You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Stale lock recovery uses the same acquisition function for both the primary lock and its .steal serialization mutex.
When the serialization mutex is itself stale or malformed, recovery recurses into .steal.steal and can continue nesting instead of keeping one bounded recovery transition.
The regression was reproduced on upstream/main at 1c00e86cf3a15008a4c0116b4aad13512383daed:
rc=0
ln-targets:
/tmp/.../state/.contend.lock.steal.steal
/tmp/.../state/.contend.lock.steal
/tmp/.../state/.contend.lock
not ok - stale steal mutex attempted nested .steal.steal acquisition
Fix
Add a non-recursive acquisition path for stale-recovery mutexes.
It reclaims stale symlink and legacy directory forms through owner-bound markers, refuses live or fresh owners, and never requests another steal mutex.
Lock creation now distinguishes retryable contention from invalid owner-record creation, and waiting callers propagate the non-retryable status instead of spinning.
The lock suite covers stale and malformed mutexes, abandoned reclaim markers, legacy directory-shaped mutexes, concurrent claimants, invalid owner-record creation, and self-abandoned recovery.
The focused rebased run completed with FM_TEST_SUMMARY total=1 failed=0.
The touched consumer run completed with FM_TEST_SUMMARY total=4 failed=0.
ShellCheck 0.11.0, actionlint 1.7.12, documentation ownership checks, and git diff --check passed on the rebased commit.
The ordinary backlog-handoff path should be fixed before merging because it can continue mutating handoff state after the new lock-acquisition failure.
The lock library now returns a non-retryable error when it cannot create an owner record, but three ordinary backlog-handoff acquisitions ignore that result and continue into serialized local or remote delivery work.
If the registry or handoff lock cannot create its owner record because its parent is missing or unwritable, fm_lock_acquire_wait returns a non-retryable error that these calls ignore, causing local or remote handoff processing to continue without serialization and race backlog, outbox, receipt, or receiver-wake state.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Stale lock recovery uses the same acquisition function for both the primary lock and its
.stealserialization mutex.When the serialization mutex is itself stale or malformed, recovery recurses into
.steal.stealand can continue nesting instead of keeping one bounded recovery transition.The regression was reproduced on
upstream/mainat1c00e86cf3a15008a4c0116b4aad13512383daed:Fix
Add a non-recursive acquisition path for stale-recovery mutexes.
It reclaims stale symlink and legacy directory forms through owner-bound markers, refuses live or fresh owners, and never requests another steal mutex.
Lock creation now distinguishes retryable contention from invalid owner-record creation, and waiting callers propagate the non-retryable status instead of spinning.
Tests
bin/fm-test-run.sh tests/fm-watcher-lock.test.shbin/fm-test-run.sh tests/fm-backlog-handoff.test.sh tests/fm-session-start.test.sh tests/fm-sessionstart-nudge.test.sh tests/fm-startup-network.test.shbin/fm-lint.shbin/fm-doc-audience-check.shEvidence
The lock suite covers stale and malformed mutexes, abandoned reclaim markers, legacy directory-shaped mutexes, concurrent claimants, invalid owner-record creation, and self-abandoned recovery.
The focused rebased run completed with
FM_TEST_SUMMARY total=1 failed=0.The touched consumer run completed with
FM_TEST_SUMMARY total=4 failed=0.ShellCheck 0.11.0, actionlint 1.7.12, documentation ownership checks, and
git diff --checkpassed on the rebased commit.