Lock the state directory and write vault files atomically (closes #34)
check / check (push) Failing after 17s
check / check (push) Failing after 17s
Each command that changes the state directory holds one lock: flock(2) on `lock` in the state directory, dropped by the kernel if the process dies, or a process-wide mutex on the in-memory test filesystem. It covers the state directory, not each vault, because `currentvault`, `vault create` and cross-vault moves span vaults, and a lock file in a vault would be deleted by `vault remove` under a waiting command. Files go through `secret.WriteFileAtomic`; versions, new secrets and cross-vault copies are built in a temporary directory and renamed into place; removals rename out of the way first. Left for later: replacing an unlocker (#71) and deleting what an interrupted command leaves under a `.tmp-` name (#75). Model: opus-5-5
This commit is contained in:
@@ -62,4 +62,10 @@ var (
|
||||
// ErrUnlockerNotFound indicates no unlocker with the given ID exists.
|
||||
// Composed as "unlocker with ID <id> not found".
|
||||
ErrUnlockerNotFound = errors.New("not found")
|
||||
|
||||
// ErrNoLockForFilesystem indicates LockStateDir was given a filesystem
|
||||
// it cannot lock. Composed as "cannot lock the state directory on
|
||||
// filesystem <type>".
|
||||
ErrNoLockForFilesystem = errors.New(
|
||||
"cannot lock the state directory on filesystem")
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user