Deep-sweep fixes: cooperative-pool starvation, stdio tail loss, epoll integrity, UI pins

Host — the two remaining app-wide stall mechanisms plus main-thread pins
found by mining all nine hang reports:
- LinuxProcess.startStdinRelay wrote to a BLOCKING stdin fd on a
  width-limited cooperative-pool thread, non-cancellably; wedged guests
  starved the whole concurrency runtime (decode loops, watchdogs — an
  app-wide freeze surviving the reconcile fix). Writes now offload to a
  per-process GCD queue (vendored patch #18).
- TranscriptWriter (actor) did blocking write/fsync on the cooperative
  pool; it now runs on its own DispatchSerialQueue executor.
- UserMessageBubble's truncation probe typeset entire pasted-log-sized
  messages through CoreText per layout pass (100% main-thread pins in
  the 07-21 hang reports); certainly-long messages now skip the probe
  and render a prefix while collapsed.
- toolGroupSignature JSON-encoded every tool input in the transcript up
  to 12.5x/s on the MainActor; now a structural hash. The summary pass
  is trailing-throttled to 0.4s, and flatItems joins streaming chunks
  once instead of re-copying the prefix per delta.
- StatusFeedFetcher.parseDate allocated three formatters per call (86%
  of a pool thread in the 07-26 report); now shared statics.

Guest (vminitd) — teardown data loss and epoll registration hazards:
- IOPair no longer closes on a bare EPOLLHUP with a backpressure flush
  in flight (dropped the CLI's final output line); EPOLLOUT finishes the
  flush, then EOF closes loss-free. ManagedProcess.setExit closes only
  stdin, letting stdout/stderr self-close on EOF, with an 8s grace pass
  (patch #16).
- Epoll events carry a registration generation; the supervisor ignores
  stale events for recycled fd numbers. registerFd refuses EEXIST
  instead of clobbering the existing handler. TerminalIO's stdin relay
  writes a dup of the terminal fd so its backpressure registration
  can't collide with the stdout relay's (patch #17).
- VsockProxy flushes bytes parked toward the surviving peer on hangup,
  closes the dialing socket on a failed backend connect, and
  StandardIO/TerminalIO clean up partially-created pairs on setup
  failure (patch #16).

Full suite: 1451+292+74+20 tests, two failures — both pre-existing
environmental (MacVM base image absent on this machine; a load-flaky
liveness test that passes 3/3 in isolation).

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
2026-07-28 15:35:35 -07:00
co-authored by Claude Fable 5
parent 6f950d859b
commit 17e84c9573
10 changed files with 358 additions and 104 deletions
+59 -2
View File
@@ -258,6 +258,55 @@ rebuild whenever a guest patch changes. Built locally, not in CI: the host frame
image is rebuilt and repointed (mind the `vminit.ext4.reference` cache sidecar). Marked
`[Nucleic vendored patch]`.
16. **Loss-free stdio teardown (`IOPair.swift`, `ManagedProcess.swift`, `VsockProxy.swift`,
`StandardIO.swift`, `TerminalIO.swift`) — the truncated-final-output class.** Four related
defects dropped the tail of a stream at teardown, plus two fd leaks:
- `IOPair`'s relay handler closed on a bare EPOLLHUP even with a backpressure flush in
flight, dropping the parked remainder (the CLI's final result line) when the
destination was momentarily full at process exit. It now returns instead; the
destination's EPOLLOUT flushes the backlog, the pump then reads EOF and closes
loss-free.
- `ManagedProcess.setExit` force-closed ALL stdio on SIGCHLD, racing the poller thread's
final EPOLLIN drain (`drain()` silently ignores short writes). It now closes only
stdin; stdout/stderr self-close on EOF (loss-free per the previous fix), with an 8s
delayed full close as a backstop for pipe-inheriting grandchildren. `ManagedProcess.IO`
is now `Sendable` for that delayed capture.
- `VsockProxy` full-hangup teardown dropped bytes already read off the dead peer that
were parked toward the SURVIVING peer; it now makes one best-effort relay pass toward
the survivor before cleanup.
- `VsockProxy` leaked the `relayTo` fd (closeOnDeinit: false) on a failed backend
`connect()`; `StandardIO.start`/`TerminalIO.start`/`attach` leaked live pairs/sockets
(retained forever by the supervisor's handler map) on partial setup failure — all
paths now close what they created before rethrowing.
Marked `[Nucleic vendored patch]`.
17. **Epoll registration integrity (`Epoll.swift` in ContainerizationOS, `ProcessSupervisor.swift`,
`IOCloser.swift`, `TerminalIO.swift`).**
- **Registration generations:** epoll events now carry the registration's generation in
`epoll_data` (high 32 bits), and the supervisor dispatches only when it matches the
live entry — a stale event queued for a closed registration of a RECYCLED fd number
can no longer fire the new registration's handler (it could tear down a brand-new
healthy connection mid-batch).
- **Non-clobbering `registerFd`:** registering an already-registered fd now fails fast
(EEXIST) instead of overwriting the existing handler and then, on the epoll EEXIST,
deleting the map entry — which left the fd armed with NO handler (a silently dead
relay).
- **`TerminalIO` shared-fd collision:** the stdin relay's write destination is now a
`dup(2)` of the terminal fd (`DupIOCloser`), so its EPOLLOUT backpressure registration
can't collide with the stdout relay's read registration on the same number — one bulk
paste used to permanently kill the terminal's stdout relay.
- `Epoll.add` now ORs `O_NONBLOCK` into existing flags instead of replacing the flag set.
Marked `[Nucleic vendored patch]`.
18. **Host-side stdin relay off the Swift cooperative pool (`LinuxProcess.swift`).** The
stdin fd is blocking (only the read fds get `O_NONBLOCK`), and `startStdinRelay`'s
`FileHandle.write` parked a width-limited cooperative-pool thread — non-cancellably —
whenever the guest stopped reading with the vsock buffer full (large prompt lines). A
few wedged sessions starved the whole Swift concurrency runtime (every decode loop and
watchdog: an app-wide stall). Writes are now offloaded to a per-process GCD queue via a
checked continuation; a wedged write costs one expendable GCD thread, and process
deletion closing the fd still unwedges it. Marked `[Nucleic vendored patch]`.
## Re-vendoring a newer upstream commit
1. `git clone` upstream (or copy `.build/checkouts/containerization` after bumping the URL pin
@@ -279,9 +328,17 @@ rebuild whenever a guest patch changes. Built locally, not in CI: the host frame
`KeychainQuery` reads: `withoutInteractiveUI` + the `errSecInteractionNotAllowed` handling +
the `save` duplicate retry), and patch #14 (the non-blocking/non-spinning guest I/O plane:
`IOPair` backpressure, the `OSFile.splice` EAGAIN return, and the `VsockProxy` pre-registration
non-blocking fds — all in `vminitd/`), and patch #15 (the per-direction
non-blocking fds — all in `vminitd/`), patch #15 (the per-direction
`OSFile.RelayDirection`/`OSFile.relay` rewrite + the two-direction `VsockProxy.handleConn`,
which supersede the upstream `SpliceFile`/`splice` shapes entirely — in `vminitd/`). After
which supersede the upstream `SpliceFile`/`splice` shapes entirely — in `vminitd/`),
patch #16 (loss-free stdio teardown: the `IOPair` HUP-with-pending return, the
`setExit` stdin-only close + grace pass, the `VsockProxy` hangup flush + connect-leak
close, and the `StandardIO`/`TerminalIO` partial-failure cleanup — in `vminitd/`),
patch #17 (epoll registration generations in `ContainerizationOS/Linux/Epoll.swift` +
the generation-checked, non-clobbering `ProcessSupervisor` handler table + `DupIOCloser`
and the `TerminalIO` dup destination — spans `Sources/` AND `vminitd/`), and patch #18
(the `startStdinRelay` GCD write offload in `Sources/Containerization/LinuxProcess.swift`
— host side). After
re-applying any `vminitd/` patch, rebuild + publish the custom init image
with `make vminit-image` + `make vminit-image-push`, and bump `ContainerEngine.vminitReference`.
5. Update the commit hash above and in the root `Package.swift` comment.