Skip to main content

ic_testkit/artifacts/
cache_fs.rs

1use fs2::FileExt as _;
2use std::{
3    fs::{self, File, OpenOptions},
4    io::{self, Read as _},
5    path::{Path, PathBuf},
6    sync::Arc,
7    time::{Duration, Instant, SystemTime, UNIX_EPOCH},
8};
9
10use super::digest::read_stamp_with_limit;
11
12/// Resolve existing components through symlinks and normalize a missing suffix.
13/// Parent traversal can return from a missing suffix to existing components.
14pub(super) fn canonicalize_allow_missing(path: &Path) -> io::Result<PathBuf> {
15    let base = if path.is_absolute() {
16        PathBuf::new()
17    } else {
18        std::env::current_dir()?
19    };
20    ic_host_fs::path::canonicalize_allow_missing(path, &base)
21}
22
23const CACHE_DIRECTORY_TAG: &str = "Signature: 8a477f597d28d172789f06886806bc55\n\
24# This file is a cache directory tag created by ic-testkit.\n\
25# For information about cache directory tags see https://bford.info/cachedir/\n";
26pub(super) const CACHE_DIRECTORY_TAG_SIGNATURE: &str =
27    "Signature: 8a477f597d28d172789f06886806bc55";
28pub(super) const LAST_USED_FILE: &str = ".ic-testkit-last-used";
29const LAST_MAINTENANCE_FILE: &str = ".ic-testkit-last-maintenance";
30// Nanoseconds are written as decimal u128 values, which need at most 39 bytes.
31const MAX_TIMESTAMP_BYTES: usize = 39;
32pub(super) const RETENTION_LOCK_FILE: &str = ".ic-testkit-retention-v1";
33
34/// Acquired under the producer/namespace lock before handing an entry to a
35/// consumer. Clones share ownership; the OS releases locks on process exit.
36#[derive(Clone, Debug)]
37pub(super) struct RetainedCacheEntry {
38    path: PathBuf,
39    _lock: Arc<RetentionLock>,
40}
41
42#[derive(Debug)]
43struct RetentionLock(File);
44
45impl Drop for RetentionLock {
46    fn drop(&mut self) {
47        // Closing alone can leave a flock held by a descriptor inherited during
48        // a concurrent spawn before exec. Release it when the final record owner
49        // drops, rather than waiting for unrelated child descriptors to close.
50        // If unlocking fails, closing the owned file remains the fallback.
51        let _ = fs2::FileExt::unlock(&self.0);
52    }
53}
54
55impl PartialEq for RetainedCacheEntry {
56    fn eq(&self, other: &Self) -> bool {
57        self.path == other.path
58    }
59}
60
61impl Eq for RetainedCacheEntry {}
62
63impl RetainedCacheEntry {
64    pub(super) fn path(&self) -> &Path {
65        &self.path
66    }
67
68    pub(super) fn acquire(path: &Path) -> Result<Self, CacheFsError> {
69        let file = open_cache_lock_file(&path.join(RETENTION_LOCK_FILE))?;
70        fs2::FileExt::lock_shared(&file).map_err(|source| CacheFsError {
71            operation: "retain cache entry",
72            path: path.to_owned(),
73            source,
74        })?;
75        Ok(Self {
76            path: path.to_owned(),
77            _lock: Arc::new(RetentionLock(file)),
78        })
79    }
80}
81
82/// The caller must hold the producer/namespace lock throughout this operation.
83pub(super) fn remove_unretained_entry(path: &Path) -> Result<(), CacheFsError> {
84    let metadata = match fs::symlink_metadata(path) {
85        Ok(metadata) => metadata,
86        Err(error) if error.kind() == io::ErrorKind::NotFound => return Ok(()),
87        Err(source) => {
88            return Err(CacheFsError {
89                operation: "inspect cache entry",
90                path: path.to_owned(),
91                source,
92            });
93        }
94    };
95    if !metadata.is_dir() {
96        return remove_path_if_present(path).map_err(|source| CacheFsError {
97            operation: "remove invalid cache entry",
98            path: path.to_owned(),
99            source,
100        });
101    }
102    let _lock =
103        try_lock_cache_file(&path.join(RETENTION_LOCK_FILE))?.ok_or_else(|| CacheFsError {
104            operation: "replace retained cache entry",
105            path: path.to_owned(),
106            source: io::Error::new(
107                io::ErrorKind::WouldBlock,
108                "cache entry is retained by a consumer",
109            ),
110        })?;
111    remove_path_if_present(path).map_err(|source| CacheFsError {
112        operation: "remove cache entry",
113        path: path.to_owned(),
114        source,
115    })
116}
117
118/// Caller-selected retention limits for content-addressed artifact entries.
119///
120/// Age pruning runs before size pruning. A policy without either limit scans
121/// the selected cache namespace and updates its cache metadata without
122/// removing entries. Entries retained by live acquisition records are skipped,
123/// even when this temporarily exceeds the limits. They become eligible for the
124/// next maintenance pass after their final owner drops or its process exits.
125#[derive(Clone, Copy, Debug, Default, Eq, PartialEq)]
126pub struct ArtifactCachePrunePolicy {
127    max_age: Option<Duration>,
128    max_size_bytes: Option<u64>,
129}
130
131/// Summary of one lock-coordinated artifact-cache pruning pass.
132#[derive(Clone, Copy, Debug, Default, Eq, PartialEq)]
133pub struct ArtifactCachePruneReport {
134    entries_scanned: usize,
135    entries_removed: usize,
136    bytes_before: u64,
137    bytes_removed: u64,
138    uncommitted_directories_removed: usize,
139    uncommitted_bytes_removed: u64,
140}
141
142/// Nonfatal retention attempted as part of a successful cache acquisition.
143#[non_exhaustive]
144#[derive(Clone, Debug, Eq, PartialEq)]
145pub enum ArtifactCacheMaintenance {
146    /// Configured retention completed under the cache lock.
147    Pruned(ArtifactCachePruneReport),
148    /// Configured retention failed after the requested artifacts were ready.
149    PruneFailed {
150        /// Cache error rendered without invalidating the successful acquisition.
151        message: String,
152    },
153}
154
155impl ArtifactCachePrunePolicy {
156    /// Create a policy that records cache metadata without removing entries.
157    #[must_use]
158    pub const fn new() -> Self {
159        Self {
160            max_age: None,
161            max_size_bytes: None,
162        }
163    }
164
165    /// Remove entries older than `max_age` before applying the size limit.
166    #[must_use]
167    pub const fn with_max_age(mut self, max_age: Duration) -> Self {
168        self.max_age = Some(max_age);
169        self
170    }
171
172    /// Remove least-recently-used entries until retained logical size is at most `bytes`.
173    #[must_use]
174    pub const fn with_max_size_bytes(mut self, bytes: u64) -> Self {
175        self.max_size_bytes = Some(bytes);
176        self
177    }
178
179    /// Configured maximum entry age, if any.
180    #[must_use]
181    pub const fn max_age(self) -> Option<Duration> {
182        self.max_age
183    }
184
185    /// Configured maximum logical cache size in bytes, if any.
186    #[must_use]
187    pub const fn max_size_bytes(self) -> Option<u64> {
188        self.max_size_bytes
189    }
190
191    pub(super) fn maintenance_identity(self) -> String {
192        format!(
193            "age={:?};size={:?}",
194            self.max_age.map(|duration| duration.as_nanos()),
195            self.max_size_bytes
196        )
197    }
198}
199
200impl ArtifactCachePruneReport {
201    /// Number of content-addressed directories considered for pruning.
202    #[must_use]
203    pub const fn entries_scanned(self) -> usize {
204        self.entries_scanned
205    }
206
207    /// Number of content-addressed directories removed.
208    #[must_use]
209    pub const fn entries_removed(self) -> usize {
210        self.entries_removed
211    }
212
213    /// Number of content-addressed directories retained.
214    #[must_use]
215    pub const fn entries_retained(self) -> usize {
216        self.entries_scanned.saturating_sub(self.entries_removed)
217    }
218
219    /// Logical bytes occupied by scanned entries before pruning.
220    #[must_use]
221    pub const fn bytes_before(self) -> u64 {
222        self.bytes_before
223    }
224
225    /// Logical bytes removed by pruning.
226    #[must_use]
227    pub const fn bytes_removed(self) -> u64 {
228        self.bytes_removed
229    }
230
231    /// Logical bytes occupied by retained entries after pruning.
232    #[must_use]
233    pub const fn bytes_retained(self) -> u64 {
234        self.bytes_before.saturating_sub(self.bytes_removed)
235    }
236
237    /// Abandoned transaction directories removed outside the committed-entry totals.
238    #[must_use]
239    pub const fn uncommitted_directories_removed(self) -> usize {
240        self.uncommitted_directories_removed
241    }
242
243    /// Logical bytes removed from abandoned transaction directories.
244    #[must_use]
245    pub const fn uncommitted_bytes_removed(self) -> u64 {
246        self.uncommitted_bytes_removed
247    }
248
249    pub(super) const fn record_uncommitted_removal(&mut self, bytes: u64) {
250        self.uncommitted_directories_removed += 1;
251        self.uncommitted_bytes_removed = self.uncommitted_bytes_removed.saturating_add(bytes);
252    }
253}
254
255impl ArtifactCacheMaintenance {
256    /// Successful pruning report, or `None` when maintenance failed.
257    #[must_use]
258    pub const fn prune_report(&self) -> Option<ArtifactCachePruneReport> {
259        match self {
260            Self::Pruned(report) => Some(*report),
261            Self::PruneFailed { .. } => None,
262        }
263    }
264
265    /// Rendered maintenance failure, or `None` when pruning succeeded.
266    #[must_use]
267    pub fn failure_message(&self) -> Option<&str> {
268        match self {
269            Self::Pruned(_) => None,
270            Self::PruneFailed { message } => Some(message),
271        }
272    }
273}
274
275#[derive(Debug)]
276pub(super) struct CacheFsError {
277    pub(super) operation: &'static str,
278    pub(super) path: PathBuf,
279    pub(super) source: io::Error,
280}
281
282pub(super) fn ensure_cache_directory_tag(cache_root: &Path) -> Result<(), CacheFsError> {
283    let path = cache_root.join("CACHEDIR.TAG");
284    // The standard recognizes the first 43 bytes, without requiring a newline
285    // or interpreting the remaining text. Symlinks are not valid tag files.
286    let mut signature = [0_u8; CACHE_DIRECTORY_TAG_SIGNATURE.len()];
287    if fs::symlink_metadata(&path).is_ok_and(|metadata| metadata.file_type().is_file())
288        && File::open(&path)
289            .and_then(|mut file| file.read_exact(&mut signature))
290            .is_ok()
291        && signature == CACHE_DIRECTORY_TAG_SIGNATURE.as_bytes()
292    {
293        return Ok(());
294    }
295    ic_host_fs::durable::write_bytes(&path, CACHE_DIRECTORY_TAG.as_bytes()).map_err(|source| {
296        CacheFsError {
297            operation: "write cache directory tag",
298            path,
299            source,
300        }
301    })
302}
303
304pub(super) fn lock_cache_file(path: &Path) -> Result<(File, Duration), CacheFsError> {
305    let file = open_cache_lock_file(path)?;
306    let started = Instant::now();
307    file.lock_exclusive().map_err(|source| CacheFsError {
308        operation: "lock cache",
309        path: path.to_owned(),
310        source,
311    })?;
312    Ok((file, started.elapsed()))
313}
314
315pub(super) fn lock_cache_file_with_wait_observer(
316    path: &Path,
317    poll_interval: Duration,
318    mut observer: impl FnMut(Duration),
319) -> Result<(File, Duration), CacheFsError> {
320    let file = open_cache_lock_file(path)?;
321    let wait = ic_host_fs::durable::lock_exclusive_with_wait(
322        &file,
323        poll_interval.min(Duration::from_millis(25)),
324        |elapsed| {
325            observer(elapsed);
326            Ok(())
327        },
328    )
329    .map_err(|source| CacheFsError {
330        operation: "try lock cache",
331        path: path.to_owned(),
332        source,
333    })?;
334    Ok((file, wait))
335}
336
337pub(super) fn try_lock_cache_file(path: &Path) -> Result<Option<File>, CacheFsError> {
338    let file = open_cache_lock_file(path)?;
339    match file.try_lock_exclusive() {
340        Ok(()) => Ok(Some(file)),
341        Err(error) if error.kind() == io::ErrorKind::WouldBlock => Ok(None),
342        Err(source) => Err(CacheFsError {
343            operation: "try lock cache",
344            path: path.to_owned(),
345            source,
346        }),
347    }
348}
349
350fn open_cache_lock_file(path: &Path) -> Result<File, CacheFsError> {
351    if let Some(parent) = path.parent() {
352        fs::create_dir_all(parent).map_err(|source| CacheFsError {
353            operation: "create cache lock directory",
354            path: parent.to_owned(),
355            source,
356        })?;
357    }
358    OpenOptions::new()
359        .create(true)
360        .read(true)
361        .write(true)
362        .truncate(false)
363        .open(path)
364        .map_err(|source| CacheFsError {
365            operation: "open cache lock",
366            path: path.to_owned(),
367            source,
368        })
369}
370
371pub(super) fn record_cache_entry_use(path: &Path) -> Result<(), CacheFsError> {
372    write_last_used(path, SystemTime::now())
373}
374
375pub(super) fn cache_maintenance_due(
376    path: &Path,
377    minimum_interval: Option<Duration>,
378    maintenance_identity: &str,
379) -> Result<bool, CacheFsError> {
380    let Some(minimum_interval) = minimum_interval else {
381        return Ok(true);
382    };
383    let marker = path.join(LAST_MAINTENANCE_FILE);
384    // Allow both LF and CRLF for the timestamp and policy-identity lines.
385    let maximum_len = MAX_TIMESTAMP_BYTES + maintenance_identity.len() + 4;
386    let contents = match read_stamp_with_limit(&marker, maximum_len) {
387        Ok(Some(contents)) => contents,
388        Ok(None) => return Ok(true),
389        Err(error) if error.kind() == io::ErrorKind::NotFound => return Ok(true),
390        Err(source) => {
391            return Err(CacheFsError {
392                operation: "read cache maintenance time",
393                path: marker,
394                source,
395            });
396        }
397    };
398    let mut lines = contents.lines();
399    let Some(last_maintenance) = lines.next().and_then(decode_system_time) else {
400        return Ok(true);
401    };
402    if lines.next() != Some(maintenance_identity) {
403        return Ok(true);
404    }
405    Ok(match SystemTime::now().duration_since(last_maintenance) {
406        Ok(elapsed) => elapsed >= minimum_interval,
407        Err(_) => true,
408    })
409}
410
411pub(super) fn record_cache_maintenance(
412    path: &Path,
413    maintenance_identity: &str,
414) -> Result<(), CacheFsError> {
415    let marker = path.join(LAST_MAINTENANCE_FILE);
416    let elapsed = encode_system_time(&marker, SystemTime::now())?;
417    let contents = format!("{}\n{maintenance_identity}\n", elapsed.as_nanos());
418    ic_host_fs::durable::write_bytes(&marker, contents.as_bytes()).map_err(|source| CacheFsError {
419        operation: "record cache maintenance time",
420        path: marker,
421        source,
422    })
423}
424
425pub(super) fn perform_scheduled_cache_maintenance(
426    path: &Path,
427    minimum_interval: Option<Duration>,
428    maintenance_identity: &str,
429    maintenance: impl FnOnce() -> Result<ArtifactCachePruneReport, String>,
430) -> (Option<ArtifactCacheMaintenance>, Option<Duration>) {
431    let started = Instant::now();
432    match cache_maintenance_due(path, minimum_interval, maintenance_identity) {
433        Ok(false) => return (None, Some(started.elapsed())),
434        Ok(true) => {}
435        Err(error) => {
436            return (
437                Some(ArtifactCacheMaintenance::PruneFailed {
438                    message: error.to_string(),
439                }),
440                Some(started.elapsed()),
441            );
442        }
443    }
444
445    let result = maintenance();
446    let marker = record_cache_maintenance(path, maintenance_identity);
447    let outcome = match (result, marker) {
448        (Ok(report), Ok(())) => ArtifactCacheMaintenance::Pruned(report),
449        (Err(message), Ok(())) => ArtifactCacheMaintenance::PruneFailed { message },
450        (Ok(_), Err(error)) => ArtifactCacheMaintenance::PruneFailed {
451            message: error.to_string(),
452        },
453        (Err(message), Err(marker)) => ArtifactCacheMaintenance::PruneFailed {
454            message: format!(
455                "{message}; additionally failed to record the maintenance attempt: {marker}"
456            ),
457        },
458    };
459    (Some(outcome), Some(started.elapsed()))
460}
461
462pub(super) fn write_last_used(path: &Path, last_used: SystemTime) -> Result<(), CacheFsError> {
463    let marker = path.join(LAST_USED_FILE);
464    write_system_time(&marker, last_used, "record cache use time")
465}
466
467fn write_system_time(
468    path: &Path,
469    timestamp: SystemTime,
470    operation: &'static str,
471) -> Result<(), CacheFsError> {
472    let elapsed = encode_system_time(path, timestamp)?;
473    ic_host_fs::durable::write_bytes(path, elapsed.as_nanos().to_string().as_bytes()).map_err(
474        |source| CacheFsError {
475            operation,
476            path: path.to_owned(),
477            source,
478        },
479    )
480}
481
482fn encode_system_time(path: &Path, timestamp: SystemTime) -> Result<Duration, CacheFsError> {
483    timestamp
484        .duration_since(UNIX_EPOCH)
485        .map_err(|source| CacheFsError {
486            operation: "encode cache time",
487            path: path.to_owned(),
488            source: io::Error::new(io::ErrorKind::InvalidInput, source),
489        })
490}
491
492fn decode_system_time(contents: &str) -> Option<SystemTime> {
493    let nanoseconds = contents.parse::<u128>().ok()?;
494    let seconds = u64::try_from(nanoseconds / 1_000_000_000).ok()?;
495    let subsecond_nanos = (nanoseconds % 1_000_000_000) as u32;
496    UNIX_EPOCH.checked_add(Duration::new(seconds, subsecond_nanos))
497}
498
499pub(super) fn prune_direct_child_directories(
500    cache_root: &Path,
501    policy: ArtifactCachePrunePolicy,
502    protected_entry: Option<&Path>,
503    is_eligible: impl Fn(&Path) -> bool,
504) -> Result<ArtifactCachePruneReport, CacheFsError> {
505    let mut entries = cache_entries(cache_root, is_eligible)?;
506    let bytes_before = entries
507        .iter()
508        .fold(0_u64, |total, entry| total.saturating_add(entry.bytes));
509    let mut report = ArtifactCachePruneReport {
510        entries_scanned: entries.len(),
511        entries_removed: 0,
512        bytes_before,
513        bytes_removed: 0,
514        uncommitted_directories_removed: 0,
515        uncommitted_bytes_removed: 0,
516    };
517    let now = SystemTime::now();
518
519    if let Some(max_age) = policy.max_age() {
520        for entry in &mut entries {
521            let age = now.duration_since(entry.last_used).unwrap_or_default();
522            if protected_entry != Some(entry.path.as_path()) && age > max_age {
523                remove_cache_entry(entry, &mut report)?;
524            }
525        }
526    }
527
528    if let Some(max_size_bytes) = policy.max_size_bytes()
529        && report.bytes_retained() > max_size_bytes
530    {
531        entries.sort_by(|left, right| {
532            left.last_used
533                .cmp(&right.last_used)
534                .then_with(|| left.path.cmp(&right.path))
535        });
536        for entry in &mut entries {
537            if report.bytes_retained() <= max_size_bytes {
538                break;
539            }
540            if protected_entry == Some(entry.path.as_path()) {
541                continue;
542            }
543            remove_cache_entry(entry, &mut report)?;
544        }
545    }
546
547    Ok(report)
548}
549
550pub(super) fn directory_logical_size(path: &Path) -> io::Result<u64> {
551    let mut total = 0_u64;
552    let mut pending = vec![path.to_owned()];
553    while let Some(current) = pending.pop() {
554        let metadata = fs::symlink_metadata(&current)?;
555        if metadata.is_dir() {
556            for entry in fs::read_dir(&current)? {
557                let path = entry?.path();
558                let metadata = fs::symlink_metadata(&path)?;
559                if metadata.is_dir() {
560                    pending.push(path);
561                } else {
562                    total = total.saturating_add(metadata.len());
563                }
564            }
565        } else {
566            total = total.saturating_add(metadata.len());
567        }
568    }
569    Ok(total)
570}
571
572pub(super) fn is_sha256_directory(path: &Path) -> bool {
573    path.file_name().is_some_and(|name| {
574        let bytes = name.as_encoded_bytes();
575        bytes.len() == 64 && bytes.iter().all(u8::is_ascii_hexdigit)
576    })
577}
578
579pub(super) fn remove_path_if_present(path: &Path) -> io::Result<()> {
580    let metadata = match fs::symlink_metadata(path) {
581        Ok(metadata) => metadata,
582        Err(error) if error.kind() == io::ErrorKind::NotFound => return Ok(()),
583        Err(error) => return Err(error),
584    };
585    if metadata.file_type().is_dir() {
586        fs::remove_dir_all(path)
587    } else {
588        fs::remove_file(path)
589    }
590}
591
592struct CacheEntry {
593    path: PathBuf,
594    bytes: u64,
595    last_used: SystemTime,
596    removed: bool,
597}
598
599impl std::fmt::Display for CacheFsError {
600    fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
601        write!(
602            formatter,
603            "failed to {} at {}: {}",
604            self.operation,
605            self.path.display(),
606            self.source
607        )
608    }
609}
610
611impl std::error::Error for CacheFsError {
612    fn source(&self) -> Option<&(dyn std::error::Error + 'static)> {
613        Some(&self.source)
614    }
615}
616
617fn cache_entries(
618    cache_root: &Path,
619    is_eligible: impl Fn(&Path) -> bool,
620) -> Result<Vec<CacheEntry>, CacheFsError> {
621    let read_dir = match fs::read_dir(cache_root) {
622        Ok(read_dir) => read_dir,
623        Err(error) if error.kind() == io::ErrorKind::NotFound => return Ok(Vec::new()),
624        Err(source) => {
625            return Err(CacheFsError {
626                operation: "read cache directory",
627                path: cache_root.to_owned(),
628                source,
629            });
630        }
631    };
632    let mut entries = Vec::new();
633    for directory_entry in read_dir {
634        let directory_entry = directory_entry.map_err(|source| CacheFsError {
635            operation: "read cache entry",
636            path: cache_root.to_owned(),
637            source,
638        })?;
639        let path = directory_entry.path();
640        let file_type = directory_entry.file_type().map_err(|source| CacheFsError {
641            operation: "inspect cache entry",
642            path: path.clone(),
643            source,
644        })?;
645        if !file_type.is_dir() || !is_eligible(&path) {
646            continue;
647        }
648        let bytes = directory_logical_size(&path).map_err(|source| CacheFsError {
649            operation: "measure cache entry",
650            path: path.clone(),
651            source,
652        })?;
653        let last_used = cache_entry_last_used(&path).map_err(|source| CacheFsError {
654            operation: "read cache use time",
655            path: path.clone(),
656            source,
657        })?;
658        entries.push(CacheEntry {
659            path,
660            bytes,
661            last_used,
662            removed: false,
663        });
664    }
665    Ok(entries)
666}
667
668pub(super) fn cache_entry_last_used(path: &Path) -> io::Result<SystemTime> {
669    let marker = path.join(LAST_USED_FILE);
670    if let Ok(Some(contents)) = read_stamp_with_limit(&marker, MAX_TIMESTAMP_BYTES)
671        && let Some(timestamp) = decode_system_time(&contents)
672    {
673        return Ok(timestamp);
674    }
675    fs::metadata(path)?.modified()
676}
677
678fn remove_cache_entry(
679    entry: &mut CacheEntry,
680    report: &mut ArtifactCachePruneReport,
681) -> Result<(), CacheFsError> {
682    if entry.removed {
683        return Ok(());
684    }
685    let Some(_retention_lock) = try_lock_cache_file(&entry.path.join(RETENTION_LOCK_FILE))? else {
686        return Ok(());
687    };
688    remove_path_if_present(&entry.path).map_err(|source| CacheFsError {
689        operation: "prune cache entry",
690        path: entry.path.clone(),
691        source,
692    })?;
693    entry.removed = true;
694    report.entries_removed += 1;
695    report.bytes_removed = report.bytes_removed.saturating_add(entry.bytes);
696    Ok(())
697}
698
699#[cfg(test)]
700mod tests {
701    use super::directory_logical_size;
702    use crate::artifacts::test_support::unique_temp_directory;
703    use std::{
704        fs,
705        time::{Duration, SystemTime, UNIX_EPOCH},
706    };
707
708    #[cfg(unix)]
709    #[test]
710    fn final_retention_owner_releases_lock_with_a_duplicate_descriptor_open() {
711        let root = unique_temp_directory("retention-duplicate-descriptor");
712        let retained = super::RetainedCacheEntry::acquire(&root).unwrap();
713        // A process spawn can duplicate this descriptor before close-on-exec.
714        let inherited = retained._lock.0.try_clone().unwrap();
715        let clone = retained.clone();
716        let independently_retained = super::RetainedCacheEntry::acquire(&root).unwrap();
717        let lock_path = root.join(super::RETENTION_LOCK_FILE);
718        let available = || super::try_lock_cache_file(&lock_path).unwrap().is_some();
719        drop(retained);
720        assert!(!available(), "a record clone still retains the entry");
721        drop(clone);
722        assert!(
723            !available(),
724            "an independent acquisition still retains the entry"
725        );
726        drop(independently_retained);
727        assert!(
728            available(),
729            "descriptor duplication must not extend record ownership"
730        );
731        drop(inherited);
732        fs::remove_dir_all(root).unwrap();
733    }
734
735    #[test]
736    fn last_use_markers_preserve_timestamps_and_bounded_fallbacks() {
737        let root = unique_temp_directory("bounded-last-use-marker");
738        let marker = root.join(super::LAST_USED_FILE);
739        let modified = || fs::metadata(&root).unwrap().modified().unwrap();
740        assert_eq!(super::cache_entry_last_used(&root).unwrap(), modified());
741        for timestamp in [
742            UNIX_EPOCH + Duration::from_nanos(123),
743            SystemTime::now() + Duration::from_secs(3600),
744        ] {
745            super::write_last_used(&root, timestamp).unwrap();
746            assert_eq!(super::cache_entry_last_used(&root).unwrap(), timestamp);
747        }
748        let overflowing_timestamp = u128::MAX.to_string();
749        for invalid in [
750            b"invalid".as_slice(),
751            overflowing_timestamp.as_bytes(),
752            &[0xff],
753        ] {
754            fs::write(&marker, invalid).unwrap();
755            assert_eq!(super::cache_entry_last_used(&root).unwrap(), modified());
756        }
757        fs::File::create(&marker)
758            .unwrap()
759            .set_len(1024 * 1024 * 1024)
760            .unwrap();
761        assert_eq!(super::cache_entry_last_used(&root).unwrap(), modified());
762        fs::remove_file(&marker).unwrap();
763        fs::create_dir(&marker).unwrap();
764        assert_eq!(super::cache_entry_last_used(&root).unwrap(), modified());
765        fs::remove_dir_all(root).unwrap();
766    }
767
768    #[test]
769    fn maintenance_markers_preserve_policy_intervals_and_read_errors() {
770        let root = unique_temp_directory("bounded-maintenance-marker");
771        let marker = root.join(super::LAST_MAINTENANCE_FILE);
772        let identity = super::ArtifactCachePrunePolicy::new().maintenance_identity();
773        let interval = Some(Duration::from_secs(3600));
774        let due = || super::cache_maintenance_due(&root, interval, &identity).unwrap();
775        assert!(due());
776        super::record_cache_maintenance(&root, &identity).unwrap();
777        assert!(!due());
778        assert!(super::cache_maintenance_due(&root, interval, "other-policy").unwrap());
779        assert!(super::cache_maintenance_due(&root, Some(Duration::ZERO), &identity).unwrap());
780
781        let now = SystemTime::now().duration_since(UNIX_EPOCH).unwrap();
782        for suffix in ["", "\r\n"] {
783            fs::write(&marker, format!("{}\r\n{identity}{suffix}", now.as_nanos())).unwrap();
784            assert!(!due());
785        }
786        for timestamp in [
787            "invalid".to_owned(),
788            "0".to_owned(),
789            (now + Duration::from_secs(3600)).as_nanos().to_string(),
790        ] {
791            fs::write(&marker, format!("{timestamp}\n{identity}\n")).unwrap();
792            assert!(due());
793        }
794        super::record_cache_maintenance(&root, &identity).unwrap();
795        fs::OpenOptions::new()
796            .write(true)
797            .open(&marker)
798            .unwrap()
799            .set_len(1024 * 1024 * 1024)
800            .unwrap();
801        assert!(due());
802
803        fs::write(&marker, [0xff]).unwrap();
804        let error = super::cache_maintenance_due(&root, interval, &identity).unwrap_err();
805        assert_eq!(error.operation, "read cache maintenance time");
806        assert_eq!(error.path, marker);
807        assert_eq!(error.source.kind(), std::io::ErrorKind::InvalidData);
808        fs::remove_file(&marker).unwrap();
809        fs::create_dir(&marker).unwrap();
810        assert!(super::cache_maintenance_due(&root, interval, &identity).is_err());
811        assert!(super::cache_maintenance_due(&root, None, &identity).unwrap());
812        fs::remove_dir_all(root).unwrap();
813    }
814
815    #[test]
816    fn cache_directory_tags_preserve_valid_standard_signatures() {
817        let root = unique_temp_directory("cache-tag-signatures");
818        let tag = root.join("CACHEDIR.TAG");
819        let signature = "Signature: 8a477f597d28d172789f06886806bc55";
820        for contents in [
821            signature.to_owned(),
822            format!("{signature}\r\n# Created by another application\r\n"),
823            format!("{signature}\n# {}\n", "comment".repeat(100_000)),
824        ] {
825            fs::write(&tag, &contents).unwrap();
826            super::ensure_cache_directory_tag(&root).unwrap();
827            assert_eq!(fs::read_to_string(&tag).unwrap(), contents);
828        }
829        for invalid in ["", &signature[..42], "Signature: incorrect"] {
830            fs::write(&tag, invalid).unwrap();
831            super::ensure_cache_directory_tag(&root).unwrap();
832            assert_eq!(
833                fs::read_to_string(&tag).unwrap(),
834                super::CACHE_DIRECTORY_TAG
835            );
836        }
837        fs::remove_dir_all(root).unwrap();
838    }
839
840    #[test]
841    #[cfg(unix)]
842    fn cache_directory_tag_replaces_symlinks_without_changing_referents() {
843        let root = unique_temp_directory("cache-tag-symlink");
844        let referent = root.join("other-application-tag");
845        let contents = "Signature: 8a477f597d28d172789f06886806bc55\n# Preserve this file\n";
846        fs::write(&referent, contents).unwrap();
847        let tag = root.join("CACHEDIR.TAG");
848        std::os::unix::fs::symlink(&referent, &tag).unwrap();
849        super::ensure_cache_directory_tag(&root).unwrap();
850        assert!(fs::symlink_metadata(&tag).unwrap().file_type().is_file());
851        assert_eq!(fs::read_to_string(&referent).unwrap(), contents);
852        assert_eq!(
853            fs::read_to_string(&tag).unwrap(),
854            super::CACHE_DIRECTORY_TAG
855        );
856
857        fs::remove_file(&tag).unwrap();
858        fs::create_dir(&tag).unwrap();
859        let error = super::ensure_cache_directory_tag(&root).unwrap_err();
860        assert_eq!(error.operation, "write cache directory tag");
861        assert!(tag.is_dir());
862        fs::remove_dir_all(root).unwrap();
863    }
864
865    #[test]
866    fn directory_size_sums_wide_and_nested_files() {
867        let root = unique_temp_directory("directory-logical-size");
868        assert_eq!(directory_logical_size(&root).unwrap(), 0);
869        fs::create_dir_all(root.join("wide")).unwrap();
870        fs::create_dir_all(root.join("nested/deep/empty")).unwrap();
871        let mut expected = 0;
872        for index in 0..128 {
873            let bytes = vec![42; index % 13];
874            fs::write(root.join("wide").join(index.to_string()), &bytes).unwrap();
875            expected += bytes.len() as u64;
876        }
877        let sparse = root.join("nested/deep/sparse");
878        fs::File::create(&sparse)
879            .unwrap()
880            .set_len(1024 * 1024)
881            .unwrap();
882        assert_eq!(directory_logical_size(&sparse).unwrap(), 1024 * 1024);
883        assert_eq!(
884            directory_logical_size(&root).unwrap(),
885            expected + 1024 * 1024
886        );
887        assert_eq!(
888            directory_logical_size(&root.join("missing"))
889                .unwrap_err()
890                .kind(),
891            std::io::ErrorKind::NotFound,
892        );
893        fs::remove_dir_all(root).unwrap();
894    }
895
896    #[test]
897    #[cfg(unix)]
898    fn directory_size_counts_symlinks_without_following_them() {
899        let root = unique_temp_directory("directory-size-symlinks");
900        let walked = root.join("walked");
901        fs::create_dir_all(&walked).unwrap();
902        fs::create_dir_all(root.join("external")).unwrap();
903        fs::write(root.join("external/payload"), vec![42; 4096]).unwrap();
904        fs::write(root.join("outside-file"), vec![42; 4096]).unwrap();
905        fs::write(walked.join("payload"), b"abc").unwrap();
906        let targets = ["../external", "../outside-file", "missing", "."];
907        for (index, target) in targets.iter().enumerate() {
908            std::os::unix::fs::symlink(target, walked.join(index.to_string())).unwrap();
909        }
910        let expected = 3 + targets
911            .iter()
912            .map(|target| target.len() as u64)
913            .sum::<u64>();
914        assert_eq!(directory_logical_size(&walked).unwrap(), expected);
915        assert_eq!(
916            directory_logical_size(&walked.join("0")).unwrap(),
917            targets[0].len() as u64,
918        );
919        fs::remove_dir_all(root).unwrap();
920    }
921}