fix(dwh): anchor generation operations to lease fd
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
# Evidence Task 6 — final fd-anchored DWH correction
|
||||
|
||||
All DWH generation state below `.tht-dwh` is now accessed relative to the directory descriptor
|
||||
retained by the shared/exclusive generation lease. ACTIVE reads, atomic temp writes, replacement,
|
||||
fsync, and rollback use `openat`/`replaceat` operations. Generation staging, validation,
|
||||
reconciliation, resume checks, retention classification, and recursive deletion likewise use owned
|
||||
root/generations/candidate descriptors with `O_NOFOLLOW`; locked operations no longer reopen
|
||||
generation paths through `workspace_root`.
|
||||
|
||||
Portable reader snapshots are copied from validated generation file descriptors into private 0700
|
||||
process-owned temporary directories while the shared lease is held. This avoids Linux-only
|
||||
`/proc/self/fd` paths and prevents a renamed/replaced `.tht-dwh` pathname from redirecting later
|
||||
schema or LSH reads. Lease-scoped copies are removed on exit and standalone snapshots are removed
|
||||
at process exit.
|
||||
|
||||
Deterministic adversarial tests rename the DWH root after lease acquisition during ACTIVE reads,
|
||||
ACTIVE publication, and retention cleanup. Each test proves the replacement tree is never read,
|
||||
written, or deleted; the descriptor-pinned original either completes consistently or fails closed.
|
||||
Existing owner binding, legacy rejection, crash reconciliation, resume, atomic rollback, retention,
|
||||
and reader/writer exclusion behavior remains covered.
|
||||
Reference in New Issue
Block a user