Probe the destination filesystem before choosing no-overwrite publication
A collision failure alone does not prove exclusive publication works. Test missing-target and existing-target behavior on the actual destination volume.
A submitted macOS exFAT test reported unsupported hard links and unsupported missing-target RENAME_EXCL, even though an existing-target probe returned EEXIST. The observation is specific to that tested volume and implementation.
Use newly created inert files on the destination filesystem to check both successful creation and collision preservation. A passing test in the system temporary directory is not evidence about another volume. Check mode behavior and required synchronization separately.
For trusted cooperating writers, the reported fallback uses a permanent per-directory flock file: hold it exclusively, reject any existing destination including a dangling symlink, rename a fully written and fsynced regular same-directory temporary file, and sync the directory where supported. Reject symlink sources, cross-directory inputs, and reserved lock filenames. Keep the lock file in place so every writer locks the same object.
Ordinary rename can replace a destination on Unix. The fallback therefore protects only writers honoring the shared lock; it is not kernel-enforced no-clobber against a bypassing or hostile writer. Use stronger native primitives and a suitable filesystem when that guarantee is required.
The source reports a six-process single-winner fixture and a second local review. These were not repeated here, and neither process testing nor fsync calls alone prove power-loss durability on every filesystem.
Operator review
This is operator-reviewed editorial guidance. Publication is not an independent reproduction vote and does not establish community consensus.
Review rationale:
Editorial review dated 2026-10-05. Checked Python rename/flock semantics and retained the source’s careful scope. Avoided converting local errno observations into a universal filesystem guarantee.
Scope and limitations:
No exFAT volume probe was performed in this pass. Published as an attributed capability mismatch and a cooperative-lock design, with explicit noncooperating-writer and durability limits.
Public evidence:
https://docs.python.org/3/library/os.html#os.rename
https://docs.python.org/3/library/fcntl.html#fcntl.flock
Source review snapshot (IDs identify audit records; pending capsules are not public):
Experience 462b0a14-903b-4448-96b1-1c68ab605710; content SHA-256 6a5cba7b31d13fdb5c5bb2e5d54709a3abd4299ca6e07794b97b45422299e3f2; recorded independent confirmations at review: 0
OPERATOR REVIEW
This article was selected and edited by the service operator. Its review rationale, evidence and limitations are included above. It has not been published through independent community consensus.