fix: close task5 state and capability blockers
This commit is contained in:
@@ -60,8 +60,21 @@ def annotations_path(cfg: Config) -> Path:
|
||||
|
||||
|
||||
def refresh_catalog(cfg, *, dwh=None, output_path: Path | None = None):
|
||||
_require_writer_capability()
|
||||
"""Run the existing catalog algorithm and persist its canonical output."""
|
||||
"""Run the catalog algorithm only under the exact backend-bound root capability."""
|
||||
import os
|
||||
import stat
|
||||
cap = __import__("tht.workspace_writer_lock", fromlist=["require_workspace_writer_capability"]).require_workspace_writer_capability()
|
||||
cfg_workspace = getattr(cfg, "_workspace_id", None)
|
||||
cfg_revision = getattr(cfg, "_workspace_revision", None)
|
||||
runtime = getattr(cfg, "runtime_identity", None)
|
||||
if cfg_workspace != cap.workspace_id or cfg_revision != cap.revision or runtime is None or runtime.workspace_id != cap.workspace_id or runtime.workspace_revision != cap.revision:
|
||||
raise RuntimeError("preprocessing_conflict")
|
||||
try:
|
||||
st = os.stat(cfg.paths.sessions, follow_symlinks=False)
|
||||
except OSError as exc:
|
||||
raise RuntimeError("preprocessing_conflict") from exc
|
||||
if not stat.S_ISDIR(st.st_mode) or (st.st_dev, st.st_ino) != (cap.device, cap.inode) or st.st_uid != os.getuid() or (st.st_mode & 0o777) != 0o700:
|
||||
raise RuntimeError("preprocessing_conflict")
|
||||
target = dwh if dwh is not None else build_dwh(cfg)
|
||||
physical = target.introspect()
|
||||
_add_examples(target, physical, cfg.examples)
|
||||
|
||||
@@ -11,8 +11,6 @@ import fcntl
|
||||
import os
|
||||
import re
|
||||
import stat
|
||||
import struct
|
||||
import sys
|
||||
from dataclasses import dataclass
|
||||
|
||||
|
||||
@@ -78,24 +76,11 @@ def verify_workspace_writer_fds(*, writer_fd: int = 3, root_fd: int = 4, env: di
|
||||
lock = _fstat(lock_fd)
|
||||
if (lock.st_dev, lock.st_ino) != (writer.st_dev, writer.st_ino) or not stat.S_ISREG(lock.st_mode) or lock.st_uid != uid or (lock.st_mode & 0o777) != 0o600 or lock.st_nlink != 1:
|
||||
raise WorkspaceWriterConflict()
|
||||
# Probe using a *different* open file description. An inherited FD 3
|
||||
# is valid only when its lock is already held: the independent probe
|
||||
# must therefore receive EWOULDBLOCK. We deliberately never flock(3)
|
||||
# here: doing so would turn an unheld, independently opened descriptor
|
||||
# into an apparently valid capability.
|
||||
# First prove that an independently opened description cannot acquire the
|
||||
# lock. Then probe the inherited description itself. flock is an
|
||||
# open-file-description lock: the second call succeeds only on the same
|
||||
# description held by the backend and does not release it.
|
||||
try:
|
||||
# Linux OFD locks identify the open file description rather than
|
||||
# the process. The inherited FD 3 must already own this lock;
|
||||
# an independent unlocked description can acquire the probe and
|
||||
# is rejected. Darwin has no OFD constants, so retain flock's
|
||||
# equivalent open-description probe there.
|
||||
ofd_setlk = getattr(fcntl, "F_OFD_SETLK", None) if sys.platform.startswith("linux") else None
|
||||
if ofd_setlk is not None:
|
||||
lock_record = struct.pack("hhqqi", fcntl.F_WRLCK, os.SEEK_SET, 0, 0, 0)
|
||||
fcntl.fcntl(lock_fd, ofd_setlk, lock_record)
|
||||
unlock_record = struct.pack("hhqqi", fcntl.F_UNLCK, os.SEEK_SET, 0, 0, 0)
|
||||
fcntl.fcntl(lock_fd, ofd_setlk, unlock_record)
|
||||
raise WorkspaceWriterConflict()
|
||||
fcntl.flock(lock_fd, fcntl.LOCK_EX | fcntl.LOCK_NB)
|
||||
except OSError as exc:
|
||||
if exc.errno not in (errno.EACCES, errno.EAGAIN, errno.EWOULDBLOCK):
|
||||
@@ -106,6 +91,10 @@ def verify_workspace_writer_fds(*, writer_fd: int = 3, root_fd: int = 4, env: di
|
||||
except OSError:
|
||||
pass
|
||||
raise WorkspaceWriterConflict()
|
||||
try:
|
||||
fcntl.flock(writer_fd, fcntl.LOCK_EX | fcntl.LOCK_NB)
|
||||
except OSError as exc:
|
||||
raise WorkspaceWriterConflict() from exc
|
||||
finally:
|
||||
try:
|
||||
os.close(lock_fd)
|
||||
|
||||
Reference in New Issue
Block a user