Skip to content

test(harness): same-handle gate proof, live fault fixtures, launcher receipts - #2686

Merged
chaliy merged 21 commits into
mainfrom
codex/syntax-diagnostic-budget
Oct 11, 2026
Merged

chaliy merged 21 commits into
mainfrom
codex/syntax-diagnostic-budget

Conversation

@chaliy

@chaliy chaliy commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

What changed

Test-only, one file: threat_model_tests.rs. Closes the completion review on #2685 without touching #2681 distinct run_bounded_probe helper:

  • join_finished returns the unfinished handle, so the paused-after-send proof releases and joins THAT SAME thread through the actual gate primitive (bounded readiness, release, finite join cleanup, elapsed watchdog). No twin thread, no detached-while-asserting-cleanup.
  • Poll-fault fixture uses a direct-exec sleeper: the shell replaces itself, so killing closes the pipes at once with no orphan and no 30s descendant.
  • reap_never keeps the real bounded OS cleanup while only the observation is discarded for the verdict: no zombies by construction, no invented exit/reap success.
  • Retained-pipe fixture runs under the fail-closed launcher; because incomplete pipe capture precludes the stderr readback by design, the effective bounds are proven through a per-process receipt file the fixture shell writes before parking the sleeper (removed afterwards). Existing fixture reused and strengthened, never duplicated.
  • Prior review debt acknowledged: test(harness): join completion gate, fault seams, launcher-bound selftests #2684 merged on formal reviews alone while the completion comment was unresolved; this followup resolves it before any merge.

Before / After

Before: twin-thread gate proof; forked sleeper orphan in the poll fixture; reap skipped under fault; no launcher proof on the retained fixture.
After: threat_model 222 passed (only pre-existing macOS nesting abort skipped, identical on unmodified code); error 14, partial_parse 11 green; fmt plus clippy -D warnings clean.

Risk

  • Test-only change. No production code touched.

Checklist

  • Tests added or updated
  • Backward compatibility considered (internal test harness)

Update: readiness gating, reaped receipt, launcher receipts

Follow-up commits on the same branch add:

  • fail_poll fires only after a readiness file proves the victim truly live under bounds (direct-exec sleeper, no orphan); readiness itself is asserted alongside the reaped receipt, cap readback, and elapsed bound.
  • BoundedRun gains a reaped receipt: OS termination accounted for, orthogonal to exit_code and to injected observation faults (which discard the observation, never the cleanup). reap_never asserts real cleanup ran alongside its discarded verdict.
  • Retained-pipe fixture runs under the fail-closed launcher; because incomplete pipe capture precludes the stderr readback by design, the effective stack/cpu bounds are proven through a per-process receipt file the fixture shell writes before parking the sleeper (removed afterwards).

chaliy added 18 commits October 10, 2026 21:58
macOS bash 3.2 reports -c input as line 0, modern GNU bash as line 1.
Compare diagnostic shape with line number normalized.
…gression

A long -c ARG0 stamped on every report line could evict the structural
payload out of the 1 KiB diagnostic budget. Truncate the shell name to 64
chars first so 'syntax error ...' always survives; renumber the threat entry
to TM-DOS-136 (main already owns 135 via #2674); add a bounded-child
regression exercising the exact finding shape (multiline token x long ARG0)
at two scales.
The 64-char cut mangled long script paths (breaking the oracle's path
replacement and hiding which script failed). Widen to 256 chars with a
16-char tail: realistic paths print verbatim with attribution suffixes
(': eval') intact, while a kilobyte-scale ARG0 still cannot evict the
structural payload out of the 1 KiB total. The total stays the enforced
bound.
All five branch commits already reached main via squash merges (#2675, #2677); conflicting files take main's reviewed state.
The scaled multiline-token x long-ARG0 regression now asserts the whole harness contract at both scales (200/2000 lines x 8 KiB ARG0): no watchdog timeout, raw child exit 2, no output-cap overshoot, finished reader threads, and effective stack=4096/cpu=10 caps read back from the launcher. Shape and 1 KiB assertions unchanged.
run_command_bounded cleanup per lifecycle review: truncate retention before extending (retention never passes the 8192 cap); retry Interrupted, fail closed with partial bytes on real reader errors (new read_error field, never relabeled as EOF); exact-cap EOF is not excess; reap inside a finite 5s grace, never an unbounded wait; timed_out retained as recorded; drain 2s + reap 5s graces documented against the execution deadline. Consumer regression gains !read_error and the corrected 8192-byte cap text. Bounded selftests: exact-cap, cap+1, Interrupted/error scripted pipes, timeout kill+reap, overflow flag.
Per lifecycle review on #2682: join readers only after all channel receipts (receipt proves all blocking work done; missing receipts skip the join and fail incomplete), with panicking readers failing visibly; reap extracted into a poll seam with deterministic verdict unit tests; timeout/overflow selftests run under the fail-closed launcher with stack/cpu readback and elapsed-total bounds; retained-pipe case gains elapsed proof and read_error distinction. Reuses existing bounded_helper_flags_retained_pipes; does not touch #2681's distinct probe helper.
…tests

Per completion review on #2683: join readers only while is_finished inside the shared completion grace (a receipt is not the termination contract); deterministic paused-after-send proof with release/cleanup watchdog; poll/read/reap faults injected through the real parent lifecycle with distinct fail-closed verdicts (no panicking expect on child poll); timeout/overflow selftests under the fail-closed launcher with cap readback and elapsed bounds; existing retained-pipe fixture reused and strengthened. Untouched: #2681 distinct probe helper.
…tests

Per completion review on #2683: join readers only while is_finished inside the shared completion grace (a receipt is not the termination contract); deterministic paused-after-send proof with release/cleanup watchdog; poll/read/reap faults injected through the real parent lifecycle with distinct fail-closed verdicts (no panicking expect on child poll); timeout/overflow selftests under the fail-closed launcher with cap readback and elapsed bounds; existing retained-pipe fixture reused and strengthened. Untouched: #2681 distinct probe helper.
… selftests

Per completion review on #2684: common cleanup termination funnels every loop exit through one reachable kill guard; bounded is_finished join gate with shared completion grace (receipt is not the termination contract); deterministic paused-after-send proof drives the actual gate with bounded readiness and release/cleanup watchdog; poll/read/reap faults injected through the real parent lifecycle with distinct fail-closed verdicts (no panicking child poll); selftests and retained-pipe fixture under the fail-closed launcher with cap readback and elapsed bounds. Reuses existing retained-pipe fixture; untouched: #2681 distinct probe helper.
…receipts

Per completion review on #2685: join_finished returns the unfinished handle so the paused-after-send proof releases and joins THAT SAME thread (no twin); poll-fault fixture uses direct-exec sleeper so killing closes the pipes with no orphan; reap_never keeps real bounded OS cleanup while the verdict reports None; retained-pipe fixture runs under the fail-closed launcher with a file side-channel receipt proving the effective bounds despite incomplete pipe capture. Reuses the existing retained-pipe fixture; untouched: #2681 distinct probe helper.
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
bashkit a73d8ed Commit Preview URL

Branch Preview URL
Oct 11 2026, 02:07 PM

@chaliy

chaliy commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

Review of PR2686 exact head7e549fdfbb6ac997a862497f4a8987eb77300af1. The same-handle Unfinished return/release/join now fixes the disconnected twin proof; preserve it. Direct-exec poll fixture and launcher-routed reap fixture are useful progress. This is not a claim of a reproduced hang or a new production defect.

Two requirements from full2685 review6108848597 remain unresolved before merge:

  1. bounded_helper_flags_retained_pipes still launches sleep30 in the background and returns in7s without terminating/observing that owned descendant or the retained reader threads. The new receipt proves effective CPU/stack for the fixture, but not controlled cleanup. Keep the existing incomplete verdict and same-runner test. Retain the descendant identity and original reader handles through a test-scoped cleanup mechanism (or equivalent controlled fixture), terminate and finitely observe completion of those actual owned resources after asserting the negative verdict, with cleanup receipts and total elapsed bound. Do not replace the negative flags with success or merely wait for the30s self-expiry. This does not require a universal portable process-tree reaper in production; it requires the test to clean up the resources it intentionally creates.

  2. The fail_poll flag fires on the first poll immediately after spawn, before any launcher readiness receipt is required. Therefore exec sleep30 may not yet have run, and this case still has no effective CPU/stack assertion or actual OS reap receipt separate from exit_code=None. Synchronize against a bounded fixture readiness/limit receipt for a truly live bounded victim, then inject the poll failure; assert the intended parent failure plus independently observed termination/reap. The reap_never test similarly must assert actual OS cleanup separately from its deliberately discarded observation. Preserve truthful None/incomplete/timed_out verdicts; no fake success.

Remove stale comments claiming retained fixture runs direct and forked poll sleeper remains orphaned. Local cargo|tail receipts are pipeline exits, not raw cargo exits;222filtered threat passes with misconfig skipped remain partial, not a Linux full-gate waiver. Read this entire issue comment and all formal/inline review threads, keep unchanged full Linux CI, execute foreground CI waits instead of ending with a no-tool Waiting-for-CI final, and obtain fresh exact-merge producer/assertion/build/root-report proof before finding closure. No forcepush, queue/DB/runtime edits, weaker tests or duplicate agents.

Per completion review on #2685: fail_poll fires only after a readiness file proves the victim truly live (direct-exec sleeper, no orphan); BoundedRun gains a reaped receipt separating actual OS cleanup from exit/observation verdicts; retained-pipe fixture runs under the fail-closed launcher with a file side-channel receipt proving the effective bounds despite incomplete pipe capture. Reuses the existing retained-pipe fixture; untouched: #2681 distinct probe helper.
The retained-pipe fixture routes through the fail-closed launcher with a file side-channel receipt; the leftover comment claiming a direct run contradicted the code. No behavior change.
…ture

The retained-pipe fixture retains its sleeper's PID through a receipt file, then terminates that exact descendant and finitely observes its completion (kill -0 absence polling inside a 5s bound) after asserting the negative verdict, with a total end-to-end elapsed bound. No waiting for the 30s self-expiry, no universal process-tree reaper, no change to the truthful incomplete flags.
@chaliy
chaliy merged commit 508967f into main Oct 11, 2026
33 checks passed
@chaliy
chaliy deleted the codex/syntax-diagnostic-budget branch October 11, 2026 14:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant