Skip to content

emrg: read-only lock probe + stop-chain caller logging (rants 13:08:41 + 13:11:34) - #866

Merged
argszero merged 1 commit into
masterfrom
feature/stop-probe-readonly-caller-log
Aug 19, 2026
Merged

emrg: read-only lock probe + stop-chain caller logging (rants 13:08:41 + 13:11:34)#866
argszero merged 1 commit into
masterfrom
feature/stop-probe-readonly-caller-log

Conversation

@argszero

Copy link
Copy Markdown
Owner

Fixes two P0 host rants about the Windows stop/installer chain:

1. Windows data-deletion bug (rant 2026-08-19T13:08:41)
_win_exclusive_open opened files with FILE_FLAG_DELETE_ON_CLOSE and cleared the disposition afterwards via the file-disposition-info API. That clear only works on Windows 10 1903+ — on older systems (or any failed/best-effort clear) the disposition stays set and CloseHandle DELETES the probed file. The probe is meant to be read-only ("would DeleteFile succeed?"), so it must never set a delete disposition.

  • Probe now opens with DELETE access + FILE_SHARE_NONE + plain FILE_ATTRIBUTE_NORMAL — identical sharing semantics, zero deletion risk.
  • Removed the disposition-clear API wiring entirely.

2. P0 stop-chain logging (rant 2026-08-19T13:11:34)
Every emrg stop / stop_all run must be attributable so "谁杀 daemon / 谁删文件" can be traced post-mortem:

  • New _caller_context(): parent pid + parent command line (ps / Get-CimInstance) + argv — printed in the stop_all header alongside a wall-clock start timestamp.
  • Daemon-side: the shutdown message now logs the requesting peer address in emrgd.log.

Tests: updated the lock-probe wiring test to assert the dangerous delete-on-close tokens are gone; +3 tests for _caller_context (POSIX/Windows/failure degradation). Test suite 974 collected, all green; import + CLI checks pass. Agent.md test count synced.

@argszero argszero left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ LGTM — cycle. Verified the read-only lock probe (delete-on-close disposition removed; GENERIC_DELETE + FILE_SHARE_NONE + FILE_ATTRIBUTE_NORMAL preserves DeleteFile sharing semantics with zero deletion risk — the 64-bit handle-truncation fix is kept), the stop-chain caller logging (pure-stdlib _caller_context with POSIX/Windows probes and graceful degrade, started timestamp in stop_all header, daemon shutdown peer log), and the test updates (dangerous tokens asserted absent, +3 _caller_context tests, Agent.md count synced 971→974). CI test + test-windows both PASS; local suite 974 collected all green.

@argszero argszero left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ LGTM — cycle (2/3). Re-verified: head unchanged (5ddeba4), mergeable, CI test + test-windows still green. The read-only probe (GENERIC_DELETE + FILE_SHARE_NONE + FILE_ATTRIBUTE_NORMAL, no delete-on-close disposition) and stop-chain caller logging are correct and complete.

@argszero argszero left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ LGTM — cycle (3/3). Head unchanged (5ddeba4), CI test + test-windows green, mergeable. Three consecutive LGTMs from different cycles (900/901/902) — merging.

@argszero
argszero merged commit 63cd361 into master Aug 19, 2026
2 checks passed
argszero added a commit that referenced this pull request Aug 19, 2026
Co-authored-by: EMRG Evolution <emrg@argszero.dev>
@argszero
argszero deleted the feature/stop-probe-readonly-caller-log branch August 19, 2026 11:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant