directory after renaming the compacted file over it through the crate's best-effort fsync_dir, which returns Ok when the directory cannot be opened. A rename needs only write and search permission, so on a directory without read permission the replacement was published, never synced, and the mount went on taking deletes against it. Sync through a helper that propagates the open error, as Go's util.FsyncDir already does, so that case fails the mount like any other post-rename sync failure. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * volume: test the no-compaction-after-failed-load rule through the Go mount The test for it handed compactEcjAfterLoad an artificial error on a volume that had loaded cleanly, so it would not notice NewEcVolume dropping the real load error on the way to compaction. Make the journal read one of the injectable ecjFsOps steps and fail it inside the real mount, after the first chunk, on a journal whose last entry is an id the first chunk does not hold. The mount must leave the file byte for byte as it was; a clean remount then compacts and keeps that id. The Rust mount fails outright on a load error, so it has no equivalent path. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * volume: register ReceiveFile's .ecj writes with the journal registry ReceiveFile refuses a mounted EC volume only once, when the info message arrives, then creates the .ecj and streams chunks into it. A volume that mounted on that journal mid-stream could find a bloated prefix, pass the inode-and-size re-check and rename a compacted file over it; the rest of the stream then went to the unlinked inode and was lost. Register the path as a writer before the file is created, in both the Go and Rust handlers, and hold it until the file is closed and any partial copy removed, as the shard-copy and index-recovery appends already do. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * volume: skip .ecj compaction when a writer ran since the journal was loaded Compaction checked only that no writer was active at the reservation, and that the file was still the loaded inode at the loaded size. A ReceiveFile truncates and refills the journal in place, so one that ran during the mount's load, or after it, and finished before the reservation could leave different ids at the same length; compaction then wrote the stale set over them. Give each path a write generation that every writer bumps as it starts. A holder records it, and whether a writer was active, when it registers, which is before it opens and loads the journal. It may compact only if no writer was active then and the generation has not moved. Same rule in Go and Rust; the journal read becomes an injectable step in Rust as it is in Go, so both test the in-place rewrite through the real mount. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * volume server: match the ReadOnly(VolumeId) variant in write_volume_needles #11543 matched VolumeError::ReadOnly as a unit variant in Store::write_volume_needles, and #11544 changed it to ReadOnly(VolumeId) in the same merge window. Each passed CI on its own, but master no longer compiles the Rust volume server. Carry the volume id through. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Chris Lu <chrislusf@users.noreply.github.com> Co-authored-by: Chris Lu <chris.lu@gmail.com>
184 lines
5.6 KiB
Go
184 lines
5.6 KiB
Go
package erasure_coding
|
|
|
|
import (
|
|
"path/filepath"
|
|
"sync"
|
|
)
|
|
|
|
// Process-wide coordination of everything that touches one .ecj path.
|
|
//
|
|
// Mount-time compaction replaces a deletion journal with a new inode. That is
|
|
// only safe while nothing else in this process can write the old one:
|
|
//
|
|
// - Holders are mounted EcVolumes with a handle on the path. A store keeps one
|
|
// EcVolume per disk location, and a shard mount or a cross-disk reconcile
|
|
// can point one disk's volume at another disk's .ecj, so several holders of
|
|
// one path are normal. A holder that keeps appending to a replaced inode
|
|
// acknowledges deletes that are gone at the next mount.
|
|
// - Writers append to or replace the path by name without holding it open
|
|
// across calls: ReceiveFile of an EC .ecj, and the unmounted append in
|
|
// Store.MergeEcJournal, which VolumeEcShardsCopy and EC index recovery
|
|
// funnel a peer's journal through.
|
|
// Bytes they write after the compactor sized the journal would be dropped
|
|
// by the rename.
|
|
//
|
|
// Compaction therefore runs only while its caller is the sole holder and no
|
|
// writer is active, and while it runs no holder may open the path and no writer
|
|
// may start. Both wait instead; a compaction rewrites only the distinct id set,
|
|
// so the wait is short.
|
|
//
|
|
// No writer active at the reservation is not enough: one that ran while the
|
|
// holder loaded the journal, or after, and has finished may have rewritten it
|
|
// in place to the same length (ReceiveFile truncates and refills), which the
|
|
// inode-and-size re-check cannot see. So each writer bumps the path's write
|
|
// generation as it starts, and a holder may compact only if no writer was
|
|
// active when it registered and the generation has not moved since.
|
|
//
|
|
// Paths are keyed by their resolved parent directory, so two disk locations
|
|
// that spell one directory differently still meet here.
|
|
|
|
type ecjPathState struct {
|
|
holders int
|
|
writers int
|
|
compacting bool
|
|
// writeGen counts writers that have started on the path. It survives as
|
|
// long as the entry does, and a registered holder keeps the entry.
|
|
writeGen uint64
|
|
}
|
|
|
|
var ecjPaths = struct {
|
|
sync.Mutex
|
|
changed *sync.Cond
|
|
state map[string]*ecjPathState
|
|
}{state: map[string]*ecjPathState{}}
|
|
|
|
func init() {
|
|
ecjPaths.changed = sync.NewCond(&ecjPaths.Mutex)
|
|
}
|
|
|
|
// ecjPathKey resolves the parent directory of path. The file itself may not
|
|
// exist yet (a copy creates it), so only the directory is resolved.
|
|
func ecjPathKey(path string) string {
|
|
dir, name := filepath.Split(path)
|
|
if dir == "" {
|
|
dir = "."
|
|
}
|
|
if abs, err := filepath.Abs(dir); err == nil {
|
|
dir = abs
|
|
}
|
|
if resolved, err := filepath.EvalSymlinks(dir); err == nil {
|
|
dir = resolved
|
|
}
|
|
return filepath.Join(dir, name)
|
|
}
|
|
|
|
// ecjUpdateWhenNotCompacting blocks until no compaction is running on key,
|
|
// then applies f to its state.
|
|
func ecjUpdateWhenNotCompacting(key string, f func(*ecjPathState)) {
|
|
ecjPaths.Lock()
|
|
defer ecjPaths.Unlock()
|
|
for {
|
|
st := ecjPaths.state[key]
|
|
if st == nil {
|
|
st = &ecjPathState{}
|
|
ecjPaths.state[key] = st
|
|
}
|
|
if !st.compacting {
|
|
f(st)
|
|
return
|
|
}
|
|
ecjPaths.changed.Wait()
|
|
}
|
|
}
|
|
|
|
func ecjRelease(key string, f func(*ecjPathState)) {
|
|
ecjPaths.Lock()
|
|
if st := ecjPaths.state[key]; st != nil {
|
|
f(st)
|
|
if st.holders == 0 && st.writers == 0 && !st.compacting {
|
|
delete(ecjPaths.state, key)
|
|
}
|
|
}
|
|
ecjPaths.Unlock()
|
|
ecjPaths.changed.Broadcast()
|
|
}
|
|
|
|
// ecjHold is a mounted EcVolume's registration as a holder of its .ecj.
|
|
type ecjHold struct {
|
|
key string
|
|
once sync.Once
|
|
// The path's write generation when the hold was taken, and whether a
|
|
// writer was active then. Taken before the journal is opened and loaded,
|
|
// so they cover every write the load might have missed.
|
|
writeGen uint64
|
|
writerAtStart bool
|
|
}
|
|
|
|
// acquireEcjHold registers a holder of ecjPath, first waiting out any
|
|
// compaction in progress so the handle opened afterwards is on the final inode.
|
|
func acquireEcjHold(ecjPath string) *ecjHold {
|
|
h := &ecjHold{key: ecjPathKey(ecjPath)}
|
|
ecjUpdateWhenNotCompacting(h.key, func(st *ecjPathState) {
|
|
st.holders++
|
|
h.writeGen = st.writeGen
|
|
h.writerAtStart = st.writers > 0
|
|
})
|
|
return h
|
|
}
|
|
|
|
func (h *ecjHold) release() {
|
|
h.once.Do(func() {
|
|
ecjRelease(h.key, func(st *ecjPathState) {
|
|
if st.holders > 0 {
|
|
st.holders--
|
|
}
|
|
})
|
|
})
|
|
}
|
|
|
|
// tryBeginCompaction reserves the path for a compaction, or reports false when
|
|
// another holder or an active writer could still reach the current inode, or
|
|
// when a writer has run on the path since the hold was taken, so the journal
|
|
// may no longer be what the holder loaded. The returned func ends the
|
|
// reservation.
|
|
func (h *ecjHold) tryBeginCompaction() (end func(), ok bool) {
|
|
ecjPaths.Lock()
|
|
defer ecjPaths.Unlock()
|
|
st := ecjPaths.state[h.key]
|
|
if st == nil || st.holders != 1 || st.writers != 0 || st.compacting {
|
|
return nil, false
|
|
}
|
|
if h.writerAtStart || st.writeGen != h.writeGen {
|
|
return nil, false
|
|
}
|
|
st.compacting = true
|
|
var once sync.Once
|
|
return func() {
|
|
once.Do(func() {
|
|
ecjRelease(h.key, func(st *ecjPathState) { st.compacting = false })
|
|
})
|
|
}, true
|
|
}
|
|
|
|
// BeginEcjWrite registers an out-of-band writer (shard copy, index recovery,
|
|
// ReceiveFile) of ecjPath, waiting out any compaction in progress. Compaction
|
|
// does not start until the returned func is called, so call it once the write,
|
|
// and any cleanup of a partial file, is done.
|
|
func BeginEcjWrite(ecjPath string) (done func()) {
|
|
key := ecjPathKey(ecjPath)
|
|
ecjUpdateWhenNotCompacting(key, func(st *ecjPathState) {
|
|
st.writers++
|
|
st.writeGen++
|
|
})
|
|
var once sync.Once
|
|
return func() {
|
|
once.Do(func() {
|
|
ecjRelease(key, func(st *ecjPathState) {
|
|
if st.writers > 0 {
|
|
st.writers--
|
|
}
|
|
})
|
|
})
|
|
}
|
|
}
|