Repository navigation
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
An upload write can create part of its file and then fail before the metadata INSERT. The current catch returns the existing upload error but leaves that unreferenced partial file on disk; normal database close does not remove it.
Acquire file ownership with an explicit exclusive
open('wx'), write through the handle and close it infinally. On failure, remove the file only if this call successfully created it. Open failures, includingEEXIST, never unlink an existing file. Metadata insertion/rollback, error responses, quotas and successful payload handling are unchanged.Testing
EFBIG; the store separately returns its mapped HTTP 500. The test does not pretend to capture the hidden native exception from the store.pnpm check,pnpm buildandgit diff --checkpassed.prlimitis absent. Full suite, manual HTTP/UI and non-Linux native failure behavior were not tested.Self-Review
Four independent scoped reviews: architecture A, correctness A-, test quality A-, spec alignment A. No blocking findings; the prior orphan-file defect and exclusive-open ownership were checked.
Retained limitations: cleanup uses the existing best-effort unlink helper, so an unremovable file can remain. Close/unlink failures and a disk-backed database restart are not covered by this regression. The successful-upload control is inside the Linux native test and also skips when that test is unavailable. These limits are disclosed rather than claimed fixed. Aggregate A-. Runtime validation is supported by retained command receipts/logs; source reviewers did not rerun it.
This is independent of #56's filename truncation fix; both changes should be retained when integrated.