Repository navigation
Simplify process forwarding and keep shim Notices in order - #456
Merged
Merged
Conversation
This comment has been minimized.
This comment has been minimized.
A Notice now goes through fd 2's output pump, after the stderr queued before it. readFD, writeFD and waitFD take one stop flag, the Request frame is built in a bytes.Buffer, and the unused Conn.Unix is gone.
The broker no longer logs its relay's end, which every view teardown causes; the agent host logs a relay lost while the view runs at ERROR. Failures, a lost shim and redials caused by the broker stopping log nothing above DEBUG.
The fake process service gives way to a peer with one operation that scripts the four faults its tests need. The fixture takes a dial function, so those tests never start processserve, and a Busy acknowledgement comes from intercept instead of a rewritten response.
Every caller of the broker and of a view is Linux-only, and agenthost.Open already reports the typed unsupported error elsewhere. Outside Linux, sessionview keeps Init and its types and processbroker its configuration.
No caller sets Process.Groups or reads Exit.CoreDumped. The view's processes keep an empty supplementary group list, which the identity test now asserts.
The shim, the relay and their IPC are processshim's to describe. The broker's doc keeps its own trust rules, acknowledgement and backpressure, background processes and qualification limits.
sessionview.Stdio makes the stdio of a process that runs as a given user: the files the caller passes, a pipe for each missing one, or /dev/null for an unwanted stdin. View.Start, View.Spawn and the agent host's view process all use it, replacing three copies of the pipe making and its cleanup. Every pipe it makes belongs to the process's user, so the relay can open it as its own, as it already could for the view's own pipes.
The relay's output pump now writes the Notices still queued when End stops it, as far as fd 2 takes them, so a Notice behind pending stderr is no longer dropped and teardown stays bounded. The agent host decides a relay loss from the view's lifecycle instead of probing the Harness. The relay ignores the view's signals, so the launcher reaps it only when it ended before the launcher: a crash, a kill, or a broker that stopped serving it, which now ends the connection. The launcher reports that, View.RelayLost closes before Wait returns, and the agent host logs the ERROR and fails the Session on it, even when the Harness exits right after. A local reader that closes its end, as on a Cancel, now logs at DEBUG; other output write failures keep INFO.
SaladDay
merged commit Oct 7, 2026
6d4dcb7
into
feature/agent-outside-sandbox
38 of 40 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
B4 simplicity audit, lane L3: process forwarding and the view. Net −117 production lines and +17 test lines, in 8 commits.
Defects fixed:
Endstops the pump, the pump still writes the queued Notices as far as fd 2 takes them, so teardown stays bounded. Tests:TestNoticeFollowsQueuedStderrandTestNoticeOutlivesEnd, which covers stderr both writable and full.View.RelayLostcloses beforeWaitreturns, and the agent host reacts to it. This replaces aSignal(0)probe that raced the Harness's exit.Deletions:
processserve;busyAcktransport, which rewrote an applied acknowledgement into Busy;broker_other.go;Init;Process.Groups, keeping an explicit empty group list, which is now asserted;Exit.CoreDumped;Stdiohelper for the view's process,Spawnand the agent host.frameBuffer, replaced bybytes.Buffer;Conn.Unix.The pipes the helper creates are now owned by the Session uid, as the view's own pipes already were. Everything in the view runs as that uid, so trust is unchanged; blind review accepted this.
Testing:
--cpuset-cpus=0.-count=50, plus-racewhere the view allows it.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.