fix: distinguish exited Linux zombies from live owners - #1678
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and resulting behavior
Lifecycle grouping #1677 exposed real descendant shutdown failures on Linux containers without a reaping init. Positive
kill(pid, 0)includes exited zombies, but a zombie thread-group leader can also retain executing workers. Independent review additionally showed that a regex could backtrack into a legal comm (worker) Z 1 x) and treat an actual liveSstate as dead.The positive signal probe now parses procfs fields only after comm's final
). It excludes onlystate=Zwithnum_threads=1. Linux retains the zombie leader in this count: a live worker makes it at least two; at the one-thread snapshot the sole remaining task is already exited and cannot create another worker. Multiple, missing or invalid counts stay live. No empty/unreadable/racing task-directory scan grants exit: no task scan is used. Permission failures remain live; ESRCH and invalid-PID/range errors remain absent. Signal order, saved descendant PIDs and shutdown budgets are unchanged.Reviewable evidence
8676b8c6: adversarial live names and zombie leaders with workers/unknown counts. Both require live roots still reaching TERM/KILL and reporting survivors. Existing positive states, procfs/permission errors and invalid PIDs remain covered.Z, count2, workerS, output continues after TERM. Old controller returned false; corrected controller stays true, executes TERM then KILL, and the managed parent reaps the subprocess in finally.cc -pthreadis a local diagnostic only, not a cross-platform test dependency. Source/logs are preserved with the local validation evidence.Validation
pnpm test:system:guardianpassed healthy conflict/graceful takeover, crashed-lock recovery and stubborn forced takeover, including actualpnpm devconflict path.The original review validation is recorded below; subsequent integration and authorized merge are recorded at the end.
Final-head CI after independent review
Head
eca2c0c16bb2e521158bf01d34ffc8fcca3a6fab: Dev PR Clean Build 36777830189 completed successfully, including workflow contracts, whole critical gate, receipt upload and complete workspace build. Receipt artifact ID11127055678is associated with this exact head. The earlier full-suite and native/platform limitations remain explicit. No release.Authorized integration and merge
After #1677 merged as
a8d2850152481f108ee76bef76ca753270382898, dev merged cleanly into this feature with no documentation conflict. Integration head2fd161147f58cc5b36fdbd74ce44b4c654b2db7dpassed workflow contracts (12 files/108), startup + desktop selections (11 files/157), Guardian selection (6 files/67), and the whole critical gate (18 required tests). Exact-head Dev PR Clean Build 36797510698 succeeded, including complete workspace build and critical-local-receipt artifact11133814770tied to that exact SHA.With explicit maintainer merge authorization, normal merge used the expected-head SHA guard and produced
0a10220d7c918f7f6b6590fff0135c6d6b45d587. Fetched dev confirms both parents and the same tested source tree. No bypass, force push, or release. PTY, installer fixture and independent Desktop smoke failures remain separate diagnosis work; this merge does not claim their acceptance.