Module: Ace::Hitl::Hermes::Molecules::HermesAtomicWriter
- Defined in:
- lib/ace/hitl/hermes/molecules/hermes_atomic_writer.rb
Overview
Atomic write protocol (spec 8wm.t.vs1 §5): same-directory tmp file (0600) + fsync + chmod 0640 + rename(2) onto the target. Readers never observe partial content; no root privileges are required or used - running as root is refused fail closed.
Class Method Summary collapse
-
.write(final_path, bytes, euid_provider: -> { Process.euid }) ⇒ Object
Writes
bytestofinal_pathatomically.
Class Method Details
.write(final_path, bytes, euid_provider: -> { Process.euid }) ⇒ Object
Writes bytes to final_path atomically. The target must not
exist (CollisionError otherwise); tmp files are removed on
every failure path. Returns the final path.
21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 |
# File 'lib/ace/hitl/hermes/molecules/hermes_atomic_writer.rb', line 21 def write(final_path, bytes, euid_provider: -> { Process.euid }) if euid_provider.call.zero? raise RootUserError, "hermes writes without root: refusing atomic write as euid 0 " \ "(#{final_path})" end folder = File.dirname(final_path) HermesContract.verify_folder!(folder) if File.exist?(final_path) raise CollisionError, "hermes message file already exists: #{final_path}" end tmp_path = File.join( folder, "#{HermesContract::TMP_PREFIX}#{Process.pid}-#{SecureRandom.hex(8)}.tmp" ) begin File.open(tmp_path, File::WRONLY | File::CREAT | File::EXCL, HermesContract::TMP_MODE) do |file| file.write(bytes) file.fsync end File.chmod(HermesContract::FILE_MODE, tmp_path) File.rename(tmp_path, final_path) rescue File.delete(tmp_path) if File.exist?(tmp_path) raise end final_path end |