Skip to content

fix(windows): rename files without requesting execute access - #130

Merged
steipete merged 5 commits into
mainfrom
claude/compile-cache-idle-progress
Oct 5, 2026
Merged

steipete merged 5 commits into
mainfrom
claude/compile-cache-idle-progress

Conversation

@steipete

@steipete steipete commented Oct 5, 2026 •

Copy link
Copy Markdown

Cold Node compile-cache persistence on Windows can exceed the existing 30-second regression deadlines while the idle loop keeps waking and cache entries keep appearing. The Windows rename helper reopened every temporary file with FILE_TRAVERSE, which is FILE_EXECUTE for a regular file. Microsoft Defender synchronously scanned these files before granting that unnecessary access.

Use the existing non-executable fallback access mask for the first and only open, removing the redundant retry. Keep synchronization, write, and delete rights, sharing defaults, and atomic rename. The compile-cache workload, test deadlines, one-second/90% idle policy, and 250 ms signal-exit budget are unchanged. The watchdog only gains entry-count and child-exit diagnostics. The CI notes distinguish this Windows timeout from the Linux idle-accounting bug already fixed by #53.

The original Windows binary at d5ada8e6d0c62a51ead1eaccee40cc8388ad3ede fails the unchanged idle test in five of five isolated runs. Independent observations show continuous progress and completion around 32 seconds. Interleaved Windows API controls over 2,000 unique files spend 24.532/24.509 seconds reopening with execute access, versus 0.119/0.116 seconds without it. Defender's trace attributes 2,001 OnOpen scans to cache temporary files, totaling 23.703 seconds during a 28.093-second flush. Defender remained enabled throughout.

With the fix at 918fe702a958256698b429e6c0f4940b1f5d4aef, three same-host pairs turn unchanged 30.089/30.085/30.085-second timeout failures into 10.714/10.172/10.250-second passes. The standalone explicit-flush reproduction drops from 29.545 seconds to 3.821 seconds while retaining all 2,001 entries. The full Windows module and filesystem suites pass. The filesystem run uses the repository runner's existing 90-second per-test policy; no configured deadline was changed.

Final head: d708b0f50d8e4dfde3d56f8ddde6719c1830243a.

  • Native CI: Linux 15/15 and Darwin 12/12, including the full module file. The tested merge tree exactly matches the PR head.
  • Windows qualification: x64 and ARM64 each pass 31/31 compatibility rows, both native smoke tests, and manifest assembly. Frozen workflow 5b3999cd3dbc0ff3d4b32c52865674e6b46bbbd2 builds/tests the exact source above. Its Windows jobs and test policy are unchanged; Linux scheduling uses existing Blacksmith runners, and signing/publication are unreachable. Native smoke verifies the full source revision and engine. Manifest/archive/executable/profile hashes and both PE architectures are independently verified.
  • Local macOS: 953 passing module/filesystem/filesystem-promises tests, zero failures. All 12 Rust targets pass without skips.
  • Isolated OpenClaw consumer checks: infrastructure compile-cache 7/7 and entry compile-cache 22/22, before and after the exact final binary.
  • Format, source/JavaScript lint, Clippy, Miri, and cargo tests pass. P2 landing review with the unchanged temporary-file and compile-cache callers is scoped-clean.

The final native and Windows runtime qualification required no test retries or exceptions. Mordant's explicitly advisory resolver style warning is unchanged from main; no suppression was added.

The same helper exists upstream. The source-only port is open as oven-sh/bun#44601, with passing Windows x64/ARM64 crate checks and source/Rust/format checks.

Use the existing non-executable source-open rights directly and remove the redundant retry. FILE_TRAVERSE aliases FILE_EXECUTE for regular files and can serialize antivirus scans during compile-cache publication.

Keep the workload, deadlines, idle-generation policy and signal-exit budget unchanged. Distinguish the resolved Linux accounting issue from Windows publication delays in the CI notes, and include entry counts in the existing stalled-progress diagnostic.
Preserve the landed embedded-module path fix and append the Windows rename entry after the current changelog. The reviewed rename implementation and compile-cache diagnostics are unchanged.
@steipete
steipete marked this pull request as ready for review October 5, 2026 22:16
@steipete
steipete merged commit 9275361 into main Oct 5, 2026
10 of 11 checks passed
@steipete
steipete deleted the claude/compile-cache-idle-progress branch October 5, 2026 22:17
steipete added a commit that referenced this pull request Oct 6, 2026
…133)

The test runner can kill an unlimited test’s live child when a completed test’s stale deadline fires. Its process-reaping check treats the no-deadline/EPOCH timestamp as expired. Exclude that sentinel, matching the existing entry timeout check, and cover the completed-deadline/live-child sequence with a deterministic regression.

The deferred compile-cache idle test now preserves its ten-second persistence-progress guard and bounds module loading, pipe flushes, child exit, and cleanup individually. The complete 2,000-module workload, late-module handshake, 2,002-file assertion, idle-generation window, and signal-exit budget remain unchanged.

The exact Windows binary from [run 37386790583](https://github.com/openclaw/bun/actions/runs/37386790583) reproduces the old 30-second aggregate timeout 3/3 under a controlled CPU quota while files keep appearing. An independent driver completes all 2,002 entries in 64.7 seconds; the proposed test passes under that quota in 52.6/52.2 seconds. Deliberately stalled persistence, startup, and exit still fail at their ten-second guards. That hosted failure retained no progress timeline, so its specific runner-level trigger remains unknown. This is distinct from #53’s Linux idle-accounting fix and #130’s Windows execute-access scan fix.

The child-lifetime regression fails 3/3 on old Mac and Windows x64 fork binaries and official upstream Bun `13a98b0d`. Exact-source Windows pairs fail 3/3 before and pass 3/3 with the owner fix. Two stale hook-error column expectations were corrected from 15 to 11 after the pre-change fork reproduced all five failures and Node 24 confirmed column 11; exact source-position and error-attribution checks remain intact.

Final validation applies to `29cbbbf595` on main `10b749212a`:

- P2 Codex autoreview and the final pre-merge review are scoped-clean.
- Local release build passes, with 25 test-runner tests and 214 module tests passing; all 12 Rust targets pass.
- [Native CI](https://github.com/openclaw/bun/actions/runs/37402121441): Linux 16/16 and Darwin 13/13, first attempt. Its merge tree exactly matches the reviewed candidate.
- [Windows CI](https://github.com/openclaw/bun/actions/runs/37402131975): x64 and ARM64 each 31/31, both native smoke jobs and manifest pass on the first attempt. The immutable workflow is separate from runtime source; native revisions, WebKit identity, archive/executable/profile hashes, and PE architectures are verified for this exact source commit.
- OpenClaw consumer tests pass 7 + 22 before and after this exact commit, with the before binary’s tree matching current main and isolated HOME/state/configuration/temp directories.

Format, JavaScript/source lint, Clippy, Miri, and lol-html tests pass. Mordant reports the existing `bare_bool_args` finding in `src/resolver/package_json.rs`; its source, baseline, configuration, toolchain, and explicitly advisory workflow setting are unchanged from main. The initial issue-finder run lacked authentication; no credentials or CI settings were changed.

The shared owner fix is also proposed in oven-sh#44613 with a passing upstream-specific build and full test-runner suite. The separate Windows rename fix remains in oven-sh#44601.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant