windows: Handle watch shutdown races (cherry-pick upstream #958) - #12
Open
cole-miller wants to merge 1 commit into
Open
cole-miller wants to merge 1 commit into
cole-miller wants to merge 1 commit into
Conversation
* windows: handle watch shutdown races ReadDirectoryChangesW can complete an outstanding request just before CancelIo runs. When stop_watch closed the directory handle and entered its alertable wait, that already-queued callback still arrived with ERROR_SUCCESS and tried to rearm the request using the closed handle. The resulting ERROR_INVALID_HANDLE was emitted to users and caused overlapping watch tests to fail intermittently. Share a stopping flag between each watch state and its completion requests. Set it before cancellation begins, then have callbacks release the completion semaphore and return without processing or rearming once the watch is stopping. This preserves the existing wait-for-completion lifetime guarantee without submitting I/O against a closed handle. Directory deletion has a second race: RemoveDirectory can return while the open watch handle keeps the directory delete-pending. In that window, try_exists may report an access error instead of absence, causing the callback to rearm the invalidated handle and emit ERROR_ACCESS_DENIED. Query FILE_STANDARD_INFO on the existing handle and treat DeletePending as directory removal while preserving genuine permission failures. The stopped-completion regression test verifies that a queued successful completion is acknowledged without an error or another unwatch. The existing delete_self_dir test covers removal notification for delete-pending directory handles. Signed-off-by: Daan De Meyer <daan@amutable.com> * docs: add changelog entry --------- Signed-off-by: Daan De Meyer <daan@amutable.com> Co-authored-by: Yuki Okushi <huyuumi.dev@gmail.com> (cherry picked from commit bc25704)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cherry-pick of notify-rs#958 (upstream
bc25704, Daan De Meyer, 2026-07-16), which fixes the intermittentwindows::tests::delete_self_dirfailure seen on #6 and #11.The race:
RemoveDirectoryreturns while the openReadDirectoryChangesWhandle keeps the directory delete-pending. The completion callback then arrives withERROR_ACCESS_DENIED, butdir.try_exists()reports an access error rather than absence, so the handler falls through, tries to re-arm the read on the invalidated handle, and surfacesIo(code 5)instead of theRemove(Folder)event. Upstream adds anis_delete_pending(handle)check (GetFileInformationByHandleEx→FileStandardInfo.DeletePending) alongsidetry_exists, and also fixes a second shutdown race where a queued callback re-armed a handle thatstop_watchhad already closed.Applied with
git cherry-pick -x; no conflicts. Compiles forx86_64-pc-windows-msvc; the Windows test run here is the verification.