Repository navigation
test(rig-lock): portable timestamp + non-root holder default (#244) - #247
Merged
Merged
Conversation
VijitSingh97
enabled auto-merge (squash)
July 12, 2026 01:58
…dening (#244) #244: two portability/permission bugs in the shared rig_lock breadcrumb (display-only; the flock itself was fine), mirrored from pithead: - RIG_LOCK_HOLDER defaulted to root-owned /run/rig-e2e.holder -> a non-root box errored. Default beside the lock: ${RIG_LOCK_FILE}.holder. - date -Iseconds is GNU-only -> date -u +%Y-%m-%dT%H:%M:%SZ. Plus pre-release scan hardening of the same helper: - Dropped the 'sudo chmod' fallback (a read-open (9<) only needs o+r, and sudo-chmod'ing a path in world-writable /run/lock could follow a planted symlink onto a root-owned target). - Refuse a symlinked lock/holder path outright. - Single-quote the EXIT trap (SC2064) so it re-derives the holder from the persistent env default at signal time. Both e2e helpers stay byte-identical (drift guard); 5 new tests. Closes #244 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
VijitSingh97
force-pushed
the
claude/rig-lock-portable-244
branch
from
July 12, 2026 02:19
494ec2a to
20a7012
Compare
VijitSingh97
added a commit
that referenced
this pull request
Jul 13, 2026
…dening (#244) (#247) #244: two portability/permission bugs in the shared rig_lock breadcrumb (display-only; the flock itself was fine), mirrored from pithead: - RIG_LOCK_HOLDER defaulted to root-owned /run/rig-e2e.holder -> a non-root box errored. Default beside the lock: ${RIG_LOCK_FILE}.holder. - date -Iseconds is GNU-only -> date -u +%Y-%m-%dT%H:%M:%SZ. Plus pre-release scan hardening of the same helper: - Dropped the 'sudo chmod' fallback (a read-open (9<) only needs o+r, and sudo-chmod'ing a path in world-writable /run/lock could follow a planted symlink onto a root-owned target). - Refuse a symlinked lock/holder path outright. - Single-quote the EXIT trap (SC2064) so it re-derives the holder from the persistent env default at signal time. Both e2e helpers stay byte-identical (drift guard); 5 new tests. Closes #244 Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #244. Two portability/permission bugs in the shared
rig_lockbreadcrumb (display-only — the kernel flock was fine), mirrored from the sibling pithead fix:RIG_LOCK_HOLDERdefaulted to/run/rig-e2e.holder;/runis root-owned, so a non-root box errored with Permission denied (lock still held, but no breadcrumb + stderr noise). Now defaults beside the lock (${RIG_LOCK_FILE}.holder).date -Isecondsis GNU-only (BSD/macOS:illegal option -- I). Nowdate -u +%Y-%m-%dT%H:%M:%SZ.Applied identically to
e2e-real.sh+e2e-pithead.sh(the #183 drift guard enforces it). The EXIT trap bakes the resolved holder path (alocalwould be out of scope when EXIT fires). 4 new tests; all 11 existing #183 lock tests green.Cross-repo note: the human-facing marker convention in
~/README.md/ the pithead soaks still references/run/rig-e2e.holder(explicit setters); this only changes the unset default. Worth aligning the README holder path once pithead's sibling change lands — flagging rather than churning it here.🤖 Generated with Claude Code