mirror of
https://github.com/rustfs/rustfs.git
synced 2026-07-27 08:38:58 +00:00
c77c5f047a
complete_multipart_upload deleted every part.N.meta via cleanup_multipart_path *before* the authoritative rename_data commit. If rename_data then failed write quorum, the upload directory was left with data files but no part metadata, so a retried CompleteMultipartUpload could never read the parts again and the upload became permanently uncompletable (client must abort and re-upload all parts). Move cleanup_multipart_path to run only after rename_data returns Ok, matching the existing "clean up only after commit" pattern already used for the old data-dir GC and the upload-dir delete_all. On a failed commit the staging part.N.meta now survive so the retry can complete. Add a hermetic regression test that forces rename_data to fail on every disk (destination bucket dir made read-only) and asserts the staging part.N.meta are preserved for retry. Fixes #946. Co-authored-by: heihutu <heihutu@gmail.com>