From 16717a555695ef666e9d2cd1bacc762a2ab15f4b Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Mon, 21 Sep 2026 23:53:58 -0300 Subject: Fixes from three adversarial reviews, and a destructive one among them The registry sweep could delete a live socket, anywhere on the filesystem. A reviewer reproduced it: a socket that is bound but has not reached listen(2) answers ECONNREFUSED exactly like a dead one -- that window is every server's startup -- and the sweep then followed the entry's symlink and unlinked whatever absolute path it named. It now follows a target only into the directory our own sockets live in and only to a `pardes-9p-*.sock` name, it re-probes immediately before deleting rather than trusting a probe that is by then several syscalls old, and a readlink that exactly filled its buffer is treated as the truncation it is. The test grew a case for an entry whose target is not ours: the entry goes, the file does not. Ctrl-V in raw tty mode was a black hole when the yank register was empty -- neither typed nor forwarded -- so vim's visual block, readline's quoted-insert and every other program's Ctrl-V simply vanished. With nothing to paste the chord belongs to the program again. The lone-ESC flush added earlier was dead code. vaxis already returns Escape for a one-byte 0x1b (`Parser.parseGround` asserts `input.len == 1`), so the carried byte it waited for can never exist; a reviewer showed a 3 ms gap and a 60 ms gap behaving identically. Removed rather than left to imply a guarantee it never provided. A shell whose editor is gone can start one again. Naming a live but unreachable session made `pardes ` exit 1, which let a stale environment variable lock someone out of their own editor; it falls through to an ordinary session, as it did before the variable existed. Also: the macOS ABI check for `pardes_topbar_pane_border_px` had been replaced by a duplicate of the line above it; `--startup` now fails on a leak the way every other measurement in that file does, and stops calling its maximum a p95 below twenty samples; the served README and the skill no longer tell you to write to `data` with `>`, which truncates the whole body before the write lands; `docs/v9fs.md` described the allocate-on-walk design that was rejected; and `test/fs.py` keys nesting off `PARDES_PID`, so its forwarding case stops passing only when the runner happens to be inside a live pardes. fs-test now reaches its one documented pre-existing failure instead of dying early. Suite 778/783 with the two known crashes. Co-Authored-By: Claude Opus 5 (1M context) --- src/main.zig | 31 +++++++++---------------------- 1 file changed, 9 insertions(+), 22 deletions(-) (limited to 'src/main.zig') diff --git a/src/main.zig b/src/main.zig index 9abc04bf..050cee60 100644 --- a/src/main.zig +++ b/src/main.zig @@ -112,16 +112,6 @@ const nested_text = \\ ; -/// $PARDES_PID named a live editor, so this shell IS inside one, but the Look -/// never got there. Saying so beats quietly opening the second editor that -/// $PARDES_PID exists to prevent. -const unreachable_text = - \\pardes: this shell is inside pardes, but that session did not take the - \\file. Check that it is still running, or pass --nested to start a second - \\editor in here anyway. - \\ -; - // The browser runtime calls a C main (exported below); everything else keeps // the std.process.Init entry. pub const main = if (is_emscripten) webMain else nativeMain; @@ -304,10 +294,13 @@ fn nativeMain(init: std.process.Init) !void { if (serial == 0) break :reaching null; break :reaching .{ .dial = dial, .serial = serial }; }; - const parent = found orelse { - try std.Io.File.stderr().writeStreamingAll(init.io, unreachable_text); - std.process.exit(1); - }; + // A pid we cannot reach is a session that is not answering: the shell + // says it is inside one, but there is nothing there to take the file. + // Starting an ordinary editor is what this did before the pid existed + // and is the more useful of the two answers -- refusing to start would + // leave a stale environment variable able to lock someone out of their + // own editor. + const parent = found orelse break :forwarding; // The pane's `look` file: one line, and the line is the clicked text // itself, which is what a right click in that pane would have been. var look_buf: [64]u8 = undefined; @@ -315,10 +308,7 @@ fn nativeMain(init: std.process.Init) !void { const word = positional orelse { var tag_buf: [64]u8 = undefined; const tag = try std.fmt.bufPrint(&tag_buf, "/pane/{d}/tag", .{parent.serial}); - const contents = ninep_io.Client.read(arena, parent.dial, tag, tag) catch { - try std.Io.File.stderr().writeStreamingAll(init.io, unreachable_text); - std.process.exit(1); - }; + const contents = ninep_io.Client.read(arena, parent.dial, tag, tag) catch break :forwarding; arena.free(contents); try std.Io.File.stderr().writeStreamingAll(init.io, nested_text); std.process.exit(1); @@ -332,10 +322,7 @@ fn nativeMain(init: std.process.Init) !void { const path = if (pardes.filesystem.isVirtual(target.path)) target.path else (pardes.filesystem.resolveOs(target.path, &realbuf) orelse break :forwarding).path; var command_buf: [8192]u8 = undefined; const command = std.fmt.bufPrint(&command_buf, "{s}{s}\n", .{ path, word[target.path.len..] }) catch break :forwarding; - ninep_io.Client.write(arena, parent.dial, look, command) catch { - try std.Io.File.stderr().writeStreamingAll(init.io, unreachable_text); - std.process.exit(1); - }; + ninep_io.Client.write(arena, parent.dial, look, command) catch break :forwarding; return; } if (positional) |a| { -- cgit v1.3