baodan/.agents/skills/impeccable/scripts/live/source-lock.mjs
wsb1224 e3479f0546 上线阻断问题全部修复
#	问题	修复	文件
1	前端构建失败(引号错误)	size="small type=" → size="small" type="	PosterHistoryPage.vue
2	migrate_014 ORM vs 缺失列	全部改为原始 SQL,不再引用 ORM 模型	migrate_014.py
3	cleanup 字段名错误	output_path → ppt_path	cleanup.py
4	文案生成 case 越权	添加 case.user_id != user_id 校验	poster/service.py
5	存储路径未接通持久化卷	全部改用 get_storage_root()(默认 /app/api/storage/insurance)	config.py, ppt/routes.py, poster/service.py, poster/tasks.py
高风险问题修复
#	问题	修复	文件
6	migrate_019 rollback 撤销成功字段	每个 ALTER 后立即 commit,失败只回滚当前语句	migrate_019.py
7	迁移锁 Windows 不兼容 + 句柄未持久化	全局变量保存锁句柄,支持 Windows msvcrt	api/insurance/db/__init__.py
8	PDF 校验异常时放行	异常返回 False(文件损坏)	security.py
9	健康检查始终返回成功	缺少关键资源时返回 503 + missing 列表	poster/routes.py
10	短密钥掩码泄露原值	≤4 字符返回 ****	ppt_admin_service.py
11	设置无键名白名单	添加 _ALLOWED_SETTING_KEYS 白名单	ppt_admin_service.py
12	容器重启任务永久 stuck	添加 recover_stale_tasks() 启动恢复函数	poster/tasks.py, ppt/parse_worker.py
2026-07-27 13:52:09 +08:00

106 lines
3.6 KiB
JavaScript

import fs from 'node:fs';
import path from 'node:path';
import { createHash, randomUUID } from 'node:crypto';
import { getLiveDir, isLiveServerPidReachable } from '../lib/impeccable-paths.mjs';
// Only used to retire a lock whose contents we cannot read (empty or truncated
// by a crash mid-write). A readable lock's fate is decided by its owner's
// liveness instead, so a slow critical section is never swept.
const UNREADABLE_LOCK_STALE_MS = 60_000;
export function sourceLockPath(file, cwd = process.cwd()) {
const digest = createHash('sha256').update(path.resolve(cwd, file)).digest('hex').slice(0, 24);
return path.join(getLiveDir(cwd), 'locks', digest + '.lock');
}
export function withSourceLockSync(file, owner, fn, {
cwd = process.cwd(),
waitMs = 0,
retryMs = 5,
} = {}) {
const lockPath = sourceLockPath(file, cwd);
fs.mkdirSync(path.dirname(lockPath), { recursive: true });
const deadline = Date.now() + Math.max(0, Number(waitMs) || 0);
// Identifies this acquisition specifically, so release can tell our own lock
// from a replacement that some other writer created.
const token = randomUUID();
let acquired = false;
while (!acquired) {
clearStaleLock(lockPath);
let fd;
try {
fd = fs.openSync(lockPath, 'wx');
fs.writeFileSync(fd, JSON.stringify({
owner,
token,
pid: process.pid,
at: Date.now(),
file: path.resolve(cwd, file),
}) + '\n');
acquired = true;
} catch (error) {
if (error?.code !== 'EEXIST') throw error;
if (Date.now() >= deadline) {
const locked = new Error('source_locked');
locked.code = 'SOURCE_LOCKED';
locked.lockPath = lockPath;
throw locked;
}
sleepSync(Math.max(1, Math.min(Number(retryMs) || 5, deadline - Date.now())));
} finally {
try { if (fd !== undefined) fs.closeSync(fd); } catch {}
}
}
try {
return fn();
} finally {
releaseOwnLock(lockPath, token);
}
}
function sleepSync(ms) {
Atomics.wait(new Int32Array(new SharedArrayBuffer(4)), 0, 0, ms);
}
function readLock(lockPath) {
try { return JSON.parse(fs.readFileSync(lockPath, 'utf-8')); } catch { return null; }
}
/**
* Remove the lock only if it is still the one this call created. If a sweeper
* judged our lock stale and another writer replaced it, unlinking here would
* end *their* critical section and admit a third writer to the same file.
*/
function releaseOwnLock(lockPath, token) {
const held = readLock(lockPath);
if (held && held.token !== token) return;
try { fs.unlinkSync(lockPath); } catch {}
}
/**
* A lock is stale when its owner is gone, not when it is old.
*
* Age alone cuts both ways: it sweeps a live holder whose critical section
* outran the timeout (a suspended laptop, a stopped process), letting two
* writers into the same source file, while still making every accept on a
* crashed holder's file wait out the full timeout. Asking the OS whether the
* recorded pid is alive answers both correctly: a dead owner releases at once,
* and a live owner keeps its lock however long it needs.
*/
function clearStaleLock(lockPath) {
const held = readLock(lockPath);
if (!held) {
// Unreadable: either a crash truncated it, or we caught the brief window
// between create and write in a live acquisition. mtime distinguishes them.
try {
const stat = fs.statSync(lockPath);
if (Date.now() - stat.mtimeMs > UNREADABLE_LOCK_STALE_MS) fs.unlinkSync(lockPath);
} catch { /* gone already */ }
return;
}
if (typeof held.pid === 'number' && isLiveServerPidReachable(held.pid)) return;
try { fs.unlinkSync(lockPath); } catch {}
}