set_key and unset_key don't fsync before replacing the .env file
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 72/100
Direzione di ricerca
Start in src/dotenv/main.py at rewrite(), then trace its callers from set_key, unset_key, and the dotenv set/unset commands. Find the existing tests covering rewrite or key updates and add coverage that records fsync and os.replace ordering. Done means the temporary file is durable before replacement, with any directory-durability behavior covered consistently across supported platforms.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
set_key and unset_key rewrite the .env file through rewrite() (src/dotenv/main.py): they write a temporary file next to the target, then os.replace it over the target. That makes the swap atomic for other processes, but nothing forces the new contents to disk before the rename. The temporary file is closed (which flushes Python's buffer to the OS) and then renamed, with no fsync.
What can go wrong
If the machine loses power or the kernel crashes shortly after set_key returns, the rename can reach the disk before the file's data does. After a reboot, .env can then be empty (zero length) or contain garbage, instead of holding either the old or the new contents. This applies to set_key, unset_key, and the dotenv set / dotenv unset commands.
How likely this is depends on the filesystem. ext4 with its default auto_da_alloc option flushes data before a rename that replaces an existing file, which covers this exact pattern. Other filesystems (XFS, and ext4 mounted with noauto_da_alloc) make no such promise, and a .env that has never existed before isn't covered by that heuristic at all. I haven't reproduced data loss; this is based on the documented semantics of rename(2) and fsync(2), and is the reason other write-then-rename implementations call fsync.
Since .env files often hold credentials, losing one silently is a bad outcome.
Proposed change
In rewrite(), before os.replace:
dest.flush()
os.fsync(dest.fileno())
This has to happen while the temporary file is still open, i.e. inside the with temp_file as dest: block, after the caller's writes have finished.
Optionally, after os.replace on POSIX, fsync the containing directory so the rename itself is durable:
if os.name == "posix":
dir_fd = os.open(os.path.dirname(os.path.abspath(path)), os.O_RDONLY)
try:
os.fsync(dir_fd)
finally:
os.close(dir_fd)
Directory fsync isn't available on Windows, and some filesystems reject it with EINVAL. Since the file contents are already safe at that point, an OSError from it could reasonably be ignored.
Cost
.env files are small and set_key is not called in hot loops, so one or two fsync calls per write should not be noticeable. A test can check that os.fsync is called on the temporary file before os.replace, for example by patching both in dotenv.main and recording the call order.
Out of scope
Concurrent writers (two set_key calls at once can lose one update) and file-replacement side effects such as single-file Docker bind mounts are separate problems and not addressed here.
- Lingua principale
- Python
- Stelle
- 8.9k
- Fork
- 600
- Merge medio
- 8g 8h
- PR unite (30g)
- 5
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di theskumar/python-dotenv
-
An empty value ignores ${name:-default}Forse già presa @SashaMIT l’ha presa 4 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
theskumar/python-dotenv#715 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 28/100
theskumar/python-dotenv#693 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
python-dotenv installation without cli masks python-dotenv cliForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
theskumar/python-dotenv#683 · 4 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Feature Request: Automatically copy `default.env` to `.env`Forse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
theskumar/python-dotenv#644 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Add `strict` parameter to `load_dotenv()` and `dotenv_values()` for fail-fast behaviorForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
theskumar/python-dotenv#631 · 3 commenti · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di theskumar/python-dotenv
Issue simili
-
Device Details tables: FS/SF columns contradict each other (nfet_01v8 Vt row, pfet_01v8 Idsat row)Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
google/skywater-pdk#450 ·
-
Drained trajectory arrays are overwritten when the sequence buffer is reusedForse già presa @sylvesterkaczmarek l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
google-deepmind/bsuite#56 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
LearningCircuit/local-deep-research#7206 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
chingu-voyages/V62-tier3-team-33#285 ·
I maintainer di solito rispondono entro 1 giorno
-
Proxy drops log notifications from backends that don't send FastMCP's msg/extra dictForse già presa @asasemahmed l’ha presa oggi. Apertabug server
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno