From e16f686706b1e0d5334fd1ae82190058d2a19694 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Sun, 13 Sep 2026 04:07:43 -0700 Subject: [PATCH] fix(state): never open+close an existing state.db inode while tightening modes create_main used O_WRONLY|O_CREAT on the main file and closed the fd, which drops this process's POSIX locks whenever state.db already exists (the gateway's own async_delegation import path). O_EXCL restricts the descriptor to a brand-new inode; existing files take the chmod(2) path. Refs #109786 #109687 --- hermes_state.py | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/hermes_state.py b/hermes_state.py index 154c269dae..31cd1521e3 100644 --- a/hermes_state.py +++ b/hermes_state.py @@ -239,20 +239,22 @@ def _secure_state_db_files(db_path: Path, *, create_main: bool = False) -> None: main_path = db_path if create_main: - flags = os.O_WRONLY | os.O_CREAT + # O_EXCL: only a brand-new inode gets a descriptor. Opening an existing + # file here and closing it would drop this process's POSIX locks on it. + flags = os.O_WRONLY | os.O_CREAT | os.O_EXCL if hasattr(os, "O_NOFOLLOW"): flags |= os.O_NOFOLLOW if hasattr(os, "O_CLOEXEC"): flags |= os.O_CLOEXEC try: fd = os.open(main_path, flags, 0o600) + except FileExistsError: + pass except IsADirectoryError: # Not a database file at all; sqlite3.connect() raises the # canonical error for this, and a directory leaks no row data. return - try: - os.fchmod(fd, 0o600) - finally: + else: os.close(fd) for path in (