fix(ci): release verified RAW Recovery file caches before RAM admission

This commit is contained in:
dh committed 2026-10-05 13:41:11 +02:00
1 parent ec5508e978
commit cae38b014f
2 files changed
+27 -3

No files matched your search

+24 -2
View File
@@ -503,7 +503,7 @@ static class NativeDiagnostic
}
static readonly string RawRecoveryPreparation = """
local raw="$dest.raw" pending="$dest.raw.tmp" source_hash after_hash raw_hash
local raw="$dest.raw" pending="$dest.raw.tmp" source_hash after_hash raw_hash cache_before cache_after
[ ! -e "$raw" ] && [ ! -e "$pending" ] && [ ! -e "$raw.json" ] || {
error 'RAW Recovery output already exists.'; return 1;
}
@@ -522,6 +522,17 @@ static class NativeDiagnostic
error 'Patched DMG changed during RAW conversion.'
return 1
fi
# These verified owned files are not guest RAM. Release only their
# persisted data cache before Dockur computes its cgroup RAM allowance.
cache_before=$(cat /sys/fs/cgroup/memory.current 2>/dev/null || printf unavailable)
if ! dd of="$pending" oflag=nocache conv=nocreat,notrunc,fdatasync count=0 status=none ||
! dd of="$source" oflag=nocache conv=nocreat,notrunc,fdatasync count=0 status=none; then
rm -f "$pending"
error 'Failed to release the verified Recovery file caches before RAM admission.'
return 1
fi
cache_after=$(cat /sys/fs/cgroup/memory.current 2>/dev/null || printf unavailable)
info "[recovery-raw-cache] files=two-owned memory-current-before=$cache_before memory-current-after=$cache_after"
if ! mv -f "$source" "$dest" || ! mv -f "$pending" "$raw"; then
rm -f "$pending"
error 'Failed to retain the patched DMG and equivalent RAW Recovery.'
@@ -572,10 +583,19 @@ static class NativeDiagnostic
*) return 65 ;;
esac
}
dd() {
[ "$2 $3 $4 $5" = 'oflag=nocache conv=nocreat,notrunc,fdatasync count=0 status=none' ] || return 65
case "$1" in
"of=$pending") [ "$TEST_CASE" != raw-cache-failed ] || return 1 ;;
"of=$source") [ "$TEST_CASE" != source-cache-failed ] || return 1 ;;
*) return 65 ;;
esac
printf '%s\n' "$1" >> "$dest.cache-eviction"
}
""";
var script = realScript.Replace(preparation, mock + "\n" + preparation, StringComparison.Ordinal);
File.WriteAllText(Path.Combine(output, "raw-recovery-mock-fixture.sh"), script);
var cases = new[] { "equal", "convert-failed", "compare-failed", "source-mutated" };
var cases = new[] { "equal", "convert-failed", "compare-failed", "source-mutated", "raw-cache-failed", "source-cache-failed" };
foreach (var name in cases)
{
var folder = Path.Combine(output, "raw-recovery-" + name);
@@ -588,6 +608,8 @@ static class NativeDiagnostic
if ((result.ExitCode == 0) != passed || passed && (!File.Exists(destination + ".raw") || !File.ReadAllBytes(destination + ".raw").SequenceEqual(bytes) || !File.ReadAllBytes(destination).SequenceEqual(bytes))
|| !passed && File.Exists(destination + ".raw"))
throw new InvalidOperationException("RAW Recovery preparation behavior failed: " + name);
if (passed && (!File.Exists(destination + ".cache-eviction") || !File.ReadAllLines(destination + ".cache-eviction").SequenceEqual(new[] { "of=" + destination + ".raw.tmp", "of=" + input })))
throw new InvalidOperationException("RAW Recovery must release only the two verified files' caches before retaining them.");
}
var entry = File.ReadAllText(Path.Combine(output, "container-entry.sh"));
var selectionStart = entry.IndexOf("# BEGIN raw Recovery backend", StringComparison.Ordinal);