Commit 353f4e8
feat(pm): declared unlocked mode where the verify lock has no flock (#11538)
The shared verification lock is declared Linux-only (maintainer ruling,
2026-08-22). A host with no usable `flock` no longer refuses at exit 99: it
runs the command in a DECLARED UNLOCKED mode, writes the degradation into the
VERDICT line so it is visible and auditable, and prints the disclosure its PR
body must carry — the wording the two unlocked-verification precedents wrote
by hand, promoted to the official format.
Nothing is created on that path: no lockfile, no holder record, no queue
ticket, no fd — so `kill -9` still leaves nothing to reap, which is the
invariant a hand-rolled lockfile would have given up. The trigger is the
FUNCTIONAL flock probe, never the platform name, so a Linux container without
util-linux degrades the same way and a brew-equipped macOS takes the locked
path. The probe file's creation is checked apart from the lock taken on it:
an unusable temp dir stays a refusal rather than reading as "no flock" and
silently dropping serialization for every agent in the container.
Where flock works, the locked path is unchanged — the acquisition loops, the
ordering layer, the budget and every verdict are byte-for-byte what they were.
Claude-Session: https://claude.ai/code/session_015ahemw8RcTgqtxrj15PEZx
Co-authored-by: Claude <noreply@anthropic.com>1 parent 3637731 commit 353f4e8
2 files changed
Lines changed: 288 additions & 29 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
| 12 | + | |
| 13 | + | |
12 | 14 | | |
13 | 15 | | |
14 | 16 | | |
| |||
0 commit comments