Describe the bug
CleanOrphanUploadFiles may skip some available file records during a cleanup run because it uses offset-based pagination while modifying the same result set being paginated.
The cleanup job queries file records with status = Available in batches of 1000. While processing a batch, orphan files are cleaned by DeleteAndMoveFileRecord, which changes their status from Available to Deleted.
Because those records no longer match the status = Available condition, the result set becomes smaller. However, the next iteration increments the page number and continues using an offset calculated from the new result set.
For example, if there are 1001 eligible orphan records:
- Page 1 queries the first 1000 records with
OFFSET 0.
- Those 1000 records are changed from
Available to Deleted.
- Only 1
Available record remains.
- Page 2 queries with
OFFSET 1000.
- The remaining record is skipped, so the query returns no records and the cleanup loop exits.
As a result, not all eligible orphan file records are guaranteed to be checked in a single cleanup run. The skipped records remain Available and may only be processed by a later cleanup run.
To Reproduce
Steps to reproduce the behavior:
-
Create 1001 file records with:
status = Available
CreatedAt older than 2 days
- no revision or other object referencing the uploaded file
- corresponding uploaded files present on disk
-
Run CleanOrphanUploadFiles.
-
Query the remaining file records with status = Available.
-
Observe that at least one eligible orphan record remains unprocessed.
The issue comes from combining offset pagination with updates to the filtered result set:
First query:
OFFSET 0 LIMIT 1000
→ 1000 records are processed
→ their status changes from Available to Deleted
Remaining Available records:
1
Second query:
OFFSET 1000 LIMIT 1000
→ returns no records
→ cleanup exits
Expected behavior
CleanOrphanUploadFiles should scan all file records that are eligible for the current cleanup run, even when previously scanned records are changed from Available to Deleted.
No eligible record should be skipped because earlier records were removed from the Available result set during the same cleanup execution.
Screenshots
Not applicable.
Platform
- Device: N/A
- OS: Not OS-specific
- Browser and version: N/A
- Version: current
main (3b9f1370612e690a0b7f230f05e688930db4c6d3)
- Deployment method: Source
Describe the bug
CleanOrphanUploadFilesmay skip some available file records during a cleanup run because it uses offset-based pagination while modifying the same result set being paginated.The cleanup job queries file records with
status = Availablein batches of 1000. While processing a batch, orphan files are cleaned byDeleteAndMoveFileRecord, which changes their status fromAvailabletoDeleted.Because those records no longer match the
status = Availablecondition, the result set becomes smaller. However, the next iteration increments the page number and continues using an offset calculated from the new result set.For example, if there are 1001 eligible orphan records:
OFFSET 0.AvailabletoDeleted.Availablerecord remains.OFFSET 1000.As a result, not all eligible orphan file records are guaranteed to be checked in a single cleanup run. The skipped records remain
Availableand may only be processed by a later cleanup run.To Reproduce
Steps to reproduce the behavior:
Create 1001 file records with:
status = AvailableCreatedAtolder than 2 daysRun
CleanOrphanUploadFiles.Query the remaining file records with
status = Available.Observe that at least one eligible orphan record remains unprocessed.
The issue comes from combining offset pagination with updates to the filtered result set:
Expected behavior
CleanOrphanUploadFilesshould scan all file records that are eligible for the current cleanup run, even when previously scanned records are changed fromAvailabletoDeleted.No eligible record should be skipped because earlier records were removed from the
Availableresult set during the same cleanup execution.Screenshots
Not applicable.
Platform
main(3b9f1370612e690a0b7f230f05e688930db4c6d3)