1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
//! The executor lock (ARCH §2.11 *The executor lock*).
//!
//! `flock(2)` on the agent's **inbox directory** fd, acquired
//! non-blocking when an executor starts and held for the whole step
//! loop. The lock is kernel state bound to process lifetime: released by
//! the kernel on any death, observable but never written — there is no
//! stale-lock cleanup because there is nothing on disk to go stale
//! (PRINCIPLES "Single source of truth"). The inbox directory lives at
//! the workspace root and persists across worktree teardown (§2.3
//! step 6), so the lock's home outlives the substrate's materialization.
//!
//! Two open file descriptions on the same directory contend even inside
//! one process (`flock(2)`: descriptors from separate `open` calls are
//! treated independently), so `try_acquire` is a true mutual-exclusion
//! probe: the caller who wins holds the lease, everyone else observes
//! `None` and steps aside (Writer/driver totality, §2.11).
//!
//! **Release is explicit `LOCK_UN`, not a bare close.** The lock rides
//! the *open file description*, and closing one fd for it releases the
//! lease only once **every** fd naming that description is gone. Spawning
//! a subprocess transiently makes more of them: `fork`/`clone` copies the
//! whole fd table, and close-on-exec fires at `execve`, not at the fork —
//! so between a spawn and its exec, a child that has nothing to do with
//! this branch holds the lease too. Any spawn anywhere in the process
//! (git, the provider adapter, a tool, a detached launch) opens that
//! window, and a lease released by close inside it stays kernel-held
//! until the unrelated child execs. A subsequent probe then reads
//! `EWOULDBLOCK` and the caller concludes *another executor drives this
//! branch* — a lie that turns a driver into a silent no-op (§2.11
//! Writer/driver totality) and a sweep candidate into a live agent (§8).
//! `flock(fd, LOCK_UN)` clears the lock from the description itself, so
//! every copy of it loses the lease at once; [`ExecutorLock`]'s `Drop`
//! makes that the only way a lease is ever given up. Nothing is written
//! either way — the release is still pure kernel state, and process death
//! still releases (the kernel drops the description with its last fd).
use File;
use io;
use AsRawFd;
use Path;
/// A held executor lease. Dropping it releases the `flock` explicitly
/// (`LOCK_UN`) and then closes the fd; nothing is written on release. The
/// `File` is the whole state — the guard exists only to tie the kernel
/// lease to a Rust lifetime.
/// Try to acquire the executor lock for the agent whose inbox is
/// `inbox_dir`. Non-blocking: `Ok(Some(_))` means the lease is now held
/// by the returned guard; `Ok(None)` means another executor holds it
/// (the branch is being driven); `Err` is an I/O failure opening the
/// inbox fd. The inbox directory is created on demand — a fresh agent
/// with no deposited messages still has a lock home (§2.3 step 6).
/// Open (creating if needed) the inbox directory and return an fd on it.
/// The only branch here is `create_dir_all`'s; `File::open` on a
/// just-ensured directory returns its `Result` straight through.
/// `flock(LOCK_EX | LOCK_NB)` the fd, mapping the outcome to a guard.
/// The error interpretation is factored into [`interpret_lock`] so all
/// three arms are unit-testable without provoking a real syscall
/// failure.
pub
/// Classify a `flock` return: `0` → lease held; `EWOULDBLOCK` → someone
/// else drives; any other errno → propagate. Kept pure (takes the fd,
/// the raw return, and the captured errno) so the Err arm is reachable
/// in a test without a genuine syscall failure.
pub