Merge nucleic/hazy-opal-yak-cjc0 into dev

This commit is contained in:
2026-07-17 23:48:59 -07:00
parent 608e7d0450
commit 65623f1c34
5 changed files with 403 additions and 202 deletions
@@ -244,6 +244,22 @@ extension VsockProxy {
try relayTo.connect()
// [Nucleic vendored patch] BOTH fds must be non-blocking BEFORE either is
// registered. `Epoll.add` sets O_NONBLOCK only at registration time, and the first
// (client) registration's handler can fire — and splice toward the server fd —
// before the second (server) registration has made that fd non-blocking. A full
// destination then turned the splice into a genuinely BLOCKING call on vminitd's
// single ProcessSupervisor poller thread, freezing every exec's stdio and every
// control-plane relay in the container until the peer drained.
for fd in [conn.fileDescriptor, relayTo.fileDescriptor] {
let flags = fcntl(fd, F_GETFL)
if flags == -1 || fcntl(fd, F_SETFL, flags | O_NONBLOCK) == -1 {
self.log?.error(
"failed to set proxy fd non-blocking",
metadata: ["fd": "\(fd)", "errno": "\(errno)"])
}
}
// `clientFile` isn't used concurrently.
nonisolated(unsafe) var clientFile = OSFile.SpliceFile(fd: conn.fileDescriptor)
nonisolated(unsafe) var eofFromClient = false