fix(installer): close each file per iteration in OCI extractTar

The tar extraction loop in extractTar used a per-entry
`defer outFile.Close()`, which runs only when the function
returns. Every extracted file's descriptor therefore stayed open
for the whole archive, so a large plugin archive could exhaust the
process file-descriptor limit mid-extraction.

Extract each regular file inside an anonymous function so the
deferred close fires at the end of every iteration, on the success,
error, and panic-unwind paths alike. At most one descriptor is now
open at a time.

Signed-off-by: Gates Wang <9372086+SetagGnaw@users.noreply.github.com>
pull/32414/head
Gates Wang 2 months ago
parent 6c45810119
commit efad11c341

@ -238,12 +238,15 @@ func extractTar(r io.Reader, targetDir string) error {
return err
}
outFile, err := os.OpenFile(path, os.O_CREATE|os.O_RDWR, os.FileMode(header.Mode))
if err != nil {
if err := func() error {
outFile, err := os.OpenFile(path, os.O_CREATE|os.O_RDWR, os.FileMode(header.Mode))
if err != nil {
return err
}
defer outFile.Close()
_, err = io.Copy(outFile, tarReader)
return err
}
defer outFile.Close()
if _, err := io.Copy(outFile, tarReader); err != nil {
}(); err != nil {
return err
}
case tar.TypeXGlobalHeader, tar.TypeXHeader:

Loading…
Cancel
Save