Deep-sweep fixes: cooperative-pool starvation, stdio tail loss, epoll integrity, UI pins
Host — the two remaining app-wide stall mechanisms plus main-thread pins found by mining all nine hang reports: - LinuxProcess.startStdinRelay wrote to a BLOCKING stdin fd on a width-limited cooperative-pool thread, non-cancellably; wedged guests starved the whole concurrency runtime (decode loops, watchdogs — an app-wide freeze surviving the reconcile fix). Writes now offload to a per-process GCD queue (vendored patch #18). - TranscriptWriter (actor) did blocking write/fsync on the cooperative pool; it now runs on its own DispatchSerialQueue executor. - UserMessageBubble's truncation probe typeset entire pasted-log-sized messages through CoreText per layout pass (100% main-thread pins in the 07-21 hang reports); certainly-long messages now skip the probe and render a prefix while collapsed. - toolGroupSignature JSON-encoded every tool input in the transcript up to 12.5x/s on the MainActor; now a structural hash. The summary pass is trailing-throttled to 0.4s, and flatItems joins streaming chunks once instead of re-copying the prefix per delta. - StatusFeedFetcher.parseDate allocated three formatters per call (86% of a pool thread in the 07-26 report); now shared statics. Guest (vminitd) — teardown data loss and epoll registration hazards: - IOPair no longer closes on a bare EPOLLHUP with a backpressure flush in flight (dropped the CLI's final output line); EPOLLOUT finishes the flush, then EOF closes loss-free. ManagedProcess.setExit closes only stdin, letting stdout/stderr self-close on EOF, with an 8s grace pass (patch #16). - Epoll events carry a registration generation; the supervisor ignores stale events for recycled fd numbers. registerFd refuses EEXIST instead of clobbering the existing handler. TerminalIO's stdin relay writes a dup of the terminal fd so its backpressure registration can't collide with the stdout relay's (patch #17). - VsockProxy flushes bytes parked toward the surviving peer on hangup, closes the dialing socket on a failed backend connect, and StandardIO/TerminalIO clean up partially-created pairs on setup failure (patch #16). Full suite: 1451+292+74+20 tests, two failures — both pre-existing environmental (MacVM base image absent on this machine; a load-flaky liveness test that passes 3/3 in isolation). Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
@@ -242,7 +242,16 @@ extension VsockProxy {
|
||||
)
|
||||
}
|
||||
|
||||
try relayTo.connect()
|
||||
// [Nucleic vendored patch] A failed backend connect must close the socket it
|
||||
// was dialing from: `closeOnDeinit` is false, so throwing out of here (the
|
||||
// caller closes only `conn`) leaked one PID-1 fd per attempt while the
|
||||
// backend was down — sustained control-plane churn walked toward EMFILE.
|
||||
do {
|
||||
try relayTo.connect()
|
||||
} catch {
|
||||
try? relayTo.close()
|
||||
throw error
|
||||
}
|
||||
|
||||
// [Nucleic vendored patch] BOTH fds must be non-blocking BEFORE either is
|
||||
// registered. `Epoll.add` sets O_NONBLOCK only at registration time, and the first
|
||||
@@ -365,6 +374,15 @@ extension VsockProxy {
|
||||
}
|
||||
|
||||
if mask.isHangup {
|
||||
// Full hangup of the client. Before tearing down, make one best-effort
|
||||
// pass toward the SURVIVING peer: bytes already read off the client may
|
||||
// be parked in toServer's pipe (its earlier flush EAGAINed), and the
|
||||
// server is still healthy — dropping them loses a delivered-to-us
|
||||
// control message. One pass only (no spin risk: a still-full server
|
||||
// just returns and cleanup proceeds).
|
||||
if !toServerDone {
|
||||
_ = apply(Self.relayStep(&toServer, description: "client:hangup:toServer", log: self.log))
|
||||
}
|
||||
toServerDone = true
|
||||
toClientDone = true
|
||||
} else if mask.isRemoteHangup && !toServerDone {
|
||||
@@ -404,6 +422,11 @@ extension VsockProxy {
|
||||
}
|
||||
|
||||
if mask.isHangup {
|
||||
// Mirror of the client handler: flush bytes parked toward the
|
||||
// surviving client before teardown.
|
||||
if !toClientDone {
|
||||
_ = apply(Self.relayStep(&toClient, description: "server:hangup:toClient", log: self.log))
|
||||
}
|
||||
toServerDone = true
|
||||
toClientDone = true
|
||||
} else if mask.isRemoteHangup && !toClientDone {
|
||||
|
||||
Reference in New Issue
Block a user