21 lines
1.4 KiB
Markdown
21 lines
1.4 KiB
Markdown
# Evidence Task 6 — final fd-anchored DWH correction
|
|
|
|
All DWH generation state below `.tht-dwh` is now accessed relative to the directory descriptor
|
|
retained by the shared/exclusive generation lease. ACTIVE reads, atomic temp writes, replacement,
|
|
fsync, and rollback use `openat`/`replaceat` operations. Generation staging, validation,
|
|
reconciliation, resume checks, retention classification, and recursive deletion likewise use owned
|
|
root/generations/candidate descriptors with `O_NOFOLLOW`; locked operations no longer reopen
|
|
generation paths through `workspace_root`.
|
|
|
|
Portable reader snapshots are copied from validated generation file descriptors into private 0700
|
|
process-owned temporary directories while the shared lease is held. This avoids Linux-only
|
|
`/proc/self/fd` paths and prevents a renamed/replaced `.tht-dwh` pathname from redirecting later
|
|
schema or LSH reads. Lease-scoped copies are removed on exit and standalone snapshots are removed
|
|
at process exit.
|
|
|
|
Deterministic adversarial tests rename the DWH root after lease acquisition during ACTIVE reads,
|
|
ACTIVE publication, and retention cleanup. Each test proves the replacement tree is never read,
|
|
written, or deleted; the descriptor-pinned original either completes consistently or fails closed.
|
|
Existing owner binding, legacy rejection, crash reconciliation, resume, atomic rollback, retention,
|
|
and reader/writer exclusion behavior remains covered.
|