Module: Ace::Hitl::Hermes::Molecules::HermesAtomicWriter

Defined in:
lib/ace/hitl/hermes/molecules/hermes_atomic_writer.rb

Overview

Atomic write protocol (spec 8wm.t.vs1 §5): same-directory tmp file (0600) + fsync + chmod 0640 + rename(2) onto the target. Readers never observe partial content; no root privileges are required or used - running as root is refused fail closed.

Class Method Summary collapse

Class Method Details

.write(final_path, bytes, euid_provider: -> { Process.euid }) ⇒ Object

Writes bytes to final_path atomically. The target must not exist (CollisionError otherwise); tmp files are removed on every failure path. Returns the final path.



21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
# File 'lib/ace/hitl/hermes/molecules/hermes_atomic_writer.rb', line 21

def write(final_path, bytes, euid_provider: -> { Process.euid })
  if euid_provider.call.zero?
    raise RootUserError,
      "hermes writes without root: refusing atomic write as euid 0 " \
      "(#{final_path})"
  end

  folder = File.dirname(final_path)
  HermesContract.verify_folder!(folder)
  if File.exist?(final_path)
    raise CollisionError, "hermes message file already exists: #{final_path}"
  end

  tmp_path = File.join(
    folder,
    "#{HermesContract::TMP_PREFIX}#{Process.pid}-#{SecureRandom.hex(8)}.tmp"
  )
  begin
    File.open(tmp_path, File::WRONLY | File::CREAT | File::EXCL,
      HermesContract::TMP_MODE) do |file|
      file.write(bytes)
      file.fsync
    end
    File.chmod(HermesContract::FILE_MODE, tmp_path)
    File.rename(tmp_path, final_path)
  rescue
    File.delete(tmp_path) if File.exist?(tmp_path)
    raise
  end
  final_path
end