1 // Copyright (C) The Arvados Authors. All rights reserved.
3 // SPDX-License-Identifier: Apache-2.0
21 var maxBlockSize = 1 << 26
23 var concurrentWriters = 4
25 // A CollectionFileSystem is a FileSystem that can be serialized as a
26 // manifest and stored as a collection.
27 type CollectionFileSystem interface {
30 // Flush all file data to Keep and return a snapshot of the
31 // filesystem suitable for saving as (Collection)ManifestText.
32 // Prefix (normally ".") is a top level directory, effectively
33 // prepended to all paths in the returned manifest.
34 MarshalManifest(prefix string) (string, error)
36 // Total data bytes in all files.
40 type collectionFileSystem struct {
45 // FileSystem returns a CollectionFileSystem for the collection.
46 func (c *Collection) FileSystem(client apiClient, kc keepClient) (CollectionFileSystem, error) {
48 if c.ModifiedAt == nil {
51 modTime = *c.ModifiedAt
53 fs := &collectionFileSystem{
55 fileSystem: fileSystem{
56 fsBackend: keepBackend{apiClient: client, keepClient: kc},
64 mode: os.ModeDir | 0755,
67 inodes: make(map[string]inode),
70 root.SetParent(root, ".")
71 if err := root.loadManifest(c.ManifestText); err != nil {
74 backdateTree(root, modTime)
79 func backdateTree(n inode, modTime time.Time) {
80 switch n := n.(type) {
82 n.fileinfo.modTime = modTime
84 n.fileinfo.modTime = modTime
85 for _, n := range n.inodes {
86 backdateTree(n, modTime)
91 func (fs *collectionFileSystem) newNode(name string, perm os.FileMode, modTime time.Time) (node inode, err error) {
92 if name == "" || name == "." || name == ".." {
93 return nil, ErrInvalidArgument
101 mode: perm | os.ModeDir,
104 inodes: make(map[string]inode),
112 mode: perm & ^os.ModeDir,
119 func (fs *collectionFileSystem) Sync() error {
123 txt, err := fs.MarshalManifest(".")
125 return fmt.Errorf("sync failed: %s", err)
131 err = fs.RequestAndDecode(nil, "PUT", "arvados/v1/collections/"+fs.uuid, fs.UpdateBody(coll), map[string]interface{}{"select": []string{"uuid"}})
133 return fmt.Errorf("sync failed: update %s: %s", fs.uuid, err)
138 func (fs *collectionFileSystem) MarshalManifest(prefix string) (string, error) {
139 fs.fileSystem.root.Lock()
140 defer fs.fileSystem.root.Unlock()
141 return fs.fileSystem.root.(*dirnode).marshalManifest(prefix, newThrottle(concurrentWriters))
144 func (fs *collectionFileSystem) Size() int64 {
145 return fs.fileSystem.root.(*dirnode).TreeSize()
148 // filenodePtr is an offset into a file that is (usually) efficient to
149 // seek to. Specifically, if filenode.repacked==filenodePtr.repacked
151 // filenode.segments[filenodePtr.segmentIdx][filenodePtr.segmentOff]
152 // corresponds to file offset filenodePtr.off. Otherwise, it is
153 // necessary to reexamine len(filenode.segments[0]) etc. to find the
154 // correct segment and offset.
155 type filenodePtr struct {
162 // seek returns a ptr that is consistent with both startPtr.off and
163 // the current state of fn. The caller must already hold fn.RLock() or
166 // If startPtr is beyond EOF, ptr.segment* will indicate precisely
171 // ptr.segmentIdx == len(filenode.segments) // i.e., at EOF
173 // filenode.segments[ptr.segmentIdx].Len() > ptr.segmentOff
174 func (fn *filenode) seek(startPtr filenodePtr) (ptr filenodePtr) {
177 // meaningless anyway
179 } else if ptr.off >= fn.fileinfo.size {
180 ptr.segmentIdx = len(fn.segments)
182 ptr.repacked = fn.repacked
184 } else if ptr.repacked == fn.repacked {
185 // segmentIdx and segmentOff accurately reflect
186 // ptr.off, but might have fallen off the end of a
188 if ptr.segmentOff >= fn.segments[ptr.segmentIdx].Len() {
195 ptr.repacked = fn.repacked
197 if ptr.off >= fn.fileinfo.size {
198 ptr.segmentIdx, ptr.segmentOff = len(fn.segments), 0
201 // Recompute segmentIdx and segmentOff. We have already
202 // established fn.fileinfo.size > ptr.off >= 0, so we don't
203 // have to deal with edge cases here.
205 for ptr.segmentIdx, ptr.segmentOff = 0, 0; off < ptr.off; ptr.segmentIdx++ {
206 // This would panic (index out of range) if
207 // fn.fileinfo.size were larger than
208 // sum(fn.segments[i].Len()) -- but that can't happen
209 // because we have ensured fn.fileinfo.size is always
211 segLen := int64(fn.segments[ptr.segmentIdx].Len())
212 if off+segLen > ptr.off {
213 ptr.segmentOff = int(ptr.off - off)
221 // filenode implements inode.
222 type filenode struct {
227 // number of times `segments` has changed in a
228 // way that might invalidate a filenodePtr
230 memsize int64 // bytes in memSegments
235 // caller must have lock
236 func (fn *filenode) appendSegment(e segment) {
237 fn.segments = append(fn.segments, e)
238 fn.fileinfo.size += int64(e.Len())
241 func (fn *filenode) SetParent(p inode, name string) {
245 fn.fileinfo.name = name
248 func (fn *filenode) Parent() inode {
254 func (fn *filenode) FS() FileSystem {
258 // Read reads file data from a single segment, starting at startPtr,
259 // into p. startPtr is assumed not to be up-to-date. Caller must have
261 func (fn *filenode) Read(p []byte, startPtr filenodePtr) (n int, ptr filenodePtr, err error) {
262 ptr = fn.seek(startPtr)
264 err = ErrNegativeOffset
267 if ptr.segmentIdx >= len(fn.segments) {
271 n, err = fn.segments[ptr.segmentIdx].ReadAt(p, int64(ptr.segmentOff))
275 if ptr.segmentOff == fn.segments[ptr.segmentIdx].Len() {
278 if ptr.segmentIdx < len(fn.segments) && err == io.EOF {
286 func (fn *filenode) Size() int64 {
289 return fn.fileinfo.Size()
292 func (fn *filenode) FileInfo() os.FileInfo {
298 func (fn *filenode) Truncate(size int64) error {
301 return fn.truncate(size)
304 func (fn *filenode) truncate(size int64) error {
305 if size == fn.fileinfo.size {
309 if size < fn.fileinfo.size {
310 ptr := fn.seek(filenodePtr{off: size})
311 for i := ptr.segmentIdx; i < len(fn.segments); i++ {
312 if seg, ok := fn.segments[i].(*memSegment); ok {
313 fn.memsize -= int64(seg.Len())
316 if ptr.segmentOff == 0 {
317 fn.segments = fn.segments[:ptr.segmentIdx]
319 fn.segments = fn.segments[:ptr.segmentIdx+1]
320 switch seg := fn.segments[ptr.segmentIdx].(type) {
322 seg.Truncate(ptr.segmentOff)
323 fn.memsize += int64(seg.Len())
325 fn.segments[ptr.segmentIdx] = seg.Slice(0, ptr.segmentOff)
328 fn.fileinfo.size = size
331 for size > fn.fileinfo.size {
332 grow := size - fn.fileinfo.size
335 if len(fn.segments) == 0 {
337 fn.segments = append(fn.segments, seg)
338 } else if seg, ok = fn.segments[len(fn.segments)-1].(*memSegment); !ok || seg.Len() >= maxBlockSize {
340 fn.segments = append(fn.segments, seg)
342 if maxgrow := int64(maxBlockSize - seg.Len()); maxgrow < grow {
345 seg.Truncate(seg.Len() + int(grow))
346 fn.fileinfo.size += grow
352 // Write writes data from p to the file, starting at startPtr,
353 // extending the file size if necessary. Caller must have Lock.
354 func (fn *filenode) Write(p []byte, startPtr filenodePtr) (n int, ptr filenodePtr, err error) {
355 if startPtr.off > fn.fileinfo.size {
356 if err = fn.truncate(startPtr.off); err != nil {
357 return 0, startPtr, err
360 ptr = fn.seek(startPtr)
362 err = ErrNegativeOffset
365 for len(p) > 0 && err == nil {
367 if len(cando) > maxBlockSize {
368 cando = cando[:maxBlockSize]
370 // Rearrange/grow fn.segments (and shrink cando if
371 // needed) such that cando can be copied to
372 // fn.segments[ptr.segmentIdx] at offset
374 cur := ptr.segmentIdx
375 prev := ptr.segmentIdx - 1
377 if cur < len(fn.segments) {
378 _, curWritable = fn.segments[cur].(*memSegment)
380 var prevAppendable bool
381 if prev >= 0 && fn.segments[prev].Len() < maxBlockSize {
382 _, prevAppendable = fn.segments[prev].(*memSegment)
384 if ptr.segmentOff > 0 && !curWritable {
385 // Split a non-writable block.
386 if max := fn.segments[cur].Len() - ptr.segmentOff; max <= len(cando) {
387 // Truncate cur, and insert a new
390 fn.segments = append(fn.segments, nil)
391 copy(fn.segments[cur+1:], fn.segments[cur:])
393 // Split cur into two copies, truncate
394 // the one on the left, shift the one
395 // on the right, and insert a new
396 // segment between them.
397 fn.segments = append(fn.segments, nil, nil)
398 copy(fn.segments[cur+2:], fn.segments[cur:])
399 fn.segments[cur+2] = fn.segments[cur+2].Slice(ptr.segmentOff+len(cando), -1)
404 seg.Truncate(len(cando))
405 fn.memsize += int64(len(cando))
406 fn.segments[cur] = seg
407 fn.segments[prev] = fn.segments[prev].Slice(0, ptr.segmentOff)
412 } else if curWritable {
413 if fit := int(fn.segments[cur].Len()) - ptr.segmentOff; fit < len(cando) {
418 // Shrink cando if needed to fit in
420 if cangrow := maxBlockSize - fn.segments[prev].Len(); cangrow < len(cando) {
421 cando = cando[:cangrow]
425 if cur == len(fn.segments) {
426 // ptr is at EOF, filesize is changing.
427 fn.fileinfo.size += int64(len(cando))
428 } else if el := fn.segments[cur].Len(); el <= len(cando) {
429 // cando is long enough that we won't
430 // need cur any more. shrink cando to
431 // be exactly as long as cur
432 // (otherwise we'd accidentally shift
433 // the effective position of all
434 // segments after cur).
436 copy(fn.segments[cur:], fn.segments[cur+1:])
437 fn.segments = fn.segments[:len(fn.segments)-1]
439 // shrink cur by the same #bytes we're growing prev
440 fn.segments[cur] = fn.segments[cur].Slice(len(cando), -1)
446 ptr.segmentOff = fn.segments[prev].Len()
447 fn.segments[prev].(*memSegment).Truncate(ptr.segmentOff + len(cando))
448 fn.memsize += int64(len(cando))
452 // Insert a segment between prev and
453 // cur, and advance prev/cur.
454 fn.segments = append(fn.segments, nil)
455 if cur < len(fn.segments) {
456 copy(fn.segments[cur+1:], fn.segments[cur:])
460 // appending a new segment does
461 // not invalidate any ptrs
464 seg.Truncate(len(cando))
465 fn.memsize += int64(len(cando))
466 fn.segments[cur] = seg
472 // Finally we can copy bytes from cando to the current segment.
473 fn.segments[ptr.segmentIdx].(*memSegment).WriteAt(cando, ptr.segmentOff)
477 ptr.off += int64(len(cando))
478 ptr.segmentOff += len(cando)
479 if ptr.segmentOff >= maxBlockSize {
480 fn.pruneMemSegments()
482 if fn.segments[ptr.segmentIdx].Len() == ptr.segmentOff {
487 fn.fileinfo.modTime = time.Now()
492 // Write some data out to disk to reduce memory use. Caller must have
494 func (fn *filenode) pruneMemSegments() {
495 // TODO: async (don't hold Lock() while waiting for Keep)
496 // TODO: share code with (*dirnode)sync()
497 // TODO: pack/flush small blocks too, when fragmented
498 for idx, seg := range fn.segments {
499 seg, ok := seg.(*memSegment)
500 if !ok || seg.Len() < maxBlockSize {
503 locator, _, err := fn.FS().PutB(seg.buf)
505 // TODO: stall (or return errors from)
506 // subsequent writes until flushing
510 fn.memsize -= int64(seg.Len())
511 fn.segments[idx] = storedSegment{
521 type dirnode struct {
522 fs *collectionFileSystem
526 func (dn *dirnode) FS() FileSystem {
530 func (dn *dirnode) Child(name string, replace func(inode) (inode, error)) (inode, error) {
531 if dn == dn.fs.rootnode() && name == ".arvados#collection" {
532 gn := &getternode{Getter: func() ([]byte, error) {
535 coll.ManifestText, err = dn.fs.MarshalManifest(".")
539 data, err := json.Marshal(&coll)
541 data = append(data, '\n')
545 gn.SetParent(dn, name)
548 return dn.treenode.Child(name, replace)
551 // sync flushes in-memory data and remote block references (for the
552 // children with the given names, which must be children of dn) to
553 // local persistent storage. Caller must have write lock on dn and the
555 func (dn *dirnode) sync(names []string, throttle *throttle) error {
556 type shortBlock struct {
560 var pending []shortBlock
563 var wg sync.WaitGroup
564 errors := make(chan error, 1)
565 flush := func(sbs []shortBlock) {
571 defer throttle.Release()
572 block := make([]byte, 0, maxBlockSize)
573 for _, sb := range sbs {
574 block = append(block, sb.fn.segments[sb.idx].(*memSegment).buf...)
576 locator, _, err := dn.fs.PutB(block)
584 for _, sb := range sbs {
585 data := sb.fn.segments[sb.idx].(*memSegment).buf
586 sb.fn.segments[sb.idx] = storedSegment{
594 sb.fn.memsize -= int64(len(data))
598 localLocator := map[string]string{}
599 for _, name := range names {
600 fn, ok := dn.inodes[name].(*filenode)
604 for idx, seg := range fn.segments {
605 switch seg := seg.(type) {
607 loc, ok := localLocator[seg.locator]
610 loc, err = dn.fs.LocalLocator(seg.locator)
614 localLocator[seg.locator] = loc
617 fn.segments[idx] = seg
619 if seg.Len() > maxBlockSize/2 {
621 go flush([]shortBlock{{fn, idx}})
624 if pendingLen+seg.Len() > maxBlockSize {
630 pending = append(pending, shortBlock{fn, idx})
631 pendingLen += seg.Len()
633 panic(fmt.Sprintf("can't sync segment type %T", seg))
644 // caller must have write lock.
645 func (dn *dirnode) marshalManifest(prefix string, throttle *throttle) (string, error) {
647 type filepart struct {
652 var fileparts []filepart
656 if len(dn.inodes) == 0 {
660 // Express the existence of an empty directory by
661 // adding an empty file named `\056`, which (unlike
662 // the more obvious spelling `.`) is accepted by the
663 // API's manifest validator.
664 return manifestEscape(prefix) + " d41d8cd98f00b204e9800998ecf8427e+0 0:0:\\056\n", nil
667 names := make([]string, 0, len(dn.inodes))
668 for name := range dn.inodes {
669 names = append(names, name)
672 for _, name := range names {
673 node := dn.inodes[name]
677 if err := dn.sync(names, throttle); err != nil {
680 for _, name := range names {
681 switch node := dn.inodes[name].(type) {
683 subdir, err := node.marshalManifest(prefix+"/"+name, throttle)
687 subdirs = subdirs + subdir
689 if len(node.segments) == 0 {
690 fileparts = append(fileparts, filepart{name: name})
693 for _, seg := range node.segments {
694 switch seg := seg.(type) {
696 if len(blocks) > 0 && blocks[len(blocks)-1] == seg.locator {
697 streamLen -= int64(seg.size)
699 blocks = append(blocks, seg.locator)
703 offset: streamLen + int64(seg.offset),
704 length: int64(seg.length),
706 if prev := len(fileparts) - 1; prev >= 0 &&
707 fileparts[prev].name == name &&
708 fileparts[prev].offset+fileparts[prev].length == next.offset {
709 fileparts[prev].length += next.length
711 fileparts = append(fileparts, next)
713 streamLen += int64(seg.size)
715 // This can't happen: we
716 // haven't unlocked since
718 panic(fmt.Sprintf("can't marshal segment type %T", seg))
722 panic(fmt.Sprintf("can't marshal inode type %T", node))
725 var filetokens []string
726 for _, s := range fileparts {
727 filetokens = append(filetokens, fmt.Sprintf("%d:%d:%s", s.offset, s.length, manifestEscape(s.name)))
729 if len(filetokens) == 0 {
731 } else if len(blocks) == 0 {
732 blocks = []string{"d41d8cd98f00b204e9800998ecf8427e+0"}
734 return manifestEscape(prefix) + " " + strings.Join(blocks, " ") + " " + strings.Join(filetokens, " ") + "\n" + subdirs, nil
737 func (dn *dirnode) loadManifest(txt string) error {
739 streams := strings.Split(txt, "\n")
740 if streams[len(streams)-1] != "" {
741 return fmt.Errorf("line %d: no trailing newline", len(streams))
743 streams = streams[:len(streams)-1]
744 segments := []storedSegment{}
745 for i, stream := range streams {
747 var anyFileTokens bool
750 segments = segments[:0]
751 for i, token := range strings.Split(stream, " ") {
753 dirname = manifestUnescape(token)
756 if !strings.Contains(token, ":") {
758 return fmt.Errorf("line %d: bad file segment %q", lineno, token)
760 toks := strings.SplitN(token, "+", 3)
762 return fmt.Errorf("line %d: bad locator %q", lineno, token)
764 length, err := strconv.ParseInt(toks[1], 10, 32)
765 if err != nil || length < 0 {
766 return fmt.Errorf("line %d: bad locator %q", lineno, token)
768 segments = append(segments, storedSegment{
775 } else if len(segments) == 0 {
776 return fmt.Errorf("line %d: bad locator %q", lineno, token)
779 toks := strings.SplitN(token, ":", 3)
781 return fmt.Errorf("line %d: bad file segment %q", lineno, token)
785 offset, err := strconv.ParseInt(toks[0], 10, 64)
786 if err != nil || offset < 0 {
787 return fmt.Errorf("line %d: bad file segment %q", lineno, token)
789 length, err := strconv.ParseInt(toks[1], 10, 64)
790 if err != nil || length < 0 {
791 return fmt.Errorf("line %d: bad file segment %q", lineno, token)
793 name := dirname + "/" + manifestUnescape(toks[2])
794 fnode, err := dn.createFileAndParents(name)
795 if fnode == nil && err == nil && length == 0 {
796 // Special case: an empty file used as
797 // a marker to preserve an otherwise
798 // empty directory in a manifest.
801 if err != nil || (fnode == nil && length != 0) {
802 return fmt.Errorf("line %d: cannot use path %q with length %d: %s", lineno, name, length, err)
804 // Map the stream offset/range coordinates to
805 // block/offset/range coordinates and add
806 // corresponding storedSegments to the filenode
808 // Can't continue where we left off.
809 // TODO: binary search instead of
810 // rewinding all the way (but this
811 // situation might be rare anyway)
814 for next := int64(0); segIdx < len(segments); segIdx++ {
815 seg := segments[segIdx]
816 next = pos + int64(seg.Len())
817 if next <= offset || seg.Len() == 0 {
821 if pos >= offset+length {
826 blkOff = int(offset - pos)
828 blkLen := seg.Len() - blkOff
829 if pos+int64(blkOff+blkLen) > offset+length {
830 blkLen = int(offset + length - pos - int64(blkOff))
832 fnode.appendSegment(storedSegment{
834 locator: seg.locator,
839 if next > offset+length {
845 if segIdx == len(segments) && pos < offset+length {
846 return fmt.Errorf("line %d: invalid segment in %d-byte stream: %q", lineno, pos, token)
850 return fmt.Errorf("line %d: no file segments", lineno)
851 } else if len(segments) == 0 {
852 return fmt.Errorf("line %d: no locators", lineno)
853 } else if dirname == "" {
854 return fmt.Errorf("line %d: no stream name", lineno)
860 // only safe to call from loadManifest -- no locking.
862 // If path is a "parent directory exists" marker (the last path
863 // component is "."), the returned values are both nil.
864 func (dn *dirnode) createFileAndParents(path string) (fn *filenode, err error) {
866 names := strings.Split(path, "/")
867 basename := names[len(names)-1]
868 for _, name := range names[:len(names)-1] {
874 // can't be sure parent will be a *dirnode
875 return nil, ErrInvalidArgument
880 node, err = node.Child(name, func(child inode) (inode, error) {
882 child, err := node.FS().newNode(name, 0755|os.ModeDir, node.Parent().FileInfo().ModTime())
886 child.SetParent(node, name)
888 } else if !child.IsDir() {
889 return child, ErrFileExists
900 } else if !permittedName(basename) {
901 err = fmt.Errorf("invalid file part %q in path %q", basename, path)
904 _, err = node.Child(basename, func(child inode) (inode, error) {
905 switch child := child.(type) {
907 child, err = node.FS().newNode(basename, 0755, node.FileInfo().ModTime())
911 child.SetParent(node, basename)
912 fn = child.(*filenode)
918 return child, ErrIsDirectory
920 return child, ErrInvalidArgument
926 func (dn *dirnode) TreeSize() (bytes int64) {
929 for _, i := range dn.inodes {
930 switch i := i.(type) {
934 bytes += i.TreeSize()
940 type segment interface {
943 // Return a new segment with a subsection of the data from this
944 // one. length<0 means length=Len()-off.
945 Slice(off int, length int) segment
948 type memSegment struct {
952 func (me *memSegment) Len() int {
956 func (me *memSegment) Slice(off, length int) segment {
958 length = len(me.buf) - off
960 buf := make([]byte, length)
961 copy(buf, me.buf[off:])
962 return &memSegment{buf: buf}
965 func (me *memSegment) Truncate(n int) {
969 newsize = newsize << 2
971 newbuf := make([]byte, n, newsize)
975 // Zero unused part when shrinking, in case we grow
976 // and start using it again later.
977 for i := n; i < len(me.buf); i++ {
984 func (me *memSegment) WriteAt(p []byte, off int) {
985 if off+len(p) > len(me.buf) {
986 panic("overflowed segment")
988 copy(me.buf[off:], p)
991 func (me *memSegment) ReadAt(p []byte, off int64) (n int, err error) {
992 if off > int64(me.Len()) {
996 n = copy(p, me.buf[int(off):])
1003 type storedSegment struct {
1006 size int // size of stored block (also encoded in locator)
1007 offset int // position of segment within the stored block
1008 length int // bytes in this segment (offset + length <= size)
1011 func (se storedSegment) Len() int {
1015 func (se storedSegment) Slice(n, size int) segment {
1018 if size >= 0 && se.length > size {
1024 func (se storedSegment) ReadAt(p []byte, off int64) (n int, err error) {
1025 if off > int64(se.length) {
1028 maxlen := se.length - int(off)
1029 if len(p) > maxlen {
1031 n, err = se.kc.ReadAt(se.locator, p, int(off)+se.offset)
1037 return se.kc.ReadAt(se.locator, p, int(off)+se.offset)
1040 func canonicalName(name string) string {
1041 name = path.Clean("/" + name)
1042 if name == "/" || name == "./" {
1044 } else if strings.HasPrefix(name, "/") {
1050 var manifestEscapeSeq = regexp.MustCompile(`\\([0-7]{3}|\\)`)
1052 func manifestUnescapeFunc(seq string) string {
1056 i, err := strconv.ParseUint(seq[1:], 8, 8)
1058 // Invalid escape sequence: can't unescape.
1061 return string([]byte{byte(i)})
1064 func manifestUnescape(s string) string {
1065 return manifestEscapeSeq.ReplaceAllStringFunc(s, manifestUnescapeFunc)
1068 var manifestEscapedChar = regexp.MustCompile(`[\000-\040:\s\\]`)
1070 func manifestEscapeFunc(seq string) string {
1071 return fmt.Sprintf("\\%03o", byte(seq[0]))
1074 func manifestEscape(s string) string {
1075 return manifestEscapedChar.ReplaceAllStringFunc(s, manifestEscapeFunc)