From 559da2eeec2b7b3fd4021b1e4671e41ba715390d Mon Sep 17 00:00:00 2001 From: Dave Date: Sun, 21 Jun 2026 13:13:06 -0400 Subject: [PATCH] chore(changeset): Fixed fragment for #1532 (core file-lock PID-liveness) Claude-Session: https://claude.ai/code/session_01R88n7Q54bAaVHFkDbbH1yz --- .changeset/1532-core-lock-liveness.md | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 .changeset/1532-core-lock-liveness.md diff --git a/.changeset/1532-core-lock-liveness.md b/.changeset/1532-core-lock-liveness.md new file mode 100644 index 000000000..fb3a3994a --- /dev/null +++ b/.changeset/1532-core-lock-liveness.md @@ -0,0 +1,5 @@ +--- +type: Fixed +pr: 1532 +--- +**Core-path file locks now verify the holder process is alive before stealing a stale lock (#1532)** — the STATE.md write lock (`acquireStateLock`) and the `.planning/` workspace lock (`withPlanningLock`) previously stole locks on a bare `mtime` timer with no liveness check, so a live-but-slow holder (e.g. a deep `.planning/` scan on slow NFS) could have its lock stolen mid-write, corrupting STATE.md or losing an update. Both locks now gate stealing on `process.kill(pid,0)` liveness with a deadman ceiling above the wait budget (pid-reuse backstop), `withPlanningLock` no longer force-steals a live holder on timeout (and can no longer leak an uncaught `EEXIST`), `writeStateMd` computes its disk scan inside the lock, and `acquireStateLock` no longer leaks a file descriptor or strands an empty lock on a recoverable write error. The uncontended path is unchanged.