fix: enforce native Windows bundle retention safely - #417
codeforester merged 41 commits into
Conversation
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…ff-check-and-mypy-do-not-cover-the-compatibility-consum
…-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc
…wned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc
…wned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…wned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
codeforester
left a comment
There was a problem hiding this comment.
Reviewed against #378's acceptance criteria. The new guards cover the POSIX side: _directory_open_flags raises OSError instead of AttributeError, there's one warning per pass, and the simulated dir_fd-less test is in place. The Windows fallback is a reasonable design. CI is green, and the Windows runner exercises test_native_count_bound_is_enforced.
There are two concerns about the Windows pinning code, inline. The first matters because the docs and comments promise a TOCTOU guarantee that I don't think the code delivers.
…fecycle-logging-costs-107-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…ff-check-and-mypy-do-not-cover-the-compatibility-consum
…d-mypy-do-not-cover-the-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc # Conflicts: # docs/integrations.md
…ogger-closes-consumer-owned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…fecycle-logging-costs-107-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
|
Re-verified at |
Retention now acquires its maintenance lock without waiting on both POSIX and Windows. Contending invocations skip the pass; subsequent successful passes enforce the existing bounds. Teardown acquires the lock before scanning, and lock cleanup never unlocks an unacquired lock. Fixes #386. ## Branch maintenance Refs #426. Targets the branch for #417. Retarget and refresh after that parent is squash-merged; preserve the ordered stack. The branch was refreshed without rewriting history to include `main` at `a576cc279739eae5e4cfc33ffab2a7fb56de24de`. ## Current-head validation At `c4af745a971534dd8ccb13fe51da250ece0d36d7`: uv lock freshness and baseline, runtime, strict typing, style, and contracts passed locally with all declared extras. Runtime result: 621 passed, 1 warning, 262 subtests passed in 8.67s. Hosted checks: 7/7 required checks passed; 0 checks pending; 0 unsuccessful checks at 2026-10-04T14:19:40.760978+00:00. See the PR Checks tab and #426 for subsequent results.
Run-bundle retention now has a native Windows removal path that pins directory ancestors, refuses reparse points and volume crossings, and preserves existing lease/metadata checks. POSIX keeps descriptor-relative deletion. Unsupported platforms skip the pass with one warning, and absent directory flags raise a handled error.
Fixes #378.
Branch maintenance
Refs #426. Targets the branch for #416. Retarget and refresh after that parent is squash-merged; preserve the ordered stack.
The branch was refreshed without rewriting history to include
mainata576cc279739eae5e4cfc33ffab2a7fb56de24de.Current-head validation
At
e82ce1fbfd7fd3675e8d703a027840d1a82d44bb: uv lock freshness and baseline, runtime, strict typing, style, and contracts passed locally with all declared extras. Runtime result: 620 passed, 1 warning, 262 subtests passed in 8.74s.Hosted checks: 7/7 required checks passed; 0 checks pending; 0 unsuccessful checks at 2026-10-04T14:19:40.760978+00:00. See the PR Checks tab and #426 for subsequent results.