Skip to content

Provision and mount the spool WAL disk for producer instances - #3993

Merged
Baishan merged 2 commits into
feat/spool-durable-bufferfrom
feat/spool-ci-disk-mount
Sep 17, 2026
Merged

Baishan merged 2 commits into
feat/spool-durable-bufferfrom
feat/spool-ci-disk-mount

Conversation

@Baishan

@Baishan Baishan commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Adds GCE startup/deploy plumbing to attach and mount a persistent disk for the spool producer's local WAL directory, and wires SPOOL_MODE/ instance-type substitutions through the staging deploy targets.

@Baishan
Baishan added this pull request to stack #3992 September 15, 2026 14:07
Comment thread cloudbuild/gce-startup.sh

prepare_wal_dir() {
mkdir -p "${WAL_HOST_MOUNT}"
chmod 0777 "${WAL_HOST_MOUNT}"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚪ Severity: LOW

chmod 0777 makes the host-backed WAL directory writable by every local user or process. A process with a local foothold can replace or delete WAL segments, or plant symlinks before RotatingWal opens them, corrupting queued production logs or causing writes to attacker-selected host paths.
Helpful? Add 👍 / 👎

💡 Fix Suggestion

Suggestion: Replace chmod 0777 with chmod 0700 to restrict the WAL directory to the owning user (root, since this is a GCE startup script) only. World-writable and group-writable bits are unnecessary because the Docker container is launched with --privileged and runs as root, so it has full access to a root-owned 0700 directory via the bind-mount. This eliminates the risk of any other local user or process tampering with, replacing, or planting symlinks inside the WAL directory.

⚠️ Experimental Feature: This code suggestion is automatically generated. Please review carefully.

Suggested change
chmod 0777 "${WAL_HOST_MOUNT}"
chmod 0700 "${WAL_HOST_MOUNT}"

@Baishan
Baishan force-pushed the feat/spool-ci-disk-mount branch 2 times, most recently from 4f0fad2 to 0ba4a4a Compare September 15, 2026 18:00
@Baishan
Baishan force-pushed the feat/spool-ci-disk-mount branch from 0ba4a4a to c2e91ab Compare September 17, 2026 12:20
Baishan and others added 2 commits September 17, 2026 14:44
Adds GCE startup/deploy plumbing to attach and mount a persistent disk
for the spool producer's local WAL directory, and wires SPOOL_MODE/
instance-type substitutions through the staging deploy targets.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@Baishan
Baishan force-pushed the feat/spool-ci-disk-mount branch from c2e91ab to bc607d5 Compare September 17, 2026 13:44
@Baishan
Baishan merged commit f82ff01 into main Sep 17, 2026
2 checks passed
@Baishan
Baishan deleted the feat/spool-ci-disk-mount branch September 17, 2026 14:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants