mirror of
https://github.com/versity/versitygw.git
synced 2026-09-24 17:04:16 +00:00
Problem:
- `posix.New` calls `os.Chdir(rootdir)` and uses cwd-relative paths for
every bucket and object. That is the cheapest way to address files, but
the cwd is process-wide: embedding the gateway (`embedgw`) silently moves
the host program's cwd. In particular, Go unit tests that embed the
gateway can no longer read their test data files by relative path.
Change:
- New `PosixOpts.AbsolutePaths`. When set, `New` leaves the working
directory alone and builds every path from the absolute root; a relative
`VersioningDir`/`SideCarDir` is then resolved against the working
directory rather than the root. The default is unchanged: chdir and
relative paths.
- All bucket and object paths go through new `BucketPath`/`ObjectPath`,
which return the name as-is by default and prefix the root with
`AbsolutePaths`. An absolute "bucket" (the versioning directory
substitution) is passed through unchanged.
- `tmpfile` records the bucket directory path so `link()` and its fallbacks
use the same addressing; `ListBuckets` reads the root through the same
helper.
- `meta.XattrMeta` needs the same root with `AbsolutePaths`. New
`meta.RootDirSetter` interface; `posix.New` calls `WithRootDir` on
storers that implement it in that mode. A zero `XattrMeta` keeps
resolving against the cwd. `SideCar`/`NoMeta` unchanged. A type that
embeds `XattrMeta` inherits a `WithRootDir` that returns a bare
`XattrMeta`, so it needs its own (documented on `RootDirSetter`).
- `DeleteObject` (directory object), `ListParts`, and `UploadPartCopy`
passed filesystem paths where the metadata API expects bucket/object
names; they now pass names, so the sidecar layout is unchanged in both
modes.
- Windows `handleParentDirError` walks up until `filepath.Dir` is a fixed
point, which works for relative and absolute paths.
- scoutfs used cwd-relative bucket/object paths in `CreateBucket`,
`GetObject`, `HeadObject`, `RestoreObject` and the glacier walk; they now
go through `BucketPath`/`ObjectPath`. `scoutfs.New` resolves `rootdir`
before `posix.New` so a relative root no longer reopens `rootdir/rootdir`
after the chdir.
- `isBucketValid` unconditionally rejects names that do not denote a single
entry under the root: `""`, `.`, `..`, names containing a path separator,
and absolute paths. `XattrMeta` rejects `""`, `.` and `..` likewise.
With relative paths `os.Stat("")` and `os.RemoveAll(".")` failed by
accident; with absolute paths they would act on the root directory itself
(reachable with strict bucket names disabled, or via the admin
`change-bucket-owner` endpoint which does not validate `bucket`).
- scoutfs had its own `isBucketValid` whose `validateBucketName` flag was
never set, so it accepted everything. It now delegates to the new exported
`Posix.IsBucketValid`.
- `UploadPartCopy` did not validate the copy source's bucket name (unlike
`CopyObject`); it does now.
- `New` opens the root after validating the versioning and sidecar
directories, so those error paths no longer leak the root handle. The
chdir still happens first, so a relative directory resolves against the
root as before.
Tests:
- New `TestDefaultModeChangesWorkingDirectory` documents the default.
- New `TestRootDirIndependentOfWorkingDirectory`: `AbsolutePaths` with a
relative root from an unrelated cwd, checks cwd is untouched and that
put/get/list/delete, copy, multipart upload with checksums and part copy,
directory-object delete, and invalid bucket names behave correctly under
the root, for both metadata storers.
- New `TestVersioningDirIndependentOfWorkingDirectory`: same setup with a
relative versioning directory; versions land there and not under the
root or cwd.
- New `TestXattrMetaPath` covers cwd-relative and root resolution, absolute
pass-through and the rejected names.
- New `BenchmarkPosix*` benchmarks (small-object head/get/put/list, both
storers, both path modes). The default mode matches `main` within noise
on both Linux and macOS. `AbsolutePaths` costs about 0.2µs (Linux) to
0.4µs (macOS) per path lookup; on Linux (arm64 VM, overlayfs) that is
+2-3% on PutObject and +10-27% on the metadata-heavy small-object
HeadObject/GetObject/ListObjectsV2 with xattr metadata, which is why it
is opt-in.
118 lines
3.8 KiB
Go
118 lines
3.8 KiB
Go
// Copyright 2026 Versity Software
|
|
// This file is licensed under the Apache License, Version 2.0
|
|
// (the "License"); you may not use this file except in compliance
|
|
// with the License. You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing,
|
|
// software distributed under the License is distributed on an
|
|
// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
|
// KIND, either express or implied. See the License for the
|
|
// specific language governing permissions and limitations
|
|
// under the License.
|
|
|
|
//go:build windows
|
|
|
|
package posix
|
|
|
|
import (
|
|
"errors"
|
|
"os"
|
|
"path/filepath"
|
|
"syscall"
|
|
|
|
"github.com/versity/versitygw/s3err"
|
|
)
|
|
|
|
func handleParentDirError(name string) error {
|
|
dir := filepath.Dir(name)
|
|
|
|
// Walk up the directory hierarchy until Dir returns its argument
|
|
// unchanged: "." for a relative path, the volume root for an absolute
|
|
// one.
|
|
for dir != filepath.Dir(dir) {
|
|
d, statErr := os.Stat(dir)
|
|
if statErr == nil {
|
|
// Path component exists
|
|
if !d.IsDir() {
|
|
// Found a file in the ancestor path
|
|
return s3err.GetAPIError(s3err.ErrObjectParentIsFile)
|
|
}
|
|
// Found a valid directory ancestor, parent truly doesn't exist
|
|
break
|
|
}
|
|
// Continue checking parent directories
|
|
dir = filepath.Dir(dir)
|
|
}
|
|
// Parent doesn't exist or is a directory, treat as ENOENT
|
|
return nil
|
|
}
|
|
|
|
// errDirectory is Windows ERROR_DIRECTORY (267): "The directory name is invalid."
|
|
// Windows returns this when opening a path like "file/" where "file" is a regular
|
|
// file rather than a directory — the POSIX equivalent is ENOTDIR.
|
|
const errDirectory = syscall.Errno(267)
|
|
|
|
// errInvalidName is Windows ERROR_INVALID_NAME (123): "The filename, directory
|
|
// name, or volume label syntax is incorrect." Windows returns this when a path
|
|
// component exceeds the filesystem name-length limit — the POSIX equivalent is
|
|
// ENAMETOOLONG.
|
|
const errInvalidName = syscall.Errno(123)
|
|
|
|
// errDirNotEmpty is Windows ERROR_DIR_NOT_EMPTY (145): "The directory is not
|
|
// empty." — the POSIX equivalent is ENOTEMPTY.
|
|
const errDirNotEmpty = syscall.Errno(145)
|
|
|
|
// isErrNameTooLong reports whether err indicates that a filename or path
|
|
// component is too long. On Windows this covers both ENAMETOOLONG
|
|
// (ERROR_FILENAME_EXCED_RANGE, 206) and ERROR_INVALID_NAME (123), which is
|
|
// what the Windows kernel returns for a 300-character filename that exceeds
|
|
// MAX_PATH.
|
|
func isErrNameTooLong(err error) bool {
|
|
if errors.Is(err, syscall.ENAMETOOLONG) {
|
|
return true
|
|
}
|
|
var sysErr syscall.Errno
|
|
if errors.As(err, &sysErr) {
|
|
return sysErr == errInvalidName
|
|
}
|
|
return false
|
|
}
|
|
|
|
// isErrDirNotEmpty reports whether err indicates that a directory is not empty.
|
|
// On Windows this covers both ENOTEMPTY and ERROR_DIR_NOT_EMPTY (145).
|
|
func isErrDirNotEmpty(err error) bool {
|
|
if errors.Is(err, syscall.ENOTEMPTY) {
|
|
return true
|
|
}
|
|
var sysErr syscall.Errno
|
|
if errors.As(err, &sysErr) {
|
|
return sysErr == errDirNotEmpty
|
|
}
|
|
return false
|
|
}
|
|
|
|
// isErrNotDir reports whether err indicates that a path component is a file,
|
|
// not a directory. On Windows this covers both ENOTDIR and ERROR_DIRECTORY
|
|
// because os.Open / os.Stat do not map ERROR_DIRECTORY to ENOTDIR.
|
|
func isErrNotDir(err error) bool {
|
|
if errors.Is(err, syscall.ENOTDIR) {
|
|
return true
|
|
}
|
|
var sysErr syscall.Errno
|
|
if errors.As(err, &sysErr) {
|
|
return sysErr == errDirectory
|
|
}
|
|
return false
|
|
}
|
|
|
|
// openForRead opens a file for reading with FILE_SHARE_DELETE so that a
|
|
// concurrent DeleteObject (os.Remove) can succeed even while the file handle
|
|
// is held open for streaming the GET response body. Without this flag,
|
|
// Windows returns "The process cannot access the file because it is being
|
|
// used by another process" on the Remove call.
|
|
func openForRead(name string, useODirect bool) (*os.File, error) {
|
|
return openDataRead(name, useODirect)
|
|
}
|