Deep-sweep fixes: cooperative-pool starvation, stdio tail loss, epoll integrity, UI pins

Host — the two remaining app-wide stall mechanisms plus main-thread pins
found by mining all nine hang reports:
- LinuxProcess.startStdinRelay wrote to a BLOCKING stdin fd on a
  width-limited cooperative-pool thread, non-cancellably; wedged guests
  starved the whole concurrency runtime (decode loops, watchdogs — an
  app-wide freeze surviving the reconcile fix). Writes now offload to a
  per-process GCD queue (vendored patch #18).
- TranscriptWriter (actor) did blocking write/fsync on the cooperative
  pool; it now runs on its own DispatchSerialQueue executor.
- UserMessageBubble's truncation probe typeset entire pasted-log-sized
  messages through CoreText per layout pass (100% main-thread pins in
  the 07-21 hang reports); certainly-long messages now skip the probe
  and render a prefix while collapsed.
- toolGroupSignature JSON-encoded every tool input in the transcript up
  to 12.5x/s on the MainActor; now a structural hash. The summary pass
  is trailing-throttled to 0.4s, and flatItems joins streaming chunks
  once instead of re-copying the prefix per delta.
- StatusFeedFetcher.parseDate allocated three formatters per call (86%
  of a pool thread in the 07-26 report); now shared statics.

Guest (vminitd) — teardown data loss and epoll registration hazards:
- IOPair no longer closes on a bare EPOLLHUP with a backpressure flush
  in flight (dropped the CLI's final output line); EPOLLOUT finishes the
  flush, then EOF closes loss-free. ManagedProcess.setExit closes only
  stdin, letting stdout/stderr self-close on EOF, with an 8s grace pass
  (patch #16).
- Epoll events carry a registration generation; the supervisor ignores
  stale events for recycled fd numbers. registerFd refuses EEXIST
  instead of clobbering the existing handler. TerminalIO's stdin relay
  writes a dup of the terminal fd so its backpressure registration
  can't collide with the stdout relay's (patch #17).
- VsockProxy flushes bytes parked toward the surviving peer on hangup,
  closes the dialing socket on a failed backend connect, and
  StandardIO/TerminalIO clean up partially-created pairs on setup
  failure (patch #16).

Full suite: 1451+292+74+20 tests, two failures — both pre-existing
environmental (MacVM base image absent on this machine; a load-flaky
liveness test that passes 3/3 in isolation).

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
2026-07-28 15:35:35 -07:00
co-authored by Claude Fable 5
parent 6f950d859b
commit 17e84c9573
10 changed files with 358 additions and 104 deletions
+66 -58
View File
@@ -50,74 +50,82 @@ final class StandardIO: ManagedProcess.IO & Sendable {
func attach(pid: Int32, fd: Int32) throws {}
func start(process: inout Command) throws {
// [Nucleic vendored patch] All-or-nothing: a failure partway (a vsock connect or a
// relay registration throwing) used to discard the IO object with earlier pairs
// LIVE — the supervisor's handler map retains a registered IOPair forever, so a
// dead exec left a relay pumping host stdin into a pipe no child would ever read,
// plus its socket, pipe fds, and epoll slot. Dial each socket safely, and on any
// failure close every pair created so far before rethrowing.
try self.state.withLock {
if let stdinPort = self.hostStdio.stdin {
let inPipe = Pipe()
process.stdin = inPipe.fileHandleForReading
$0.stdinPipe = inPipe
let type = VsockType(
port: stdinPort,
cid: VsockType.hostCID
)
let stdinSocket = try Socket(type: type, closeOnDeinit: false)
try stdinSocket.connect()
let pair = IOPair(
readFrom: stdinSocket,
writeTo: inPipe.fileHandleForWriting,
reason: "StandardIO stdin",
logger: log
)
$0.stdin = pair
try pair.relay()
func dialHost(port: UInt32) throws -> Socket {
let type = VsockType(port: port, cid: VsockType.hostCID)
let socket = try Socket(type: type, closeOnDeinit: false)
do {
try socket.connect()
} catch {
try? socket.close()
throw error
}
return socket
}
do {
if let stdinPort = self.hostStdio.stdin {
let inPipe = Pipe()
process.stdin = inPipe.fileHandleForReading
$0.stdinPipe = inPipe
if let stdoutPort = self.hostStdio.stdout {
let outPipe = Pipe()
process.stdout = outPipe.fileHandleForWriting
$0.stdoutPipe = outPipe
let pair = IOPair(
readFrom: try dialHost(port: stdinPort),
writeTo: inPipe.fileHandleForWriting,
reason: "StandardIO stdin",
logger: log
)
$0.stdin = pair
let type = VsockType(
port: stdoutPort,
cid: VsockType.hostCID
)
let stdoutSocket = try Socket(type: type, closeOnDeinit: false)
try stdoutSocket.connect()
try pair.relay()
}
let pair = IOPair(
readFrom: outPipe.fileHandleForReading,
writeTo: stdoutSocket,
reason: "StandardIO stdout",
logger: log
)
$0.stdout = pair
if let stdoutPort = self.hostStdio.stdout {
let outPipe = Pipe()
process.stdout = outPipe.fileHandleForWriting
$0.stdoutPipe = outPipe
try pair.relay()
}
let pair = IOPair(
readFrom: outPipe.fileHandleForReading,
writeTo: try dialHost(port: stdoutPort),
reason: "StandardIO stdout",
logger: log
)
$0.stdout = pair
if let stderrPort = self.hostStdio.stderr {
let errPipe = Pipe()
process.stderr = errPipe.fileHandleForWriting
$0.stderrPipe = errPipe
try pair.relay()
}
let type = VsockType(
port: stderrPort,
cid: VsockType.hostCID
)
let stderrSocket = try Socket(type: type, closeOnDeinit: false)
try stderrSocket.connect()
if let stderrPort = self.hostStdio.stderr {
let errPipe = Pipe()
process.stderr = errPipe.fileHandleForWriting
$0.stderrPipe = errPipe
let pair = IOPair(
readFrom: errPipe.fileHandleForReading,
writeTo: stderrSocket,
reason: "StandardIO stderr",
logger: log
)
$0.stderr = pair
let pair = IOPair(
readFrom: errPipe.fileHandleForReading,
writeTo: try dialHost(port: stderrPort),
reason: "StandardIO stderr",
logger: log
)
$0.stderr = pair
try pair.relay()
try pair.relay()
}
} catch {
// IOPair.close is idempotent and closes both of a pair's fds; pairs whose
// relay registration never happened are closed the same way.
$0.stdin?.close()
$0.stdin = nil
$0.stdout?.close()
$0.stdout = nil
$0.stderr?.close()
$0.stderr = nil
throw error
}
}
}