Repository navigation
test(harness): same-handle gate proof, live fault fixtures, launcher receipts - #2686
Conversation
macOS bash 3.2 reports -c input as line 0, modern GNU bash as line 1. Compare diagnostic shape with line number normalized.
…gression A long -c ARG0 stamped on every report line could evict the structural payload out of the 1 KiB diagnostic budget. Truncate the shell name to 64 chars first so 'syntax error ...' always survives; renumber the threat entry to TM-DOS-136 (main already owns 135 via #2674); add a bounded-child regression exercising the exact finding shape (multiline token x long ARG0) at two scales.
The 64-char cut mangled long script paths (breaking the oracle's path
replacement and hiding which script failed). Widen to 256 chars with a
16-char tail: realistic paths print verbatim with attribution suffixes
(': eval') intact, while a kilobyte-scale ARG0 still cannot evict the
structural payload out of the 1 KiB total. The total stays the enforced
bound.
The scaled multiline-token x long-ARG0 regression now asserts the whole harness contract at both scales (200/2000 lines x 8 KiB ARG0): no watchdog timeout, raw child exit 2, no output-cap overshoot, finished reader threads, and effective stack=4096/cpu=10 caps read back from the launcher. Shape and 1 KiB assertions unchanged.
run_command_bounded cleanup per lifecycle review: truncate retention before extending (retention never passes the 8192 cap); retry Interrupted, fail closed with partial bytes on real reader errors (new read_error field, never relabeled as EOF); exact-cap EOF is not excess; reap inside a finite 5s grace, never an unbounded wait; timed_out retained as recorded; drain 2s + reap 5s graces documented against the execution deadline. Consumer regression gains !read_error and the corrected 8192-byte cap text. Bounded selftests: exact-cap, cap+1, Interrupted/error scripted pipes, timeout kill+reap, overflow flag.
Per lifecycle review on #2682: join readers only after all channel receipts (receipt proves all blocking work done; missing receipts skip the join and fail incomplete), with panicking readers failing visibly; reap extracted into a poll seam with deterministic verdict unit tests; timeout/overflow selftests run under the fail-closed launcher with stack/cpu readback and elapsed-total bounds; retained-pipe case gains elapsed proof and read_error distinction. Reuses existing bounded_helper_flags_retained_pipes; does not touch #2681's distinct probe helper.
…tests Per completion review on #2683: join readers only while is_finished inside the shared completion grace (a receipt is not the termination contract); deterministic paused-after-send proof with release/cleanup watchdog; poll/read/reap faults injected through the real parent lifecycle with distinct fail-closed verdicts (no panicking expect on child poll); timeout/overflow selftests under the fail-closed launcher with cap readback and elapsed bounds; existing retained-pipe fixture reused and strengthened. Untouched: #2681 distinct probe helper.
…tests Per completion review on #2683: join readers only while is_finished inside the shared completion grace (a receipt is not the termination contract); deterministic paused-after-send proof with release/cleanup watchdog; poll/read/reap faults injected through the real parent lifecycle with distinct fail-closed verdicts (no panicking expect on child poll); timeout/overflow selftests under the fail-closed launcher with cap readback and elapsed bounds; existing retained-pipe fixture reused and strengthened. Untouched: #2681 distinct probe helper.
… selftests Per completion review on #2684: common cleanup termination funnels every loop exit through one reachable kill guard; bounded is_finished join gate with shared completion grace (receipt is not the termination contract); deterministic paused-after-send proof drives the actual gate with bounded readiness and release/cleanup watchdog; poll/read/reap faults injected through the real parent lifecycle with distinct fail-closed verdicts (no panicking child poll); selftests and retained-pipe fixture under the fail-closed launcher with cap readback and elapsed bounds. Reuses existing retained-pipe fixture; untouched: #2681 distinct probe helper.
…receipts Per completion review on #2685: join_finished returns the unfinished handle so the paused-after-send proof releases and joins THAT SAME thread (no twin); poll-fault fixture uses direct-exec sleeper so killing closes the pipes with no orphan; reap_never keeps real bounded OS cleanup while the verdict reports None; retained-pipe fixture runs under the fail-closed launcher with a file side-channel receipt proving the effective bounds despite incomplete pipe capture. Reuses the existing retained-pipe fixture; untouched: #2681 distinct probe helper.
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
bashkit | a73d8ed | Commit Preview URL Branch Preview URL |
Oct 11 2026, 02:07 PM |
|
Review of PR2686 exact head7e549fdfbb6ac997a862497f4a8987eb77300af1. The same-handle Unfinished return/release/join now fixes the disconnected twin proof; preserve it. Direct-exec poll fixture and launcher-routed reap fixture are useful progress. This is not a claim of a reproduced hang or a new production defect. Two requirements from full2685 review6108848597 remain unresolved before merge:
Remove stale comments claiming retained fixture runs direct and forked poll sleeper remains orphaned. Local cargo|tail receipts are pipeline exits, not raw cargo exits;222filtered threat passes with misconfig skipped remain partial, not a Linux full-gate waiver. Read this entire issue comment and all formal/inline review threads, keep unchanged full Linux CI, execute foreground CI waits instead of ending with a no-tool Waiting-for-CI final, and obtain fresh exact-merge producer/assertion/build/root-report proof before finding closure. No forcepush, queue/DB/runtime edits, weaker tests or duplicate agents. |
Per completion review on #2685: fail_poll fires only after a readiness file proves the victim truly live (direct-exec sleeper, no orphan); BoundedRun gains a reaped receipt separating actual OS cleanup from exit/observation verdicts; retained-pipe fixture runs under the fail-closed launcher with a file side-channel receipt proving the effective bounds despite incomplete pipe capture. Reuses the existing retained-pipe fixture; untouched: #2681 distinct probe helper.
The retained-pipe fixture routes through the fail-closed launcher with a file side-channel receipt; the leftover comment claiming a direct run contradicted the code. No behavior change.
…ture The retained-pipe fixture retains its sleeper's PID through a receipt file, then terminates that exact descendant and finitely observes its completion (kill -0 absence polling inside a 5s bound) after asserting the negative verdict, with a total end-to-end elapsed bound. No waiting for the 30s self-expiry, no universal process-tree reaper, no change to the truthful incomplete flags.
What changed
Test-only, one file: threat_model_tests.rs. Closes the completion review on #2685 without touching #2681 distinct run_bounded_probe helper:
Before / After
Before: twin-thread gate proof; forked sleeper orphan in the poll fixture; reap skipped under fault; no launcher proof on the retained fixture.
After: threat_model 222 passed (only pre-existing macOS nesting abort skipped, identical on unmodified code); error 14, partial_parse 11 green; fmt plus clippy -D warnings clean.
Risk
Checklist
Update: readiness gating, reaped receipt, launcher receipts
Follow-up commits on the same branch add: