Skip to content

Keep an Owned Tree Recognizable When Its Final Directory Removal Fails #1795

Description

@ptr727

Removing the ownership marker last protects a removal that stops while clearing a tree's contents. It does not protect one that fails on the directory itself.

In bootstrap.sh remove_tree and bootstrap.ps1 Remove-Tree, the final rm -rf "$1" or Remove-Item -Recurse deletes .bootstrap-owned and then fails on the now-empty directory. That leaves an unmarked, empty directory at a managed name.

  • Triggers: a parent directory that is not writable. On Windows, likely also a directory that is some process's working directory (inferred, not run there).
  • Consequence: every later run refuses the leftover with "exists and this loader did not create it ... Choose another --dir". The PowerShell warnings saying "a later run removes it once nothing holds a file in it" are then wrong.
  • Fix direction: treat an empty directory at a managed name as removable, since it holds nothing to lose, or rename the tree aside under a marker-carrying name before the final removal.

Not a regression: the plain rm -rf this replaced had the same final-step behavior, and it also lost the marker on a partial removal. Found by the local strict review on #1794. Related: #1790.

Activity

  1. added
    bugSomething isn't working
    pre-existingReview finding classed pre-existing per local-strict-review Disposing of Findings
    scriptA defect in hub tooling
    on Sep 25, 2026
  2. ptr727 commented on Oct 7, 2026

    @ptr727
    OwnerAuthor

    Lock design settled with the maintainer for both loaders (windows lane, round 3):

    • Lock the Bootstrap Directory for a Kept-Tree Run #1792: a kept-tree run holds an OS lock on $DIR/<tree>.lock for its whole length. bootstrap.sh takes flock -n on it, and bootstrap.ps1 opens it with FileShare.None, which .NET implements as flock on Linux, so the two loaders coordinate there. The OS releases the lock when a process dies, so a crashed run leaves no stale lock. A run that finds the lock held refuses rather than waits.
    • Keep an Owned Tree Recognizable When Its Final Directory Removal Fails #1795: with the lock held, an unmarked empty directory at a managed name is removed rather than refused, since it holds nothing to lose and no live run can own it.
    • Both loaders' halves land in one pull request. The PowerShell half is verified natively on Windows, the bash half by the Linux test suite, leaving a native WSL check to the wsl lane.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingpre-existingReview finding classed pre-existing per local-strict-review Disposing of FindingsscriptA defect in hub tooling

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions