![Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack](https://cdn.sanity.io/images/cgdhsj6q/production/6af25114feaaac7179b18127c83327568ff592d1-1024x1024.webp?w=800&fit=max&auto=format)
Security News
Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack
Polyfill.io has been serving malware for months via its CDN, after the project's open source maintainer sold the service to a company based in China.
proper-lockfile
Advanced tools
Readme
A lockfile utility based on fs that works cross process and machine (network file systems).
$ npm install proper-lockfile --save
There are various ways to achieve file locking.
This library utilizes the mkdir
strategy which works atomically on any kind of file system, even network based ones.
The lockfile path is based on the file path you are trying to lock by suffixing it with .lock
.
When a lock is successfully acquired, the lockfile's mtime
(modified time) is periodically updated to prevent staleness. This allows to effectively check if a lock is stale by checking its mtime
against a stale threshold. If the update of the mtime fails several times, the lock might be compromised.
This library is similar to lockfile but the later has some drawbacks:
open
with O_EXCL
flag which has problems in network file systems. proper-lockfile
uses mkdir
which doesn't have this issue.O_EXCL is broken on NFS file systems; programs which rely on it for performing locking tasks will contain a race condition.
The lockfile staleness check is done via creation time, which is unsuitable for long running processes. proper-lockfile
constantly updates lockfiles mtime to do proper staleness check.
It does not check if the lockfile was compromised, which can led to undesirable situations. proper-lockfile
checks the lockfile when updating the mtime.
Tries to acquire a lock on file
.
If the lock succeeds, an unlock
function is given that should be called when you want to release the lock.
If the lock get compromised, the provided compromised
function will be called (optionally).
Available options:
stale
: Duration in milliseconds in which the lock is considered stale, defaults to 10000
(false
to disable)update
: The interval in which the lockfile's mtime will be updated, defaults to 5000
retries
: The number of retries or a retry options object, defaults to 0
resolve
: Resolve to a canonical path to handle relative paths & symlinks properly, defaults to true
fs
: A custom fs to use, defaults to graceful-fs
var lockfile = require('proper-lockfile');
lockfile.lock('some/file', function (err, unlock) {
if (err) {
throw err; // Lock failed
}
// Do something while the file is locked
// Call the provided unlock function when you're done
// Note that you can optionally handle unlock errors
unlock(/* function (err) {
if (err) {
throw err; // Unlock failed
}
// Lock is released
}*/)
}, function (err) {
// If we get here, the lock has been compromised
// e.g.: the lock has been manually deleted
});
Removes a lock.
You should NOT call this function to unlock a lockfile that isn't owned by you.
This function is an alternative to the provided unlock
function (as explained above) and you should ONLY call it if you own the lock.
Available options:
resolve
: Resolve to a canonical path to handle relative paths & symlinks properly, defaults to true
fs
: A custom fs to use, defaults to graceful-fs
var lockfile = require('proper-lockfile');
lockfile.remove('some/file', function (err, unlock) {
if (err) {
throw err; // Removal failed
}
});
Simply run the test suite with $ npm test
The test suite is very extensive. We even have a stress test to guarantee exclusiveness of locks.
Released under the MIT License.
FAQs
A inter-process and inter-machine lockfile utility that works on a local or network file system
The npm package proper-lockfile receives a total of 1,660,829 weekly downloads. As such, proper-lockfile popularity was classified as popular.
We found that proper-lockfile demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Polyfill.io has been serving malware for months via its CDN, after the project's open source maintainer sold the service to a company based in China.
Security News
OpenSSF is warning open source maintainers to stay vigilant against reputation farming on GitHub, where users artificially inflate their status by manipulating interactions on closed issues and PRs.
Security News
A JavaScript library maintainer is under fire after merging a controversial PR to support legacy versions of Node.js.