Skip to content

fix(auth): recover stale credential file locks via PID liveness - #1194

Open
TheGreatAxios wants to merge 5 commits into
mainfrom
cl-8998-auth-lock
Open

TheGreatAxios wants to merge 5 commits into
mainfrom
cl-8998-auth-lock

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Collaborator

Stale Codex/xAI credential-file locks from crashed holders brick the auth store until manual removal. Tag new locks with the holder PID and take over dead-holder and aged legacy locks; live holders still wait out the existing timeout.

Verification: bun test src/auth/store.test.ts (11 pass), bun test src/auth/ (82 pass), bun run build (exit 0). Typecheck reports only the pre-existing vendor/intx-types semver error, reproduced on the pristine tree.

Fixes CL-8998

@linear-code

linear-code Bot commented Sep 28, 2026

Copy link
Copy Markdown

CL-8998

The steal re-read narrows but does not close the unlink window, so a loser that deletes a winner's live lock could run two holders. Claims are now unique per waiter and re-read after create; a mismatch closes and re-contends. Steal contention also falls through to the deadline and sleep path instead of hot-spinning.
@TheGreatAxios

Copy link
Copy Markdown
Collaborator Author

Follow-up (175be0b) addresses the two review notes:

  1. Re-read→unlink TOCTOU: lock claims are now unique per waiter (pid:counter, still parsed by holderPid), and after a successful exclusive create the waiter re-reads the path — on mismatch it closes its handle (never unlinks a winner's live lock) and re-contends through the paced deadline/sleep path. This closes the practical window; a fully atomic steal would need kernel-conditional unlink, which POSIX does not offer.
  2. Hot-spin nit: the bare continue is gone — steal contention falls through to the shared deadline/sleep helper (paceLockWait), as does the post-create mismatch path.

No deterministic test for the steal race: forcing one would require fault-injection hooks in the lock path for a window that is now a single-syscall race, so I kept the 4 existing takeover tests green instead (store suite 11/11, full src/auth/ 82/82). Pre-existing, unrelated: oxfmt --check flags untouched store.test.ts, and tsc --noEmit fails on vendor/intx-types missing semver types — both reproduce on the pristine branch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant