diff options
| author | Ophestra <cat@gensokyo.uk> | 2026-10-07 03:11:54 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2026-10-07 03:11:54 +0900 |
| commit | 7ff313f463bcc73225e8d62764c06607eda8f36d (patch) | |
| tree | c53af1256e9fe828f148c0ed89cb9da11bb13486 /check/overlay.go | |
| parent | df3987f291c45b38a8c3ea96a95cfad24d1e2860 (diff) | |
container: recover from intermittent EACCES
This change works around a race in the vfs, where ACLs are ineffective
for a very short window of time while they are being written.
This remained undiscovered until now due to the previous integration
test suite's complete inability to handle concurrency (the nixos vm test
machinery could not even support python multithreading). At the time, it
was deemed unnecessary to run this kind of test in the integration vm,
as the entire container package up to the syscall wrappers had full test
coverage and plenty of tests for race conditions, and a race in vfs was
simply unexpected.
This workaround adds around 60 milliseconds of latency for a truly
inaccessible path. While this is not ideal, it is somewhat cheaper and
a lot easier to implement than synchronising container startup all the
way up from shim to the priv-side process. Regardless, EACCES should not
occur at all during regular use, and a 60-millisecond delay during
application development is hardly a problem.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'check/overlay.go')
0 files changed, 0 insertions, 0 deletions
