fix: reconcile stopped Codex runtime cleanup (#101) - #186
Conversation
Replace the unbounded TERM-resistant busy loop with a blocking sleep loop so the fixture no longer competes for the scheduler inside the fixed 300 ms cleanup window. The TERM resistance, SIGKILL escalation, parent-reap marker, ownership retirement, and process-group assertions remain unchanged.
#101 v6 implementation and audit evidenceExact head:
The literal canonical tracer command is intentionally sequenced after integration through rebased #104 v6. This target predates #104's accepted separation of native-picker dismissal from the 100 ms Keiko projection metric; on the current pre-#104 target it fails only the superseded mixed timing evidence. No #101-scope change can or should alter that harness. After this child integrates, #104 v6 will be rebased and its exact packaged/canonical acceptance rerun before the epic is handed off. |
Emit the readiness handshake from the descendant only after it installs the TERM-resistant trap. This removes the fixture startup race while preserving the fixed cleanup deadline and the existing SIGKILL, parent-reap, ownership, and process-group assertions.
Post-failure exact-head evidence —
|
Block the synchronized TERM-resistant descendant in the shell's built-in read on a Rust-owned open pipe. This keeps one stable descendant for the fixed cleanup window instead of repeatedly spawning sleep children between ownership refresh and SIGKILL.
Explicitly redirect the background TERM-resistant shell from fd0 so POSIX non-interactive shell semantics cannot replace its piped stdin with /dev/null. The built-in read now blocks without CPU churn while preserving the fixed cleanup lifecycle proof.
Final fixture candidate —
|
Classify the four existing cleanup predicates only when the fixture would fail, reconcile test-owned resources, and emit one bounded body-free K101 flag directly to stderr before exiting nonzero. Passing runs still execute every original assertion unchanged.
Emit the four existing cleanup predicates unconditionally to direct stderr before the unchanged assertions. This preserves the sanitized failure signal without adding failure-only cleanup branches or changing fixture semantics.
|
Temporary authoritative-run diagnostic at |
|
Authoritative diagnosis captured at temporary head |
Final #101 v6 candidate —
|
v6 stop condition reached; #101 replanned as accepted v7Final v6 head Issue #101 has therefore been semantically replanned as contract v7 with accepted fingerprint
The PR remains draft and its prior v6 receipts are intentionally stale. Implementation resumes only under the accepted v7 authority; no #104 or #49 scope is included. |
Reap the proven-stopped direct child and revalidate process-group and authenticated-owned absence before retiring ownership. Keep the fixed readiness budget focused on zero residue while proving descendant-first kill and parent wait semantics under a separate test-owned deadline.
Bind final reconciliation and retirement to the exact active process identity so a mismatched or reused process group cannot be reaped or cleared as success. Preserve retained ownership on failure and prove later recovery after an already-reaped group becomes absent.
Emit one bounded failure-only stage code from the flaky readiness cleanup proof so authoritative runners can distinguish deadline exhaustion, process observation, direct-child wait, and exact-identity retirement without exposing process identifiers or content.
Remove the temporary stage flags after the authoritative F001 capture confirmed readiness final-phase starvation. The signed diagnostic commit remains in history as bounded failure-first evidence.
Select an explicit readiness-only descendant phase that sends authenticated descendant KILL before proceeding directly to group KILL, reserving the remaining fixed 300 ms budget for zero-residue reconciliation. Turn cleanup and default parent-reap grace remain unchanged.
Final exact-head evidence —
|
|
@codex review |
|
@codex review Review exact head |
|
@codex review |
Dedicated Codex review — exact head
|
Scope
v7codex/101-cleanup-fixture-v6epic/98-codex-tracerdefect31297856180retainedK101:C0A0M0G1on macOS 14 and 26, proving the absent process group was not reconciled into a successful reap and ownership retirementnative/crates/keiko-host-macos/src/runtime.rskeiko-host-macos; authenticated process identity, direct-child reap proof, and ownership retirement remain fail closedProduct and architecture alignment
semantic planning change was absorbed during implementation.
CONTEXT.md, accepted ADRs, and the issue QualityPlan.
why Existing Keiko evidence is not applicable.
Keiko.
layer.
Acceptance criteria and evidence
Evidence must identify the exact file, test, command, artifact, or platform result. Do not mark a
row complete from intention or a processing badge.
24d87e94dfcd6dbafda7a908d3443c1e9139fde3K101R:F001proved group KILL occurred after the deadline; the phase-policy regression failed before the correction and passes after it24d87e94dfcd6dbafda7a908d3443c1e9139fde324d87e94dfcd6dbafda7a908d3443c1e9139fde324d87e94dfcd6dbafda7a908d3443c1e9139fde3Acceptance journey evidence
Complete for user-facing work. Otherwise state
Not applicablewith the issue rationale and removethe placeholder data row. Evidence records what ran; the issue remains the source for expected
behavior.
Applicability:
Not applicable — non-user-facing runtime cleanup defect; parent J1 behavior is unchanged and covered by runtime and packaged gates.Automated checks exercise user-visible outcomes rather than incidental implementation
details.
Required failure, recovery, accessibility, visual, and platform observations are settled.
Quality Plan settlement
covered.
attached or linked.
tests, logs, evidence, artifacts, issues, and this pull request.
Verification
npm ci --ignore-scriptsnpm run qualitynpm audit --audit-level=highmodes.
Additional affected checks and concise results:
Independent audit and findings
24d87e94dfcd6dbafda7a908d3443c1e9139fde392bd7d7; authoritativeF001at diagnostic head98ee30424d87e94dfcd6dbafda7a908d3443c1e9139fde3; independent re-audit findings=0a scoped follow-up that does not invalidate current acceptance.
Integrated epic acceptance
Complete when this PR delivers or changes an epic's integrated acceptance surface; otherwise state
Not applicablewith rationale.Not applicable — #101 proves owning runtime cleanup; rebased #104 owns final canonical tracer requalification on the integrated epic head.31317318841attempt 2 greenDelivery
child issue -> epic branchpush, gate bypass, finding dismissal, or authority widening occurred.
producer.
policy.
Ready for Human Reviewbefore every requiredAcceptance Journey result and exact-head gate was complete.
For a child-issue pull request targeting its designated epic branch:
blocking finding or review conversation remains.
This child pull request does not target
dev; the epic delivery remains human-only.Residual risks and follow-ups