fix: acknowledge pi maintenance barrier
This commit is contained in:
@@ -79,6 +79,9 @@ func readState(path string) (State, error) {
|
||||
if state.Version != stateFileVersion || state.Previous.ID == "" || state.Previous.Reference == "" || state.Previous.MountFingerprint == "" {
|
||||
return State{}, errors.New("update recovery state is incomplete")
|
||||
}
|
||||
if mountFingerprint(state.Previous.Mounts) != state.Previous.MountFingerprint || (state.Candidate.ID != "" && mountFingerprint(state.Candidate.Mounts) != state.Candidate.MountFingerprint) {
|
||||
return State{}, errors.New("update recovery state mount fingerprint is invalid")
|
||||
}
|
||||
return state, nil
|
||||
}
|
||||
|
||||
@@ -144,9 +147,10 @@ func acquireLock(statePath string) (*updateLock, error) {
|
||||
return nil, errors.New("could not create Pi update recovery directory")
|
||||
}
|
||||
path := statePath + ".lock"
|
||||
if err := os.Mkdir(path, 0o700); err != nil {
|
||||
file, err := os.OpenFile(path, os.O_WRONLY|os.O_CREATE|os.O_EXCL, 0o600)
|
||||
if err != nil {
|
||||
if errors.Is(err, os.ErrExist) {
|
||||
if reclaimDeadLocalLock(path) {
|
||||
if reclaimDeadLocalLock(path, statePath) {
|
||||
return acquireLock(statePath)
|
||||
}
|
||||
return nil, ErrLockHeld
|
||||
@@ -154,28 +158,36 @@ func acquireLock(statePath string) (*updateLock, error) {
|
||||
return nil, errors.New("could not acquire Pi update lock")
|
||||
}
|
||||
host, err := os.Hostname()
|
||||
if err != nil { _ = os.Remove(path); return nil, errors.New("could not identify Pi update lock owner") }
|
||||
if err != nil { _ = file.Close(); _ = os.Remove(path); return nil, errors.New("could not identify Pi update lock owner") }
|
||||
owner := lockOwner{PID: os.Getpid(), Host: host, StartedAt: time.Now().UTC(), Transaction: fmt.Sprintf("%d-%d", os.Getpid(), time.Now().UnixNano())}
|
||||
contents, err := json.Marshal(owner)
|
||||
if err != nil { _ = os.Remove(path); return nil, errors.New("could not record Pi update lock owner") }
|
||||
if err := writeFileDurably(filepath.Join(path, "owner.json"), ".owner-", append(contents, '\n')); err != nil {
|
||||
_ = os.Remove(path)
|
||||
if err != nil { _ = file.Close(); _ = os.Remove(path); return nil, errors.New("could not record Pi update lock owner") }
|
||||
if _, err := file.Write(append(contents, '\n')); err != nil || file.Sync() != nil || file.Close() != nil {
|
||||
_ = file.Close(); _ = os.Remove(path)
|
||||
return nil, errors.New("could not record Pi update lock owner")
|
||||
}
|
||||
return &updateLock{path: path}, nil
|
||||
}
|
||||
func (l *updateLock) Release() { _ = os.Remove(filepath.Join(l.path, "owner.json")); _ = os.Remove(l.path) }
|
||||
func (l *updateLock) Release() { _ = os.Remove(l.path) }
|
||||
|
||||
// reclaimDeadLocalLock is deliberately conservative: a malformed, remote, or merely old lock
|
||||
// is recovery-required. Only a process we can prove is gone on this machine is reclaimed.
|
||||
func reclaimDeadLocalLock(path string) bool {
|
||||
contents, err := os.ReadFile(filepath.Join(path, "owner.json"))
|
||||
if err != nil { return false }
|
||||
func reclaimDeadLocalLock(path, statePath string) bool {
|
||||
info, err := os.Stat(path)
|
||||
if err != nil || time.Since(info.ModTime()) < 5*time.Minute || !hasPendingRecoveryState(statePath) { return false }
|
||||
contents, err := os.ReadFile(path)
|
||||
if err != nil { return os.Remove(path) == nil }
|
||||
var owner lockOwner
|
||||
if json.Unmarshal(contents, &owner) != nil || owner.PID <= 0 || owner.Host == "" { return false }
|
||||
host, err := os.Hostname()
|
||||
if err != nil || owner.Host != host { return false }
|
||||
if processAlive(owner.PID) { return false }
|
||||
if err := os.Remove(filepath.Join(path, "owner.json")); err != nil { return false }
|
||||
return os.Remove(path) == nil
|
||||
}
|
||||
|
||||
func hasPendingRecoveryState(path string) bool {
|
||||
contents, err := os.ReadFile(path); if err != nil { return false }
|
||||
var state State
|
||||
if json.Unmarshal(contents, &state) != nil { return false }
|
||||
return state.Phase != PhaseVerified && state.Phase != PhaseRolledBack && state.Phase != PhaseNoop
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user