mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-06 13:27:43 +00:00
85fd824581
* feat(object-data-cache): close write/delete-side invalidation gaps The object data cache exposed only a single per-(bucket,object) invalidation primitive and no write-side ecstore hook, so several delete paths left dead bodies resident until TTL (hygiene/capacity, not stale-serving: lookups follow a fresh metadata quorum and cannot serve a gone object). This adds the missing primitives and wires them in. ODC-26 (backlog#1131): add an `ObjectMutationHook` trait beside the GET body hook, registered next to it at startup, and call it from the ecstore-internal delete paths (`apply_expiry_on_non_transitioned_objects`, `expire_transitioned_object` including the restored-copy branch, and `delete_object_versions`). The app impl is one `invalidate_object` call under a new `AfterLifecycleExpiry` reason. ODC-27 (backlog#1132): force prefix delete now invalidates the whole prefix, not just the prefix string. `store.delete_object(delete_prefix)` returns no deleted-name list, so this uses a new prefix primitive rather than the batch path. ODC-28 (backlog#1133): DeleteBucket now flushes the bucket via a new bucket-scope primitive (covers force and non-force, which share the delete_bucket call). ODC-C2 (backlog#1143): add `ObjectDataCache::clear()` and two admin handlers (GET stats, POST flush) routed through admin runtime_sources. The starshard identity index gains a single `remove_matching` full-scan API backing prefix/bucket/clear; it is documented as admin/delete-path only and never runs on the GET or fill hot path. New invalidation reasons and metric labels added; outcome (removed/noop) labelling kept correct for every new primitive. Also fixes a pre-existing broken intra-doc link in memory.rs. Co-Authored-By: heihutu <heihutu@gmail.com> * refactor(ecstore): extract the shared HookSlot behind both cache hooks This PR introduced object_mutation_hook.rs by mirroring body_cache_hook.rs, which left two process-global registration slots whose register/get/clear bodies were line-for-line identical except the trait type and the WARN string: a RwLock<Option<Arc<dyn _>>>, an Arc::ptr_eq "different instance" warning, the poison-recovery closure, and the same read-lock-and-clone read. Two copies of the same swap-vs-warn logic can drift apart under maintenance. Hoist it into a generic HookSlot<T: ?Sized> that owns the logic once. Each hook module keeps its `static HOOK: HookSlot<dyn XxxHook>` and its thin, unchanged public wrappers (register_/get_/clear_), so the crate's public surface and every call site are untouched — this is an internal consolidation, not a contract change. The load-bearing #1126 guarantee (newest registration wins, so a rebuilt AppContext is never stranded on a first-wins slot) previously had no direct test — the hook tests only covered register-then-notify. HookSlot now has its own unit tests including re_registration_swaps_to_the_latest_instance; mutation-testing confirms a first-wins regression fails exactly that test. No behavior change: the two hooks' existing tests, the P0 body_cache_hook_e2e regressions, and the app-layer mutation-hook tests all pass unchanged. Refs: backlog#1126, backlog#1131 Co-Authored-By: heihutu <heihutu@gmail.com> * fix(admin): register the object-data-cache routes in the policy inventory This PR added GET /object-data-cache/stats and POST /object-data-cache/flush but did not list them in the two registries that must account for every admin route: the route-policy inventory (route_policy.rs) and the route matrix (route_registration_test.rs). Their coverage tests — route_policy_inventory_covers_registered_routes and test_admin_route_matrix_matches_registered_routes — failed on CI because a registered route had no policy/matrix entry. These two tests are not part of `make pre-commit` (which runs fmt + arch + quick-check, not the full suite), so the gap passed local pre-commit and only surfaced in the CI Test-and-Lint lane. stats is a read (ServerInfoAdminAction, Sensitive); flush mutates (ConfigUpdateAdminAction, High) — matching the actions the handlers already enforce. The MinIO-alias matrix test is unaffected: these are native rustfs endpoints with no MinIO equivalent. Refs: backlog#1143 Co-Authored-By: heihutu <heihutu@gmail.com> --------- Co-authored-by: heihutu <heihutu@gmail.com>
76 lines
3.5 KiB
Rust
76 lines
3.5 KiB
Rust
// Copyright 2024 RustFS Team
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
//! Hook that lets the application layer serve a GET body from its object data
|
|
//! cache after metadata resolution but before the erasure data read.
|
|
//!
|
|
//! The cache itself lives above ecstore (it needs app-level config, metrics
|
|
//! and invalidation), but the lookup must happen inside `get_object_reader`:
|
|
//! probing earlier would require a second metadata fan-out, and probing later
|
|
//! (after the reader is built) means a hit no longer saves any disk I/O.
|
|
|
|
use crate::object_api::ObjectInfo;
|
|
use crate::object_api::hook_slot::HookSlot;
|
|
use bytes::Bytes;
|
|
use std::sync::Arc;
|
|
|
|
/// Serves full-object GET bodies from a cache keyed by object identity.
|
|
///
|
|
/// Implementations must validate identity (etag/version/size) against the
|
|
/// provided `ObjectInfo`, which reflects the just-resolved metadata quorum,
|
|
/// and must return `None` for anything they cannot serve byte-identically
|
|
/// (encrypted objects, remote/transitioned objects, size mismatches, ...).
|
|
#[async_trait::async_trait]
|
|
pub trait GetObjectBodyCacheHook: Send + Sync + 'static {
|
|
async fn lookup(&self, bucket: &str, object: &str, info: &ObjectInfo) -> Option<Bytes>;
|
|
}
|
|
|
|
// A `HookSlot` (RwLock<Option<Arc<dyn ...>>>) rather than `ArcSwapOption`:
|
|
// arc-swap's `RefCnt` is implemented only for the sized `Arc<T>` (it stores a
|
|
// thin `*mut T`), so it cannot hold an `Arc<dyn GetObjectBodyCacheHook>`
|
|
// without a sized newtype wrapper. The probe reads this slot once per
|
|
// full-object GET, but the read guard only clones an `Arc`, which is negligible
|
|
// next to the metadata quorum fan-out already completed before the probe.
|
|
// Registration is a startup / config-reload event, so writer contention is a
|
|
// non-issue.
|
|
static GET_OBJECT_BODY_CACHE_HOOK: HookSlot<dyn GetObjectBodyCacheHook> = HookSlot::new();
|
|
|
|
/// Register (or re-register) the process-wide GET body cache hook.
|
|
///
|
|
/// Re-registration atomically swaps to `hook`, so a rebuilt `AppContext`
|
|
/// (config reload, or the test re-init pattern) leaves ecstore's GET probe
|
|
/// pointed at the newest adapter. A first-wins slot would instead pin the probe
|
|
/// to the original adapter while every usecase-layer fill and invalidation
|
|
/// targeted the replacement, silently degrading the feature to a 0% hit rate
|
|
/// and stranding entries in the unreachable cache until their TTL (backlog#1126).
|
|
pub fn register_get_object_body_cache_hook(hook: Arc<dyn GetObjectBodyCacheHook>) {
|
|
GET_OBJECT_BODY_CACHE_HOOK.register(
|
|
hook,
|
|
"GET object body cache hook re-registered with a different instance; \
|
|
the previous adapter's cache is now unreachable by ecstore's GET probe",
|
|
);
|
|
}
|
|
|
|
/// The registered hook, if any.
|
|
pub(crate) fn get_object_body_cache_hook() -> Option<Arc<dyn GetObjectBodyCacheHook>> {
|
|
GET_OBJECT_BODY_CACHE_HOOK.get()
|
|
}
|
|
|
|
/// Test-only: unregister the hook so tests can register and clear the slot
|
|
/// deterministically without leaking a hook into unrelated tests.
|
|
#[cfg(test)]
|
|
pub(crate) fn clear_get_object_body_cache_hook() {
|
|
GET_OBJECT_BODY_CACHE_HOOK.clear();
|
|
}
|