From 131e69e29be7456cebdb2c1cdd3901707483aed1 Mon Sep 17 00:00:00 2001 From: Tony Butler Date: Fri, 27 Jan 2017 17:26:24 +0000 Subject: [PATCH] MDL-57801 core_filestorage: Verify hash of temp file before committing This addresses an edge scenario on NFS filesystems with no space remaining, where subsequent uploads fail silently while zero byte files are saved to the pool (and for some reason the filesize check passes). --- lib/filestorage/file_storage.php | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/lib/filestorage/file_storage.php b/lib/filestorage/file_storage.php index a5bc30c0d34..7b5f5b99439 100644 --- a/lib/filestorage/file_storage.php +++ b/lib/filestorage/file_storage.php @@ -1990,9 +1990,9 @@ class file_storage { ignore_user_abort($prev); throw new file_exception('storedfilecannotcreatefile'); } - if (filesize($hashfile.'.tmp') !== $filesize) { - // This should not happen. - unlink($hashfile.'.tmp'); + if (sha1_file($hashfile.'.tmp') !== $contenthash) { + // Highly unlikely edge case, but this can happen on an NFS volume with no space remaining. + @unlink($hashfile.'.tmp'); ignore_user_abort($prev); throw new file_exception('storedfilecannotcreatefile'); }