repository.py 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602
  1. from configparser import RawConfigParser
  2. from binascii import hexlify
  3. from itertools import islice
  4. import errno
  5. import os
  6. import shutil
  7. import struct
  8. import sys
  9. from zlib import crc32
  10. from .hashindex import NSIndex
  11. from .helpers import Error, IntegrityError, read_msgpack, write_msgpack, unhexlify, UpgradableLock
  12. from .lrucache import LRUCache
  13. MAX_OBJECT_SIZE = 20 * 1024 * 1024
  14. MAGIC = b'BORG_SEG'
  15. TAG_PUT = 0
  16. TAG_DELETE = 1
  17. TAG_COMMIT = 2
  18. class Repository:
  19. """Filesystem based transactional key value store
  20. On disk layout:
  21. dir/README
  22. dir/config
  23. dir/data/<X / SEGMENTS_PER_DIR>/<X>
  24. dir/index.X
  25. dir/hints.X
  26. """
  27. DEFAULT_MAX_SEGMENT_SIZE = 5 * 1024 * 1024
  28. DEFAULT_SEGMENTS_PER_DIR = 10000
  29. class DoesNotExist(Error):
  30. """Repository {} does not exist."""
  31. class AlreadyExists(Error):
  32. """Repository {} already exists."""
  33. class InvalidRepository(Error):
  34. """{} is not a valid repository."""
  35. class CheckNeeded(Error):
  36. """Inconsistency detected. Please run "borg check {}"."""
  37. class ObjectNotFound(Error):
  38. """Object with key {} not found in repository {}."""
  39. def __init__(self, path, create=False, exclusive=False):
  40. self.path = path
  41. self.io = None
  42. self.lock = None
  43. self.index = None
  44. self._active_txn = False
  45. if create:
  46. self.create(path)
  47. self.open(path, exclusive)
  48. def __del__(self):
  49. self.close()
  50. def create(self, path):
  51. """Create a new empty repository at `path`
  52. """
  53. if os.path.exists(path) and (not os.path.isdir(path) or os.listdir(path)):
  54. raise self.AlreadyExists(path)
  55. if not os.path.exists(path):
  56. os.mkdir(path)
  57. with open(os.path.join(path, 'README'), 'w') as fd:
  58. fd.write('This is a Borg repository\n')
  59. os.mkdir(os.path.join(path, 'data'))
  60. config = RawConfigParser()
  61. config.add_section('repository')
  62. config.set('repository', 'version', '1')
  63. config.set('repository', 'segments_per_dir', self.DEFAULT_SEGMENTS_PER_DIR)
  64. config.set('repository', 'max_segment_size', self.DEFAULT_MAX_SEGMENT_SIZE)
  65. config.set('repository', 'id', hexlify(os.urandom(32)).decode('ascii'))
  66. with open(os.path.join(path, 'config'), 'w') as fd:
  67. config.write(fd)
  68. def destroy(self):
  69. """Destroy the repository at `self.path`
  70. """
  71. self.close()
  72. os.remove(os.path.join(self.path, 'config')) # kill config first
  73. shutil.rmtree(self.path)
  74. def get_index_transaction_id(self):
  75. indices = sorted((int(name[6:]) for name in os.listdir(self.path) if name.startswith('index.') and name[6:].isdigit()))
  76. if indices:
  77. return indices[-1]
  78. else:
  79. return None
  80. def get_transaction_id(self):
  81. index_transaction_id = self.get_index_transaction_id()
  82. segments_transaction_id = self.io.get_segments_transaction_id()
  83. if index_transaction_id is not None and segments_transaction_id is None:
  84. raise self.CheckNeeded(self.path)
  85. # Attempt to automatically rebuild index if we crashed between commit
  86. # tag write and index save
  87. if index_transaction_id != segments_transaction_id:
  88. if index_transaction_id is not None and index_transaction_id > segments_transaction_id:
  89. replay_from = None
  90. else:
  91. replay_from = index_transaction_id
  92. self.replay_segments(replay_from, segments_transaction_id)
  93. return self.get_index_transaction_id()
  94. def open(self, path, exclusive):
  95. self.path = path
  96. if not os.path.isdir(path):
  97. raise self.DoesNotExist(path)
  98. self.config = RawConfigParser()
  99. self.config.read(os.path.join(self.path, 'config'))
  100. if 'repository' not in self.config.sections() or self.config.getint('repository', 'version') != 1:
  101. raise self.InvalidRepository(path)
  102. self.lock = UpgradableLock(os.path.join(path, 'config'), exclusive)
  103. self.max_segment_size = self.config.getint('repository', 'max_segment_size')
  104. self.segments_per_dir = self.config.getint('repository', 'segments_per_dir')
  105. self.id = unhexlify(self.config.get('repository', 'id').strip())
  106. self.io = LoggedIO(self.path, self.max_segment_size, self.segments_per_dir)
  107. def close(self):
  108. if self.lock:
  109. if self.io:
  110. self.io.close()
  111. self.io = None
  112. self.lock.release()
  113. self.lock = None
  114. def commit(self):
  115. """Commit transaction
  116. """
  117. self.io.write_commit()
  118. self.compact_segments()
  119. self.write_index()
  120. self.rollback()
  121. def open_index(self, transaction_id):
  122. if transaction_id is None:
  123. return NSIndex()
  124. return NSIndex.read((os.path.join(self.path, 'index.%d') % transaction_id).encode('utf-8'))
  125. def prepare_txn(self, transaction_id, do_cleanup=True):
  126. self._active_txn = True
  127. try:
  128. self.lock.upgrade()
  129. except UpgradableLock.WriteLockFailed:
  130. # if upgrading the lock to exclusive fails, we do not have an
  131. # active transaction. this is important for "serve" mode, where
  132. # the repository instance lives on - even if exceptions happened.
  133. self._active_txn = False
  134. raise
  135. if not self.index:
  136. self.index = self.open_index(transaction_id)
  137. if transaction_id is None:
  138. self.segments = {}
  139. self.compact = set()
  140. else:
  141. if do_cleanup:
  142. self.io.cleanup(transaction_id)
  143. hints = read_msgpack(os.path.join(self.path, 'hints.%d' % transaction_id))
  144. if hints[b'version'] != 1:
  145. raise ValueError('Unknown hints file version: %d' % hints['version'])
  146. self.segments = hints[b'segments']
  147. self.compact = set(hints[b'compact'])
  148. def write_index(self):
  149. hints = {b'version': 1,
  150. b'segments': self.segments,
  151. b'compact': list(self.compact)}
  152. transaction_id = self.io.get_segments_transaction_id()
  153. write_msgpack(os.path.join(self.path, 'hints.%d' % transaction_id), hints)
  154. self.index.write(os.path.join(self.path, 'index.tmp'))
  155. os.rename(os.path.join(self.path, 'index.tmp'),
  156. os.path.join(self.path, 'index.%d' % transaction_id))
  157. # Remove old indices
  158. current = '.%d' % transaction_id
  159. for name in os.listdir(self.path):
  160. if not name.startswith('index.') and not name.startswith('hints.'):
  161. continue
  162. if name.endswith(current):
  163. continue
  164. os.unlink(os.path.join(self.path, name))
  165. self.index = None
  166. def compact_segments(self):
  167. """Compact sparse segments by copying data into new segments
  168. """
  169. if not self.compact:
  170. return
  171. index_transaction_id = self.get_index_transaction_id()
  172. segments = self.segments
  173. for segment in sorted(self.compact):
  174. if self.io.segment_exists(segment):
  175. for tag, key, offset, data in self.io.iter_objects(segment, include_data=True):
  176. if tag == TAG_PUT and self.index.get(key, (-1, -1)) == (segment, offset):
  177. new_segment, offset = self.io.write_put(key, data)
  178. self.index[key] = new_segment, offset
  179. segments.setdefault(new_segment, 0)
  180. segments[new_segment] += 1
  181. segments[segment] -= 1
  182. elif tag == TAG_DELETE:
  183. if index_transaction_id is None or segment > index_transaction_id:
  184. self.io.write_delete(key)
  185. assert segments[segment] == 0
  186. self.io.write_commit()
  187. for segment in sorted(self.compact):
  188. assert self.segments.pop(segment) == 0
  189. self.io.delete_segment(segment)
  190. self.compact = set()
  191. def replay_segments(self, index_transaction_id, segments_transaction_id):
  192. self.prepare_txn(index_transaction_id, do_cleanup=False)
  193. for segment, filename in self.io.segment_iterator():
  194. if index_transaction_id is not None and segment <= index_transaction_id:
  195. continue
  196. if segment > segments_transaction_id:
  197. break
  198. self.segments[segment] = 0
  199. for tag, key, offset in self.io.iter_objects(segment):
  200. if tag == TAG_PUT:
  201. try:
  202. s, _ = self.index[key]
  203. self.compact.add(s)
  204. self.segments[s] -= 1
  205. except KeyError:
  206. pass
  207. self.index[key] = segment, offset
  208. self.segments[segment] += 1
  209. elif tag == TAG_DELETE:
  210. try:
  211. s, _ = self.index.pop(key)
  212. self.segments[s] -= 1
  213. self.compact.add(s)
  214. except KeyError:
  215. pass
  216. self.compact.add(segment)
  217. elif tag == TAG_COMMIT:
  218. continue
  219. else:
  220. raise self.CheckNeeded(self.path)
  221. if self.segments[segment] == 0:
  222. self.compact.add(segment)
  223. self.write_index()
  224. self.rollback()
  225. def check(self, repair=False):
  226. """Check repository consistency
  227. This method verifies all segment checksums and makes sure
  228. the index is consistent with the data stored in the segments.
  229. """
  230. error_found = False
  231. def report_error(msg):
  232. nonlocal error_found
  233. error_found = True
  234. print(msg, file=sys.stderr)
  235. assert not self._active_txn
  236. try:
  237. transaction_id = self.get_transaction_id()
  238. current_index = self.open_index(transaction_id)
  239. except Exception:
  240. transaction_id = self.io.get_segments_transaction_id()
  241. current_index = None
  242. if transaction_id is None:
  243. transaction_id = self.get_index_transaction_id()
  244. if transaction_id is None:
  245. transaction_id = self.io.get_latest_segment()
  246. if repair:
  247. self.io.cleanup(transaction_id)
  248. segments_transaction_id = self.io.get_segments_transaction_id()
  249. self.prepare_txn(None)
  250. for segment, filename in self.io.segment_iterator():
  251. if segment > transaction_id:
  252. continue
  253. try:
  254. objects = list(self.io.iter_objects(segment))
  255. except (IntegrityError, struct.error):
  256. report_error('Error reading segment {}'.format(segment))
  257. objects = []
  258. if repair:
  259. self.io.recover_segment(segment, filename)
  260. objects = list(self.io.iter_objects(segment))
  261. self.segments[segment] = 0
  262. for tag, key, offset in objects:
  263. if tag == TAG_PUT:
  264. try:
  265. s, _ = self.index[key]
  266. self.compact.add(s)
  267. self.segments[s] -= 1
  268. except KeyError:
  269. pass
  270. self.index[key] = segment, offset
  271. self.segments[segment] += 1
  272. elif tag == TAG_DELETE:
  273. try:
  274. s, _ = self.index.pop(key)
  275. self.segments[s] -= 1
  276. self.compact.add(s)
  277. except KeyError:
  278. pass
  279. self.compact.add(segment)
  280. elif tag == TAG_COMMIT:
  281. continue
  282. else:
  283. report_error('Unexpected tag {} in segment {}'.format(tag, segment))
  284. # We might need to add a commit tag if no committed segment is found
  285. if repair and segments_transaction_id is None:
  286. report_error('Adding commit tag to segment {}'.format(transaction_id))
  287. self.io.segment = transaction_id + 1
  288. self.io.write_commit()
  289. self.io.close_segment()
  290. if current_index and not repair:
  291. if len(current_index) != len(self.index):
  292. report_error('Index object count mismatch. {} != {}'.format(len(current_index), len(self.index)))
  293. elif current_index:
  294. for key, value in self.index.iteritems():
  295. if current_index.get(key, (-1, -1)) != value:
  296. report_error('Index mismatch for key {}. {} != {}'.format(key, value, current_index.get(key, (-1, -1))))
  297. if repair:
  298. self.compact_segments()
  299. self.write_index()
  300. self.rollback()
  301. return not error_found or repair
  302. def rollback(self):
  303. """
  304. """
  305. self.index = None
  306. self._active_txn = False
  307. def __len__(self):
  308. if not self.index:
  309. self.index = self.open_index(self.get_transaction_id())
  310. return len(self.index)
  311. def list(self, limit=None, marker=None):
  312. if not self.index:
  313. self.index = self.open_index(self.get_transaction_id())
  314. return [id_ for id_, _ in islice(self.index.iteritems(marker=marker), limit)]
  315. def get(self, id_):
  316. if not self.index:
  317. self.index = self.open_index(self.get_transaction_id())
  318. try:
  319. segment, offset = self.index[id_]
  320. return self.io.read(segment, offset, id_)
  321. except KeyError:
  322. raise self.ObjectNotFound(id_, self.path)
  323. def get_many(self, ids, is_preloaded=False):
  324. for id_ in ids:
  325. yield self.get(id_)
  326. def put(self, id, data, wait=True):
  327. if not self._active_txn:
  328. self.prepare_txn(self.get_transaction_id())
  329. try:
  330. segment, _ = self.index[id]
  331. self.segments[segment] -= 1
  332. self.compact.add(segment)
  333. segment = self.io.write_delete(id)
  334. self.segments.setdefault(segment, 0)
  335. self.compact.add(segment)
  336. except KeyError:
  337. pass
  338. segment, offset = self.io.write_put(id, data)
  339. self.segments.setdefault(segment, 0)
  340. self.segments[segment] += 1
  341. self.index[id] = segment, offset
  342. def delete(self, id, wait=True):
  343. if not self._active_txn:
  344. self.prepare_txn(self.get_transaction_id())
  345. try:
  346. segment, offset = self.index.pop(id)
  347. except KeyError:
  348. raise self.ObjectNotFound(id, self.path)
  349. self.segments[segment] -= 1
  350. self.compact.add(segment)
  351. segment = self.io.write_delete(id)
  352. self.compact.add(segment)
  353. self.segments.setdefault(segment, 0)
  354. def preload(self, ids):
  355. """Preload objects (only applies to remote repositories
  356. """
  357. class LoggedIO:
  358. header_fmt = struct.Struct('<IIB')
  359. assert header_fmt.size == 9
  360. put_header_fmt = struct.Struct('<IIB32s')
  361. assert put_header_fmt.size == 41
  362. header_no_crc_fmt = struct.Struct('<IB')
  363. assert header_no_crc_fmt.size == 5
  364. crc_fmt = struct.Struct('<I')
  365. assert crc_fmt.size == 4
  366. _commit = header_no_crc_fmt.pack(9, TAG_COMMIT)
  367. COMMIT = crc_fmt.pack(crc32(_commit)) + _commit
  368. def __init__(self, path, limit, segments_per_dir, capacity=90):
  369. self.path = path
  370. self.fds = LRUCache(capacity)
  371. self.segment = 0
  372. self.limit = limit
  373. self.segments_per_dir = segments_per_dir
  374. self.offset = 0
  375. self._write_fd = None
  376. def close(self):
  377. for segment in list(self.fds.keys()):
  378. self.fds.pop(segment).close()
  379. self.close_segment()
  380. self.fds = None # Just to make sure we're disabled
  381. def segment_iterator(self, reverse=False):
  382. data_path = os.path.join(self.path, 'data')
  383. dirs = sorted((dir for dir in os.listdir(data_path) if dir.isdigit()), key=int, reverse=reverse)
  384. for dir in dirs:
  385. filenames = os.listdir(os.path.join(data_path, dir))
  386. sorted_filenames = sorted((filename for filename in filenames
  387. if filename.isdigit()), key=int, reverse=reverse)
  388. for filename in sorted_filenames:
  389. yield int(filename), os.path.join(data_path, dir, filename)
  390. def get_latest_segment(self):
  391. for segment, filename in self.segment_iterator(reverse=True):
  392. return segment
  393. return None
  394. def get_segments_transaction_id(self):
  395. """Verify that the transaction id is consistent with the index transaction id
  396. """
  397. for segment, filename in self.segment_iterator(reverse=True):
  398. if self.is_committed_segment(filename):
  399. return segment
  400. return None
  401. def cleanup(self, transaction_id):
  402. """Delete segment files left by aborted transactions
  403. """
  404. self.segment = transaction_id + 1
  405. for segment, filename in self.segment_iterator(reverse=True):
  406. if segment > transaction_id:
  407. os.unlink(filename)
  408. else:
  409. break
  410. def is_committed_segment(self, filename):
  411. """Check if segment ends with a COMMIT_TAG tag
  412. """
  413. with open(filename, 'rb') as fd:
  414. try:
  415. fd.seek(-self.header_fmt.size, os.SEEK_END)
  416. except OSError as e:
  417. # return False if segment file is empty or too small
  418. if e.errno == errno.EINVAL:
  419. return False
  420. raise e
  421. return fd.read(self.header_fmt.size) == self.COMMIT
  422. def segment_filename(self, segment):
  423. return os.path.join(self.path, 'data', str(segment // self.segments_per_dir), str(segment))
  424. def get_write_fd(self, no_new=False):
  425. if not no_new and self.offset and self.offset > self.limit:
  426. self.close_segment()
  427. if not self._write_fd:
  428. if self.segment % self.segments_per_dir == 0:
  429. dirname = os.path.join(self.path, 'data', str(self.segment // self.segments_per_dir))
  430. if not os.path.exists(dirname):
  431. os.mkdir(dirname)
  432. self._write_fd = open(self.segment_filename(self.segment), 'ab')
  433. self._write_fd.write(MAGIC)
  434. self.offset = 8
  435. return self._write_fd
  436. def get_fd(self, segment):
  437. try:
  438. return self.fds[segment]
  439. except KeyError:
  440. fd = open(self.segment_filename(segment), 'rb')
  441. self.fds[segment] = fd
  442. return fd
  443. def delete_segment(self, segment):
  444. try:
  445. os.unlink(self.segment_filename(segment))
  446. except OSError:
  447. pass
  448. def segment_exists(self, segment):
  449. return os.path.exists(self.segment_filename(segment))
  450. def iter_objects(self, segment, include_data=False):
  451. fd = self.get_fd(segment)
  452. fd.seek(0)
  453. if fd.read(8) != MAGIC:
  454. raise IntegrityError('Invalid segment header')
  455. offset = 8
  456. header = fd.read(self.header_fmt.size)
  457. while header:
  458. crc, size, tag = self.header_fmt.unpack(header)
  459. if size > MAX_OBJECT_SIZE:
  460. raise IntegrityError('Invalid segment object size')
  461. rest = fd.read(size - self.header_fmt.size)
  462. if crc32(rest, crc32(memoryview(header)[4:])) & 0xffffffff != crc:
  463. raise IntegrityError('Segment checksum mismatch')
  464. if tag not in (TAG_PUT, TAG_DELETE, TAG_COMMIT):
  465. raise IntegrityError('Invalid segment entry header')
  466. key = None
  467. if tag in (TAG_PUT, TAG_DELETE):
  468. key = rest[:32]
  469. if include_data:
  470. yield tag, key, offset, rest[32:]
  471. else:
  472. yield tag, key, offset
  473. offset += size
  474. header = fd.read(self.header_fmt.size)
  475. def recover_segment(self, segment, filename):
  476. self.fds.pop(segment).close()
  477. # FIXME: save a copy of the original file
  478. with open(filename, 'rb') as fd:
  479. data = memoryview(fd.read())
  480. os.rename(filename, filename + '.beforerecover')
  481. print('attempting to recover ' + filename, file=sys.stderr)
  482. with open(filename, 'wb') as fd:
  483. fd.write(MAGIC)
  484. while len(data) >= self.header_fmt.size:
  485. crc, size, tag = self.header_fmt.unpack(data[:self.header_fmt.size])
  486. if size < self.header_fmt.size or size > len(data):
  487. data = data[1:]
  488. continue
  489. if crc32(data[4:size]) & 0xffffffff != crc:
  490. data = data[1:]
  491. continue
  492. fd.write(data[:size])
  493. data = data[size:]
  494. def read(self, segment, offset, id):
  495. if segment == self.segment and self._write_fd:
  496. self._write_fd.flush()
  497. fd = self.get_fd(segment)
  498. fd.seek(offset)
  499. header = fd.read(self.put_header_fmt.size)
  500. crc, size, tag, key = self.put_header_fmt.unpack(header)
  501. if size > MAX_OBJECT_SIZE:
  502. raise IntegrityError('Invalid segment object size')
  503. data = fd.read(size - self.put_header_fmt.size)
  504. if crc32(data, crc32(memoryview(header)[4:])) & 0xffffffff != crc:
  505. raise IntegrityError('Segment checksum mismatch')
  506. if tag != TAG_PUT or id != key:
  507. raise IntegrityError('Invalid segment entry header')
  508. return data
  509. def write_put(self, id, data):
  510. size = len(data) + self.put_header_fmt.size
  511. fd = self.get_write_fd()
  512. offset = self.offset
  513. header = self.header_no_crc_fmt.pack(size, TAG_PUT)
  514. crc = self.crc_fmt.pack(crc32(data, crc32(id, crc32(header))) & 0xffffffff)
  515. fd.write(b''.join((crc, header, id, data)))
  516. self.offset += size
  517. return self.segment, offset
  518. def write_delete(self, id):
  519. fd = self.get_write_fd()
  520. header = self.header_no_crc_fmt.pack(self.put_header_fmt.size, TAG_DELETE)
  521. crc = self.crc_fmt.pack(crc32(id, crc32(header)) & 0xffffffff)
  522. fd.write(b''.join((crc, header, id)))
  523. self.offset += self.put_header_fmt.size
  524. return self.segment
  525. def write_commit(self):
  526. fd = self.get_write_fd(no_new=True)
  527. header = self.header_no_crc_fmt.pack(self.header_fmt.size, TAG_COMMIT)
  528. crc = self.crc_fmt.pack(crc32(header) & 0xffffffff)
  529. fd.write(b''.join((crc, header)))
  530. self.close_segment()
  531. def close_segment(self):
  532. if self._write_fd:
  533. self.segment += 1
  534. self.offset = 0
  535. self._write_fd.flush()
  536. os.fsync(self._write_fd.fileno())
  537. if hasattr(os, 'posix_fadvise'): # python >= 3.3, only on UNIX
  538. # tell the OS that it does not need to cache what we just wrote,
  539. # avoids spoiling the cache for the OS and other processes.
  540. os.posix_fadvise(self._write_fd.fileno(), 0, 0, os.POSIX_FADV_DONTNEED)
  541. self._write_fd.close()
  542. self._write_fd = None