fix: make conditional publish lock modes explicit

Conditional PUTs require a lock primitive that excludes competing gateway
processes sharing a backend filesystem. A successful flock call does not prove
that property: some clustered filesystem configurations accept flock but scope
it to one node, silently leaving cross-gateway check-and-publish races open.

Add an object-lock mode that lets operators select flock or fcntl for
filesystems where that primitive is cluster-coherent, local for the existing
per-process behavior, or none to reject conditional writes with NotImplemented.
Keep the legacy disable flag as an alias for local.

Shared lock modes now verify the selected primitive on the root lock filesystem
during startup and fail closed if it cannot be used. Runtime lock failures no
longer silently downgrade to process-local exclusion. The startup check cannot
establish cross-node coherence, so that remains an explicit operator
requirement.

ScoutFS defaults to none since posix locks are not cluster consistent, but
allow setting local for single node deployments.

Fixes #2351
This commit is contained in:
Ben McClelland
2026-09-10 19:01:56 -07:00
parent 8d57a38e37
commit 9c363b280a
11 changed files with 258 additions and 68 deletions
+12 -8
View File
@@ -704,14 +704,18 @@ ROOT_SECRET_ACCESS_KEY=
# NFS servers that may hang on this call.
#VGW_DISABLE_COPY_FILE_RANGE=false
# The VGW_DISABLE_OBJECT_LOCK_FILE option disables shared advisory lock files
# used for conditional object publishes. This can be necessary on filesystems
# that do not support advisory file locking. When enabled, conditional writes
# are atomic only within a single versitygw process and are unsafe with
# multiple gateway processes sharing the same backend.
# This can be set to true to disable the .vgwlocks directory if running in
# single versitygw instance mode or conditional writes are not important
# to this deployment.
# The VGW_OBJECT_LOCK_MODE option selects the advisory lock used for conditional
# object publishes. Use flock (default) or fcntl only after verifying that the
# selected primitive is cluster-coherent for the backend filesystem and mount
# options. The local mode disables the .vgwlocks directory and is atomic only
# within one versitygw process, so it is unsafe with multiple gateways. The
# none mode rejects conditional writes with a NotImplemented response.
# At startup, flock and fcntl modes verify that their primitive works on the
# filesystem hosting .vgwlocks; this cannot verify cross-node lock coherence.
#VGW_OBJECT_LOCK_MODE=flock
# VGW_DISABLE_OBJECT_LOCK_FILE is a deprecated alias for
# VGW_OBJECT_LOCK_MODE=local.
#VGW_DISABLE_OBJECT_LOCK_FILE=false
# The VGW_ENABLE_O_DIRECT option enables best-effort O_DIRECT for object data