From 5dcfade5f102256de787b2157b01293160780411 Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Mon, 21 Sep 2026 22:37:06 -0300 Subject: Make a pane by opening /pane/new, and a Plan 9 idiom pass The Tcreate that replaced acme's /new was a step away from the idiom dressed up as a step toward it. A pane is named by a server-assigned serial, so the create ignored the client's name: `mkdir /pane/foo` succeeded and left you /pane/12. A mkdir that does not make the directory you named is worse than the read-with-side-effect it replaced, and it broke in the shell workflow that motivated the change. `create` is out of the declared features, so Tcreate is EPERM again; Tremove stays, since `rm` to close a pane is unambiguously right. /pane/new is now opened, not created: the open makes the pane, the read of that fid answers its serial, two reads agree, and closing it leaves the pane. That is /net/tcp/clone's mechanism (kernel/network/ip/devip.c, in ipopen), not acme's, and the difference is deliberate. acme allocates during the walk and lands inside the new window, so /dev/new/body works in one step, and it can afford to list `new` because a Plan 9 directory read carries every entry's stat and nothing walks. A kernel or FUSE mount walks and stats each name a listing gave it, so allocate-on-walk would make a pane per `ls -l`. Allocating on open keeps `new` listed -- a stat is not an open -- at the cost of the one-step new/body. `new` stays unreachable from an editor path, because that resolution serves Look hover previews. The idiom pass behind it, read out of the Plan 9 tree at ~/05-genizah/principia-softwarica rather than recalled: Rerror carries a string, not an errno (man 5 error: `ename[s]`), and acme names every refusal. The five refusals pardes shares with acme now say what they mean; the generic sites keep their bare errno rather than invent strings acme does not have. body and tag declare DMAPPEND, which they had always behaved as (acme(4): "always appended; the file offset is ignored"), checked first against Linux's fs/9p, which never maps the bit. excl stays unset everywhere, because acme sets DMEXCL on nothing. Blocking reads, per-object addr scope and the readable pane ctl were already right. Real stat sizes and qid versions stay: acme reports length 0 and version 0 for everything, and Linux clients need better. One bug fell out of it. open reset the addr range, so `echo '#0,#5' >addr; cat addr` answered `0 0` and `cp addr dot` copied zeros. acme(4) makes the contract explicit -- "a regular expression may be evaluated by writing it to addr and reading it back" -- and acme gets away with resetting on the 0-to-1 open only because its clients hold the fid across both. A shell cannot: that is two opens. The register is cleared by truncating it now. Co-Authored-By: Claude Opus 5 (1M context) --- test/v9fs.py | 29 +++++++++++++---------------- 1 file changed, 13 insertions(+), 16 deletions(-) (limited to 'test/v9fs.py') diff --git a/test/v9fs.py b/test/v9fs.py index fa35388f..30efe9fb 100644 --- a/test/v9fs.py +++ b/test/v9fs.py @@ -45,6 +45,7 @@ def worker(mountpoint, socket, uid, gid, original_namespace): tree = mountpoint assert {'os', 'index', 'pane', 'status', 'look', 'exec', 'log', 'screen', 'README'} <= set(os.listdir(tree)) assert 'self' not in os.listdir(tree) and 'new' not in os.listdir(tree) + assert 'new' not in os.listdir(tree / 'pane'), 'a listing would make a pane per stat' # A direct connection provides independent evidence for VFS reads/writes. with Client(socket) as client: assert (tree / 'index').read_bytes() == client.read('/index') @@ -55,26 +56,22 @@ def worker(mountpoint, socket, uid, gid, original_namespace): subprocess.run(['find', str(tree / 'pane'), '-ls'], check=True, capture_output=True, timeout=5) assert (tree / 'README').read_bytes() == client.read('/README') assert client.read('/index') == before, 'browsing created panes' - # mkdir through the kernel mount opens a pane. The editor names it - # after its serial, not after the name asked for, so the kernel's own - # revalidation of that name may fail; the index is the answer. + # Opening pane/new makes a pane and the read names it, so no trip + # through the index. Whether a repeated path reaches the server at all + # is the kernel's dentry cache's business, so the second pane comes + # over the wire, where the open is exact. def serials(): return {int(row.split()[0]) for row in (tree / 'index').read_bytes().splitlines()} - def mkpane(name): + def mkpane(): known = serials() - try: - (tree / 'pane' / name).mkdir() - except FileNotFoundError: - pass - made = serials() - known - assert len(made) == 1, (name, made) - return made.pop() - - serial = mkpane('kernel-made') - another = mkpane('kernel-made-again') - assert serial != another, 'a second mkdir reused a pane' - assert not (tree / 'pane' / 'kernel-made').exists() + made = int((tree / 'pane' / 'new').read_bytes()) + assert made not in known, 'the open of new made no pane' + return made + + serial = mkpane() + another = int(client.read('/pane/new')) + assert serial != another, 'a second open of new reused a pane' (tree / 'pane' / str(another)).rmdir() assert another not in serials() pane = tree / 'pane' / str(serial) -- cgit v1.3