fix(vloer): stop the whole process tree before capturing a candidate #184
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/vloer-stop-process-tree"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The relay worker signalled only the direct harness child, replied
stopped:true without waiting after SIGKILL, and did not track
/__vloer/exec subprocesses at all. Grandchildren and exec subprocesses
kept running after a stop or a cancelled request, so files could still
change while captureInPlace exported the candidate.
The worker now starts the harness and every exec subprocess in its own
process group. A stop sends SIGTERM to the group, SIGKILL after a grace
period, and replies stopped:true only once no live member of the group
remains (zombies excluded, read from /proc). Otherwise it replies
stopped:false, /__vloer/run refuses to start a new child, and
captureInPlace refuses the export as stop_unconfirmed. Exec groups are
stopped on request cancellation, on an optional timeoutMs (the warm
sandbox clone now passes one), when the leader exits, and when the
worker shuts down.
Harness and exec subprocesses run in their own process groups; stop sends TERM then KILL to the group and replies stopped:true only when /proc shows no live member (zombies ignored because the worker is PID 1). Known limits: a grandchild that calls setsid() (e.g. git's auto-gc daemon) escapes the group; orphaned zombies accumulate because the image has no init (tini would fix that, an image change).
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1743
🤖 Generated with Claude Code