diff options
| author | Lukasz Kasprzak <lukas@labunix.xyz> | 2026-09-17 13:34:20 +0200 |
|---|---|---|
| committer | Lukasz Kasprzak <lukas@labunix.xyz> | 2026-09-17 13:34:20 +0200 |
| commit | 6971543d4749574d4ca575c4e8acf04f9e86d6bb (patch) | |
| tree | fbd600dc512e9fcf360f7bbebc258d2a5acac6de /cmd/krino/sort.go | |
| parent | 1884d56b0d399e9cdb80016a9c166b0120989933 (diff) | |
| download | krino-6971543d4749574d4ca575c4e8acf04f9e86d6bb.tar.gz krino-6971543d4749574d4ca575c4e8acf04f9e86d6bb.zip | |
the directory lock is the kernel's, not a pid we believe
flock(2) on the lock file's descriptor replaces "write my pid, and
decide whether the pid in the file is still alive". The kernel drops
the lock when the process ends, however it ends, so there is no stale
krino lock to detect and no takeover to race over.
What that fixes:
- Two runs that both judged a lock stale could remove and recreate it
and both believe they held it. Remove-then-create cannot be made
atomic; there is nothing to make atomic now. Pinned by a test with
eight callers over twenty rounds.
- A pid reused after a crash made the lock live for ever, and the
message named neither the file nor the pid, so there was nothing to
act on. The message now names both.
- Signal(0) reads EPERM as "not running", so a lock held by another
user was taken over. There is no such judgement left to get wrong.
A run that waits for a held lock now says so first. Waiting is what
the spec asks for, but the wait has no timeout, and in silence it is
indistinguishable from a hang - I spent two minutes on one myself
today, waiting on a lock the window was holding.
Tests that faked a held lock by writing a file now hold a real one.
Diffstat (limited to 'cmd/krino/sort.go')
| -rw-r--r-- | cmd/krino/sort.go | 17 |
1 files changed, 16 insertions, 1 deletions
diff --git a/cmd/krino/sort.go b/cmd/krino/sort.go index 35d8123..a381239 100644 --- a/cmd/krino/sort.go +++ b/cmd/krino/sort.go @@ -18,6 +18,7 @@ import ( "golang.org/x/term" "git.labunix.xyz/krino/internal/engine" + "git.labunix.xyz/krino/internal/lock" "git.labunix.xyz/krino/internal/plan" "git.labunix.xyz/krino/internal/scan" "git.labunix.xyz/krino/internal/xdg" @@ -126,7 +127,7 @@ func cmdSort(g *globals, names []string, stdout, stderr io.Writer) int { // behind a stuck run. lock.Acquire takes ctx precisely so that wait // is not unbounded in practice: a signal cancels it and Acquire // returns ctx.Err() promptly instead of polling forever. - l, err := sess.Lock(ctx, d, !g.yes) + l, err := lockDir(ctx, sess, d, !g.yes, stderr) if err != nil { if interrupted(err) { // Interrupted while waiting for the lock: an interrupt, not @@ -602,3 +603,17 @@ func interrupted(err error) bool { func stopAfterApply(action rune, err error) bool { return interrupted(err) || action == 'w' } + +// lockDir takes d's lock, saying out loud what a silent wait would hide. +// The lock is tried without waiting first: when it is held and this run may +// wait, the holder is named before the wait begins, so a run that is +// waiting does not look like a run that has hung - there is no timeout on +// the wait, and until it prints something the two are indistinguishable. +func lockDir(ctx context.Context, sess *engine.Session, d *engine.Dir, wait bool, stderr io.Writer) (*lock.Lock, error) { + l, err := sess.Lock(ctx, d, false) + if wait && errors.Is(err, lock.ErrHeld) { + fmt.Fprintf(stderr, "krino: %s: %v; waiting\n", d.Name, err) + return sess.Lock(ctx, d, true) + } + return l, err +} |
