diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-09 18:23:52 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-09 18:23:56 +0200 |
| commit | c85c7f48e8f29923038d4c90cc1a6f9b8bcd7673 (patch) | |
| tree | 10a5a62416bafd58c891e1fff290036bb75c7318 /docs/MESHBAY_DESIGN.md | |
| parent | fbc2c5d86aed931be38c5fccfff75190eb4d16d1 (diff) | |
| download | meshbay-c85c7f48e8f29923038d4c90cc1a6f9b8bcd7673.tar.gz | |
feat(node): refuse an upload on a full disk with a stated reason
Nothing on the upload path knew about ENOSPC: a write that found no room
raised out of the handler, the catch-all answered "Request failed", and the
.part stayed behind holding the space that had run out. The node now refuses
with `disk_full` at chunk 0 when the announced size would leave less than
1 GiB free, and at any write that fails with ENOSPC/EDQUOT, dropping the
partial. The client carries the code on the error and the transfers panel
says "The node's disk is full" in every catalogue.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 11 |
1 files changed, 11 insertions, 0 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index c0ccbbc..47fe62a 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -1693,6 +1693,17 @@ Five protections, and they are the substance: disk one capped file at a time; - the target root must be **writable and available**, enforced by the node. +**A full disk is a stated refusal, `disk_full`.** At chunk 0 the node compares the +announced size (`total_chunks` × the chunk's length, an upper bound within one +chunk) with the free space of the destination's filesystem, and refuses when the +upload would leave less than `DISK_RESERVE_BYTES` (1 GiB) — a disk filled to its +last byte breaks the node's own databases and the operator's system too. Two +uploads can pass that check together, so a write that fails with `ENOSPC` or +`EDQUOT` is refused the same way, and its `.part` and state are dropped: they +cannot be finished until the operator makes room, and keeping them holds the +space that ran out. The client carries the code on the error and translates it, +so a caller can stop rather than retry. + **There is no quarantine subdirectory.** A folder appearing beside the operator's library because somebody sent a file is the node deciding how their disk is arranged. What made a quarantine worth having was never the subdirectory — it is |