Skip to content

fix(lock): bound stale lock recovery with a non-recursive steal mutex - #3593

Open
withally wants to merge 1 commit into
kunchenguid:mainfrom
withally:upstream/lock-steal-mutex
Open

withally wants to merge 1 commit into
kunchenguid:mainfrom
withally:upstream/lock-steal-mutex

Conversation

@withally

@withally withally commented Sep 3, 2026

Copy link
Copy Markdown

Problem

Stale lock recovery uses the same acquisition function for both the primary lock and its .steal serialization mutex.
When the serialization mutex is itself stale or malformed, recovery recurses into .steal.steal and can continue nesting instead of keeping one bounded recovery transition.

The regression was reproduced on upstream/main at 1c00e86cf3a15008a4c0116b4aad13512383daed:

rc=0
ln-targets:
/tmp/.../state/.contend.lock.steal.steal
/tmp/.../state/.contend.lock.steal
/tmp/.../state/.contend.lock
not ok - stale steal mutex attempted nested .steal.steal acquisition

Fix

Add a non-recursive acquisition path for stale-recovery mutexes.
It reclaims stale symlink and legacy directory forms through owner-bound markers, refuses live or fresh owners, and never requests another steal mutex.
Lock creation now distinguishes retryable contention from invalid owner-record creation, and waiting callers propagate the non-retryable status instead of spinning.

Tests

  • bin/fm-test-run.sh tests/fm-watcher-lock.test.sh
  • bin/fm-test-run.sh tests/fm-backlog-handoff.test.sh tests/fm-session-start.test.sh tests/fm-sessionstart-nudge.test.sh tests/fm-startup-network.test.sh
  • bin/fm-lint.sh
  • bin/fm-doc-audience-check.sh

Evidence

The lock suite covers stale and malformed mutexes, abandoned reclaim markers, legacy directory-shaped mutexes, concurrent claimants, invalid owner-record creation, and self-abandoned recovery.
The focused rebased run completed with FM_TEST_SUMMARY total=1 failed=0.
The touched consumer run completed with FM_TEST_SUMMARY total=4 failed=0.
ShellCheck 0.11.0, actionlint 1.7.12, documentation ownership checks, and git diff --check passed on the rebased commit.

@greptile-apps

greptile-apps Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Confidence Score: 4/5

The ordinary backlog-handoff path should be fixed before merging because it can continue mutating handoff state after the new lock-acquisition failure.

The lock library now returns a non-retryable error when it cannot create an owner record, but three ordinary backlog-handoff acquisitions ignore that result and continue into serialized local or remote delivery work.

Files Needing Attention: bin/fm-backlog-handoff.sh

Comments Outside Diff (1)

  1. bin/fm-backlog-handoff.sh, line 754 (link)

    P1 Handoff proceeds without locks

    If the registry or handoff lock cannot create its owner record because its parent is missing or unwritable, fm_lock_acquire_wait returns a non-retryable error that these calls ignore, causing local or remote handoff processing to continue without serialization and race backlog, outbox, receipt, or receiver-wake state.

    Knowledge Base Used: Session transitions and teardown

Reviews (1): Last reviewed commit: "fix(lock): bound stale lock recovery wit..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant