summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGabriel Schneider <[email protected]>2026-09-29 18:23:04 -0300
committerGabriel Schneider <[email protected]>2026-10-01 00:12:17 -0300
commit1db5ba2b267f030e2de54a2cb4de9fb155c4139d (patch)
tree11d20f29b4773b92e492d2035e103e38d083007e
parent09ef40318a3a3d1b9494e2a5fa41f71363929676 (diff)
downloadpardes-1db5ba2b267f030e2de54a2cb4de9fb155c4139d.tar.gz
pardes-1db5ba2b267f030e2de54a2cb4de9fb155c4139d.zip
Only a write logs an err: a refused open or truncation, create or remove, or a write to pane/new, is its error alone, and every refusal is said in words
The one-failure rule is a write's. A refused remove, pane/new's open refused for want of a slot, and an OTRUNC open's refused truncation (data's after a failed addr) also logged an err, and a reply carrying only an errno reached the client as the C library's text (Operation not permitted). tree.handle now gives such a reply Plan 9's words, chosen so 9ns maps each back to its errno (EPERM's to EACCES, as Plan 9's does), and serveFs logs errs for writes only, not a write to pane/new, which is only read. docs/fs.md and the 9P skill say so, and that a look miss quotes what was written. Co-Authored-By: Claude Opus 5.5 <[email protected]>
-rw-r--r--.agents/skills/pardes-9p/SKILL.md6
-rw-r--r--docs/fs.md12
-rw-r--r--src/ninep/cols.zig5
-rw-r--r--src/ninep/events.zig4
-rw-r--r--src/ninep/tree.zig56
-rw-r--r--src/pardes.zig6
6 files changed, 79 insertions, 10 deletions
diff --git a/.agents/skills/pardes-9p/SKILL.md b/.agents/skills/pardes-9p/SKILL.md
index 56123b89..18700589 100644
--- a/.agents/skills/pardes-9p/SKILL.md
+++ b/.agents/skills/pardes-9p/SKILL.md
@@ -210,7 +210,11 @@ leaves a multi-line input at `...`). A middle click, or an event
write-back, sends what it needs by itself. Sent line by line, a blank line ends a Python block, and Python
3.14's REPL auto-indents each line it is typed. Every refused 9P write adds an `err <serial|->
<file>: <why>` record to `$m/log`; through a mount the write itself only says
-`Invalid argument`.
+`Invalid argument`. Only writes log one: a refused open or truncation
+(an OTRUNC open, as `data`'s after a failed `addr`), create or remove is
+its error alone, as are a write to `pane/new` (`permission denied`) and a
+write on a fid opened read-only (`bad use of fid`). Errors are words, never
+a C errno string. A look miss quotes what was written: `no match for "zzq:#3"`.
## Edit through addresses, dot and the flag files
diff --git a/docs/fs.md b/docs/fs.md
index 760693e5..52f991c2 100644
--- a/docs/fs.md
+++ b/docs/fs.md
@@ -819,9 +819,17 @@ nothing empties it rather than leave the last rows), while a plain
word's `LookWord list` search keeps a pane a pattern, ENOSPC for no room or
slot, EBUSY for a held lock) -- and logs its reason exactly once, as `err <serial|->
<file>: <why>`, with no `msg` for it. A builtin a click runs (Save, get's
-`Modified`, Tty with no room, Edit) is no exception. What is not a
+`Modified`, Tty with no room, Edit) is no exception. The rule is a write's:
+a refused open or truncation -- an OTRUNC open, such as `data`'s after a
+failed `addr` --, create or remove answers its error and
+logs no `err`, and so do a write to `pane/new` (`permission denied`: it is
+only read) and a write on a fid opened OREAD (`bad use of fid`). Every
+refusal is said in words, Plan 9's where pardes has none of its own
+(`permission denied`, `file does not exist`, `bad argument`), never a C
+library string such as `Operation not permitted`. What is not a
failure: a look that finds nothing answers nothing and logs one `err`
-(`look: no match for ...`, the same miss again counted, `(x2)`, as any
+(`look: no match for ...`, quoting what was written in every form --
+`no match for "zzq:#3"`, `no match for "zzq:2"` -- the same miss again counted, `(x2)`, as any
repeated `err` is), the write succeeding; and a command line run in
a command pane ends in its own time, told by its `exit` record.
diff --git a/src/ninep/cols.zig b/src/ninep/cols.zig
index 6b59f9e5..cc583c93 100644
--- a/src/ninep/cols.zig
+++ b/src/ninep/cols.zig
@@ -368,10 +368,11 @@ test "a column's ctl and exec act on it as its tag would, and rmdir closes it on
try testing.expectEqual(E.INVAL, th.wr(p, Node.ofCol(empty, .ctl), "Exit\n").errno());
var rec: [64]u8 = undefined;
try testing.expect(th.logHas(p, try std.fmt.bufPrint(&rec, "err - col/{d}/ctl: unknown control message \"Exit\"", .{empty})));
- // rmdir refuses a column with a pane, and says why.
+ // rmdir refuses a column with a pane, and says why, in its error alone.
const full = th.call(p, .{ .tag = 1, .op = .release, .node = Node.ofCol(empty, .dir), .remove = true });
try testing.expectEqual(E.NOTEMPTY, full.errno());
- try testing.expect(th.logHas(p, try std.fmt.bufPrint(&rec, "err - col/{d}: column not empty", .{empty})));
+ try testing.expect(std.mem.startsWith(u8, full.reply.ename, "column not empty"));
+ try testing.expect(!th.logHas(p, try std.fmt.bufPrint(&rec, "err - col/{d}: column not empty", .{empty})));
// exec runs a word as a click in that column's tag: Delcol closes it.
try testing.expectEqual(tree.Status.ok, th.wr(p, Node.ofCol(empty, .exec), "Delcol\n").reply.status);
try testing.expectEqual(@as(?usize, null), layout.columnBySerial(p, empty));
diff --git a/src/ninep/events.zig b/src/ninep/events.zig
index f76a5212..c0bf4a9a 100644
--- a/src/ninep/events.zig
+++ b/src/ninep/events.zig
@@ -174,8 +174,8 @@ pub fn noteMessage(p: *Pardes, serial: u32, said: []const u8) void {
std.fmt.bufPrint(&buf, "msg {d} {s}{s}\n", .{ serial, kept, cut })) catch return, said);
}
-/// Records `err <serial|-> <file>: <why>` for a write or truncation that was
-/// refused or failed: through a mount a shell sees only the errno the
+/// Records `err <serial|-> <file>: <why>` for a write that was refused or
+/// failed: through a mount a shell sees only the errno the
/// kernel mapped the reply to (`Invalid argument`), and here is the reason.
/// The log is the one place for it, as acme's `errors` file takes text and
/// answers nothing: a per-pane readable error file would be a second.
diff --git a/src/ninep/tree.zig b/src/ninep/tree.zig
index 94fa5d1e..30bf073d 100644
--- a/src/ninep/tree.zig
+++ b/src/ninep/tree.zig
@@ -454,6 +454,33 @@ pub fn stagedReply(p: *Pardes, req: Req) Reply {
// ---- dispatch ----
pub fn handle(p: *Pardes, req: Req) Reply {
+ var reply = serve(p, req);
+ if (reply.status == .err and reply.ename.len == 0) reply.ename = errWords(reply.errno);
+ return reply;
+}
+
+/// A refusal with no reason of its own said in Plan 9's words, not the C
+/// library's (`Operation not permitted`); each maps back to its errno in
+/// 9ns (enameToErrno), EPERM's to EACCES as Plan 9's does.
+pub fn errWords(errno: u16) []const u8 {
+ return switch (errno) {
+ E.PERM => "permission denied",
+ E.NOENT => "file does not exist",
+ E.NOMEM => "out of memory",
+ E.BUSY => "file in use",
+ E.EXIST => "file already exists",
+ E.NOTDIR => "not a directory",
+ E.ISDIR => "is a directory",
+ E.INVAL => "bad argument",
+ E.NFILE => "too many open files",
+ E.NOSPC => "no space left",
+ E.NOSYS => "not supported",
+ E.NOTEMPTY => "directory not empty",
+ else => "i/o error",
+ };
+}
+
+fn serve(p: *Pardes, req: Req) Reply {
// Held writes go in before anything but the next write of their open.
if (p.fs.batch.bytes.items.len > 0 and !(req.op == .write and req.node == p.fs.batch.node and req.handle == p.fs.batch.handle))
pane.flushBatch(p);
@@ -1564,8 +1591,8 @@ test "at the pane cap, pane/new, look and New each say so, and look reads back e
const refused = call(p, .{ .tag = 2, .op = .open, .node = new });
try testing.expectEqual(E.NOSPC, refused.errno());
try testing.expect(std.mem.endsWith(u8, refused.reply.ename, said));
- try testing.expect(th.logHas(p, said));
- // Its err alone says it: no msg besides (the one rule).
+ // A refused open is its error alone: no err, and no msg besides.
+ try testing.expect(!th.logHas(p, said));
try testing.expect(!th.logHas(p, "New: no space"));
// A look that would open a pane fails its write, and says the same.
var tmp = testing.tmpDir(.{});
@@ -1614,6 +1641,31 @@ test "a command line cut across writes runs once whole, and the last runs at rel
try testing.expectEqualStrings("x\none\ntwo\n", p.panes[0].?.file.?.content);
}
+test "a refused open, create or remove says why in words and logs no err; a refused write logs one" {
+ const p = try th.withFile(testing.allocator, "x\n");
+ defer p.deinit();
+ const serial = serialOf(p);
+ // pane/new is read, never written: a write is refused, and is no
+ // failure the log tells of.
+ const new = th.wr(p, @intFromEnum(TopFile.new), "x\n");
+ try testing.expectEqual(Status.err, new.reply.status);
+ try testing.expectEqualStrings("permission denied", new.reply.ename);
+ const made = call(p, .{ .tag = 2, .op = .open, .node = Node.of(serial, .body), .create = true });
+ try testing.expectEqualStrings("permission denied", made.reply.ename);
+ const gone = th.rmdir(p, @intFromEnum(TopFile.index));
+ try testing.expectEqual(Status.err, gone.reply.status);
+ try testing.expect(gone.reply.ename.len > 0 and !std.ascii.isUpper(gone.reply.ename[0]));
+ // An OTRUNC open's truncation of data after a failed addr: refused, no err.
+ _ = th.wr(p, Node.of(serial, .addr), "/nothere/");
+ const errs = th.logCount(p, "\nerr ");
+ try testing.expectEqual(Status.err, call(p, .{ .tag = 3, .op = .setattr, .node = Node.of(serial, .data), .truncate = true }).reply.status);
+ try testing.expectEqual(errs, th.logCount(p, "\nerr "));
+ try testing.expectEqual(@as(usize, 1), errs); // the addr write's own
+ // A write is the rule's: refused, it logs its one err, in words too.
+ try testing.expectEqual(Status.err, th.wr(p, Node.of(serial, .ctl), "bogus\n").reply.status);
+ try testing.expectEqual(@as(usize, 2), th.logCount(p, "\nerr "));
+}
+
test "a write with no newline, whole in its Twrite, runs then and fails the write; one needing more waits" {
const p = try th.withFile(testing.allocator, "abc\n");
defer p.deinit();
diff --git a/src/pardes.zig b/src/pardes.zig
index cb39b5d1..19fe51d1 100644
--- a/src/pardes.zig
+++ b/src/pardes.zig
@@ -5729,7 +5729,11 @@ pub const Pardes = struct {
p.fs.lsp_answer_at = null;
const reply = ctlfs.handle(p, req);
p.fs.serving = false;
- if (reply.status == .err and (req.op == .write or req.op == .setattr or (req.op == .open and reply.errno == ctlfs.E.NOSPC) or (req.op == .release and req.remove))) ctlfs.events.noteError(p, req, reply);
+ // The one-failure rule is a write's: a refused open (its OTRUNC's
+ // truncation, a setattr, too), create or remove is its Rerror alone,
+ // no err, as is a write to pane/new, which is only ever read.
+ const ruled = req.op == .write and req.node != @intFromEnum(ctlfs.TopFile.new);
+ if (reply.status == .err and ruled) ctlfs.events.noteError(p, req, reply);
// The request was a whole step of its own, so it settles the way a
// step does: the cursor and scroll reconciled, the scripted panes
// told, and the panes it made announced to /log now rather than at