Repository navigation
Fix filesystem eviction races and recover missing cache files - #2762
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
MarcusSorealheis
force-pushed
the
filesystem-race-conditions-combined-prs
branch
from
September 15, 2026 08:41
ffc5e29 to
2e74dd3
Compare
Give each upload a distinct generation-owned content path, publish before indexing, and repair missing files during duplicate comparison. Remove stale read entries conditionally so recovery preserves concurrent uploads. Combine the generation-based ownership design from #2715 with upload self-healing from #2644, with regression coverage and layout migration. Co-authored-by: Cormac Relf <web@cormacrelf.net> Co-authored-by: Jiří Szkandera <jirik.sz@gmail.com>
MarcusSorealheis
force-pushed
the
filesystem-race-conditions-combined-prs
branch
from
September 15, 2026 08:48
2e74dd3 to
4148f25
Compare
palfrey
approved these changes
Sep 15, 2026
palfrey
left a comment
Member
There was a problem hiding this comment.
LGTM, definitely better than the previous tangle of actions
MarcusSorealheis
deleted the
filesystem-race-conditions-combined-prs
branch
September 15, 2026 09:17
This was referenced Sep 15, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
A delayed filesystem eviction can rename away a newer upload of the same key. The index then reports a file that is missing from disk, and subsequent uploads fail while opening it for duplicate comparison with
No such file or directory, propagating through the inner store to ByteStream writes.This combines generation-specific file ownership from #2715 with missing-file upload recovery from #2644:
NotFoundby conditionally removing the stale entry and continuing the upload. Other open errors still propagate. Read-side recovery also checks entry identity before removal.How was this verified?
d//s/layouts, string keys with numeric suffixes, failed migrations, replacement of unmigrated files, restart, and leftover generations.NotFound/No such file or directoryfailure; making generations share a content filename madestale_unref_must_not_delete_reuploaded_filefail because cleanup deleted the replacement. Both fixes were restored before the final passing test run.Production rollout and observation remain a follow-up.
Risk
On-disk layout change: new files use
d2/<hash>-<size>-<generation>ands2/<key>-<generation>. Writable startup migrates existing cache files; failed migrations remain readable and retry at the next startup. Earlier NativeLink versions cannot read the new directories, so rollback requires a separate cache directory or a planned cache rebuild. The filesystem-store guide documents this behavior.The ownership mechanism works without Unix inode checks or a shared rename-lock pool. Cleanup, restart selection, and concurrent replacement are the main correctness risks covered by the regression tests.
This change is