fix: close task5 state and capability blockers

This commit is contained in:
2026-08-11 19:52:10 +02:00
parent e35e62a5c6
commit 11ca7d111d
9 changed files with 200 additions and 185 deletions
+8 -19
View File
@@ -11,8 +11,6 @@ import fcntl
import os
import re
import stat
import struct
import sys
from dataclasses import dataclass
@@ -78,24 +76,11 @@ def verify_workspace_writer_fds(*, writer_fd: int = 3, root_fd: int = 4, env: di
lock = _fstat(lock_fd)
if (lock.st_dev, lock.st_ino) != (writer.st_dev, writer.st_ino) or not stat.S_ISREG(lock.st_mode) or lock.st_uid != uid or (lock.st_mode & 0o777) != 0o600 or lock.st_nlink != 1:
raise WorkspaceWriterConflict()
# Probe using a *different* open file description. An inherited FD 3
# is valid only when its lock is already held: the independent probe
# must therefore receive EWOULDBLOCK. We deliberately never flock(3)
# here: doing so would turn an unheld, independently opened descriptor
# into an apparently valid capability.
# First prove that an independently opened description cannot acquire the
# lock. Then probe the inherited description itself. flock is an
# open-file-description lock: the second call succeeds only on the same
# description held by the backend and does not release it.
try:
# Linux OFD locks identify the open file description rather than
# the process. The inherited FD 3 must already own this lock;
# an independent unlocked description can acquire the probe and
# is rejected. Darwin has no OFD constants, so retain flock's
# equivalent open-description probe there.
ofd_setlk = getattr(fcntl, "F_OFD_SETLK", None) if sys.platform.startswith("linux") else None
if ofd_setlk is not None:
lock_record = struct.pack("hhqqi", fcntl.F_WRLCK, os.SEEK_SET, 0, 0, 0)
fcntl.fcntl(lock_fd, ofd_setlk, lock_record)
unlock_record = struct.pack("hhqqi", fcntl.F_UNLCK, os.SEEK_SET, 0, 0, 0)
fcntl.fcntl(lock_fd, ofd_setlk, unlock_record)
raise WorkspaceWriterConflict()
fcntl.flock(lock_fd, fcntl.LOCK_EX | fcntl.LOCK_NB)
except OSError as exc:
if exc.errno not in (errno.EACCES, errno.EAGAIN, errno.EWOULDBLOCK):
@@ -106,6 +91,10 @@ def verify_workspace_writer_fds(*, writer_fd: int = 3, root_fd: int = 4, env: di
except OSError:
pass
raise WorkspaceWriterConflict()
try:
fcntl.flock(writer_fd, fcntl.LOCK_EX | fcntl.LOCK_NB)
except OSError as exc:
raise WorkspaceWriterConflict() from exc
finally:
try:
os.close(lock_fd)