Deep-sweep fixes: cooperative-pool starvation, stdio tail loss, epoll integrity, UI pins
Host — the two remaining app-wide stall mechanisms plus main-thread pins found by mining all nine hang reports: - LinuxProcess.startStdinRelay wrote to a BLOCKING stdin fd on a width-limited cooperative-pool thread, non-cancellably; wedged guests starved the whole concurrency runtime (decode loops, watchdogs — an app-wide freeze surviving the reconcile fix). Writes now offload to a per-process GCD queue (vendored patch #18). - TranscriptWriter (actor) did blocking write/fsync on the cooperative pool; it now runs on its own DispatchSerialQueue executor. - UserMessageBubble's truncation probe typeset entire pasted-log-sized messages through CoreText per layout pass (100% main-thread pins in the 07-21 hang reports); certainly-long messages now skip the probe and render a prefix while collapsed. - toolGroupSignature JSON-encoded every tool input in the transcript up to 12.5x/s on the MainActor; now a structural hash. The summary pass is trailing-throttled to 0.4s, and flatItems joins streaming chunks once instead of re-copying the prefix per delta. - StatusFeedFetcher.parseDate allocated three formatters per call (86% of a pool thread in the 07-26 report); now shared statics. Guest (vminitd) — teardown data loss and epoll registration hazards: - IOPair no longer closes on a bare EPOLLHUP with a backpressure flush in flight (dropped the CLI's final output line); EPOLLOUT finishes the flush, then EOF closes loss-free. ManagedProcess.setExit closes only stdin, letting stdout/stderr self-close on EOF, with an 8s grace pass (patch #16). - Epoll events carry a registration generation; the supervisor ignores stale events for recycled fd numbers. registerFd refuses EEXIST instead of clobbering the existing handler. TerminalIO's stdin relay writes a dup of the terminal fd so its backpressure registration can't collide with the stdout relay's (patch #17). - VsockProxy flushes bytes parked toward the surviving peer on hangup, closes the dialing socket on a failed backend connect, and StandardIO/TerminalIO clean up partially-created pairs on setup failure (patch #16). Full suite: 1451+292+74+20 tests, two failures — both pre-existing environmental (MacVM base image absent on this machine; a load-flaky liveness test that passes 3/3 in isolation). Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
@@ -27,7 +27,9 @@ import Synchronization
|
||||
|
||||
final class ManagedProcess: ContainerProcess, Sendable {
|
||||
// swiftlint: disable type_name
|
||||
protocol IO {
|
||||
// [Nucleic vendored patch] Sendable so the exit path's delayed grace-close can capture
|
||||
// the IO existential; both conformers (StandardIO, TerminalIO) already are.
|
||||
protocol IO: Sendable {
|
||||
func attach(pid: Int32, fd: Int32) throws
|
||||
func start(process: inout Command) throws
|
||||
func resize(size: Terminal.Size) throws
|
||||
@@ -332,10 +334,30 @@ extension ManagedProcess {
|
||||
let exitStatus = ContainerExitStatus(exitCode: status, exitedAt: Date.now)
|
||||
state.exitStatus = exitStatus
|
||||
|
||||
// [Nucleic vendored patch] Close only stdin here. Force-closing ALL stdio at
|
||||
// exit raced the relay: SIGCHLD is serviced before the poller thread drains the
|
||||
// pipe's final EPOLLIN edge, and the old `io.close()` drain silently dropped
|
||||
// whatever the destination wouldn't take (`drain` ignores short writes) — the
|
||||
// CLI's final output line, truncated at process exit. The stdout/stderr write
|
||||
// ends inside vminitd were already closed by `closeAfterExec`, so the child's
|
||||
// exit delivers EOF/HUP to each relay, which self-closes loss-free (the relay
|
||||
// never closes with a backpressure flush in flight). The delayed full close is
|
||||
// a backstop for a grandchild that inherited the pipes and never exits, or a
|
||||
// host that never drains — it must never fire on a healthy teardown path.
|
||||
do {
|
||||
try state.io.close()
|
||||
try state.io.closeStdin()
|
||||
} catch {
|
||||
self.log.error("failed to close I/O for process: \(error)")
|
||||
self.log.error("failed to close stdin for exited process: \(error)")
|
||||
}
|
||||
let io = state.io
|
||||
let log = self.log
|
||||
DispatchQueue.global(qos: .utility).asyncAfter(deadline: .now() + 8) {
|
||||
// Idempotent: a relay already self-closed on EOF makes this a no-op.
|
||||
do {
|
||||
try io.close()
|
||||
} catch {
|
||||
log.error("failed to close I/O for exited process (grace pass): \(error)")
|
||||
}
|
||||
}
|
||||
|
||||
for waiter in state.waiters {
|
||||
|
||||
Reference in New Issue
Block a user