When creating a new controller, the options dictionary was used by-reference.
This meant that code could update the options dictionary *after* creating the controller, which would not be thread-safe.
It does not have much effect on regular operations as the normal method is to create the dictionary, pass it, and not modify it.
But in the tests, we frequently re-use the dictionary and update it with new values to test various cases.
Due to the dictionary being a reference, the controller would update the dictionary to fit the operations, but this would reflect back into the tests, meaning that some tests were being run with options that were not supposed to be there.
This meant that at least two edge cases that we test for were never found to have errors, even though they do.
The first issue is the listing of files using a non-default blocksize. The second issue is recreating the database with a non-default file-hash algorithm.
This PR removes the reference passing, and fixes the issues that were uncovered.
This PR has a large blast radius because it takes the final step and bumps up the Controller to be fully async.
We have historically done a piece-by-piece update, so all operations were already async but the controller interface was kept synchronous.
With this update, the controller is now fully async and all tests are updated.
Most places where the new C# compiler warns about function names not ending in `Async` were also adressed, giving a massive refactor change.
Functionally, no changes are done.
This PR fixes an issue where backups of an empty file could prevent the backups running after a database recreate.
The issue would not prevent restore or backup, but in the case the user decided to rebuild the database, empty files could in some cases trigger the database consistency validation and prevent backups from running on the recreated database.
This fixes#6822
This fixes a bug where restoring with `--no-local-db` and `--version=0` would fail because the database consistency check sees that data is missing.
The missing data is intentional in this case, as we deliberately recreate a partial database.
The PR adds a test for this scenario and fixes the validation to allow for the partial database. Additionally, the partial database is marked as such, in case it is not correctly deleted after the restore.
This PR adds checks on limited restores, where the user has asked for files to be restored within a specific folder.
This PR adds explicit checks to ensure that the restore data cannot accidentially or maliciously constructed in such a way that it will affect files outside of the restore target folder.
Renamed the options to be more descriptive.
Rewrote the dependency query to be more readable and also check for metadata dependency.
Fixed an edge case where there were no modified files, and no new backup is created.
Fixed some issues with local/utc datetime compares.
Fixed logic for deleting filesets to only look at the filesets themselves. This makes the version lock follow the dlist file, and can create "dangling" volumes that have no filesets, but these will be picked up by compaction.
Updated tests to work correctly.
Added lock-info update option for the backup recreate call, so the UI can also re-create lock information on database rebuilds.
This adds an extra option to allow setting the SQLite page cache size as a regular option.
Prior to this commit it was only possible to set the SQLite page cache size via environment variables.
The option to use environment variables is preserved, and as options from the environment variable are applied after the new setting, environment variables take precedence.
The default value for the new option is to use 1% of the system memory for the page cache. For the restore process, a connection per worker may be made which defaults to half the number of cores, so the maximum amount of memory is 1% * half the CPU cores.
This is just the upper limit, and SQLite may choose not to use all of it.
This fixes#6178
If the passphrase is not supplied it will not be possible to recreate the database.
Prior to this commit, attempting this would result in a string of error messages that do not point to the problem.
With this commit, a single error message is given explaining the problem.
This adds a common way to catch stop exceptions and handles them so error resilient logic does not continue when a stop exception is thrown.
Previously, the logic would only check for `ThreadAbortException` which was used to signal a stop prior to .NET8.
This PR adds a few extra consistency checks to the database, so any failure in the operations is detected earlier than before.
Especially when cleaning temporary and partial files, it is important that the deletes do not remove unexpected entries.
Also, after a recreate, repair or purge command, the database consistency is verified, so it becomes easier to identify which operation caused the failure.
To assist in trouble shooting, there is also a more elaborate error message if a fileset discrepancy is detected, that pinpoints which versions are affected.
Finally, the repair command has been extended to support recreating a fileset from the remote data.
The code was using a two-way reference linking the database to the results and the results to the database.
However, this was not really used so it ended up just cluttering the code. With this commit, the results and databases are no longer keeping track of each other, and the only interaction is when the results are written to the database at the end of the operation.
To ensure result data is always written, this code has been moved into the controller, which will now flush the results for all operations. Prior to this, only some operations would write result data to the log.
The controller now also handles logic for cleaning old log data and invoking the vacuum command.
Fixed a bug due to using System.Text.Json where some attributes from NewtonSoft.Json were being applied and not picked up.
Rewrote all operation handlers to be async.
This moves the async/sync threshold out into the controller.
Fixed all the uses of cancellation token in the handlers to use the provided cancellation token.
Introduced a new ReusableTransaction that can be passed around, avoiding a ref parameter passing of the transaction instance.
* Rewrite the backend manager.
This creates a new more logic backend manager that handles all backend operations.
For each top-level operation, there is now a single backend manager instance that is passed to sub-commands.
The internals of the backend manager are now rewritten to use async logic instead of threading.
The design uses a single task runner that dispatches operations and honors concurrent settings and limits from one place.
The logic for each operation has been moved into a separate files/classes to make it easier to understand each operation.
This fixes#5804
* Fixed a few issues with not awaiting tasks
* Fixed not creating empty databases
* Fixed an issue with hashes not being recorded on download
* Reworked the download logic to avoid attempting to decrypt the file if it has been modified.
* Review fixes
* Renamed db collector to better reflect the purpose.
* Review fixes
* Simplified task control by having all logic in a single class and using async control mechanism
* Fixed the tests
* Made the marking of a backup partial explicitly communicated if the enumeration process is stopped.
* Added support for pausing active transfers
* Introduced transfer token to abort operations.
* Updated the way LiveControl is emitting events.
* Retains the paused state of the server across reboots, this fixes#5760.
* Reworked the way throttle speeds are propagated through LiveControls.
* Added option to pause transfers in the UI.
* Removed throttle settings from the LiveControls class so it is exclusively handled by the ApplicationSettings.
* Removed `thread-priority` as it does not work at all when tasks are used.
* Fixed the stop dialog and API to only support stop and abort.
* Removed unused variables
This fixes that the recreate will move unused blocks into the `DeletedBlock` table after the database has been recreated.
Due to this, the disruption test can now be verified.
Update the SQL to also group on size (just in case).
Renamed the normal read method to signal that it is unverified.
Made the verified reader use enumeration state machine to avoid materializing the list.
`var`-ified some of the test code.