5 Commits
Author SHA1 Message Date
clawbot fbe45af544 Test that a reconciliation pass logs nothing once cancelled
check / check (push) Failing after 2s
A reconciliation pass run with an already cancelled context logs no
warning, so a periodic tick the eviction loop takes after a stop adds
no warning to the one from the pass the stop interrupted.

Model: opus-5-5
2026-10-04 06:49:02 +00:00
clawbot b9d32985f6 Start no eviction pass after a stop, and end a pass quietly
Both pass runners do nothing once the loop's context is cancelled, so
a stop no longer starts an eviction pass after a cancelled
reconciliation or on a pending write-pressure wakeup or tick. In
evictBatch, a candidate that fails after cancellation ends the batch
with the context's error instead of logging its own warning; this
replaces the check before each candidate, since every candidate
started after cancellation fails at its first database call. A stop
now logs at most one warning.

Model: opus-5-5
2026-10-04 06:45:53 +00:00
clawbot 92e48a7a91 Test the warnings a stop logs and stopping between eviction candidates
The stop-during-reconciliation test now also expects exactly one
warning; it fails while the loop still starts an eviction pass after a
cancelled reconciliation. A new test cancels the context while the
oldest of three source blobs is evicted and expects EvictToLimit to
return context.Canceled, leave the other two on disk and log no
warning for them.

Model: opus-5-5
2026-10-04 06:45:53 +00:00
clawbot d930e352b0 Stop cache eviction in progress at shutdown (closes #102)
StartEviction runs the eviction goroutine with its own context, which
StopEviction cancels in place of the old stop channel, so a pass in
progress stops at its next database call, file, row or eviction
candidate instead of running to completion. StopEviction takes a
context: when it ends before the goroutine exits, StopEviction stops
waiting and returns an error wrapping it. The handlers' stop hook
passes fx's stop context, so an eviction still running at fx's stop
deadline fails the stop and the exit code is 1. The contextcheck
suppression on the start hook stays, with a one-line reason: the loop
outlives OnStart.

Model: opus-5-5
2026-10-04 06:45:53 +00:00
clawbot 6830bdc5de Remove unimplemented Purge and three unused interfaces (closes #73)
check / check (push) Failing after 2s
Purge only returned an error and nothing called it, so it is gone from
the ImageCache interface and from Service, along with its error value.
It can be added back when something needs it; eviction reclaims disk
space meanwhile. The SignatureValidator, Allowlist and Storage
interfaces in imgcache.go had no implementers and no users, and
described types that look different from the real ones, so they are
deleted. No behaviour changes.

Model: opus-5-5
2026-10-04 08:41:37 +02:00
4 changed files with 32 additions and 39 deletions
+5
View File
@@ -38,6 +38,11 @@ P2: security: referer blacklist
goroutine exits, stops waiting and returns its error; the handlers' stop hook
passes fx's stop context, so an eviction still running when fx's stop
deadline ends fails the stop and makes the exit code 1.
- 2026-10-04 dead code in `internal/imgcache` is gone (closes #73): `Purge`,
which only returned an error and which nothing called, is no longer part of
the `ImageCache` interface or `Service`; the `SignatureValidator`,
`Allowlist` and `Storage` interfaces, which nothing implemented or used, are
deleted. Nothing else changes.
- 2026-10-04 upstream host semaphores and variant `.meta` files no longer
outlive their use (closes #87): the fetcher counts the fetches holding or
waiting for a slot of each upstream host's semaphore and removes the host's
@@ -1077,6 +1077,30 @@ func TestReconciliationWalksStopOnceCancelled(t *testing.T) {
}
}
// TestReconciliationPassLogsNoWarningOnceCancelled checks that a
// reconciliation pass run with an already cancelled context logs no
// warning, so a periodic tick the loop takes after a stop adds no
// warning to the one from the pass the stop interrupted.
func TestReconciliationPassLogsNoWarningOnceCancelled(t *testing.T) {
t.Parallel()
cache, _ := newEvictionTestCache(t, 1<<30)
var logBuf bytes.Buffer
cache.log = slog.New(slog.NewJSONHandler(&logBuf, nil))
ctx, cancel := context.WithCancel(t.Context())
cancel()
cache.runReconciliationPass(ctx)
t.Logf("log output: %s", logBuf.String())
if strings.Contains(logBuf.String(), `"level":"WARN"`) {
t.Errorf("runReconciliationPass logged a warning with a cancelled context")
}
}
// TestEvictSourceBlobExcludesConcurrentStoreOfIdenticalContent exercises
// the exact TOCTOU window between evictSourceBlob's row-deletion
// transaction commit and its content file unlink: a concurrent
-30
View File
@@ -5,7 +5,6 @@ import (
"context"
"errors"
"io"
"net/url"
"time"
)
@@ -154,9 +153,6 @@ type ImageCache interface {
// Warm pre-fetches and caches an image without returning it
Warm(ctx context.Context, req *ImageRequest) error
// Purge removes a cached image
Purge(ctx context.Context, req *ImageRequest) error
// Stats returns cache statistics
Stats(ctx context.Context) (*CacheStats, error)
}
@@ -176,29 +172,3 @@ type CacheStats struct {
// HitRate is HitCount / (HitCount + MissCount)
HitRate float64
}
// SignatureValidator validates request signatures
type SignatureValidator interface {
// Validate checks if the signature is valid for the request
Validate(req *ImageRequest) error
// Generate creates a signature for a request
Generate(req *ImageRequest) string
}
// Allowlist checks if a URL is allowlisted (no signature required)
type Allowlist interface {
// IsAllowlisted returns true if the URL doesn't require a signature
IsAllowlisted(u *url.URL) bool
}
// Storage handles persistent storage of cached content
type Storage interface {
// Store saves content and returns its hash
Store(ctx context.Context, content io.Reader) (hash string, err error)
// Load retrieves content by hash
Load(ctx context.Context, hash string) (io.ReadCloser, error)
// Delete removes content by hash
Delete(ctx context.Context, hash string) error
// Exists checks if content exists
Exists(ctx context.Context, hash string) (bool, error)
}
+3 -9
View File
@@ -56,11 +56,10 @@ type ServiceConfig struct {
Logger *slog.Logger
}
// Static errors for service construction and unimplemented operations.
// Static errors for service construction.
var (
errCacheRequired = errors.New("cache is required")
errSigningKeyRequired = errors.New("signing key is required")
errPurgeNotImplemented = errors.New("purge not implemented")
errCacheRequired = errors.New("cache is required")
errSigningKeyRequired = errors.New("signing key is required")
)
// NewService creates a new image service.
@@ -189,11 +188,6 @@ func (s *Service) Warm(ctx context.Context, req *ImageRequest) error {
return err
}
// Purge removes a cached image. Purging is not implemented yet.
func (s *Service) Purge(_ context.Context, _ *ImageRequest) error {
return errPurgeNotImplemented
}
// Stats returns cache statistics.
func (s *Service) Stats(ctx context.Context) (*CacheStats, error) {
return s.cache.Stats(ctx)