Skip to content

fork_repo / create_repo orphan on-disk repos (and a spent iCaptcha proof / uploaded object) on late DB failure #205

Description

@beardthelion

Surfaced during review of #196 (pre-existing ordering; not in that PR's diff).

fork_repo ordering (api/repos.rs:1555 -> 1567 -> 1585 -> 1605): spend proof -> git clone --mirror to disk -> release_after_write (Tigris upload) -> db.create_repo. If create_repo fails, the on-disk mirror and the already-uploaded Tigris object are left with no DB row, and the single-use iCaptcha proof is already consumed.

create_repo (api/repos.rs:208 -> 210-219 -> 236): proof.consume then repo_store.init (blocking git init) run before db.create_repo; a DB failure orphans the freshly-initialized directory. No cleanup-on-failure exists on either path.

Fix direction: make disk materialization + proof spend adjacent to a guaranteed-successful DB write; on db.create_repo failure best-effort remove_dir_all(disk_path), and prefer deferring the Tigris upload until after the row commits. Verified by tracing the ordering during the #196 review.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:nodegitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existssubsystem:apiNode REST API request/response surfacesubsystem:attestationCertificates, anchoring, per-ref attestationsubsystem:storageBlob/object store, Arweave, IPFS, archives

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions