From: Joey Hess Date: Thu, 20 Jan 2022 15:49:56 +0000 (-0400) Subject: prevent manual git-annex upgrade to v10 when unsafe X-Git-Tag: archive/raspbian/10.20250416-2+rpi1~2^2^2~53^2~332 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=90027f71586f4e2745eb7685df491668d2e05147;p=git-annex.git prevent manual git-annex upgrade to v10 when unsafe Allow --force Sponsored-by: Dartmouth College's Datalad project --- diff --git a/Upgrade/V9.hs b/Upgrade/V9.hs index 029cd74fd5..92cc12adf8 100644 --- a/Upgrade/V9.hs +++ b/Upgrade/V9.hs @@ -8,6 +8,7 @@ module Upgrade.V9 where import Annex.Common +import qualified Annex import Types.Upgrade import Annex.Content import Annex.Perms @@ -22,31 +23,43 @@ import Data.Time.Clock.POSIX upgrade :: Bool -> Annex UpgradeResult upgrade automatic - | automatic = do - {- For automatic upgrade, wait until a year after the v9 - - upgrade. This is to give time for any old processes - - that were running before the v9 upgrade to finish. - - Such old processes lock content using the old method, - - and it is not safe for such to still be running after - - this upgrade. -} - timeOfUpgrade (RepoVersion 9) >>= \case - Nothing -> performUpgrade automatic - Just t -> do - now <- liftIO getPOSIXTime - if now - 365*24*60*60 > t - then return UpgradeDeferred - else checkassistantrunning $ - performUpgrade automatic - | otherwise = performUpgrade automatic + | automatic = ifM oldprocessesdanger + ( return UpgradeDeferred + , performUpgrade automatic + ) + | otherwise = ifM (oldprocessesdanger <&&> (not <$> Annex.getState Annex.force)) + ( giveup $ unlines unsafeupgrade + , performUpgrade automatic + ) where + {- Wait until a year after the v9 upgrade, to give time for + - any old processes that were running before the v9 upgrade + - to finish. Such old processes lock content using the old method, + - and it is not safe for such to still be running after + - this upgrade. -} + oldprocessesdanger = timeOfUpgrade (RepoVersion 9) >>= \case + Nothing -> pure True + Just t -> do + now <- liftIO getPOSIXTime + if now - 365*24*60*60 > t + then return True + else not <$> assistantrunning + {- Skip upgrade when git-annex assistant (or watch) is running, - because these are long-running daemons that could conceivably - run for an entire year and so predate the v9 upgrade. -} - checkassistantrunning a = do + assistantrunning = do pidfile <- fromRepo gitAnnexPidFile - liftIO (checkDaemon (fromRawFilePath pidfile)) >>= \case - Just _pid -> return UpgradeDeferred - Nothing -> a + isJust <$> liftIO (checkDaemon (fromRawFilePath pidfile)) + + unsafeupgrade = + [ "Not upgrading from v9 to v10, because there may be git-annex" + , "processes running that predate the v9 upgrade. Upgrading with" + , "such processes running could lead to data loss. This upgrade" + , "will be deferred until one year after the v9 upgrade to make" + , "sure there are no such old processes running." + , "(Use --force to upgrade immediately.)" + ] performUpgrade :: Bool -> Annex UpgradeResult performUpgrade automatic = do