repository.py 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616
  1. from configparser import RawConfigParser
  2. from binascii import hexlify
  3. from itertools import islice
  4. import errno
  5. import os
  6. import shutil
  7. import struct
  8. import sys
  9. from zlib import crc32
  10. from .hashindex import NSIndex
  11. from .helpers import Error, IntegrityError, read_msgpack, write_msgpack, unhexlify
  12. from .locking import UpgradableLock
  13. from .lrucache import LRUCache
  14. MAX_OBJECT_SIZE = 20 * 1024 * 1024
  15. MAGIC = b'BORG_SEG'
  16. MAGIC_LEN = len(MAGIC)
  17. TAG_PUT = 0
  18. TAG_DELETE = 1
  19. TAG_COMMIT = 2
  20. class Repository:
  21. """Filesystem based transactional key value store
  22. On disk layout:
  23. dir/README
  24. dir/config
  25. dir/data/<X / SEGMENTS_PER_DIR>/<X>
  26. dir/index.X
  27. dir/hints.X
  28. """
  29. DEFAULT_MAX_SEGMENT_SIZE = 5 * 1024 * 1024
  30. DEFAULT_SEGMENTS_PER_DIR = 10000
  31. class DoesNotExist(Error):
  32. """Repository {} does not exist."""
  33. class AlreadyExists(Error):
  34. """Repository {} already exists."""
  35. class InvalidRepository(Error):
  36. """{} is not a valid repository."""
  37. class CheckNeeded(Error):
  38. """Inconsistency detected. Please run "borg check {}"."""
  39. class ObjectNotFound(Error):
  40. """Object with key {} not found in repository {}."""
  41. def __init__(self, path, create=False, exclusive=False):
  42. self.path = path
  43. self.io = None
  44. self.lock = None
  45. self.index = None
  46. self._active_txn = False
  47. if create:
  48. self.create(path)
  49. self.open(path, exclusive)
  50. def __del__(self):
  51. self.close()
  52. def create(self, path):
  53. """Create a new empty repository at `path`
  54. """
  55. if os.path.exists(path) and (not os.path.isdir(path) or os.listdir(path)):
  56. raise self.AlreadyExists(path)
  57. if not os.path.exists(path):
  58. os.mkdir(path)
  59. with open(os.path.join(path, 'README'), 'w') as fd:
  60. fd.write('This is a Borg repository\n')
  61. os.mkdir(os.path.join(path, 'data'))
  62. config = RawConfigParser()
  63. config.add_section('repository')
  64. config.set('repository', 'version', '1')
  65. config.set('repository', 'segments_per_dir', self.DEFAULT_SEGMENTS_PER_DIR)
  66. config.set('repository', 'max_segment_size', self.DEFAULT_MAX_SEGMENT_SIZE)
  67. config.set('repository', 'id', hexlify(os.urandom(32)).decode('ascii'))
  68. with open(os.path.join(path, 'config'), 'w') as fd:
  69. config.write(fd)
  70. def destroy(self):
  71. """Destroy the repository at `self.path`
  72. """
  73. self.close()
  74. os.remove(os.path.join(self.path, 'config')) # kill config first
  75. shutil.rmtree(self.path)
  76. def get_index_transaction_id(self):
  77. indices = sorted((int(name[6:]) for name in os.listdir(self.path) if name.startswith('index.') and name[6:].isdigit()))
  78. if indices:
  79. return indices[-1]
  80. else:
  81. return None
  82. def get_transaction_id(self):
  83. index_transaction_id = self.get_index_transaction_id()
  84. segments_transaction_id = self.io.get_segments_transaction_id()
  85. if index_transaction_id is not None and segments_transaction_id is None:
  86. raise self.CheckNeeded(self.path)
  87. # Attempt to automatically rebuild index if we crashed between commit
  88. # tag write and index save
  89. if index_transaction_id != segments_transaction_id:
  90. if index_transaction_id is not None and index_transaction_id > segments_transaction_id:
  91. replay_from = None
  92. else:
  93. replay_from = index_transaction_id
  94. self.replay_segments(replay_from, segments_transaction_id)
  95. return self.get_index_transaction_id()
  96. def open(self, path, exclusive):
  97. self.path = path
  98. if not os.path.isdir(path):
  99. raise self.DoesNotExist(path)
  100. self.lock = UpgradableLock(os.path.join(path, 'repo'), exclusive).acquire()
  101. self.config = RawConfigParser()
  102. self.config.read(os.path.join(self.path, 'config'))
  103. if 'repository' not in self.config.sections() or self.config.getint('repository', 'version') != 1:
  104. raise self.InvalidRepository(path)
  105. self.max_segment_size = self.config.getint('repository', 'max_segment_size')
  106. self.segments_per_dir = self.config.getint('repository', 'segments_per_dir')
  107. self.id = unhexlify(self.config.get('repository', 'id').strip())
  108. self.io = LoggedIO(self.path, self.max_segment_size, self.segments_per_dir)
  109. def close(self):
  110. if self.lock:
  111. if self.io:
  112. self.io.close()
  113. self.io = None
  114. self.lock.release()
  115. self.lock = None
  116. def commit(self):
  117. """Commit transaction
  118. """
  119. self.io.write_commit()
  120. self.compact_segments()
  121. self.write_index()
  122. self.rollback()
  123. def open_index(self, transaction_id):
  124. if transaction_id is None:
  125. return NSIndex()
  126. return NSIndex.read((os.path.join(self.path, 'index.%d') % transaction_id).encode('utf-8'))
  127. def prepare_txn(self, transaction_id, do_cleanup=True):
  128. self._active_txn = True
  129. try:
  130. self.lock.upgrade()
  131. except UpgradableLock.ExclusiveLockFailed:
  132. # if upgrading the lock to exclusive fails, we do not have an
  133. # active transaction. this is important for "serve" mode, where
  134. # the repository instance lives on - even if exceptions happened.
  135. self._active_txn = False
  136. raise
  137. if not self.index:
  138. self.index = self.open_index(transaction_id)
  139. if transaction_id is None:
  140. self.segments = {}
  141. self.compact = set()
  142. else:
  143. if do_cleanup:
  144. self.io.cleanup(transaction_id)
  145. hints = read_msgpack(os.path.join(self.path, 'hints.%d' % transaction_id))
  146. if hints[b'version'] != 1:
  147. raise ValueError('Unknown hints file version: %d' % hints['version'])
  148. self.segments = hints[b'segments']
  149. self.compact = set(hints[b'compact'])
  150. def write_index(self):
  151. hints = {b'version': 1,
  152. b'segments': self.segments,
  153. b'compact': list(self.compact)}
  154. transaction_id = self.io.get_segments_transaction_id()
  155. write_msgpack(os.path.join(self.path, 'hints.%d' % transaction_id), hints)
  156. self.index.write(os.path.join(self.path, 'index.tmp'))
  157. os.rename(os.path.join(self.path, 'index.tmp'),
  158. os.path.join(self.path, 'index.%d' % transaction_id))
  159. # Remove old indices
  160. current = '.%d' % transaction_id
  161. for name in os.listdir(self.path):
  162. if not name.startswith('index.') and not name.startswith('hints.'):
  163. continue
  164. if name.endswith(current):
  165. continue
  166. os.unlink(os.path.join(self.path, name))
  167. self.index = None
  168. def compact_segments(self):
  169. """Compact sparse segments by copying data into new segments
  170. """
  171. if not self.compact:
  172. return
  173. index_transaction_id = self.get_index_transaction_id()
  174. segments = self.segments
  175. for segment in sorted(self.compact):
  176. if self.io.segment_exists(segment):
  177. for tag, key, offset, data in self.io.iter_objects(segment, include_data=True):
  178. if tag == TAG_PUT and self.index.get(key, (-1, -1)) == (segment, offset):
  179. new_segment, offset = self.io.write_put(key, data)
  180. self.index[key] = new_segment, offset
  181. segments.setdefault(new_segment, 0)
  182. segments[new_segment] += 1
  183. segments[segment] -= 1
  184. elif tag == TAG_DELETE:
  185. if index_transaction_id is None or segment > index_transaction_id:
  186. self.io.write_delete(key)
  187. assert segments[segment] == 0
  188. self.io.write_commit()
  189. for segment in sorted(self.compact):
  190. assert self.segments.pop(segment) == 0
  191. self.io.delete_segment(segment)
  192. self.compact = set()
  193. def replay_segments(self, index_transaction_id, segments_transaction_id):
  194. self.prepare_txn(index_transaction_id, do_cleanup=False)
  195. for segment, filename in self.io.segment_iterator():
  196. if index_transaction_id is not None and segment <= index_transaction_id:
  197. continue
  198. if segment > segments_transaction_id:
  199. break
  200. self.segments[segment] = 0
  201. for tag, key, offset in self.io.iter_objects(segment):
  202. if tag == TAG_PUT:
  203. try:
  204. s, _ = self.index[key]
  205. self.compact.add(s)
  206. self.segments[s] -= 1
  207. except KeyError:
  208. pass
  209. self.index[key] = segment, offset
  210. self.segments[segment] += 1
  211. elif tag == TAG_DELETE:
  212. try:
  213. s, _ = self.index.pop(key)
  214. self.segments[s] -= 1
  215. self.compact.add(s)
  216. except KeyError:
  217. pass
  218. self.compact.add(segment)
  219. elif tag == TAG_COMMIT:
  220. continue
  221. else:
  222. raise self.CheckNeeded(self.path)
  223. if self.segments[segment] == 0:
  224. self.compact.add(segment)
  225. self.write_index()
  226. self.rollback()
  227. def check(self, repair=False):
  228. """Check repository consistency
  229. This method verifies all segment checksums and makes sure
  230. the index is consistent with the data stored in the segments.
  231. """
  232. error_found = False
  233. def report_error(msg):
  234. nonlocal error_found
  235. error_found = True
  236. print(msg, file=sys.stderr)
  237. assert not self._active_txn
  238. try:
  239. transaction_id = self.get_transaction_id()
  240. current_index = self.open_index(transaction_id)
  241. except Exception:
  242. transaction_id = self.io.get_segments_transaction_id()
  243. current_index = None
  244. if transaction_id is None:
  245. transaction_id = self.get_index_transaction_id()
  246. if transaction_id is None:
  247. transaction_id = self.io.get_latest_segment()
  248. if repair:
  249. self.io.cleanup(transaction_id)
  250. segments_transaction_id = self.io.get_segments_transaction_id()
  251. self.prepare_txn(None)
  252. for segment, filename in self.io.segment_iterator():
  253. if segment > transaction_id:
  254. continue
  255. try:
  256. objects = list(self.io.iter_objects(segment))
  257. except IntegrityError as err:
  258. report_error('Error reading segment {}: {}'.format(segment, err))
  259. objects = []
  260. if repair:
  261. self.io.recover_segment(segment, filename)
  262. objects = list(self.io.iter_objects(segment))
  263. self.segments[segment] = 0
  264. for tag, key, offset in objects:
  265. if tag == TAG_PUT:
  266. try:
  267. s, _ = self.index[key]
  268. self.compact.add(s)
  269. self.segments[s] -= 1
  270. except KeyError:
  271. pass
  272. self.index[key] = segment, offset
  273. self.segments[segment] += 1
  274. elif tag == TAG_DELETE:
  275. try:
  276. s, _ = self.index.pop(key)
  277. self.segments[s] -= 1
  278. self.compact.add(s)
  279. except KeyError:
  280. pass
  281. self.compact.add(segment)
  282. elif tag == TAG_COMMIT:
  283. continue
  284. else:
  285. report_error('Unexpected tag {} in segment {}'.format(tag, segment))
  286. # We might need to add a commit tag if no committed segment is found
  287. if repair and segments_transaction_id is None:
  288. report_error('Adding commit tag to segment {}'.format(transaction_id))
  289. self.io.segment = transaction_id + 1
  290. self.io.write_commit()
  291. self.io.close_segment()
  292. if current_index and not repair:
  293. if len(current_index) != len(self.index):
  294. report_error('Index object count mismatch. {} != {}'.format(len(current_index), len(self.index)))
  295. elif current_index:
  296. for key, value in self.index.iteritems():
  297. if current_index.get(key, (-1, -1)) != value:
  298. report_error('Index mismatch for key {}. {} != {}'.format(key, value, current_index.get(key, (-1, -1))))
  299. if repair:
  300. self.compact_segments()
  301. self.write_index()
  302. self.rollback()
  303. return not error_found or repair
  304. def rollback(self):
  305. """
  306. """
  307. self.index = None
  308. self._active_txn = False
  309. def __len__(self):
  310. if not self.index:
  311. self.index = self.open_index(self.get_transaction_id())
  312. return len(self.index)
  313. def __contains__(self, id):
  314. if not self.index:
  315. self.index = self.open_index(self.get_transaction_id())
  316. return id in self.index
  317. def list(self, limit=None, marker=None):
  318. if not self.index:
  319. self.index = self.open_index(self.get_transaction_id())
  320. return [id_ for id_, _ in islice(self.index.iteritems(marker=marker), limit)]
  321. def get(self, id_):
  322. if not self.index:
  323. self.index = self.open_index(self.get_transaction_id())
  324. try:
  325. segment, offset = self.index[id_]
  326. return self.io.read(segment, offset, id_)
  327. except KeyError:
  328. raise self.ObjectNotFound(id_, self.path)
  329. def get_many(self, ids, is_preloaded=False):
  330. for id_ in ids:
  331. yield self.get(id_)
  332. def put(self, id, data, wait=True):
  333. if not self._active_txn:
  334. self.prepare_txn(self.get_transaction_id())
  335. try:
  336. segment, _ = self.index[id]
  337. self.segments[segment] -= 1
  338. self.compact.add(segment)
  339. segment = self.io.write_delete(id)
  340. self.segments.setdefault(segment, 0)
  341. self.compact.add(segment)
  342. except KeyError:
  343. pass
  344. segment, offset = self.io.write_put(id, data)
  345. self.segments.setdefault(segment, 0)
  346. self.segments[segment] += 1
  347. self.index[id] = segment, offset
  348. def delete(self, id, wait=True):
  349. if not self._active_txn:
  350. self.prepare_txn(self.get_transaction_id())
  351. try:
  352. segment, offset = self.index.pop(id)
  353. except KeyError:
  354. raise self.ObjectNotFound(id, self.path)
  355. self.segments[segment] -= 1
  356. self.compact.add(segment)
  357. segment = self.io.write_delete(id)
  358. self.compact.add(segment)
  359. self.segments.setdefault(segment, 0)
  360. def preload(self, ids):
  361. """Preload objects (only applies to remote repositories
  362. """
  363. class LoggedIO:
  364. header_fmt = struct.Struct('<IIB')
  365. assert header_fmt.size == 9
  366. put_header_fmt = struct.Struct('<IIB32s')
  367. assert put_header_fmt.size == 41
  368. header_no_crc_fmt = struct.Struct('<IB')
  369. assert header_no_crc_fmt.size == 5
  370. crc_fmt = struct.Struct('<I')
  371. assert crc_fmt.size == 4
  372. _commit = header_no_crc_fmt.pack(9, TAG_COMMIT)
  373. COMMIT = crc_fmt.pack(crc32(_commit)) + _commit
  374. def __init__(self, path, limit, segments_per_dir, capacity=90):
  375. self.path = path
  376. self.fds = LRUCache(capacity)
  377. self.segment = 0
  378. self.limit = limit
  379. self.segments_per_dir = segments_per_dir
  380. self.offset = 0
  381. self._write_fd = None
  382. def close(self):
  383. for segment in list(self.fds.keys()):
  384. self.fds.pop(segment).close()
  385. self.close_segment()
  386. self.fds = None # Just to make sure we're disabled
  387. def segment_iterator(self, reverse=False):
  388. data_path = os.path.join(self.path, 'data')
  389. dirs = sorted((dir for dir in os.listdir(data_path) if dir.isdigit()), key=int, reverse=reverse)
  390. for dir in dirs:
  391. filenames = os.listdir(os.path.join(data_path, dir))
  392. sorted_filenames = sorted((filename for filename in filenames
  393. if filename.isdigit()), key=int, reverse=reverse)
  394. for filename in sorted_filenames:
  395. yield int(filename), os.path.join(data_path, dir, filename)
  396. def get_latest_segment(self):
  397. for segment, filename in self.segment_iterator(reverse=True):
  398. return segment
  399. return None
  400. def get_segments_transaction_id(self):
  401. """Verify that the transaction id is consistent with the index transaction id
  402. """
  403. for segment, filename in self.segment_iterator(reverse=True):
  404. if self.is_committed_segment(filename):
  405. return segment
  406. return None
  407. def cleanup(self, transaction_id):
  408. """Delete segment files left by aborted transactions
  409. """
  410. self.segment = transaction_id + 1
  411. for segment, filename in self.segment_iterator(reverse=True):
  412. if segment > transaction_id:
  413. os.unlink(filename)
  414. else:
  415. break
  416. def is_committed_segment(self, filename):
  417. """Check if segment ends with a COMMIT_TAG tag
  418. """
  419. with open(filename, 'rb') as fd:
  420. try:
  421. fd.seek(-self.header_fmt.size, os.SEEK_END)
  422. except OSError as e:
  423. # return False if segment file is empty or too small
  424. if e.errno == errno.EINVAL:
  425. return False
  426. raise e
  427. return fd.read(self.header_fmt.size) == self.COMMIT
  428. def segment_filename(self, segment):
  429. return os.path.join(self.path, 'data', str(segment // self.segments_per_dir), str(segment))
  430. def get_write_fd(self, no_new=False):
  431. if not no_new and self.offset and self.offset > self.limit:
  432. self.close_segment()
  433. if not self._write_fd:
  434. if self.segment % self.segments_per_dir == 0:
  435. dirname = os.path.join(self.path, 'data', str(self.segment // self.segments_per_dir))
  436. if not os.path.exists(dirname):
  437. os.mkdir(dirname)
  438. self._write_fd = open(self.segment_filename(self.segment), 'ab')
  439. self._write_fd.write(MAGIC)
  440. self.offset = MAGIC_LEN
  441. return self._write_fd
  442. def get_fd(self, segment):
  443. try:
  444. return self.fds[segment]
  445. except KeyError:
  446. fd = open(self.segment_filename(segment), 'rb')
  447. self.fds[segment] = fd
  448. return fd
  449. def delete_segment(self, segment):
  450. try:
  451. os.unlink(self.segment_filename(segment))
  452. except OSError:
  453. pass
  454. def segment_exists(self, segment):
  455. return os.path.exists(self.segment_filename(segment))
  456. def iter_objects(self, segment, include_data=False):
  457. fd = self.get_fd(segment)
  458. fd.seek(0)
  459. if fd.read(MAGIC_LEN) != MAGIC:
  460. raise IntegrityError('Invalid segment magic')
  461. offset = MAGIC_LEN
  462. header = fd.read(self.header_fmt.size)
  463. while header:
  464. try:
  465. crc, size, tag = self.header_fmt.unpack(header)
  466. except struct.error as err:
  467. raise IntegrityError('Invalid segment entry header [offset {}]: {}'.format(offset, err))
  468. if size > MAX_OBJECT_SIZE:
  469. raise IntegrityError('Invalid segment entry size [offset {}]'.format(offset))
  470. length = size - self.header_fmt.size
  471. rest = fd.read(length)
  472. if len(rest) != length:
  473. raise IntegrityError('Segment entry data short read [offset {}]: expected: {}, got {} bytes'.format(
  474. offset, length, len(rest)))
  475. if crc32(rest, crc32(memoryview(header)[4:])) & 0xffffffff != crc:
  476. raise IntegrityError('Segment entry checksum mismatch [offset {}]'.format(offset))
  477. if tag not in (TAG_PUT, TAG_DELETE, TAG_COMMIT):
  478. raise IntegrityError('Invalid segment entry tag [offset {}]'.format(offset))
  479. key = None
  480. if tag in (TAG_PUT, TAG_DELETE):
  481. key = rest[:32]
  482. if include_data:
  483. yield tag, key, offset, rest[32:]
  484. else:
  485. yield tag, key, offset
  486. offset += size
  487. header = fd.read(self.header_fmt.size)
  488. def recover_segment(self, segment, filename):
  489. self.fds.pop(segment).close()
  490. # FIXME: save a copy of the original file
  491. with open(filename, 'rb') as fd:
  492. data = memoryview(fd.read())
  493. os.rename(filename, filename + '.beforerecover')
  494. print('attempting to recover ' + filename, file=sys.stderr)
  495. with open(filename, 'wb') as fd:
  496. fd.write(MAGIC)
  497. while len(data) >= self.header_fmt.size:
  498. crc, size, tag = self.header_fmt.unpack(data[:self.header_fmt.size])
  499. if size < self.header_fmt.size or size > len(data):
  500. data = data[1:]
  501. continue
  502. if crc32(data[4:size]) & 0xffffffff != crc:
  503. data = data[1:]
  504. continue
  505. fd.write(data[:size])
  506. data = data[size:]
  507. def read(self, segment, offset, id):
  508. if segment == self.segment and self._write_fd:
  509. self._write_fd.flush()
  510. fd = self.get_fd(segment)
  511. fd.seek(offset)
  512. header = fd.read(self.put_header_fmt.size)
  513. crc, size, tag, key = self.put_header_fmt.unpack(header)
  514. if size > MAX_OBJECT_SIZE:
  515. raise IntegrityError('Invalid segment object size')
  516. data = fd.read(size - self.put_header_fmt.size)
  517. if crc32(data, crc32(memoryview(header)[4:])) & 0xffffffff != crc:
  518. raise IntegrityError('Segment checksum mismatch')
  519. if tag != TAG_PUT or id != key:
  520. raise IntegrityError('Invalid segment entry header')
  521. return data
  522. def write_put(self, id, data):
  523. size = len(data) + self.put_header_fmt.size
  524. fd = self.get_write_fd()
  525. offset = self.offset
  526. header = self.header_no_crc_fmt.pack(size, TAG_PUT)
  527. crc = self.crc_fmt.pack(crc32(data, crc32(id, crc32(header))) & 0xffffffff)
  528. fd.write(b''.join((crc, header, id, data)))
  529. self.offset += size
  530. return self.segment, offset
  531. def write_delete(self, id):
  532. fd = self.get_write_fd()
  533. header = self.header_no_crc_fmt.pack(self.put_header_fmt.size, TAG_DELETE)
  534. crc = self.crc_fmt.pack(crc32(id, crc32(header)) & 0xffffffff)
  535. fd.write(b''.join((crc, header, id)))
  536. self.offset += self.put_header_fmt.size
  537. return self.segment
  538. def write_commit(self):
  539. fd = self.get_write_fd(no_new=True)
  540. header = self.header_no_crc_fmt.pack(self.header_fmt.size, TAG_COMMIT)
  541. crc = self.crc_fmt.pack(crc32(header) & 0xffffffff)
  542. fd.write(b''.join((crc, header)))
  543. self.close_segment()
  544. def close_segment(self):
  545. if self._write_fd:
  546. self.segment += 1
  547. self.offset = 0
  548. self._write_fd.flush()
  549. os.fsync(self._write_fd.fileno())
  550. if hasattr(os, 'posix_fadvise'): # python >= 3.3, only on UNIX
  551. # tell the OS that it does not need to cache what we just wrote,
  552. # avoids spoiling the cache for the OS and other processes.
  553. os.posix_fadvise(self._write_fd.fileno(), 0, 0, os.POSIX_FADV_DONTNEED)
  554. self._write_fd.close()
  555. self._write_fd = None