Host — the two remaining app-wide stall mechanisms plus main-thread pins found by mining all nine hang reports: - LinuxProcess.startStdinRelay wrote to a BLOCKING stdin fd on a width-limited cooperative-pool thread, non-cancellably; wedged guests starved the whole concurrency runtime (decode loops, watchdogs — an app-wide freeze surviving the reconcile fix). Writes now offload to a per-process GCD queue (vendored patch #18). - TranscriptWriter (actor) did blocking write/fsync on the cooperative pool; it now runs on its own DispatchSerialQueue executor. - UserMessageBubble's truncation probe typeset entire pasted-log-sized messages through CoreText per layout pass (100% main-thread pins in the 07-21 hang reports); certainly-long messages now skip the probe and render a prefix while collapsed. - toolGroupSignature JSON-encoded every tool input in the transcript up to 12.5x/s on the MainActor; now a structural hash. The summary pass is trailing-throttled to 0.4s, and flatItems joins streaming chunks once instead of re-copying the prefix per delta. - StatusFeedFetcher.parseDate allocated three formatters per call (86% of a pool thread in the 07-26 report); now shared statics. Guest (vminitd) — teardown data loss and epoll registration hazards: - IOPair no longer closes on a bare EPOLLHUP with a backpressure flush in flight (dropped the CLI's final output line); EPOLLOUT finishes the flush, then EOF closes loss-free. ManagedProcess.setExit closes only stdin, letting stdout/stderr self-close on EOF, with an 8s grace pass (patch #16). - Epoll events carry a registration generation; the supervisor ignores stale events for recycled fd numbers. registerFd refuses EEXIST instead of clobbering the existing handler. TerminalIO's stdin relay writes a dup of the terminal fd so its backpressure registration can't collide with the stdout relay's (patch #17). - VsockProxy flushes bytes parked toward the surviving peer on hangup, closes the dialing socket on a failed backend connect, and StandardIO/TerminalIO clean up partially-created pairs on setup failure (patch #16). Full suite: 1451+292+74+20 tests, two failures — both pre-existing environmental (MacVM base image absent on this machine; a load-flaky liveness test that passes 3/3 in isolation). Co-Authored-By: Claude Fable 5 <[email protected]>
62 lines
2.1 KiB
Swift
62 lines
2.1 KiB
Swift
//===----------------------------------------------------------------------===//
|
|
// Copyright © 2026 Apple Inc. and the Containerization project authors.
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// https://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
#if os(Linux)
|
|
|
|
import ContainerizationOS
|
|
import Foundation
|
|
|
|
protocol IOCloser: Sendable {
|
|
var fileDescriptor: Int32 { get }
|
|
|
|
func close() throws
|
|
}
|
|
|
|
struct UnownedIOCloser: IOCloser {
|
|
private let inner: IOCloser
|
|
|
|
var fileDescriptor: Int32 { inner.fileDescriptor }
|
|
|
|
init(_ inner: IOCloser) {
|
|
self.inner = inner
|
|
}
|
|
|
|
func close() throws {}
|
|
}
|
|
|
|
/// [Nucleic vendored patch] Owns a `dup(2)` of another descriptor. Epoll keys registrations
|
|
/// on the fd NUMBER, so two IOPairs sharing one underlying file (TerminalIO: the stdout
|
|
/// relay reads the terminal fd, the stdin relay writes it) collide the moment the stdin
|
|
/// side needs an EPOLLOUT backpressure registration on the number the stdout side already
|
|
/// registered — which now fails fast (EEXIST) and killed the stdin relay. A dup shares the
|
|
/// open file description but has its own number, so each relay registers independently; the
|
|
/// description stays valid until every descriptor over it is closed.
|
|
struct DupIOCloser: IOCloser {
|
|
let fileDescriptor: Int32
|
|
|
|
init(duplicating fd: Int32) throws {
|
|
let duplicate = dup(fd)
|
|
guard duplicate != -1 else { throw POSIXError.fromErrno() }
|
|
self.fileDescriptor = duplicate
|
|
}
|
|
|
|
func close() throws {
|
|
guard Foundation.close(fileDescriptor) == 0 else { throw POSIXError.fromErrno() }
|
|
}
|
|
}
|
|
|
|
#endif
|