git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH v2 7/7] fsync docs: add new fsyncMethod.batch.quarantine, elaborate on old

From
NSNeeraj Singh <nksingh85@gmail.com>
Date
Mar 23, 2022, 21:08 UTC
Message-ID
<CANQDOdcFN5GgOPZ3hqCsjHDTiRfRpqoAKxjF1n9D6S8oD9--_A@mail.gmail.com>
In-Reply-To
<RFC-patch-v2-7.7-a5951366c6e-20220323T140753Z-avarab@gmail.com>

On Wed, Mar 23, 2022 at 7:18 AM Ævar Arnfjörð Bjarmason <avarab@gmail.com> wrote:

Show 74 quoted lines
>
> Add a new fsyncMethod.batch.quarantine setting which defaults to
> "false". Preceding (RFC, and not meant to flip-flop like that
> eventually) commits ripped out the "tmp-objdir" part of the
> core.fsyncMethod=batch.
>
> This documentation proposes to keep that as the default for the
> reasons discussed in it, while allowing users to set
> "fsyncMethod.batch.quarantine=true".
>
> Furthermore update the discussion of "core.fsyncObjectFiles" with
> information about what it *really* does, why you probably shouldn't
> use it, and how to safely emulate most of what it gave users in the
> past in terms of performance benefit.
>
> Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>
> ---
>  Documentation/config/core.txt | 80 +++++++++++++++++++++++++++++++----
>  1 file changed, 72 insertions(+), 8 deletions(-)
>
> diff --git a/Documentation/config/core.txt b/Documentation/config/core.txt
> index f598925b597..365a12dc7ae 100644
> --- a/Documentation/config/core.txt
> +++ b/Documentation/config/core.txt
> @@ -607,21 +607,85 @@ stored on NTFS or ReFS filesystems.
>  +
>  The `batch` is currently only applies to loose-object files and will
>  kick in when using the linkgit:git-unpack-objects[1] and
> -linkgit:update-index[1] commands. Note that the "last" file to be
> +linkgit:git-update-index[1] commands. Note that the "last" file to be
>  synced may be the last object, as in the case of
>  linkgit:git-unpack-objects[1], or relevant "index" (or in the future,
>  "ref") update, as in the case of linkgit:git-update-index[1]. I.e. the
>  batch syncing of the loose objects may be deferred until a subsequent
>  fsync() to a file that makes them "active".
>
> +fsyncMethod.batch.quarantine::
> +       A boolean which if set to `true` will cause "batched" writes
> +       to objects to be "quarantined" if
> +       `core.fsyncMethod=batch`. This is `false` by default.
> ++
> +The primary object of these fsync() settings is to protect against
> +repository corruption of things which are reachable, i.e. "reachable",
> +via references, the index etc. Not merely objects that were present in
> +the object store.
> ++
> +Historically setting `core.fsyncObjectFiles=false` assumed that on a
> +filesystem with where an fsync() would flush all preceding outstanding
> +I/O that we might end up with a corrupt loose object, but that was OK
> +as long as no reference referred to it. We'd eventually the corrupt
> +object with linkgit:git-gc[1], and linkgit:git-fsck[1] would only
> +report it as a minor annoyance
> ++
> +Setting `fsyncMethod.batch.quarantine=true` takes the view that
> +something like a corrupt *unreferenced* loose object in the object
> +store is something we'd like to avoid, at the cost of reduced
> +performance when using `core.fsyncMethod=batch`.
> ++
> +Currently this uses the same mechanism described in the "QUARANTINE
> +ENVIRONMENT" in the linkgit:git-receive-pack[1] documentation, but
> +that's subject to change. The performance loss is because we need to
> +"stage" the objects in that quarantine environment, fsync() it, and
> +once that's done rename() or link() it in-place into the main object
> +store, possibly with an fsync() of the index or ref at the end
> ++
> +With `fsyncMethod.batch.quarantine=false` we'll "stage" things in the
> +main object store, and then do one fsync() at the very end, either on
> +the last object we write, or file (index or ref) that'll make it
> +"reachable".
> ++
> +The bad thing about setting this to `true` is lost performance, as
> +well as not being able to access the objects as they're written (which
> +e.g. consumers of linkgit:git-update-index[1]'s `--verbose` mode might
> +want to do).

I wasn't able to understand clearly from your performance numbers. What did you measure as the additional cost from quarantine=true versus quarantine=false? Just if you have the numbers handy...

Show 47 quoted lines
> ++
> +The good thing is that you should be guaranteed not to get e.g. short
> +or otherwise corrupt loose objects if you pull your power cord, in
> +practice various git commands deal quite badly with discovering such a
> +stray corrupt object (including perhaps assuming it's valid based on
> +its existence, or hard dying on an error rather than replacing
> +it). Repairing such "unreachable corruption" can require manual
> +intervention.
> +
>  core.fsyncObjectFiles::
> -       This boolean will enable 'fsync()' when writing object files.
> -       This setting is deprecated. Use core.fsync instead.
> -+
> -This setting affects data added to the Git repository in loose-object
> -form. When set to true, Git will issue an fsync or similar system call
> -to flush caches so that loose-objects remain consistent in the face
> -of a unclean system shutdown.
> +       This boolean will enable 'fsync()' when writing loose object
> +       files.
> ++
> +This setting is the historical fsync configuration setting. It's now
> +*deprecated*, you should use `core.fsync` instead, perhaps in
> +combination with `core.fsyncMethod=batch`.
> ++
> +The `core.fsyncObjectFiles` was initially added based on integrity
> +assumptions that early (pre-ext-4) versions of Linux's "ext"
> +filesystems provided.
> ++
> +I.e. that a write of file A without an `fsync()` followed by a write
> +of file `B` with `fsync()` would implicitly guarantee that `A' would
> +be `fsync()`'d by calling `fsync()` on `B`. This asssumption is *not*
> +backed up by any standard (e.g. POSIX), but worked in practice on some
> +Linux setups.
> ++
> +Nowadays you should almost certainly want to use
> +`core.fsync=loose-object` instead in combination with
> +`core.fsyncMethod=bulk`, and possibly with
> +`fsyncMethod.batch.quarantine=true`, see above. On modern OS's (Linux,
> +OSX, Windows) that gives you most of the performance benefit of
> +`core.fsyncObjectFiles=false` with all of the safety of the old
> +`core.fsyncObjectFiles=true`.
>
>  core.preloadIndex::
>         Enable parallel index preload for operations like 'git diff'
> --
> 2.35.1.1428.g1c1a0152d61
>

I think the notion of minimizing fsyncs across the whole repository is a great one. However, your implementation isn't clean from an API perspective, since people modifying the top-level commands need to reason about the full set of operations to avoid silently breaking the fsync requirements. I think we should phrase this as a "transaction" that the top level command can begin and end. Subcomponents of the repo can "enlist" in the transaction and do the right thing optimally when the overall transaction commits or aborts.

In the end, I think the optimal solution should be layered on top of the final form of my current patch series as an incremental improvement. I'm going to start the rebranding of plug/unplug_bulk_checkin in V3 of the patch series.

Thanks, Neeraj LAST MAIL

Previous: Ævar Arnfjörð BjarmasonNext: Ævar Arnfjörð Bjarmason
Message 53 of 175 in “core.fsyncmethod: add 'batch' mode for faster fsyncing of multiple objects”
  1. 0/7 core.fsyncmethod: add 'batch' mode for faster fsyncing of multiple objectsNeeraj K. Singh via GitGitGadget, Mar 15, 2022
  2. 1/7 bulk-checkin: rename 'state' variable and separate 'plugged' booleanNeeraj Singh via GitGitGadget, Mar 15, 2022
  3. Junio C HamanoMar 16, 2022
  4. Neeraj SinghMar 16, 2022
  5. Junio C HamanoMar 16, 2022
  6. Neeraj SinghMar 16, 2022
  7. Junio C HamanoMar 16, 2022
  8. Neeraj SinghMar 16, 2022
  9. 2/7 core.fsyncmethod: batched disk flushes for loose-objectsNeeraj Singh via GitGitGadget, Mar 15, 2022
  10. Patrick SteinhardtMar 16, 2022
  11. Neeraj SinghMar 16, 2022
  12. Patrick SteinhardtMar 17, 2022
  13. Bagas SanjayaMar 16, 2022
  14. Neeraj SinghMar 16, 2022
  15. 4/7 unpack-objects: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 15, 2022
  16. 3/7 update-index: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 15, 2022
  17. 5/7 core.fsync: use batch mode and sync loose objects by default on WindowsNeeraj Singh via GitGitGadget, Mar 15, 2022
  18. 6/7 core.fsyncmethod: tests for batch modeNeeraj Singh via GitGitGadget, Mar 15, 2022
  19. 7/7 core.fsyncmethod: performance tests for add and stashNeeraj Singh via GitGitGadget, Mar 15, 2022
  20. 0/7 core.fsyncmethod: add 'batch' mode for faster fsyncing of multiple objectsNeeraj K. Singh via GitGitGadget, Mar 20, 2022
  21. 1/7 bulk-checkin: rename 'state' variable and separate 'plugged' booleanNeeraj Singh via GitGitGadget, Mar 20, 2022
  22. 2/7 core.fsyncmethod: batched disk flushes for loose-objectsNeeraj Singh via GitGitGadget, Mar 20, 2022
  23. Ævar Arnfjörð BjarmasonMar 21, 2022
  24. Neeraj SinghMar 21, 2022
  25. Ævar Arnfjörð BjarmasonMar 21, 2022
  26. Neeraj SinghMar 21, 2022
  27. Ævar Arnfjörð BjarmasonMar 21, 2022
  28. Neeraj SinghMar 22, 2022
  29. Ævar Arnfjörð BjarmasonMar 22, 2022
  30. Neeraj SinghMar 22, 2022
  31. 0/7 bottom-up ns/batched-fsync & "plugging" in object-file.cÆvar Arnfjörð Bjarmason, Mar 23, 2022
  32. 2/7 unpack-objects: add skeleton HASH_N_OBJECTS{,_{FIRST,LAST}} flagsÆvar Arnfjörð Bjarmason, Mar 23, 2022
  33. 1/7 write-or-die.c: remove unused fsync_component() functionÆvar Arnfjörð Bjarmason, Mar 23, 2022
  34. Neeraj SinghMar 23, 2022
  35. 4/7 update-index: use a utility function for stdin consumptionÆvar Arnfjörð Bjarmason, Mar 23, 2022
  36. 3/7 object-file: pass down unpack-objects.c flags for "bulk" checkinÆvar Arnfjörð Bjarmason, Mar 23, 2022
  37. 5/7 update-index: pass down an "oflags" argumentÆvar Arnfjörð Bjarmason, Mar 23, 2022
  38. 6/7 update-index: rename "buf" to "line"Ævar Arnfjörð Bjarmason, Mar 23, 2022
  39. 7/7 update-index: make use of HASH_N_OBJECTS{,_{FIRST,LAST}} flagsÆvar Arnfjörð Bjarmason, Mar 23, 2022
  40. Neeraj SinghMar 23, 2022
  41. Ævar Arnfjörð BjarmasonMar 23, 2022
  42. Neeraj SinghMar 23, 2022
  43. 0/7 bottom-up ns/batched-fsync & "plugging" in object-file.cÆvar Arnfjörð Bjarmason, Mar 23, 2022
  44. 1/7 unpack-objects: add skeleton HASH_N_OBJECTS{,_{FIRST,LAST}} flagsÆvar Arnfjörð Bjarmason, Mar 23, 2022
  45. Neeraj SinghMar 23, 2022
  46. 2/7 object-file: pass down unpack-objects.c flags for "bulk" checkinÆvar Arnfjörð Bjarmason, Mar 23, 2022
  47. Neeraj SinghMar 23, 2022
  48. 3/7 update-index: pass down skeleton "oflags" argumentÆvar Arnfjörð Bjarmason, Mar 23, 2022
  49. 4/7 update-index: have the index fsync() flush the loose objectsÆvar Arnfjörð Bjarmason, Mar 23, 2022
  50. Neeraj SinghMar 23, 2022
  51. 5/7 add: use WLI_NEED_LOOSE_FSYNC for new "only the index" bulk fsync()Ævar Arnfjörð Bjarmason, Mar 23, 2022
  52. 7/7 fsync docs: add new fsyncMethod.batch.quarantine, elaborate on oldÆvar Arnfjörð Bjarmason, Mar 23, 2022
  53. Neeraj SinghMar 23, 2022
  54. 6/7 fsync docs: update for new syncing semanticsÆvar Arnfjörð Bjarmason, Mar 23, 2022
  55. Junio C HamanoMar 21, 2022
  56. Neeraj SinghMar 21, 2022
  57. Ævar Arnfjörð BjarmasonMar 23, 2022
  58. Neeraj SinghMar 24, 2022
  59. 3/7 update-index: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 20, 2022
  60. Ævar Arnfjörð BjarmasonMar 21, 2022
  61. Neeraj SinghMar 21, 2022
  62. Ævar Arnfjörð BjarmasonMar 21, 2022
  63. Junio C HamanoMar 21, 2022
  64. Neeraj SinghMar 21, 2022
  65. 4/7 unpack-objects: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 20, 2022
  66. Junio C HamanoMar 21, 2022
  67. Neeraj SinghMar 21, 2022
  68. Neeraj SinghMar 22, 2022
  69. 7/7 core.fsyncmethod: performance tests for add and stashNeeraj Singh via GitGitGadget, Mar 20, 2022
  70. 5/7 core.fsync: use batch mode and sync loose objects by default on WindowsNeeraj Singh via GitGitGadget, Mar 20, 2022
  71. 6/7 core.fsyncmethod: tests for batch modeNeeraj Singh via GitGitGadget, Mar 20, 2022
  72. Junio C HamanoMar 21, 2022
  73. Neeraj SinghMar 22, 2022
  74. Junio C HamanoMar 21, 2022
  75. Neeraj SinghMar 21, 2022
  76. Junio C HamanoMar 21, 2022
  77. 00/11 core.fsyncmethod: add 'batch' mode for faster fsyncing of multiple objectsNeeraj K. Singh via GitGitGadget, Mar 24, 2022
  78. 01/11 bulk-checkin: rebrand plug/unplug APIs as 'odb transactions'Neeraj Singh via GitGitGadget, Mar 24, 2022
  79. Ævar Arnfjörð BjarmasonMar 24, 2022
  80. Neeraj SinghMar 24, 2022
  81. 02/11 bulk-checkin: rename 'state' variable and separate 'plugged' booleanNeeraj Singh via GitGitGadget, Mar 24, 2022
  82. 03/11 object-file: pass filename to fsync_or_dieNeeraj Singh via GitGitGadget, Mar 24, 2022
  83. 04/11 core.fsyncmethod: batched disk flushes for loose-objectsNeeraj Singh via GitGitGadget, Mar 24, 2022
  84. 05/11 update-index: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 24, 2022
  85. Junio C HamanoMar 24, 2022
  86. Neeraj SinghMar 24, 2022
  87. Junio C HamanoMar 24, 2022
  88. Neeraj SinghMar 24, 2022
  89. 06/11 unpack-objects: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 24, 2022
  90. 07/11 core.fsync: use batch mode and sync loose objects by default on WindowsNeeraj Singh via GitGitGadget, Mar 24, 2022
  91. 08/11 test-lib-functions: add parsing helpers for ls-files and ls-treeNeeraj Singh via GitGitGadget, Mar 24, 2022
  92. 10/11 core.fsyncmethod: performance tests for add and stashNeeraj Singh via GitGitGadget, Mar 24, 2022
  93. 11/11 core.fsyncmethod: correctly camel-case warning messageNeeraj Singh via GitGitGadget, Mar 24, 2022
  94. 09/11 core.fsyncmethod: tests for batch modeNeeraj Singh via GitGitGadget, Mar 24, 2022
  95. Ævar Arnfjörð BjarmasonMar 24, 2022
  96. Neeraj SinghMar 24, 2022
  97. Ævar Arnfjörð BjarmasonMar 26, 2022
  98. Junio C HamanoMar 24, 2022
  99. Neeraj SinghMar 24, 2022
  100. 00/13 core.fsyncmethod: add 'batch' mode for faster fsyncing of multiple objectsNeeraj K. Singh via GitGitGadget, Mar 29, 2022
  101. 01/13 bulk-checkin: rename 'state' variable and separate 'plugged' booleanNeeraj Singh via GitGitGadget, Mar 29, 2022
  102. 02/13 bulk-checkin: rebrand plug/unplug APIs as 'odb transactions'Neeraj Singh via GitGitGadget, Mar 29, 2022
  103. 03/13 object-file: pass filename to fsync_or_dieNeeraj Singh via GitGitGadget, Mar 29, 2022
  104. 04/13 core.fsyncmethod: batched disk flushes for loose-objectsNeeraj Singh via GitGitGadget, Mar 29, 2022
  105. 05/13 cache-tree: use ODB transaction around writing a treeNeeraj Singh via GitGitGadget, Mar 29, 2022
  106. 06/13 update-index: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 29, 2022
  107. 07/13 unpack-objects: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 29, 2022
  108. 08/13 core.fsync: use batch mode and sync loose objects by default on WindowsNeeraj Singh via GitGitGadget, Mar 29, 2022
  109. 12/13 core.fsyncmethod: performance tests for add and stashNeeraj Singh via GitGitGadget, Mar 29, 2022
  110. Neeraj SinghMar 29, 2022
  111. 10/13 core.fsyncmethod: tests for batch modeNeeraj Singh via GitGitGadget, Mar 29, 2022
  112. 13/13 core.fsyncmethod: correctly camel-case warning messageNeeraj Singh via GitGitGadget, Mar 29, 2022
  113. 11/13 t/perf: add iteration setup mechanism to perf-libNeeraj Singh via GitGitGadget, Mar 29, 2022
  114. Neeraj SinghMar 29, 2022
  115. Junio C HamanoMar 29, 2022
  116. 09/13 test-lib-functions: add parsing helpers for ls-files and ls-treeNeeraj Singh via GitGitGadget, Mar 29, 2022
  117. Ævar Arnfjörð BjarmasonMar 29, 2022
  118. Neeraj SinghMar 29, 2022
  119. Ævar Arnfjörð BjarmasonMar 29, 2022
  120. Neeraj SinghMar 29, 2022
  121. 00/14 core.fsyncmethod: add 'batch' mode for faster fsyncing of multiple objectsNeeraj K. Singh via GitGitGadget, Mar 30, 2022
  122. 02/14 bulk-checkin: rebrand plug/unplug APIs as 'odb transactions'Neeraj Singh via GitGitGadget, Mar 30, 2022
  123. Junio C HamanoMar 30, 2022
  124. Neeraj SinghMar 31, 2022
  125. 01/14 bulk-checkin: rename 'state' variable and separate 'plugged' booleanNeeraj Singh via GitGitGadget, Mar 30, 2022
  126. Junio C HamanoMar 30, 2022
  127. Neeraj SinghMar 30, 2022
  128. Junio C HamanoMar 30, 2022
  129. Neeraj SinghMar 31, 2022
  130. Junio C HamanoMar 31, 2022
  131. Neeraj SinghMar 31, 2022
  132. 03/14 object-file: pass filename to fsync_or_dieNeeraj Singh via GitGitGadget, Mar 30, 2022
  133. Junio C HamanoMar 30, 2022
  134. Neeraj SinghMar 30, 2022
  135. 04/14 core.fsyncmethod: batched disk flushes for loose-objectsNeeraj Singh via GitGitGadget, Mar 30, 2022
  136. Junio C HamanoMar 30, 2022
  137. Neeraj SinghMar 31, 2022
  138. Junio C HamanoMar 31, 2022
  139. Neeraj SinghMar 31, 2022
  140. Junio C HamanoApr 1, 2022
  141. 05/14 cache-tree: use ODB transaction around writing a treeNeeraj Singh via GitGitGadget, Mar 30, 2022
  142. Junio C HamanoMar 30, 2022
  143. Neeraj SinghMar 30, 2022
  144. 07/14 update-index: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 30, 2022
  145. Junio C HamanoMar 30, 2022
  146. Neeraj SinghMar 30, 2022
  147. 09/14 core.fsync: use batch mode and sync loose objects by default on WindowsNeeraj Singh via GitGitGadget, Mar 30, 2022
  148. 10/14 test-lib-functions: add parsing helpers for ls-files and ls-treeNeeraj Singh via GitGitGadget, Mar 30, 2022
  149. 08/14 unpack-objects: use the bulk-checkin infrastructureNeeraj Singh via GitGitGadget, Mar 30, 2022
  150. 06/14 builtin/add: add ODB transaction around add_files_to_cacheNeeraj Singh via GitGitGadget, Mar 30, 2022
  151. Junio C HamanoMar 30, 2022
  152. 11/14 core.fsyncmethod: tests for batch modeNeeraj Singh via GitGitGadget, Mar 30, 2022
  153. Junio C HamanoMar 30, 2022
  154. Neeraj SinghMar 31, 2022
  155. 12/14 t/perf: add iteration setup mechanism to perf-libNeeraj Singh via GitGitGadget, Mar 30, 2022
  156. 13/14 core.fsyncmethod: performance tests for batch modeNeeraj Singh via GitGitGadget, Mar 30, 2022
  157. Neeraj SinghMar 31, 2022
  158. 14/14 core.fsyncmethod: correctly camel-case warning messageNeeraj Singh via GitGitGadget, Mar 30, 2022
  159. 01/12 bulk-checkin: rename 'state' variable and separate 'plugged' booleannksingh85@gmail.com, Apr 5, 2022
  160. 00/12 core.fsyncmethod: add 'batch' mode for faster fsyncing of multiple objectsnksingh85@gmail.com, Apr 5, 2022
  161. Junio C HamanoApr 6, 2022
  162. Junio C HamanoMay 19, 2022
  163. Neeraj SinghMay 19, 2022
  164. Johannes SchindelinMay 24, 2022
  165. 04/12 cache-tree: use ODB transaction around writing a treenksingh85@gmail.com, Apr 5, 2022
  166. 10/12 core.fsyncmethod: tests for batch modenksingh85@gmail.com, Apr 5, 2022
  167. 12/12 core.fsyncmethod: performance tests for batch modenksingh85@gmail.com, Apr 5, 2022
  168. 11/12 t/perf: add iteration setup mechanism to perf-libnksingh85@gmail.com, Apr 5, 2022
  169. 09/12 test-lib-functions: add parsing helpers for ls-files and ls-treenksingh85@gmail.com, Apr 5, 2022
  170. 07/12 unpack-objects: use the bulk-checkin infrastructurenksingh85@gmail.com, Apr 5, 2022
  171. 05/12 builtin/add: add ODB transaction around add_files_to_cachenksingh85@gmail.com, Apr 5, 2022
  172. 08/12 core.fsync: use batch mode and sync loose objects by default on Windowsnksingh85@gmail.com, Apr 5, 2022
  173. 02/12 bulk-checkin: rebrand plug/unplug APIs as 'odb transactions'nksingh85@gmail.com, Apr 5, 2022
  174. 03/12 core.fsyncmethod: batched disk flushes for loose-objectsnksingh85@gmail.com, Apr 5, 2022
  175. 06/12 update-index: use the bulk-checkin infrastructurenksingh85@gmail.com, Apr 5, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.