config: retry acquiring config.lock, configurable via core.configLockTimeout

Concurrent config writers race for the ".lock" file, which is taken with open(O_EXCL) and no retry, so the losers fail right away with "could not lock config file". This shows up with parallel "git worktree add -b" against the same repository: each one writes a couple of branch.* keys and the losers fail at random. Worse, "git worktree add" doesn't propagate that failure to its exit code, so the tracking config is silently dropped. (The swallowed error is a separate bug.) Retry instead of giving up on the first EEXIST. The lock is only held while rewriting a small file, so the loser only has to wait out the other writers. Same approach as 4ff0f01cb7 (refs: retry acquiring reference locks for 100ms, 2017-08-21). On the semantics: the on-disk config is read only after the lock is taken, so writers touching different keys can't lose each other's change. Writers touching the same key still get last-writer-wins, but that is already the case today and would need a compare-and-swap config API to fix. The retry only turns hard failures into successes. Default to 1000ms, like core.packedRefsTimeout: same shape of problem, one shared file everyone serializes through. A larger timeout only costs anything when a stale lock is left behind by a crash, which is rare; a smaller one fails spuriously on slow filesystems (NTFS has been seen needing more than 100ms). Make it configurable as core.configLockTimeout. There is no chicken-and-egg problem: we read the config before we lock it. microsoft/git carries a similar patch (core.configWriteLockTimeoutMS, default off) for Scalar's tests. Defaulting to non-zero here because the worktree case fails silently. Helped-by: Patrick Steinhardt <ps@pks.im> Helped-by: Johannes Schindelin <Johannes.Schindelin@gmx.de> Signed-off-by: Jörg Thalheim <joerg@thalheim.io> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jörg Thalheim committed May 17, 2026 at 15:21 UTC df67d73ca3268eec5c924d6fe9d2c050ce23f3b1
5 files changed +53 -5
Documentation/config/core.adoc
+8
@@ -589,6 +589,14 @@ core.packedRefsTimeout::
589 all; -1 means to try indefinitely. Default is 1000 (i.e.,
590 retry for 1 second).
591
592 +core.configLockTimeout::
593 + The length of time, in milliseconds, to retry when trying to
594 + lock a configuration file for writing. Value 0 means not to
595 + retry at all; -1 means to try indefinitely. Default is 1000
596 + (i.e., retry for 1 second). This is read from the configuration
597 + that is already on disk before the lock is taken, so it can be
598 + set persistently like any other option.
599 +
600 core.pager::
601 Text viewer for use by Git commands (e.g., 'less'). The value
602 is meant to be interpreted by the shell. The order of preference
config.c
+22 -2
@@ -2903,6 +2903,24 @@ char *git_config_prepare_comment_string(const char *comment)
2903 return prepared;
2904 }
2905
2906 +/*
2907 + * How long to retry acquiring config.lock when another process holds
2908 + * it. Default matches core.packedRefsTimeout; override via
2909 + * core.configLockTimeout.
2910 + */
2911 +static long config_lock_timeout_ms(struct repository *r)
2912 +{
2913 + static int configured;
2914 + static int timeout_ms = 1000;
2915 +
2916 + if (!configured) {
2917 + repo_config_get_int(r, "core.configlocktimeout", &timeout_ms);
2918 + configured = 1;
2919 + }
2920 +
2921 + return timeout_ms;
2922 +}
2923 +
2924 static void validate_comment_string(const char *comment)
2925 {
2926 size_t leading_blanks;
@@ -2986,7 +3004,8 @@ int repo_config_set_multivar_in_file_gently(struct repository *r,
3004 * The lock serves a purpose in addition to locking: the new
3005 * contents of .git/config will be written into it.
3006 */
2989 - fd = hold_lock_file_for_update(&lock, config_filename, 0);
3007 + fd = hold_lock_file_for_update_timeout(&lock, config_filename, 0,
3008 + config_lock_timeout_ms(r));
3009 if (fd < 0) {
3010 error_errno(_("could not lock config file %s"), config_filename);
3011 ret = CONFIG_NO_LOCK;
@@ -3331,7 +3350,8 @@ static int repo_config_copy_or_rename_section_in_file(
3350 if (!config_filename)
3351 config_filename = filename_buf = repo_git_path(r, "config");
3352
3334 - out_fd = hold_lock_file_for_update(&lock, config_filename, 0);
3353 + out_fd = hold_lock_file_for_update_timeout(&lock, config_filename, 0,
3354 + config_lock_timeout_ms(r));
3355 if (out_fd < 0) {
3356 ret = error(_("could not lock config file %s"), config_filename);
3357 goto out;
t/t1300-config.sh
+17
@@ -2939,4 +2939,21 @@ test_expect_success 'writing value with trailing CR not stripped on read' '
2939 test_cmp expect actual
2940 '
2941
2942 +test_expect_success 'writing config fails immediately with core.configLockTimeout=0' '
2943 + test_when_finished "rm -f .git/config.lock" &&
2944 + >.git/config.lock &&
2945 + test_must_fail git -c core.configLockTimeout=0 config foo.bar baz 2>err &&
2946 + test_grep "could not lock config file" err
2947 +'
2948 +
2949 +test_expect_success 'writing config retries until lock is released' '
2950 + test_when_finished "rm -f .git/config.lock" &&
2951 + >.git/config.lock &&
2952 + {
2953 + ( sleep 1 && rm -f .git/config.lock ) &
2954 + } &&
2955 + git -c core.configLockTimeout=5000 config retried.key value &&
2956 + test "$(git config retried.key)" = value
2957 +'
2958 +
2959 test_done
t/t3200-branch.sh
+4 -2
@@ -1037,7 +1037,8 @@ test_expect_success '--set-upstream-to fails on locked config' '
1037 test_when_finished "rm -f .git/config.lock" &&
1038 >.git/config.lock &&
1039 git branch locked &&
1040 - test_must_fail git branch --set-upstream-to locked 2>err &&
1040 + test_must_fail git -c core.configLockTimeout=0 \
1041 + branch --set-upstream-to locked 2>err &&
1042 test_grep "could not lock config file .git/config" err
1043 '
1044
@@ -1068,7 +1069,8 @@ test_expect_success '--unset-upstream should fail if config is locked' '
1069 test_when_finished "rm -f .git/config.lock" &&
1070 git branch --set-upstream-to locked &&
1071 >.git/config.lock &&
1071 - test_must_fail git branch --unset-upstream 2>err &&
1072 + test_must_fail git -c core.configLockTimeout=0 \
1073 + branch --unset-upstream 2>err &&
1074 test_grep "could not lock config file .git/config" err
1075 '
1076
t/t5505-remote.sh
+2 -1
@@ -1327,7 +1327,8 @@ test_expect_success 'remote set-url with locked config' '
1327 test_when_finished "rm -f .git/config.lock" &&
1328 git config --get-all remote.someremote.url >expect &&
1329 >.git/config.lock &&
1330 - test_must_fail git remote set-url someremote baz &&
1330 + test_must_fail git -c core.configLockTimeout=0 \
1331 + remote set-url someremote baz &&
1332 git config --get-all remote.someremote.url >actual &&
1333 cmp expect actual
1334 '