Skip to content

gh-pulse: a lock that names no pid is stale, not pid 0 (0.49.1) - #114

Merged
ralyodio merged 1 commit into
masterfrom
worktree-gh-pulse-stale-lock
Sep 29, 2026
Merged

ralyodio merged 1 commit into
masterfrom
worktree-gh-pulse-stale-lock

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

gh-pulse has failed every day since 2026-09-24 with another gh-pulse run is in progress (pid 0): ~/.local/share/gh-pulse/run.lock was an empty file, Number('') is 0, and process.kill(0, 0) signals the caller's own process group, so the lock always looked held.

  • lockHolder() parses the lock strictly: a positive integer, else no holder (empty, 0, negative, garbage all count as stale)
  • isAlive() returns false for pid <= 0 before touching kill
  • the lock is written to run.lock.<pid>.tmp and renamed, so a run killed mid-write never leaves an empty lock again

Tests: three new cases in test/gh-pulse-client.test.ts (stale texts with an always-alive checker, strict parsing, and the real liveness check against an empty lock). gh-pulse suites 39/39.

🤖 Generated with Claude Code

An empty run.lock read as Number('') = 0, and kill(0, 0) signals our own
process group, so it always looked alive: every daily run since 2026-09-24
refused with 'another gh-pulse run is in progress (pid 0)'. The holder is
now parsed strictly (positive integer or nothing), isAlive refuses pid <= 0,
and the lock is written to a temp file and renamed so a run killed mid-write
cannot leave an empty one behind.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

25 finding(s)

HIGH/CRITICAL: 4 | MEDIUM: 12 | LOW: 9

Severity Rule Location
HIGH sh-remote-script-execution root-ubuntu.sh:3236
HIGH sh-remote-script-execution root-ubuntu.sh:3237
HIGH sh-remote-script-execution root-ubuntu.sh:5071
HIGH sh-remote-script-execution root-ubuntu.sh:5075
MEDIUM sql-template-interpolation dev2/dev2-site:812
MEDIUM sql-template-interpolation dev2/dev2-site:889
MEDIUM sh-remote-script-execution root-ubuntu.sh:5248
MEDIUM redos-nested-quantifier src/domain-free.ts:56
MEDIUM redos-nested-quantifier src/emoji.ts:167
MEDIUM redos-nested-quantifier src/icon.ts:166
MEDIUM redos-nested-quantifier src/mail.ts:1042
MEDIUM sql-template-interpolation src/users-dump.ts:487
MEDIUM sql-string-concatenation src/users-dump.ts:507
MEDIUM sql-template-interpolation src/users-dump.ts:540
MEDIUM sql-string-concatenation src/users-dump.ts:574
MEDIUM redos-nested-quantifier src/wcag.ts:556
LOW secret-generic-credential src/credentials.ts:36
LOW secret-generic-credential src/user-export.ts:632
LOW secret-generic-credential src/user-export.ts:638
LOW secret-generic-api-key test/credentials.test.ts:208
LOW secret-generic-credential test/mail.test.ts:141
LOW secret-generic-credential test/shorten.test.ts:36
LOW secret-database-url test/users-dump.test.ts:108
LOW secret-database-url test/users-dump.test.ts:119
LOW secret-database-url test/users-dump.test.ts:120

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit b9f15ee into master Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant