Deep-sweep fixes: cooperative-pool starvation, stdio tail loss, epoll integrity, UI pins
Host — the two remaining app-wide stall mechanisms plus main-thread pins found by mining all nine hang reports: - LinuxProcess.startStdinRelay wrote to a BLOCKING stdin fd on a width-limited cooperative-pool thread, non-cancellably; wedged guests starved the whole concurrency runtime (decode loops, watchdogs — an app-wide freeze surviving the reconcile fix). Writes now offload to a per-process GCD queue (vendored patch #18). - TranscriptWriter (actor) did blocking write/fsync on the cooperative pool; it now runs on its own DispatchSerialQueue executor. - UserMessageBubble's truncation probe typeset entire pasted-log-sized messages through CoreText per layout pass (100% main-thread pins in the 07-21 hang reports); certainly-long messages now skip the probe and render a prefix while collapsed. - toolGroupSignature JSON-encoded every tool input in the transcript up to 12.5x/s on the MainActor; now a structural hash. The summary pass is trailing-throttled to 0.4s, and flatItems joins streaming chunks once instead of re-copying the prefix per delta. - StatusFeedFetcher.parseDate allocated three formatters per call (86% of a pool thread in the 07-26 report); now shared statics. Guest (vminitd) — teardown data loss and epoll registration hazards: - IOPair no longer closes on a bare EPOLLHUP with a backpressure flush in flight (dropped the CLI's final output line); EPOLLOUT finishes the flush, then EOF closes loss-free. ManagedProcess.setExit closes only stdin, letting stdout/stderr self-close on EOF, with an 8s grace pass (patch #16). - Epoll events carry a registration generation; the supervisor ignores stale events for recycled fd numbers. registerFd refuses EEXIST instead of clobbering the existing handler. TerminalIO's stdin relay writes a dup of the terminal fd so its backpressure registration can't collide with the stdout relay's (patch #17). - VsockProxy flushes bytes parked toward the surviving peer on hangup, closes the dialing socket on a failed backend connect, and StandardIO/TerminalIO clean up partially-created pairs on setup failure (patch #16). Full suite: 1451+292+74+20 tests, two failures — both pre-existing environmental (MacVM base image absent on this machine; a load-flaky liveness test that passes 3/3 in isolation). Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
@@ -59,24 +59,45 @@ final class TerminalIO: ManagedProcess.IO & Sendable {
|
||||
process.stdout = nil
|
||||
process.stderr = nil
|
||||
|
||||
if let stdinPort = self.hostStdio.stdin {
|
||||
let type = VsockType(
|
||||
port: stdinPort,
|
||||
cid: VsockType.hostCID
|
||||
)
|
||||
let stdinSocket = try Socket(type: type, closeOnDeinit: false)
|
||||
try stdinSocket.connect()
|
||||
$0.stdinSocket = stdinSocket
|
||||
}
|
||||
// [Nucleic vendored patch] Close whatever connected on a partial failure —
|
||||
// these sockets are closeOnDeinit: false, so a discarded IO object would leak
|
||||
// the earlier fd in PID-1.
|
||||
do {
|
||||
if let stdinPort = self.hostStdio.stdin {
|
||||
let type = VsockType(
|
||||
port: stdinPort,
|
||||
cid: VsockType.hostCID
|
||||
)
|
||||
let stdinSocket = try Socket(type: type, closeOnDeinit: false)
|
||||
do {
|
||||
try stdinSocket.connect()
|
||||
} catch {
|
||||
try? stdinSocket.close()
|
||||
throw error
|
||||
}
|
||||
$0.stdinSocket = stdinSocket
|
||||
}
|
||||
|
||||
if let stdoutPort = self.hostStdio.stdout {
|
||||
let type = VsockType(
|
||||
port: stdoutPort,
|
||||
cid: VsockType.hostCID
|
||||
)
|
||||
let stdoutSocket = try Socket(type: type, closeOnDeinit: false)
|
||||
try stdoutSocket.connect()
|
||||
$0.stdoutSocket = stdoutSocket
|
||||
if let stdoutPort = self.hostStdio.stdout {
|
||||
let type = VsockType(
|
||||
port: stdoutPort,
|
||||
cid: VsockType.hostCID
|
||||
)
|
||||
let stdoutSocket = try Socket(type: type, closeOnDeinit: false)
|
||||
do {
|
||||
try stdoutSocket.connect()
|
||||
} catch {
|
||||
try? stdoutSocket.close()
|
||||
throw error
|
||||
}
|
||||
$0.stdoutSocket = stdoutSocket
|
||||
}
|
||||
} catch {
|
||||
if let stdinSocket = $0.stdinSocket {
|
||||
try? stdinSocket.close()
|
||||
$0.stdinSocket = nil
|
||||
}
|
||||
throw error
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -98,13 +119,23 @@ final class TerminalIO: ManagedProcess.IO & Sendable {
|
||||
$0.parent = term
|
||||
|
||||
if let stdinSocket = $0.stdinSocket {
|
||||
// [Nucleic vendored patch] The stdin relay's destination is a dup of the
|
||||
// terminal fd, NOT the terminal fd itself: both relays sharing one number
|
||||
// meant the stdin side's EPOLLOUT backpressure registration collided with
|
||||
// the stdout side's read registration (see DupIOCloser) — one bulk paste
|
||||
// permanently killed the terminal's stdout relay.
|
||||
let pair = IOPair(
|
||||
readFrom: stdinSocket,
|
||||
writeTo: UnownedIOCloser(term),
|
||||
writeTo: try DupIOCloser(duplicating: term.fileDescriptor),
|
||||
reason: "TerminalIO stdin",
|
||||
logger: log
|
||||
)
|
||||
try pair.relay(ignoreHup: true)
|
||||
do {
|
||||
try pair.relay(ignoreHup: true)
|
||||
} catch {
|
||||
pair.close()
|
||||
throw error
|
||||
}
|
||||
$0.stdin = pair
|
||||
}
|
||||
|
||||
@@ -115,7 +146,17 @@ final class TerminalIO: ManagedProcess.IO & Sendable {
|
||||
reason: "TerminalIO stdout",
|
||||
logger: log
|
||||
)
|
||||
try pair.relay(ignoreHup: true)
|
||||
do {
|
||||
try pair.relay(ignoreHup: true)
|
||||
} catch {
|
||||
// [Nucleic vendored patch] The stdin pair (and its relay) is already
|
||||
// live; a discarded IO object would leave it registered and pumping
|
||||
// forever (the supervisor's handler map retains it).
|
||||
pair.close()
|
||||
$0.stdin?.close()
|
||||
$0.stdin = nil
|
||||
throw error
|
||||
}
|
||||
$0.stdout = pair
|
||||
}
|
||||
}
|
||||
@@ -123,11 +164,11 @@ final class TerminalIO: ManagedProcess.IO & Sendable {
|
||||
|
||||
func close() throws {
|
||||
self.state.withLock {
|
||||
// stdout must close before stdin because both IOPairs share the
|
||||
// Terminal fd. stdout registered that fd with epoll (as its read
|
||||
// source) and needs to unregister it while the fd is still valid.
|
||||
// stdin closes the Terminal as its write destination, which would
|
||||
// invalidate the fd before stdout can unregister.
|
||||
// stdout closes first: it registered the Terminal fd with epoll (as its read
|
||||
// source) and unregisters it while the fd is still valid. The stdin pair's
|
||||
// write destination is its own dup of the terminal (see attach), so its
|
||||
// close-time flush stays valid regardless of ordering — the shared open file
|
||||
// description outlives the stdout side's close until the dup closes too.
|
||||
if let stdout = $0.stdout {
|
||||
stdout.close()
|
||||
$0.stdout = nil
|
||||
|
||||
Reference in New Issue
Block a user