From efad11c3411ca7244202d42899744b1306acf5fc Mon Sep 17 00:00:00 2001 From: Gates Wang <9372086+SetagGnaw@users.noreply.github.com> Date: Mon, 20 Jul 2026 21:50:22 -0400 Subject: [PATCH] fix(installer): close each file per iteration in OCI extractTar The tar extraction loop in extractTar used a per-entry `defer outFile.Close()`, which runs only when the function returns. Every extracted file's descriptor therefore stayed open for the whole archive, so a large plugin archive could exhaust the process file-descriptor limit mid-extraction. Extract each regular file inside an anonymous function so the deferred close fires at the end of every iteration, on the success, error, and panic-unwind paths alike. At most one descriptor is now open at a time. Signed-off-by: Gates Wang <9372086+SetagGnaw@users.noreply.github.com> --- internal/plugin/installer/oci_installer.go | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/internal/plugin/installer/oci_installer.go b/internal/plugin/installer/oci_installer.go index 383ddb914..e00e39ad9 100644 --- a/internal/plugin/installer/oci_installer.go +++ b/internal/plugin/installer/oci_installer.go @@ -238,12 +238,15 @@ func extractTar(r io.Reader, targetDir string) error { return err } - outFile, err := os.OpenFile(path, os.O_CREATE|os.O_RDWR, os.FileMode(header.Mode)) - if err != nil { + if err := func() error { + outFile, err := os.OpenFile(path, os.O_CREATE|os.O_RDWR, os.FileMode(header.Mode)) + if err != nil { + return err + } + defer outFile.Close() + _, err = io.Copy(outFile, tarReader) return err - } - defer outFile.Close() - if _, err := io.Copy(outFile, tarReader); err != nil { + }(); err != nil { return err } case tar.TypeXGlobalHeader, tar.TypeXHeader: