fix: take the signal-time autosave on the game goroutine (closes #24)

The SIGHUP/SIGTERM handler gob-encoded the live game tree from the signal
goroutine while the game goroutine was mid-turn mutating it, and AutoSave
removed the save file before encoding — so the failure mode was not a
stale save but a deleted one followed by a possibly torn replacement,
with a window in which the player had neither. The suite has run under
-race since 2026-08-09 and was green because nothing had ever driven the
turn loop concurrently with a signal: evidence of untested, not of safe.

The handler no longer writes anything. AutoSaveOnSignal posts a request,
wakes the input read, and waits up to signalSaveTimeout for the game
goroutine to take it; the encode runs on the goroutine that owns the
state, at the three points where that goroutine can sit: between turns
(command), on waking from a blocked readchar, and while parked in the `!`
shell escape (runShellEscape, which now runs the shell on a helper
goroutine so a hangup during it still rescues the game).

Blocked on input is the case that matters — a dropped connection lands
while the player is thinking, so a flag checked only between turns would
never be looked at. Terminal.ReadChar therefore returns (byte, bool),
with ok false meaning "woken by Interrupt, no key", and term.Tcell posts
a tcell.EventInterrupt onto tcell's own event queue to unpark PollEvent.
readchar services the request and reads again, so no caller sees it.

Running the shell on a helper goroutine would also have moved
term.Tcell.ShellEscape's panic on a failed Screen.Resume onto it, and a
panic at the top of any goroutine terminates the process without running
the deferred calls of the others — including cmd/rogue/main.go's
`defer t.Fini()`. The tty would have been left raw on precisely the path
where the terminal is already broken, which is issue #12's failure on a
path this change created. runShellEscape therefore recovers the helper's
panic and re-raises it on the game goroutine, whose stack has the restore
in it, so "every path restores the terminal via Terminal.Fini before
exiting" stays true.

saveFile writes a temporary file in the save's own directory, fsyncs it
and renames it over the target instead of truncating in place, so a save
that fails — or never happens because the deadline ran out — leaves the
player's previous save whole.

What the handoff guarantees is stated exactly rather than flatteringly:
the encode runs on the state-owning goroutine, so the snapshot is
internally consistent and restorable, but it is not necessarily taken
between commands. Only the check at the top of command is; the other two
service points both sit inside a command call already under way. readchar
is reached from mid-command prompts (--More--, askOverwrite, getStr, the
direction and pack prompts) with the command's mutations already applied,
and runShellEscape is reached from shell, an ordinary '!' command handler
dispatched inside command, with that turn's DoDaemons(Before) and
DoFuses(Before) already fired and its AFTER pass not yet. Restoring
re-enters playit at the top of command, so either way the rest of that
command is lost and a fresh BEFORE pass runs on top of the one in the
snapshot.

The SIGINT/SIGQUIT no-save decision and the single-signal-read ordering
guarantee are untouched. pendingSaver reads the game out from under its
mutex rather than delegating with it held, because the delegated call now
blocks until the save is taken.
This commit is contained in:
clawbot
2026-08-09 06:47:40 +00:00
committed by sneak
parent e1bf46b241
commit 3a01283358
13 changed files with 1176 additions and 98 deletions

68
TODO.md
View File

@@ -34,6 +34,74 @@ wizard commands).
# Completed Steps
- 2026-08-09 Signal-time autosave moved onto the game goroutine
(`fix/autosave-race`, closes #24): the SIGHUP/SIGTERM handler gob-encoded the
live game tree from the signal goroutine while the game goroutine was mid-turn
mutating it, and `AutoSave` **removed** the save file before encoding — so the
failure mode was not a stale save but a deleted one followed by a possibly
torn replacement, with a window in which the player had neither. `make test`
has run with `-race` since 2026-08-09 and was green, because no test had ever
driven the turn loop concurrently with a signal: evidence of untested, not of
safe. The handler now writes nothing itself. `AutoSaveOnSignal` posts a
request on a one-deep channel, wakes the input read, and waits up to
`signalSaveTimeout` (3s) for the game goroutine to take it; the encode happens
on the goroutine that owns the state. **The blocked-on-input case is the whole
point** — a dropped connection lands while the player is thinking, so a flag
checked only between turns would never be looked at — and it is handled by
making the read interruptible: `Terminal.ReadChar` returns `(byte, bool)` with
`ok == false` meaning "woken by `Interrupt`, no key", `term.Tcell.Interrupt`
posts a `tcell.EventInterrupt` onto tcell's own event queue to unpark
`PollEvent`, and `readchar` services the request and reads again, so no caller
sees the wake-up. The other unbounded park is the `!` shell escape, where a
hangup used to save and would otherwise have regressed to not saving: the
shell now runs on a helper goroutine and `runShellEscape` selects on {shell
finished, save request}, keeping the encode on the game goroutine while it
draws nothing. Between turns (`command`) covers a game that is busy rather
than parked. The wait is bounded so that a game goroutine wedged with no
service point can never stop a signal from getting the process out; giving up
costs nothing now that `saveFile` writes a temporary file in the save's own
directory, fsyncs it, and renames it over the target instead of truncating in
place — a failed or skipped save leaves the previous save whole. New
`game/autosave_test.go` drives the real turn loop while a second goroutine
asks for 25 saves (the interleaving that never existed before), plus the
parked-on-input case with a terminal fake that genuinely blocks, the shell
case, the deadline case (previous save byte-for-byte intact), the no-file-name
case, and the rename discipline — the last pinned by a handle opened before
the save, which still reads the old file whole after it. Each was
mutation-proved: reverting `AutoSaveOnSignal` to encode on the calling
goroutine (the pre-fix behavior) makes the turn-loop test fail under `-race`
with over a hundred reports, and removing each of the three service points
fails exactly the test for that park with its own message. `pendingSaver` now
reads the game out from under its mutex instead of delegating with it held,
because the delegated call blocks until the save is taken — the PR #23
review's N3 note, load-bearing rather than hypothetical, and pinned by a test.
The SIGINT/SIGQUIT no-save decision and the single-signal-read ordering
guarantee are untouched; `savesOnSignal`'s third ground ("safety") is
rewritten, since the corruption window it weighed no longer exists.
`MEMORY.md` stops listing signal-time autosave among the deliberate `_ =`
discards and states the new discipline; `ARCHITECTURE.md` §5.3, the `Terminal`
sketch, the C-to-Go mapping row and §9's SIGTSTP paragraph are corrected to
match. Two things review caught and this entry records so they are not undone:
moving the shell onto a helper goroutine also moved `term.Tcell.ShellEscape`'s
`panic` on a failed `Screen.Resume` there, and a panic at the top of any
goroutine kills the process without running the deferred calls of the others —
including `cmd/rogue/main.go`'s `defer t.Fini()`, so the tty would have been
left raw on exactly the path where the terminal is already broken (issue #12's
failure, reintroduced on a new path). `runShellEscape` recovers the helper's
panic and re-raises it on the game goroutine, pinned by
`TestShellEscapePanicUnwindsTheGameGoroutine`. And the doc comment took two
rounds to get right: the first version claimed in four places that nothing is
half-mutated at the `readchar` service point, and the revision that fixed that
claimed two of the three service points were between-commands. Both are false.
Only the check at the top of `command` is between commands — `readchar` is
reached from mid-command prompts, and `runShellEscape` is reached from
`shell`, an ordinary `'!'` command handler dispatched inside `command`, with
that turn's `DoDaemons(Before)`/`DoFuses(Before)` already fired and its AFTER
pass and ring effects not yet. What is actually guaranteed is that the encode
runs on the state-owning goroutine, so the snapshot is internally consistent
and restorable, though it may freeze a command half applied. `Next Step`
deliberately not rotated: out-of-band issue work.
- 2026-08-09 Signal-time terminal restore (`sig-leave`, closes #12): the port
handled only SIGHUP and SIGTERM, so SIGINT and SIGQUIT killed the process with
tcell still holding the tty, leaving the user at a shell with no echo. All