Dedup probe labels timed-out incomplete uploads as corrupted completed files #485

Open
opened 2026-09-30 06:09:07 +00:00 by kayg · 0 comments
Owner

Found in the fifth required local dedup campaign for #375, merged head 6d2c1b4d03. The first four complete campaigns each exited 0 with FINDINGS 0.

The fifth campaign exceeded the HTTP helper's 30-second POST/PATCH deadline. The helper returned -1 with timed out. Subsequent integrity checks still treat every requested fixture as a completed upload. They report missing files as the completed upload bytes differ from its source, compare quota against all requested bytes, and compare near-identical inodes against all requested paths.

I inspected the live synthetic Index read-only before cleanup. Counts only:

{"pending_campaign_upload_rows":4,"pending_declared_bytes":1048768,"pending_received_bytes":0,"pending_installing_rows":0}

These four fixtures were created but received no PATCH bytes. They account for the four missing near-identical paths and their quota/inode deficits. The probe has not observed wrong bytes for an upload that returned success. This is not proof of cross-User corruption.

Locations: tests/adversarial/attack2.py upload helper (30-second request default) and dedup fixture verification around lines 5060–5085 and 5249–5253.

Keep the failed-upload finding and existing status expectations. The owner should decide how to report incomplete fixture-dependent checks so an uncompleted upload is not called corrupted content. Do not weaken the byte, quota, or per-User inode assertions for completed uploads. No expectation was changed in #375.

This issue records a non-SLOW probe finding as required by the job rules. The fifth run cannot be reported as a clean pass. #375's final report will include its actual result.

Found in the fifth required local dedup campaign for #375, merged head 6d2c1b4d037615f8f3095f151e8fd7488f268712. The first four complete campaigns each exited 0 with FINDINGS 0. The fifth campaign exceeded the HTTP helper's 30-second POST/PATCH deadline. The helper returned -1 with `timed out`. Subsequent integrity checks still treat every requested fixture as a completed upload. They report missing files as `the completed upload bytes differ from its source`, compare quota against all requested bytes, and compare near-identical inodes against all requested paths. I inspected the live synthetic Index read-only before cleanup. Counts only: ```json {"pending_campaign_upload_rows":4,"pending_declared_bytes":1048768,"pending_received_bytes":0,"pending_installing_rows":0} ``` These four fixtures were created but received no PATCH bytes. They account for the four missing near-identical paths and their quota/inode deficits. The probe has not observed wrong bytes for an upload that returned success. This is not proof of cross-User corruption. Locations: `tests/adversarial/attack2.py` upload helper (30-second request default) and dedup fixture verification around lines 5060–5085 and 5249–5253. Keep the failed-upload finding and existing status expectations. The owner should decide how to report incomplete fixture-dependent checks so an uncompleted upload is not called corrupted content. Do not weaken the byte, quota, or per-User inode assertions for completed uploads. No expectation was changed in #375. This issue records a non-SLOW probe finding as required by the job rules. The fifth run cannot be reported as a clean pass. #375's final report will include its actual result.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#485
No description provided.