Repository navigation
Conversation
… that lost a race writes nothing ADR-0042 decision 10 with amendments A1 (per-host lock dir), A2 (1024 stripe files, bounded) and A5 (compare before the in-place truncate). Not wired into any writer yet. Refs #730 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
markramm
force-pushed
the
feature/b6-p2-file-lock
branch
from
October 3, 2026 17:02
3abc710 to
83bcb6d
Compare
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Collaborator
Author
|
Superseded by the maintainer's decision on Andon pyrite-security#97: the lock lives in Conductor (automated agent). |
markramm
added a commit
that referenced
this pull request
Oct 6, 2026
lock_dir_for(path) is the one answer to where the lock is: <git-dir>/pyrite/locks of the work tree holding realpath(path), beside git's index.lock. It follows git's discovery rules (gitfile, commondir, HEAD validity, bare/inside-git-dir refused, stop at a filesystem boundary) without running git and without reading the environment: with GIT_DIR exported, 'git rev-parse' names another repository for the same file, two lock dirs, failing open. git rev-parse costs 22-27 ms a call on macOS and may be absent on a server, so the tests use git as the reference instead, comparing on every adversary layout. The lock dir gets the git dir's mode (never wider, umask-independent); a read-only git dir, a widened lock dir, a move across repositories and a KB outside git are refused for expect= writes. Carried over from #733: atomic_write_text(expect=) with FileChanged / LockTimeout, the compare under the lock before the rename and before the truncate on the three in-place paths (A5), expect validation, a bounded wait, register_at_fork, N=1024 case- and Unicode-folded stripes opened O_NOFOLLOW/O_EXCL relative to a verified dir fd, the process tests. Dropped: the env-derived lock dir, PYRITE_LOCK_DIR, the uid fallback and the shared-sticky-dir logic. Refs #730 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #730
Harden lock-dir and stripe handling. P2 of B6:
pyrite/utils/file_lock.pyandatomic_write_text(expect=); nothing is wired into a writer yet (P3). Windows is unsupported:expect=writes fail closed there. The lock directory is per user in every environment; sharing across OS users needsPYRITE_LOCK_DIRnaming one absolute root-owned sticky directory. Left: thelock_dirconfig setting and theindex healthwarning (A1).Fix round 1 (pushed 0506d2b): harden lock-dir and stripe handling
tests/test_file_lock.pypass at-n 4, and the pre-push test-affected run passed.LOCK_TIMEOUT, 10 s);expect(bytes, or a 64-hex digest);PYRITE_LOCK_DIR), matching ADR-0042 §10a A1 as amended in process: retro 2026-10-03 decisions (feedback/ per entry; A1 shared only when configured; quality theme) #742.lock_dirconfig setting, theindex healthwarning, and wiring (P3).Guards: delete the guard alone, this test fails
atomic_write_text% STRIPES)test_lock_files_are_boundedtest_threads_exclude_each_other_when_the_os_lock_does_nottest_eight_processes_one_key_form_one_chainO_NOFOLLOWon stripetest_a_symlinked_stripe_is_refused_and_its_target_untouchedO_EXCL(mode set only on created file)test_an_existing_stripe_keeps_its_modeO_NOFOLLOWon directorytest_a_symlinked_directory_is_refusedtest_a_directory_owned_by_someone_else_is_refusedtest_a_world_writable_directory_without_sticky_is_refusedtest_a_restrictive_umask_does_not_leave_the_directory_unusabletest_a_stripe_that_is_not_a_regular_file_is_refusedtest_a_stripe_opens_relative_to_the_verified_directorytest_a_group_writable_sticky_directory_counts_as_sharedtest_every_default_branch_is_per_user(incl. 2775 base)test_the_fallbacks_parent_must_not_let_others_renametest_every_default_branch_is_per_usertest_every_default_branch_is_per_userPYRITE_LOCK_DIRtest_a_relative_lock_dir_is_refusedtest_windows_is_unsupported_and_says_sotest_a_forked_child_does_not_inherit_a_locked_process_locktest_stripes_fold_case_and_unicode_formtest_a_wait_for_the_lock_is_boundedexpectstr/type validationtest_text_is_not_mistaken_for_a_digestTestCompare/TestWritePathsStated limits (module docstring): another user can restrict a stripe they created, and any user can hold any stripe (LockTimeout); only the final component of the lock directory is checked; group-writable counts as shared; ACLs are not read; a forked child shares the open file description.
🤖 Generated with Claude Code
Fix round 2 (pushed 3abc710): harden lock-dir and stripe handling
<tmp>/pyrite-locks-<uid>.test_every_default_branch_is_per_usercovers all six branches with two uids.PYRITE_LOCK_DIRis refused. The deadS_ISDIRcheck is removed.expect=and fails closed with an error naming it. The msvcrt code is removed.lock_dirconfig setting, theindex healthwarning, and wiring (P3).Round 3, scoped and maintainer-approved (pushed df99ec6): harden lock-dir handling
_others_can_renameis true for group- or other-write without the sticky bit. It is used for the lock dir and for the fallback parent, which is now checked and fails closed._is_sharedholds the underlying bits. The base check avoids any group or other write bit, sticky or not, which is stricter than the predicate.