From 16717a555695ef666e9d2cd1bacc762a2ab15f4b Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Mon, 21 Sep 2026 23:53:58 -0300 Subject: Fixes from three adversarial reviews, and a destructive one among them The registry sweep could delete a live socket, anywhere on the filesystem. A reviewer reproduced it: a socket that is bound but has not reached listen(2) answers ECONNREFUSED exactly like a dead one -- that window is every server's startup -- and the sweep then followed the entry's symlink and unlinked whatever absolute path it named. It now follows a target only into the directory our own sockets live in and only to a `pardes-9p-*.sock` name, it re-probes immediately before deleting rather than trusting a probe that is by then several syscalls old, and a readlink that exactly filled its buffer is treated as the truncation it is. The test grew a case for an entry whose target is not ours: the entry goes, the file does not. Ctrl-V in raw tty mode was a black hole when the yank register was empty -- neither typed nor forwarded -- so vim's visual block, readline's quoted-insert and every other program's Ctrl-V simply vanished. With nothing to paste the chord belongs to the program again. The lone-ESC flush added earlier was dead code. vaxis already returns Escape for a one-byte 0x1b (`Parser.parseGround` asserts `input.len == 1`), so the carried byte it waited for can never exist; a reviewer showed a 3 ms gap and a 60 ms gap behaving identically. Removed rather than left to imply a guarantee it never provided. A shell whose editor is gone can start one again. Naming a live but unreachable session made `pardes ` exit 1, which let a stale environment variable lock someone out of their own editor; it falls through to an ordinary session, as it did before the variable existed. Also: the macOS ABI check for `pardes_topbar_pane_border_px` had been replaced by a duplicate of the line above it; `--startup` now fails on a leak the way every other measurement in that file does, and stops calling its maximum a p95 below twenty samples; the served README and the skill no longer tell you to write to `data` with `>`, which truncates the whole body before the write lands; `docs/v9fs.md` described the allocate-on-walk design that was rejected; and `test/fs.py` keys nesting off `PARDES_PID`, so its forwarding case stops passing only when the runner happens to be inside a live pardes. fs-test now reaches its one documented pre-existing failure instead of dying early. Suite 778/783 with the two known crashes. Co-Authored-By: Claude Opus 5 (1M context) --- test/fs.py | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) (limited to 'test/fs.py') diff --git a/test/fs.py b/test/fs.py index b20dc8ee..c8dea2d9 100644 --- a/test/fs.py +++ b/test/fs.py @@ -470,7 +470,13 @@ def test(binary, quic=False): spaced = child_dir / 'space name.txt' spaced.write_bytes(b'first line\nsecond line\n') env = os.environ.copy() - env.update(PARDES_9P=str(address), PARDES_PANE='1', PARDES_FORWARD_LOOK='1') + # PARDES_PID is what says "you are inside a pardes"; the socket + # and the pane only say how to reach it. Without the pid the child + # starts its own session, so this test used to pass only when the + # runner itself happened to be running inside one. + status = dict(line.split(maxsplit=1) for line in client.read('/status').decode().splitlines()) + env.update(PARDES_9P=str(address), PARDES_PANE='1', PARDES_PID=status['pid']) + env.pop('PARDES_FORWARD_LOOK', None) for word, expected, selected, reuse in [('space name.txt:2:4', spaced.read_bytes(), [14, 14], False), ('/n/self/pane/1/body', b'initial\n', None, False), ('/virtual/pane/1/body:1:2-4', b'initial\n', [1, 4], True)]: @@ -518,7 +524,7 @@ def test(binary, quic=False): assert time.monotonic() < deadline, 'forwarding fixture Dump did not finish' time.sleep(.005) before = client.read('/index') - inherited = {key: env[key] for key in ['PARDES_9P', 'PARDES_PANE', 'PARDES_FORWARD_LOOK']} + inherited = {key: env[key] for key in ['PARDES_9P', 'PARDES_PANE', 'PARDES_PID']} cases = [ ('mount', ['--mount=peer=' + str(address), '/n/peer/pane/1/body'], None), ('name', ['--9p=forwarded-name'], 'forwarded-name'), @@ -543,7 +549,10 @@ def test(binary, quic=False): assert local.read('/index') == before assert local.read('/pane/1/body') == b'initial\n' else: - assert len(index) == (3 if name == 'shells' else 1), index + # A bare tty launch is a shell plus the empty text pane + # the boot puts under it; --shells=3 is the classic + # three-shell layout and has no scratch. + assert len(index) == (3 if name == 'shells' else 2), index if name in ['tcp', 'quic']: assert (name + '!127.0.0.1!').encode() in local.read('/listeners') assert client.read('/index') == before @@ -554,7 +563,9 @@ def test(binary, quic=False): ('stale-missing', dict(inherited, PARDES_9P=str(root / 'absent.sock')), 'missing-child-file.txt'), ('stale-noarg', dict(inherited, PARDES_9P=str(root / 'absent.sock')), None), ('stale-pane', dict(inherited, PARDES_PANE='4294967295'), str(spaced)), - ('disabled', dict(inherited, PARDES_FORWARD_LOOK='0'), str(spaced)), + # No pid means "not inside a pardes at all", which is what + # --nested withholds and what a plain shell has. + ('not-nested', {k: v for k, v in inherited.items() if k != 'PARDES_PID'}, str(spaced)), ]: with session(binary, root, name, tty=True, inherited=identity, launch=['--tty', *([word] if word else [])]) as (local, local_address): -- cgit v1.3