summaryrefslogtreecommitdiffstats
path: root/packages/meshbay-node/tests/test_disk_io_off_loop.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-18 16:13:53 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-18 16:13:53 +0200
commit20b906057d1c1df810cd0c2cfe235c27df9f3e5f (patch)
treeef36187c7423ca127a36d57a3ce92fda66496349 /packages/meshbay-node/tests/test_disk_io_off_loop.py
parent5fa158fab709d3d24a33318b3d910f75c051af2e (diff)
downloadmeshbay-20b906057d1c1df810cd0c2cfe235c27df9f3e5f.tar.gz
fix(node): creating and removing a folder are syscalls too
The last two handlers on the loop. Both were synchronous, so a member creating a folder on a root that had spun down held the node for the spin-up, exactly as a chunk read did. Where a check and an act belong together they are now one call rather than two awaits, and the single disk thread is what makes that atomic: `_mkdir_if_absent` so two members creating the same name cannot both find nothing there and have the second `mkdir` raise where a refusal was meant, and `_rmdir_if_empty` for the reason the caller already re-tested emptiness — the first test happened before a round trip to the operator's browser, and a file can land in between. Two awaits would reopen that window one size smaller. The guard is now the whole class rather than the calls that were fixed. It walks the module's syntax tree and fails on any filesystem call outside the handful of functions written to be run through `off_disk` — a new handler that stats a root inline would pass every measured test, because those exercise the handlers that exist today. Checked by putting a call back: it names the function and the line. It leaves ffmpeg's own scratch files out, listed rather than silently allowed: they are under `tempfile.mkstemp` on the system disk, not on a group root, so they are not what spins down — but they do read a whole transcode into memory from the loop, and the day that matters it is a different measurement from this one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-node/tests/test_disk_io_off_loop.py')
-rw-r--r--packages/meshbay-node/tests/test_disk_io_off_loop.py84
1 files changed, 60 insertions, 24 deletions
diff --git a/packages/meshbay-node/tests/test_disk_io_off_loop.py b/packages/meshbay-node/tests/test_disk_io_off_loop.py
index 2811836..2179e66 100644
--- a/packages/meshbay-node/tests/test_disk_io_off_loop.py
+++ b/packages/meshbay-node/tests/test_disk_io_off_loop.py
@@ -19,8 +19,8 @@ means two reads of the same file can never be inside it at once, and that is
what makes the single `f.seek()`/`f.read()` pair safe without a lock.
"""
+import ast
import asyncio
-import re
import threading
import time
from pathlib import Path
@@ -204,29 +204,6 @@ async def test_one_root_set_reads_one_chunk_at_a_time(tmp_path):
assert peak == 1, f"{peak} reads of one root set were inside the disk at once"
-def test_no_handler_resolves_a_path_on_the_loop():
- """
- `entry_abs_path` is `Path.resolve()`, which is syscalls — it belongs on the
- disk thread with everything else.
-
- This reads the source because there is nothing else to read: a handler added
- later that resolves an entry inline would pass every test above, since those
- only exercise the handlers that exist today. `_locate` is the one place
- allowed to call it, and `off_disk` is how `_locate` is reached.
- """
- src = Path(webrtc_server.__file__).read_text()
- # Every call site, not the first one: a guard that stops at the first
- # occurrence stops guarding the moment a new call is inserted above it.
- calls = [m.start() for m in re.finditer(r"\bentry_abs_path\(", src)]
- body = re.search(r"\ndef _locate\(.*?\n(?=\n\ndef |\n\nclass )", src, re.S)
- assert body, "_locate is gone or has been renamed — this guard needs rewriting"
- allowed = range(body.start(), body.end())
- stray = [c for c in calls if c not in allowed]
- assert not stray, (
- f"{len(stray)} call(s) to entry_abs_path outside _locate: "
- f"resolve a path through `off_disk(roots, _locate, ...)` instead")
-
-
async def test_the_availability_poll_does_not_stop_the_loop(tmp_path, monkeypatch):
"""
The poll is the one that runs whether anybody asked for anything.
@@ -255,6 +232,65 @@ async def test_the_availability_poll_does_not_stop_the_loop(tmp_path, monkeypatc
f"the loop was blocked: {ticker.ticks} wake-ups during a {SLOW_S}s poll")
+def test_no_handler_touches_the_disk_on_the_loop():
+ """
+ The whole class, not the calls that were fixed.
+
+ Every measured test above exercises a handler that exists today; a new one
+ that stats a root inline would pass all of them. So this walks the module's
+ syntax tree instead and fails on any filesystem call outside the few
+ functions written to be run through `off_disk`.
+
+ `entry_abs_path` and `safe_subdir` are in the list because both are
+ `Path.resolve()` underneath, and a resolve is syscalls whatever it is
+ called.
+ """
+ blocking = {"is_dir", "exists", "mkdir", "unlink", "rename", "rmdir",
+ "iterdir", "read_bytes", "write_bytes", "stat",
+ "resolve", "entry_abs_path"}
+ # Written to block, and reached only through `off_disk`.
+ on_the_disk_thread = {"_locate", "_append_chunk", "_read_and_encrypt",
+ "_mkdir_if_absent", "_is_empty_dir", "_rmdir_if_empty",
+ "safe_subdir"}
+ # ffmpeg's own output, under `tempfile.mkstemp` on the system disk — not a
+ # group root, so not what spins down. Listed rather than silently allowed:
+ # these still read a whole transcode into memory from the loop, and the day
+ # that matters it is a different measurement from this one.
+ ffmpeg_scratch = {"_transcode_audio_to_aac", "_seek_lands_at",
+ "_extract_subtitle_to_webvtt"}
+ allowed = on_the_disk_thread | ffmpeg_scratch
+
+ found = []
+
+ def visit(node, owner):
+ for child in ast.iter_child_nodes(node):
+ if isinstance(child, (ast.FunctionDef, ast.AsyncFunctionDef)):
+ visit(child, child.name)
+ continue
+ if isinstance(child, ast.Call):
+ fn = child.func
+ name = (fn.attr if isinstance(fn, ast.Attribute)
+ else getattr(fn, "id", ""))
+ if name in blocking and owner not in allowed:
+ found.append(f"{owner} calls {name}() at line {child.lineno}")
+ visit(child, owner)
+
+ tree = ast.parse(Path(webrtc_server.__file__).read_text())
+ for node in tree.body:
+ if isinstance(node, ast.ClassDef):
+ for member in node.body:
+ if isinstance(member, (ast.FunctionDef, ast.AsyncFunctionDef)):
+ visit(member, member.name)
+ elif isinstance(node, (ast.FunctionDef, ast.AsyncFunctionDef)):
+ visit(node, node.name)
+
+ assert not found, (
+ "filesystem calls made from the event loop:\n "
+ + "\n ".join(found)
+ + "\nRun them through `off_disk(roots, ...)`, or put the call in a "
+ "helper that is only reached that way.")
+
+
def _upload_session(tmp_path):
"""One connection into a group with one writable root, as a node has."""
shared = tmp_path / "shared"