Fork-lock gates cannot reach the third executable-writing door (File::create + write! + chmod), and plugin-host/tests/kill_cost.rs is a live member #271
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#271
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found during I066 (#269 follow-up), round-2 review. Recorded rather than fixed, because the fix is structural and the gate could not offer that file a remedy.
Background
crates/test-support/tests/exec_copy_registry.rsrefuses a test that creates an executable and then forks without the fork lock. The reason is specific: writing a file holds a write fd on it, and a fork from any other thread in the same test binary inside that window leaves the child holding that fd — Linux then refuses to exec a file held open for writing, so the exec failsETXTBSYabout a state no operator ever created.I066 closed two of the three doors:
fs::copyof a built binary — the original rule.fs::write+set_permissionswith an execute bit, on the same path expression in one function body — added in I066 after it was found live incrates/cli/tests/installer_e2e.rs.The door that is still open
File::create+write!+set_permissions.crates/plugin-host/tests/kill_cost.rs'sscript()is a real member: it writes a/bin/shworker, chmods it0o755, and the supervisor execs it.Why the gate could not fix it
Two independent obstacles, both measured:
crates/plugin-hostcarries nocode-index-test-supportdev-dependency, andthe_dependency_lists_are_exactly_thesegrades that manifest — so the gate cannot point that file atwrite_executable, which is the remedy it offers everyone else. A gate that names a defect while offering no reachable fix is worse than one that states its boundary.code_index_plugin_host::Supervisor, not inCommandcalls a suite could redirect. The other half of the rule — route the target's spawns throughlocked_output/locked_status/locked_spawn— has nothing to attach to here.So the current gate states this boundary in its own documentation instead of implying coverage it does not have.
Why it is worth closing anyway
The ETXTBSY window is a race, not a deterministic failure. It was measured at roughly 10% under a four-thread soak in the
installer_e2ecase, which is exactly the rate that produces an occasional inexplicable red in CI and gets retried away. A door left open in a gate whose whole purpose is to make that race impossible will eventually be walked through.Options, none obviously right
crates/plugin-hostthecode-index-test-supportdev-dependency and update the manifest gate in the same change — cheapest, but it widens the sandboxed worker crate's dev graph, which that gate exists to keep narrow.plugin-hostalready depends on.Supervisortake the lock around its own spawn, which fixes the general case rather than the test case, at the cost of putting test-support machinery in production code.kill_cost.rsis the only member.Scope note
Pre-existing; not introduced by I066. The two doors I066 did close are graded with executed mutations, including the coupling that neither half alone is sufficient — reverting the write helper removes the string the spawn gate triggers on, so that target stops being checked at all.