git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] enable core.fsyncObjectFiles by default

From
Jeff King <peff@peff.net>
Date
Jan 17, 2018, 20:55 UTC
Message-ID
<20180117205509.GA14828@sigill.intra.peff.net>
In-Reply-To
<20180117184828.31816-1-hch@lst.de>
On Wed, Jan 17, 2018 at 07:48:28PM +0100, Christoph Hellwig wrote:
Show 9 quoted lines
> fsync is required for data integrity as there is no gurantee that
> data makes it to disk at any specified time without it.  Even for
> ext3 with data=ordered mode the file system will only commit all
> data at some point in time that is not guaranteed.
> 
> I've lost data on development machines with various times countless
> times due to the lack of this option, and now lost trees on a
> git server with ext4 as well yesterday.  It's time to make git
> safe by default.

I'm definitely sympathetic, and I've contemplated a patch like this a few times. But I'm not sure we're "safe by default" here after this patch. In particular:

  1. This covers only loose objects. We generally sync pack writes
     already, so we're covered there. But we do not sync ref updates at
     all, which we'd probably want to in a default-safe setup (a common
     post-crash symptom I've seen is zero-length ref files).
  2. Is it sufficient to fsync() the individual file's descriptors?
     We often do other filesystem operations (like hardlinking or
     renaming) that also need to be committed to disk before an
     operation can be considered saved.
  3. Related to (2), we often care about the order of metadata commits.
     E.g., a common sequence is:
       a. Write object contents to tempfile.
       b. rename() or hardlink tempfile to final name.
       c. Write object name into ref.lock file.
       d. rename() ref.lock to ref
     If we see (d) but not (b), then the result is a corrupted
     repository. Is this guaranteed by ext4 journaling with
     data=ordered?

It may be that data=ordered gets us what we need for (2) and (3). But I think at the very least we should consider fsyncing ref updates based on a config option, too.

-Peff
Previous: Junio C HamanoNext: Christoph Hellwig
Message 51 of 52 in “enable core.fsyncObjectFiles by default”
  1. enable core.fsyncObjectFiles by defaultChristoph Hellwig, Jan 17, 2018
  2. Junio C HamanoJan 17, 2018
  3. Christoph HellwigJan 17, 2018
  4. Andreas SchwabJan 17, 2018
  5. Matthew WilcoxJan 17, 2018
  6. Christoph HellwigJan 17, 2018
  7. Ævar Arnfjörð BjarmasonJan 17, 2018
  8. Linus TorvaldsJan 17, 2018
  9. Linus TorvaldsJan 17, 2018
  10. Ævar Arnfjörð BjarmasonJan 17, 2018
  11. Linus TorvaldsJan 17, 2018
  12. Theodore Ts'oJan 17, 2018
  13. Linus TorvaldsJan 17, 2018
  14. Christoph HellwigJan 18, 2018
  15. Junio C HamanoJan 19, 2018
  16. Theodore Ts'oJan 20, 2018
  17. Junio C HamanoJan 20, 2018
  18. Ævar Arnfjörð BjarmasonJan 22, 2018
  19. Theodore Ts'oJan 22, 2018
  20. Jeff KingJan 23, 2018
  21. Theodore Ts'oJan 23, 2018
  22. Jeff KingJan 23, 2018
  23. Jeff KingJan 23, 2018
  24. Chris MasonJan 21, 2018
  25. Ævar Arnfjörð BjarmasonSep 17, 2020
  26. 2/2 core.fsyncObjectFiles: make the docs less flippantÆvar Arnfjörð Bjarmason, Sep 17, 2020
  27. Junio C HamanoSep 17, 2020
  28. Johannes SixtSep 17, 2020
  29. Johannes SchindelinOct 8, 2020
  30. Ævar Arnfjörð BjarmasonOct 8, 2020
  31. Junio C HamanoOct 8, 2020
  32. Johannes SchindelinOct 9, 2020
  33. Christoph HellwigSep 17, 2020
  34. Marc BranchaudSep 17, 2020
  35. 0/2 should core.fsyncObjectFiles fsync the dir entry + docsÆvar Arnfjörð Bjarmason, Sep 17, 2020
  36. 1/2 sha1-file: fsync() loose dir entry when core.fsyncObjectFilesÆvar Arnfjörð Bjarmason, Sep 17, 2020
  37. Jeff KingSep 17, 2020
  38. Christoph HellwigSep 17, 2020
  39. Christoph HellwigSep 17, 2020
  40. Jeff KingSep 17, 2020
  41. Christoph HellwigSep 17, 2020
  42. Junio C HamanoSep 17, 2020
  43. Jeff KingSep 17, 2020
  44. Taylor BlauSep 17, 2020
  45. Ævar Arnfjörð BjarmasonSep 22, 2020
  46. Johannes SixtSep 17, 2020
  47. Ævar Arnfjörð BjarmasonSep 22, 2020
  48. Johannes SchindelinNov 19, 2020
  49. Christoph HellwigSep 17, 2020
  50. Junio C HamanoSep 17, 2020
  51. Jeff KingJan 17, 2018
  52. Christoph HellwigJan 17, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.