diff options
Diffstat (limited to 'docs')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 11 | ||||
| -rw-r--r-- | docs/USERGUIDE.md | 5 |
2 files changed, 14 insertions, 2 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index c0ccbbc..47fe62a 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -1693,6 +1693,17 @@ Five protections, and they are the substance: disk one capped file at a time; - the target root must be **writable and available**, enforced by the node. +**A full disk is a stated refusal, `disk_full`.** At chunk 0 the node compares the +announced size (`total_chunks` × the chunk's length, an upper bound within one +chunk) with the free space of the destination's filesystem, and refuses when the +upload would leave less than `DISK_RESERVE_BYTES` (1 GiB) — a disk filled to its +last byte breaks the node's own databases and the operator's system too. Two +uploads can pass that check together, so a write that fails with `ENOSPC` or +`EDQUOT` is refused the same way, and its `.part` and state are dropped: they +cannot be finished until the operator makes room, and keeping them holds the +space that ran out. The client carries the code on the error and translates it, +so a caller can stop rather than retry. + **There is no quarantine subdirectory.** A folder appearing beside the operator's library because somebody sent a file is the node deciding how their disk is arranged. What made a quarantine worth having was never the subdirectory — it is diff --git a/docs/USERGUIDE.md b/docs/USERGUIDE.md index f7e3c72..7afb77b 100644 --- a/docs/USERGUIDE.md +++ b/docs/USERGUIDE.md @@ -1040,8 +1040,9 @@ Better to know now than to go looking for it: text recognition. - **There is no overall storage quota.** Files are capped at 8 GB each — lower or raise it on the node, above — but somebody can still fill a disk one file - at a time. Worth a glance now and then if you have opened a folder to people - you do not know well. + at a time, up to the last gigabyte: the node always keeps 1 GB free, and + refuses uploads beyond that with "The node's disk is full". Worth a glance + now and then if you have opened a folder to people you do not know well. - **Searching the film database by hand has no per-member limit**, and it draws on the node's own quota. Only likely to matter on a large group. - **The record of who uploaded what belongs to the node.** It is kept and it is |