mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 16:09:43 +02:00
fix(cases): tell an unreachable path from an absent one, scope the stall cap
The bounded path probe answered "absent" both when a path did not exist and
when it simply did not answer, so a stalled linked case 404'd and the Run
button scaffolded a stray local case over it, and two stalled paths anywhere
made every unrelated path read as absent (hooks skipped, statusLine
overridden, the clone warning lost).
- probePath()/probePathKind() are tri-state: present (or directory/file),
absent (ENOENT/ENOTDIR only) and unknown (timeout, other errors, refusal).
boundedPathExists() stays as the display-only boolean.
- A stalled path takes only its own mount out of probing (deepest mount
point from /proc/self/mounts, never /; just the path itself when there is
no mount table). Unrelated paths keep probing. The process-wide cap is a
backstop that answers unknown, and a single-path user request can probe
past it ({ pastCap: true }), still bounded and still recorded as stalled.
One console.warn when a path first stalls and one when the cap engages.
- GET /api/cases/:name keeps NOT_FOUND for definite absence only. An
unreachable linked case answers with its registered path and
unreachable: true; a local one answers OPERATION_FAILED. runClaude and
runShell create a case only on errorCode NOT_FOUND. The case list keeps an
unreachable linked case, marked unreachable, instead of dropping it, and
fix-plan reports an unreadable plan as an error, not "no plan".
- applyWorkspaceHooks and the statusLine helpers skip only a workspace that
is absent or on the stalled mount; a capacity refusal no longer stops
hooks being installed elsewhere, and an unreadable settings file never
lets the exporter override a user's own statusLine.
- The clone flow's repo-settings warning is back on its synchronous check,
and stripCaseEnvKeys uses pathExistsForWrite.
- POST /api/sessions (workingDir) and POST /api/quick-start (case folder)
probe with the bounded probe instead of statSync/existsSync. Missing and
non-directory keep INVALID_INPUT; unknown is OPERATION_FAILED, and
quick-start never scaffolds over a folder that did not answer.
- PATH_PROBE_TIMEOUT_MS and MAX_STALLED_PATH_PROBES move to
src/config/path-probe.ts, overridable via CODEMAN_PATH_PROBE_TIMEOUT_MS
(default 1500) and CODEMAN_PATH_PROBE_MAX_STALLED (default 3), and are
documented in the Settings Reference.
- The probe is exported from the utils barrel and imported from there.
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
/**
|
||||
* @fileoverview Limits for the bounded path probe (`src/utils/bounded-path-probe.ts`).
|
||||
*
|
||||
* A linked case can live on a network mount, and a hard mount that went away makes
|
||||
* `stat()` wait until the mount comes back. The probe gives up on such a path after
|
||||
* `PATH_PROBE_TIMEOUT_MS` and answers "unknown", and it stops starting new probes
|
||||
* once `MAX_STALLED_PATH_PROBES` timed-out stats are still holding libuv threadpool
|
||||
* workers (the pool is shared by every `fs`, `dns.lookup` and `crypto` call in the
|
||||
* process, and holds 4 workers unless `UV_THREADPOOL_SIZE` says otherwise).
|
||||
*
|
||||
* Both are env-overridable, in the same style as the other config modules. A slow
|
||||
* but healthy mount (an sshfs that needs a couple of seconds on first touch) may want
|
||||
* a longer timeout; a server started with a larger `UV_THREADPOOL_SIZE` can afford a
|
||||
* higher stall cap.
|
||||
*
|
||||
* @module config/path-probe
|
||||
*/
|
||||
|
||||
function envInt(name: string, fallback: number, min: number, max: number): number {
|
||||
const raw = parseInt(process.env[name] || '', 10);
|
||||
if (!Number.isFinite(raw) || raw <= 0) return fallback;
|
||||
return Math.max(min, Math.min(max, raw));
|
||||
}
|
||||
|
||||
/** How long a caller waits for one path probe before the answer is "unknown". */
|
||||
export const PATH_PROBE_TIMEOUT_MS = envInt('CODEMAN_PATH_PROBE_TIMEOUT_MS', 1_500, 100, 60_000);
|
||||
|
||||
/**
|
||||
* Timed-out probes allowed to stay pending before new probes are refused (answered
|
||||
* "unknown" without a stat). This is a backstop, not the main defence: a stalled
|
||||
* path already takes its neighbours (same parent directory) out of probing, so the
|
||||
* cap only engages once three UNRELATED places have stopped answering. The default
|
||||
* leaves one of libuv's default four workers free for the rest of the process.
|
||||
*/
|
||||
export const MAX_STALLED_PATH_PROBES = envInt('CODEMAN_PATH_PROBE_MAX_STALLED', 3, 1, 64);
|
||||
Reference in New Issue
Block a user