edit: plan every edit from the file the editor holds, not its path

FileEditor re-opened its path to plan each edit but wrote through the file
it held open, and the Python 'r+' handle re-opened the path after every
edit to read. When the path came to name another file between edits (a
rename or replacement, or a relative path after os.chdir), an edit was laid
out from the other file's metadata and written into the held one,
corrupting it, and later reads came from the other file (the review's
repro: h5py then reports "invalid dataset size, likely file corruption").

The editor now plans from a mapping of its own file (a clone of the held
descriptor, dropped before the edit writes) and canonicalises its path at
open. New FileEditor::reader() opens the held file anew for reading,
without sharing the editor's flock (a mapping of a cloned descriptor holds
the lock until unmapped): through /proc/self/fd on Linux, which follows a
renamed file; elsewhere by path, refused on Unix when the path no longer
names the held file. The Python handle reads through it and keeps no path;
a 'w' file is written at the absolute path it was opened with.

Tests: edit_tests.rs edits_go_to_the_file_held_not_the_path; test_edit.py
test_relative_path_and_chdir and test_path_replaced_between_edits.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
osobh
2026-09-27 07:47:03 -05:00
co-authored by Claude Opus 5.5
parent bdf584abb2
commit 39f25e5d4e
9 changed files with 292 additions and 27 deletions
+17
View File
@@ -39,6 +39,23 @@ impl MmapReader {
Ok(Self { _file: file, mmap })
}
/// Memory-map a file that is already open (for reading).
///
/// The mapping references `file`'s open file description for as long as
/// it lives, so a `flock` taken through that description (or a
/// `try_clone` of it) is held until the reader is dropped.
///
/// # Safety
///
/// The same contract as [`open`](Self::open): the file must not be
/// modified while the mapping is active.
pub fn from_file(file: fs::File) -> io::Result<Self> {
// SAFETY: a read-only mapping; the caller keeps the file unmodified
// while it is alive.
let mmap = unsafe { Mmap::map(&file)? };
Ok(Self { _file: file, mmap })
}
/// Zero-copy access to the entire file contents.
pub fn as_bytes(&self) -> &[u8] {
&self.mmap