Repository navigation
fix: write tabs session file atomically to survive unclean shutdown - #2356
Open
jorgeecardona wants to merge 2 commits into
Open
jorgeecardona wants to merge 2 commits into
jorgeecardona wants to merge 2 commits into
Conversation
save_tabs truncated session.json in place, so a crash or power loss mid-write left a half-written file that restore_tabs then discarded as broken, losing the saved tabs in exactly the abnormal-shutdown case. Dump to a sibling .tmp file, flush and os.fsync it, then os.replace onto session.json. os.replace is atomic, so restore always sees either the previous complete file or the new one.
os.replace is atomic, but the rename lives in the directory entry. Until the directory is synced, a power loss right after a save can bring back the previous session.json. It is complete but stale, so the tabs saved last are lost. fsync the directory so the new file is durable.
There was a problem hiding this comment.
🟡 Changes recommended
Temporary-path construction breaks custom filenames containing directory components, and the test does not exercise interrupted writes.
2 open findings
What changed in this PR
Makes tab-session persistence crash-safe through atomic replacement and filesystem syncing.
Changes:
- Writes sessions through a temporary file and atomically replaces the destination.
- Adds atomic-save coverage and a release note.
| File | Description |
|---|---|
guake/guake_app.py |
Implements atomic, durable session saving. |
guake/tests/test_guake.py |
Tests the new save path. |
releasenotes/notes/crash-safe-save-tabs-adf00755bead6ea5.yaml |
Documents the fix. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| # it, then os.replace() onto the real path. os.replace is atomic, so a | ||
| # restore always sees either the previous complete file or the new one. | ||
| # Finally fsync the directory so the rename itself survives power loss. | ||
| tmp_file = session_file.with_name(f"{filename}.tmp") |
Comment on lines
+195
to
+200
| assert fsync.call_count == 2 | ||
| assert os.path.exists("/foobar/session.json") | ||
| assert not os.path.exists("/foobar/session.json.tmp") | ||
| with open("/foobar/session.json", encoding="utf-8") as f: | ||
| config = json.load(f) | ||
| assert "schema_version" in config |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


save_tabstruncatedsession.jsonand rewrote it in place. A crash or power loss during the write left a half-written file. On the next startrestore_tabstreated it as broken and moved it to.bak, so the saved tabs were lost exactly when they were needed.session.json.tmp,flush+os.fsync, thenos.replaceontosession.json. The replace is atomic, so a restore sees either the old complete file or the new one.fsyncthe directory after the replace, so the rename itself survives a power cut..tmpfile is left, the result is valid JSON, andfsyncruns for both the file and the directory.All 31 tests pass locally; black and flake8 report no issues. A reno note is included.
🤖 Generated with Claude Code