Conversation
4 tasks done
This was referenced Sep 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Primary Issue
Closes #108
Target Version
3.0-dev
Scope
修复 Transmite 在确认 worker_id 租约丢失后的退出路径。原实现到达 abort 后,在容器 PID 1 中经历两次 SIGABRT,最终触发 libc hlt 并以 139 退出;现在输出固定诊断并通过 std::_Exit(EXIT_FAILURE) 明确退出 1。退出前不等待注销 RPC,防止延迟全进程 fencing。增加 RL-WORKER-01,记录原进程退出、恢复策略和恢复后的延迟观察。
Non-goals
不更改租约丢失检测周期、worker 分配/耗尽策略、公共 API、消息幂等协议或默认构建目标;不以本修复关闭 #104 或 #96;不执行生产故障演练。
Architecture Impact
No — 服务边界、基础设施和持久化结构未变。
Core-flow Impact
Yes — worker 所有权丢失后的全进程退出不再依赖信号及注销网络调用;原租约检测与停服保护保留,注册由既有 TTL 或重启替换收敛。
Updated Skills
RED Evidence
Linux 独占合成栈,原始 fb2bb88 镜像:
go test -tags=reliability ./reliability/... -run '^TestRL_WorkerLeaseLossFencesProcess$' -v -count=1 -timeout=120s重复观测退出 139,OOMKilled=false。明确退出验收的最后一次 RED 为 expected 1 / actual 139,测试耗时 15.17s,exit=1。原始 worker-red-explicit.log 保留。
受控调试器只输出调用栈,不输出参数、局部变量或 core:watchdog → abort → SIGABRT 两次 → SIGSEGV,PC 为 libc abort+386 的 hlt。worker-gdb.log、worker-signals.log、worker-segv.log 保留。PID namespace 的 init 信号约束参见 https://man7.org/linux/man-pages/man7/pid_namespaces.7.html 。
GREEN Evidence
当前工作树:Transmite Release 编译通过(cmake --build build --target transmite_server -j2,exit=0)。定向相同命令 -count=3 -timeout=180s 连续三次通过,exit=0,43.683s;每次退出码 1、ProtectionLogged=true、OOMKilled=false,恢复后七秒进程稳定。
Regression Verification
当前提交
2bdd7c63c757bae6b2b9f80ca4743564a02cda9b,本地 Linux 独占合成栈;七个增量文件的 LF 归一化 SHA-256 与受测源码全部一致。go test ./pkg/contracts ./pkg/agentpolicy ./cmd/agent-policy ./pkg/client ./pkg/cleanup ./pkg/chaos -count=1static-final.log,六包通过,exit=0go vet -tags=reliability ./...;test -z "$(gofmt -l .)"vet.log/fmt-final.log,exit=0agent-policy issue/branch/commits/pull-request/skill-sync/skills六项;git diff origin/3.0-dev...HEAD --checkmake test-reliabilityreliability.log,7 项通过,112.636s,exit=0make test-bvtbvt.log,18 项通过,14.314s,exit=0make test-funcfunctional-recovered.log,191 项通过、2 项外部 SMTP 条件跳过,250.111s,exit=0make test-scenarioscenario-recovered.log,12 项通过,36.488s,exit=0完整原始日志保留在本地审计目录
issue108/vm/(本任务绝对路径见下);修复前 RED、调试栈和失败回归也一并保留。首次静态检查暴露归档 CRLF 和缺少 Git index,修复验证副本后通过;首次 Functional/Scenario 中三项搜索用例失败,实测为 VM 空间跌至约 375 MB,触发 Elasticsearch 512 MB flood-stage 只读保护。仅清理可重建缓存后释放到约 1.2 GB,索引自动解除只读;三项定向搜索连续两轮通过(search-recovery.log),再运行上述完整回归通过。未下调磁盘阈值或删除业务数据。云端当前提交 CI 34759231921 已完成:build、service-artifacts、BVT、Functional、Reliability 全部成功;两个 Performance 作业按现有非定时触发条件跳过。Agent Policy 的 PR 校验通过。
审计目录:
C:/Users/legion/.codex/visualizations/2026/09/13/01a09ad5-45db-76c1-9764-83a843e3d9ed/issue108/。Linux 原始目录:/home/icepop/issue108-audit/。Security and Compatibility
Security: 保留失去 worker 所有权后停止发号的安全边界;固定 stderr 诊断不含凭据或用户数据。仅操作同一独占 Compose 项目中唯一 worker 租约;清理恢复原自动重启策略并启动服务。
Compatibility: 无 Protobuf、API、配置或数据库变化。保护退出码从非预期 139 改为 1;不产生 core。退出不再主动注销,原注册最多保留既有 30 秒 TTL,重启会替换注册。
Migration: 无数据迁移;仅需替换 Transmite 镜像。生产部署和合并由人工决定。
Unverified Items
本轮要求的编译、定向和完整相关回归、当前提交 CI 已通过;PR 保持 Draft,等待前序堆叠合入后的同步及人工审查。
#104 云端间歇消息失败与 #96 历史崩溃保留独立跟踪;本次根因证据不能推广到它们。此次 191 项 Functional 全绿也不构成间歇问题永久消失的证明。
未运行生产、任意网络分区、长期压力、worker 槽耗尽或检测瞬间的严格线性化发号验证;本修复保持既有检测策略。Performance 非本次退出路径修复的必需检查,CI 按现有规则跳过。
Rollback Plan
回退本 PR 增量并恢复前序 Transmite 镜像;无数据或协议回退。此举会恢复旧退出路径,是否部署回退由人工根据运行情况决定。
Stacked PR Dependencies
Dependency: #89 → #98 → #100 → #103 → #106 → #107
Final target version: 3.0-dev
Merge order: #89 → #98 → #100 → #103 → #106 → #107 → 本 PR;均由人工审查决定。
After predecessor merge: 同步开发线并确认祖先关系,保持 3.0-dev 目标,不重写共享历史。
Full-diff Self-review
Base and range: origin/3.0-dev...HEAD;本轮增量 fb2bb88...HEAD。
Verdict: 本轮七文件增量复核了全进程 fencing、固定无敏感信息诊断、故障前恢复登记、精确原进程退出观察和四份 Skill 同步;前序堆叠内容继承 fb2bb88。无生成文件、凭据或无关清理。本轮必需检查已通过;保持 Draft,前序合入后的最终集成验证和合并由人工审查流程决定。
Agent Acknowledgements