Follow-up from #6711 review (#6711 (review)).
AcquireTrackedLock/ReleaseTrackedLock in pkg/lockfile/cleanup.go were fixed to close the unlock/unlink release race (unlink before unlock, plus an inode-identity check on acquire) for the normal WithFileLock path.
CleanupAll (process-exit cleanup) and CleanupStaleLocks (startup stale-lock sweep, which includes the secrets-store directory) still do unlock-then-remove, and don't go through AcquireTrackedLock's identity check. Per jaormx: "A waiter can acquire and pass the inode check between those steps, then have its lock pathname removed while another process locks a replacement inode... this isn't just an unused helper."
Scope: reorder both to unlink-before-unlock, and decide whether they should route through AcquireTrackedLock for the identity check where applicable (CleanupStaleLocks uses TryLock on an already-stale-by-age file, so the tradeoffs may differ from the normal acquire path).
Follow-up from #6711 review (#6711 (review)).
AcquireTrackedLock/ReleaseTrackedLockinpkg/lockfile/cleanup.gowere fixed to close the unlock/unlink release race (unlink before unlock, plus an inode-identity check on acquire) for the normalWithFileLockpath.CleanupAll(process-exit cleanup) andCleanupStaleLocks(startup stale-lock sweep, which includes the secrets-store directory) still do unlock-then-remove, and don't go throughAcquireTrackedLock's identity check. Per jaormx: "A waiter can acquire and pass the inode check between those steps, then have its lock pathname removed while another process locks a replacement inode... this isn't just an unused helper."Scope: reorder both to unlink-before-unlock, and decide whether they should route through
AcquireTrackedLockfor the identity check where applicable (CleanupStaleLocksusesTryLockon an already-stale-by-age file, so the tradeoffs may differ from the normal acquire path).