diff --git a/atomicwrite.go b/atomicwrite.go new file mode 100644 index 0000000..72ba70c --- /dev/null +++ b/atomicwrite.go @@ -0,0 +1,56 @@ +package util + +import ( + "os" + "path/filepath" +) + +// AtomicWriteFile writes data to path without ever leaving a half-written file +// behind. It writes to a temporary file in the same directory, flushes it to +// disk, gives it the mode in perm and renames it over path, so anything reading +// path sees either the previous contents or the complete new contents and +// never something in between. If any step fails, the temporary file is removed +// and path is left as it was. +// +// The temporary file has to live in the same directory as path, because a +// rename across two filesystems is not possible and would not be instant if it +// were. +// +// Two details differ from os.WriteFile. The mode is applied after the file is +// created, so perm is what the finished file ends up with rather than perm with +// the process umask taken out of it. And the directory holding the file is not +// flushed, so a machine that loses power immediately after this returns may +// come back with the rename undone, even though the data itself was written. +func AtomicWriteFile(path string, data []byte, perm os.FileMode) error { + directory := filepath.Dir(path) + + temporary, err := os.CreateTemp(directory, "."+filepath.Base(path)+".tmp") + if err != nil { + return err + } + temporaryPath := temporary.Name() + + // Does nothing once the rename below has succeeded, because by then the + // temporary name no longer refers to anything. + defer os.Remove(temporaryPath) + + if _, err := temporary.Write(data); err != nil { + temporary.Close() + return err + } + + if err := temporary.Sync(); err != nil { + temporary.Close() + return err + } + + if err := temporary.Close(); err != nil { + return err + } + + if err := os.Chmod(temporaryPath, perm); err != nil { + return err + } + + return os.Rename(temporaryPath, path) +} diff --git a/atomicwrite_test.go b/atomicwrite_test.go new file mode 100644 index 0000000..749b336 --- /dev/null +++ b/atomicwrite_test.go @@ -0,0 +1,110 @@ +package util + +import ( + "os" + "path/filepath" + "testing" +) + +func TestAtomicWriteFile(t *testing.T) { + tests := []struct { + name string + existing string + data []byte + perm os.FileMode + }{ + {"a new file", "", []byte("hello"), 0644}, + {"replacing a shorter file", "old", []byte("a much longer set of contents"), 0644}, + {"replacing a longer file", "a much longer set of contents", []byte("new"), 0644}, + {"an empty payload", "something", []byte{}, 0644}, + {"a nil payload", "something", nil, 0644}, + {"a private mode", "", []byte("secret"), 0600}, + {"an executable mode", "", []byte("#!/bin/sh\n"), 0755}, + {"binary contents", "", []byte{0x00, 0xff, 0x10, 0x00}, 0644}, + } + + for _, test := range tests { + t.Run(test.name, func(t *testing.T) { + directory := t.TempDir() + path := filepath.Join(directory, "target") + + if test.existing != "" { + if err := os.WriteFile(path, []byte(test.existing), 0666); err != nil { + t.Fatalf("could not write the file to be replaced: %v", err) + } + } + + if err := AtomicWriteFile(path, test.data, test.perm); err != nil { + t.Fatalf("did not expect an error, got %v", err) + } + + written, err := os.ReadFile(path) + if err != nil { + t.Fatalf("could not read the file back: %v", err) + } + if string(written) != string(test.data) { + t.Errorf("expected contents %q got %q", string(test.data), string(written)) + } + + info, err := os.Stat(path) + if err != nil { + t.Fatalf("could not look at the file: %v", err) + } + if info.Mode().Perm() != test.perm { + t.Errorf("expected mode %v got %v", test.perm, info.Mode().Perm()) + } + + entries, err := os.ReadDir(directory) + if err != nil { + t.Fatalf("could not list the directory: %v", err) + } + if len(entries) != 1 { + names := make([]string, 0, len(entries)) + for _, entry := range entries { + names = append(names, entry.Name()) + } + t.Errorf("expected only the target file to be left, got %v", names) + } + }) + } +} + +func TestAtomicWriteFileReportsAMissingDirectory(t *testing.T) { + path := filepath.Join(t.TempDir(), "not-there", "target") + + if err := AtomicWriteFile(path, []byte("hello"), 0644); err == nil { + t.Errorf("expected an error for a directory that does not exist") + } +} + +func TestAtomicWriteFileLeavesTheOldFileAloneOnFailure(t *testing.T) { + directory := t.TempDir() + path := filepath.Join(directory, "target") + + if err := os.WriteFile(path, []byte("original"), 0644); err != nil { + t.Fatalf("could not write the file to be replaced: %v", err) + } + + // A directory that cannot be written to means the temporary file cannot + // be created, so the write has to fail before anything is replaced. + if err := os.Chmod(directory, 0500); err != nil { + t.Fatalf("could not change the directory mode: %v", err) + } + defer os.Chmod(directory, 0700) + + if os.Geteuid() == 0 { + t.Skip("running as root, which ignores the directory mode") + } + + if err := AtomicWriteFile(path, []byte("replacement"), 0644); err == nil { + t.Fatalf("expected an error for a directory that cannot be written to") + } + + existing, err := os.ReadFile(path) + if err != nil { + t.Fatalf("could not read the file back: %v", err) + } + if string(existing) != "original" { + t.Errorf("expected the original contents to survive, got %q", string(existing)) + } +}