Skip to content

Simplify process forwarding and keep shim Notices in order - #456

Merged
SaladDay merged 8 commits into
feature/agent-outside-sandboxfrom
aos/b4-forwarding
Oct 7, 2026
Merged

SaladDay merged 8 commits into
feature/agent-outside-sandboxfrom
aos/b4-forwarding

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

B4 simplicity audit, lane L3: process forwarding and the view. Net −117 production lines and +17 test lines, in 8 commits.

Defects fixed:

  • Notice order (shim IPC step 8). A Notice is now an item on fd 2's output queue, so it follows the stderr already queued. When End stops the pump, the pump still writes the queued Notices as far as fd 2 takes them, so teardown stays bounded. Tests: TestNoticeFollowsQueuedStderr and TestNoticeOutlivesEnd, which covers stderr both writable and full.
  • Teardown log levels. A normal view end and a Cancel log nothing above DEBUG. A real relay loss still logs ERROR and fails the Session.
    • The relay ignores the view's signals, so the launcher reaps it only when the relay ended first. The launcher reports that, View.RelayLost closes before Wait returns, and the agent host reacts to it. This replaces a Signal(0) probe that raced the Harness's exit.
    • A broker that stops serving a live relay now ends the relay's connection.

Deletions:

  • processbroker:
    • the 410-line fake process service, replaced by a scripted single-operation peer for the four fault tests; their assertions are kept, and they no longer start processserve;
    • the busyAck transport, which rewrote an applied acknowledgement into Busy;
    • broker_other.go;
    • the doc's restatement of the relay.
  • sessionview:
    • the non-Linux stubs except Init;
    • Process.Groups, keeping an explicit empty group list, which is now asserted;
    • Exit.CoreDumped;
    • one Stdio helper for the view's process, Spawn and the agent host.
  • processshim:
    • the variadic stop flags;
    • frameBuffer, replaced by bytes.Buffer;
    • Conn.Unix.

The pipes the helper creates are now owned by the Session uid, as the view's own pipes already were. Everything in the view runs as that uid, so trust is unchanged; blind review accepted this.

Testing:

  • The sessionview, processbroker, processshim and agenthost suites in privileged containers, on all CPUs and with --cpuset-cpus=0.
  • The new and changed tests at -count=50, plus -race where the view allows it.
  • Mutation checks on both defect fixes.
  • Blind review (Codex): its three findings are fixed in f5cf15a.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@blacksmith-sh

This comment has been minimized.

A Notice now goes through fd 2's output pump, after the stderr queued
before it. readFD, writeFD and waitFD take one stop flag, the Request
frame is built in a bytes.Buffer, and the unused Conn.Unix is gone.
The broker no longer logs its relay's end, which every view teardown
causes; the agent host logs a relay lost while the view runs at ERROR.
Failures, a lost shim and redials caused by the broker stopping log
nothing above DEBUG.
The fake process service gives way to a peer with one operation that
scripts the four faults its tests need. The fixture takes a dial
function, so those tests never start processserve, and a Busy
acknowledgement comes from intercept instead of a rewritten response.
Every caller of the broker and of a view is Linux-only, and agenthost.Open
already reports the typed unsupported error elsewhere. Outside Linux,
sessionview keeps Init and its types and processbroker its configuration.
No caller sets Process.Groups or reads Exit.CoreDumped. The view's
processes keep an empty supplementary group list, which the identity
test now asserts.
The shim, the relay and their IPC are processshim's to describe. The
broker's doc keeps its own trust rules, acknowledgement and
backpressure, background processes and qualification limits.
sessionview.Stdio makes the stdio of a process that runs as a given user: the files the caller passes, a pipe for each missing one, or /dev/null for an unwanted stdin. View.Start, View.Spawn and the agent host's view process all use it, replacing three copies of the pipe making and its cleanup. Every pipe it makes belongs to the process's user, so the relay can open it as its own, as it already could for the view's own pipes.
The relay's output pump now writes the Notices still queued when End stops it, as far as fd 2 takes them, so a Notice behind pending stderr is no longer dropped and teardown stays bounded.

The agent host decides a relay loss from the view's lifecycle instead of probing the Harness. The relay ignores the view's signals, so the launcher reaps it only when it ended before the launcher: a crash, a kill, or a broker that stopped serving it, which now ends the connection. The launcher reports that, View.RelayLost closes before Wait returns, and the agent host logs the ERROR and fails the Session on it, even when the Harness exits right after.

A local reader that closes its end, as on a Cancel, now logs at DEBUG; other output write failures keep INFO.
@SaladDay
SaladDay merged commit 6d4dcb7 into feature/agent-outside-sandbox Oct 7, 2026
38 of 40 checks passed
@SaladDay
SaladDay deleted the aos/b4-forwarding branch October 7, 2026 00:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant