Private/Lock-KadenUpdate.ps1

function Lock-KadenUpdate {
    <#
    .SYNOPSIS
        Create the update lock only when no other update already holds it.
    .DESCRIPTION
        Uses exclusive create so two updates cannot both pass a separate existence check.
    #>

    [CmdletBinding()]
    param(
        [Parameter(Mandatory = $true)]
        [string]$LockPath,
        [Parameter(Mandatory = $true)]
        [string]$TransactionId
    )

    $dir = Split-Path -Parent $LockPath
    if (-not (Test-Path -LiteralPath $dir)) {
        New-Item -ItemType Directory -Path $dir -Force | Out-Null
    }

    $stream = $null
    try {
        $stream = [System.IO.File]::Open(
            $LockPath,
            [System.IO.FileMode]::CreateNew,
            [System.IO.FileAccess]::Write,
            [System.IO.FileShare]::None)
    }
    catch [System.IO.IOException] {
        throw 'KDN-TXN-LOCK-UNAVAILABLE: another update is already in progress.'
    }

    try {
        $bytes = [System.Text.Encoding]::UTF8.GetBytes($TransactionId)
        $stream.Write($bytes, 0, $bytes.Length)
    }
    finally {
        $stream.Dispose()
    }
}