Repository navigation
Persist lifecycle JSON atomically - #477
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a8b2a09c7b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f3f4815e85
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c6c7bfd0b9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cccf8babc2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e848e725d6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5ef7c1ffe5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7a1be7cad7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 05e72a7a68
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4f1c84efdb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Fixes #475
Fixes #478
Fixes #479
Fixes #481
Fixes #482
Fixes #483
Fixes #484
Fixes #485
Fixes #487
Fixes #489
Fixes #490
Fixes #493
Fixes #494
Fixes #496
Contract
fsync, and callos.replaceonly after those steps succeed.writes, and anchor replacement to one retained directory descriptor.
0600through payload write and atomicpublication, restore the intended final mode through the retained descriptor
only after replacement, and retain failed temps rather than performing a
racy name-based unlink.
by group/other principals, and reject macOS extended ACLs; same-principal
processes form the trust boundary.
0700so collaborative umasks cannot violate that boundary.
Scope
atomic_write_jsonpersistence primitive.Verification
test_json_contract.py,test_workflow.py,test_fair_run.py,test_equivalence_run.py,test_shards.py, andtest_report.pyall pass in one focused run.git diff --check: PASS...; the regression nowcanonicalizes and retains the destination directory identity, and the exact
failing native-suite test passes.
regressions now cover both.
use descriptor-relative
O_CREAT|O_EXCL|O_NOFOLLOWwith requested mode0666, leaving the effective mode to the process umask.ownership; absolute-path cleanup was removed and descriptor closure plus
same-name replacement behavior gained deterministic regressions.
created at the existing destination mode (still masked by umask), then
restored to the exact mode before any payload write.
statfollowed byunlinkcannot providean atomic inode-bound cleanup guarantee. Name-based failure cleanup is now
absent: failed temps remain
0600while writing, completed replacement tempsuse the intended final mode, and unrelated same-name entries are never a
cleanup target.
Python/POSIX also lacks compare-and-rename, shared-writable destination
directories are rejected before any temporary or destination mutation. A
follow-up exact-SHA review found the macOS ACL bypass; Darwin now queries the
extended ACL from the retained directory fd and conservatively rejects it.
request
0700under umask002/000, and complete temps remain0600through replace. Run/input/artifact/observation and recursive shard output
directories all request
0700. A mode-restoration failure leaves the newdocument at
0600; a later fsync failure leaves it at the intended mode.root/runsancestor iscreated explicitly at
0700before the private run leaf.creating each level explicitly from the nearest existing parent.
recursive ancestor change, rejecting a destination created between initial
validation and publication.
git diff --check: PASS.210f0e65df0b015c7400a818190627fce1a5603e.NO_LEANwith native executable linkage.Formal boundary
This is an executable filesystem contract, not a Lean theorem. The tests connect
the lifecycle invariant to Python and OS behavior. The code claims an atomic
rename boundary after successful
os.replace; it does not claim directorymetadata or power-loss durability.
Primary sources
os.replace: https://docs.python.org/3/library/os.html#os.replaceos.open: https://docs.python.org/3/library/os.html#os.openos.fchmod: https://docs.python.org/3/library/os.html#os.fchmodos.fsync: https://docs.python.org/3/library/os.html#os.fsyncacl_get_fd: https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/acl_get_fd.3.html