Merge branch 'main' into golangci-v2.12.2
Absorbs the cache size management and LRU eviction work (#55). All four textual conflicts resolved in favor of main's implementation, with this branch's mechanical lint conformance re-applied on top: - internal/config/config.go: took main's cache_max_bytes wiring (CacheMaxBytes, cacheMaxBytesExplicit) verbatim and expressed the key through this branch's constant convention as keyCacheMaxBytes. - internal/imgcache/cache.go: took main's disabled-cache guards, LRU touch on lookup, and variant_content size accounting verbatim; re-applied this branch's signature wrapping for lll. - internal/imgcache/storage.go: took main's new writeIfAbsent helper and its temp-file cleanup defer verbatim. The auto-merge had silently dropped that defer in favor of this branch's inline cleanup form; restored so the cleanup semantics that arrived from main are intact. - TODO.md: kept both sides' Completed Steps entries. .golangci.yml resolves to this branch's canonical version (sha256 021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb). make build and make test are green; #55's code is not yet conformant with the canonical lint config, which the following commits address.
This commit is contained in:
30
TODO.md
30
TODO.md
@@ -12,15 +12,14 @@
|
||||
|
||||
pre-1.0. No git tags exist. Recent work extracted the internal/magic,
|
||||
internal/allowlist, internal/httpfetcher, and internal/signature
|
||||
packages. The gosec findings from the 2026-07-06 survey are resolved:
|
||||
the last two open findings (G124, session cookie attributes in
|
||||
internal/session) are fixed as of this change, so `make check` is green
|
||||
on main.
|
||||
packages. The gosec findings from the 2026-07-06 survey are resolved
|
||||
and `make check` is green on main. The disk cache is now size-bounded
|
||||
with LRU eviction (`cache_max_bytes`), closing the unbounded disk
|
||||
growth DoS vector.
|
||||
|
||||
# Next Step
|
||||
|
||||
P0: implement cache size management and eviction so the disk cannot
|
||||
fill up
|
||||
P1: implement blocked networks configuration to extend SSRF protection
|
||||
|
||||
# Completed Steps
|
||||
|
||||
@@ -34,6 +33,23 @@ fill up
|
||||
`testpackage` — white-box test files renamed to
|
||||
`*_internal_test.go`); three `//nolint:tagliatelle` directives keep
|
||||
the snake_case JSON wire/disk formats unchanged; `make check` green
|
||||
- 2026-08-07 implement cache size management and eviction (closes
|
||||
#51): new `cache_max_bytes` config key validated by the startup
|
||||
framework (explicit values used exactly with no floor, `0` disables
|
||||
the disk cache entirely, omitted defaults to max(75% of free space
|
||||
on the filesystem containing `<state_dir>/cache/`, 500 MiB), logged
|
||||
at startup); processed variants are now tracked in the database (a
|
||||
new `variant_content` table and an LRU timestamp on `source_content`)
|
||||
so total usage is two SUMs, never a directory scan on the hot path; a
|
||||
background goroutine evicts globally least-recently-used entries
|
||||
(variants and source blobs merged) to the limit, woken by a periodic
|
||||
ticker and by write-pressure notifications from stores; a source
|
||||
blob and ALL of its `source_metadata` references are deleted in one
|
||||
transaction before the file is unlinked, so multi-referenced blobs
|
||||
are never removed while referenced and rows never point at deleted
|
||||
files; a startup and periodic reconciliation pass adopts untracked
|
||||
variant files, drops rows for missing files, removes unreachable
|
||||
source blobs, and sweeps stale temp files
|
||||
- 2026-08-07 validate configuration on startup, fail fast on bad
|
||||
config (closes #52): a config value that is set but unparseable or
|
||||
invalid aborts startup naming the key and value (defaults apply only
|
||||
@@ -89,8 +105,6 @@ fill up
|
||||
|
||||
# Future Steps
|
||||
|
||||
- P1: implement blocked networks configuration to extend SSRF
|
||||
protection
|
||||
- P1: rate limit global concurrent upstream fetches to prevent
|
||||
resource exhaustion
|
||||
- P1: strip EXIF and other metadata from processed images (privacy)
|
||||
|
||||
Reference in New Issue
Block a user