fix: harden durable workspace runtime config leases

This commit is contained in:
2026-08-11 09:44:08 +02:00
parent e0950f5ed4
commit 390122480a
5 changed files with 510 additions and 175 deletions
+12 -6
View File
@@ -321,24 +321,30 @@ export class ThtRunner {
env.THT_SSL_CA = ca;
}
let snapshotFd: number | undefined;
let canonicalFd: number | undefined;
let ch;
try {
snapshotFd = workspaceConfigPath && this.runtimeSnapshots.has(workspaceConfigPath)
? this.openTrustedRuntimeSnapshot(workspaceConfigPath)
: undefined;
? this.openTrustedRuntimeSnapshot(workspaceConfigPath) : undefined;
// Runtime lease publication is durable, but the child must consume the verified
// bytes rather than reopening a mutable pathname after spawn. Keep canonical -c
// for CLI compatibility and hand the same open file as fd 3.
canonicalFd = snapshotFd === undefined && workspaceConfigPath && this.runtimeLeases.has(workspaceConfigPath)
? openSync(workspaceConfigPath, fsConstants.O_RDONLY | fsConstants.O_NOFOLLOW) : undefined;
const handoffFd = snapshotFd ?? canonicalFd;
if (canonicalFd !== undefined) env.THT_CONFIG_FD = "3";
ch = spawn(
this.cfg.thtBin,
snapshotFd === undefined
? this.buildArgv(args, workspaceConfigPath)
: [...args, "-c", "/dev/fd/3"],
snapshotFd === undefined ? this.buildArgv(args, workspaceConfigPath) : [...args, "-c", "/dev/fd/3"],
{
cwd: this.cfg.harnessDir,
env,
...(snapshotFd === undefined ? {} : { stdio: ["ignore", "pipe", "pipe", snapshotFd] }),
...(handoffFd === undefined ? {} : { stdio: ["ignore", "pipe", "pipe", handoffFd] }),
},
);
} finally {
if (snapshotFd !== undefined) closeSync(snapshotFd);
if (canonicalFd !== undefined) closeSync(canonicalFd);
}
let stdout = "";
let stderr = "";