Metadata backup - #666
Metadata backup#666GX020124 wants to merge 6 commits into
Conversation
seafile-dev
left a comment
There was a problem hiding this comment.
Verdict: Request changes
Blocking:
- seafevents 的运行时依赖缺失,服务启动时会因无法导入 openpyxl 而失败(见行内评论)。
Warnings:
- 两个 PR 均未包含导出、格式校验和覆盖恢复的自动化回归测试;该流程会删除列、表及关系,缺少测试难以发现数据丢失回归。
Suggested fix: 为 Excel 导出/导入、跨资料库拒绝、公式拒绝、文件匹配、标签关系重建及失败不修改数据补充单元或集成测试。
| from openpyxl.utils import get_column_letter | ||
|
|
||
|
|
||
| FORMAT_VERSION = 'metadata-backup-v1' |
There was a problem hiding this comment.
[Critical] 缺少 openpyxl 运行时依赖
Why this matters:
此模块在 seafevent_server 启动时经 task manager 被导入,但 requirements.txt 没有声明 openpyxl。按现有部署依赖安装时会在此处抛出 ModuleNotFoundError,导致整个 seafevents 服务无法启动,而不只是备份功能不可用。
Suggested fix: 在 seafevents 的 requirements.txt 中添加经过兼容性验证且受版本约束的 openpyxl 依赖,并在 CI/镜像构建中验证新环境能够导入并执行备份流程。
seafile-dev
left a comment
There was a problem hiding this comment.
Verdict: Request changes
Blocking:
- 同一资料库的备份、解析和恢复任务没有互斥控制;多 worker 并发恢复会交错删除/创建列、标签表和关联,造成不可预测的部分恢复(见行内评论)。
Warnings:
- Excel 解析只在 Metadata 与部分 value 单元格检查公式;_Schema、_Links 等隐藏表用 values_only 读取,公式会作为普通字符串继续进入恢复负载,未满足设计的“导入时拒绝公式”约束。
Suggested fix: 统一以 Cell 对象读取所有受信任工作表字段,发现 data_type == 'f' 立即使预览任务失败,并为各隐藏工作表补充回归用例。 - 两个 PR 仍未包含导出/导入 round-trip、跨资料库拒绝、失败不修改数据、标签关系重建和并发互斥的自动化回归测试。
Suggested fix: 为这些关键破坏性路径补充单元或集成测试;本次已在 requirements.txt 中补上 openpyxl,先前依赖阻塞已解决。
| if task: | ||
| shutil.rmtree(task['directory'], ignore_errors=True) | ||
|
|
||
| def _new_task(self, operation, repo_id, username): |
There was a problem hiding this comment.
[Critical] 同库任务缺少互斥
Why this matters:
_new_task 对同一 repo_id 的 export/import/restore 全部直接入队;多个管理员或浏览器会让多个 worker 同时执行恢复。恢复会永久删除并重建列、非主表和关联,两个任务交错后会留下部分恢复或使后续请求失败。
Suggested fix: 按 repo_id 维护活动任务锁,在创建或确认恢复时拒绝/串行化同库任务,并在所有成功、失败和清理路径释放锁。
| def _read_schema(sheet): | ||
| raw_columns = {} | ||
| allowed_modes = {'identity', 'preserve', 'conditional', 'restore'} | ||
| for values in sheet.iter_rows(min_row=2, values_only=True): |
There was a problem hiding this comment.
[Warning] 隐藏表公式未被拒绝
Why this matters:
_read_schema 和 _read_links 使用 values_only=True,不会检查 Cell.data_type;_Schema/_Links 中的公式会以公式字符串通过校验并参与列或关联恢复。设计要求导入时拒绝公式,因此损坏或被篡改的备份未必会在预览阶段失败。
Suggested fix: 以 Cell 对象遍历所有隐藏表字段并统一拒绝 data_type == 'f',同时覆盖 schema、links、manifest 和 values 表中的公式用例。
seafile-dev
left a comment
There was a problem hiding this comment.
Verdict: Comment
Blocking:
- 无。当前 head 已按 repo_id 串行执行导出、解析和恢复任务,并通过统一的 Cell 遍历拒绝所有工作表中的公式;此前两项阻塞问题已解决。
Warnings:
- 破坏性恢复路径仍没有自动化回归测试:Excel 导出/导入 round-trip、跨资料库拒绝、失败时不修改数据、标签关系重建以及并发互斥都未覆盖。
Suggested fix: 为上述场景补充单元或集成测试,至少验证解析失败不会调用恢复、恢复后的列/行/标签关系与备份一致,以及同一 repo 的任务不会并发执行。
No description provided.