fix: make WAL segment directory fsync failure fatal (C6)
Per design §3.2 line 248-272, segment directory fsync is a hard requirement for durable-ready state, not best-effort. rename is atomic in memory but not guaranteed to survive power loss without a directory fsync. The previous code silently swallowed both os.Open(dir) and dirFD.Sync() errors, leaving WAL writer to confirm batches as durable when their segment might not exist after a crash. Failure propagation: - Initial segment creation: NewSegmentWriter fails -> NewSegmentManager fails -> DB.Open fails (user sees error, no data promise violated). - Rotation during AppendBatch: NewSegmentWriter fails -> AppendBatch fails -> WalWriter.stopWithError(ErrCommitUnknown) -> write-stopped (per design line 272). Changes: - wal/segment_writer.go: extract dirFsync helper (Open -> f.Stat -> IsDir -> f.Sync, avoiding TOCTOU window), replace silent swallow with fatal error; on failure clean up resources (fd.Close + os.Remove) and surface cleanup errors via errors.Join so nothing is silently lost. - wal/dir_fsync_test.go (new): unit test the helper with valid dir, non-existent dir (fails at os.Open), and not-a-dir (fails at IsDir). - wal/segment_writer_test.go: add TestNewSegmentWriterDirFsyncFailure (injects failure via package-level dirFsyncFn override; documents the not-parallel-safe constraint), TestNewSegmentWriterNormalPathStillWorks (regression), and TestNewSegmentWriterRetryAfterDirFsyncFailure (verifies cleanup is effective for retry). - wal/segment_manager_test.go: add TestSegmentManagerRotateFailsOnDirFsyncFailure (fills segment until rotation triggers, injects failure, verifies propagation through AppendBatch path) and TestNewSegmentManagerFailsOnDirFsyncFailure (covers the DB.Open failure path). dirFsyncFn injection note: tests that override this package-level var must not use t.Parallel(). All existing wal tests run serially within the package; this is the lightest mechanism that doesn't require interface indirection in production code. Verified: each new test fails on pre-fix code (silent swallow returned nil error) and passes after the fix. Full suite green including go test -race ./... . Audit context: docs/audit-3.2.md C6 (Oracle-verified bg_ef425776).
This commit is contained in:
+13
-4
@@ -1,6 +1,7 @@
|
||||
package wal
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
@@ -82,10 +83,18 @@ func NewSegmentWriter(
|
||||
return nil, fmt.Errorf("wal: open segment file for append: %w", err)
|
||||
}
|
||||
|
||||
// Sync directory to make rename durable (best-effort on Linux).
|
||||
if dirFD, derr := os.Open(dir); derr == nil {
|
||||
dirFD.Sync()
|
||||
dirFD.Close()
|
||||
// Per design §3.2 line 258, directory fsync is a hard requirement for
|
||||
// durable-ready. Without it, the rename above is not guaranteed to survive
|
||||
// power loss, violating the Always-mode "no loss of acknowledged writes"
|
||||
// promise.
|
||||
if err := dirFsyncFn(dir); err != nil {
|
||||
closeErr := fd.Close()
|
||||
removeErr := os.Remove(finalPath)
|
||||
if closeErr != nil || removeErr != nil {
|
||||
cleanup := errors.Join(closeErr, removeErr)
|
||||
return nil, fmt.Errorf("wal: fsync directory after segment rename (cleanup: %v): %w", cleanup, err)
|
||||
}
|
||||
return nil, fmt.Errorf("wal: fsync directory after segment rename: %w", err)
|
||||
}
|
||||
|
||||
return &SegmentWriter{
|
||||
|
||||
Reference in New Issue
Block a user