fix: grok socket guard, lock reaper race, companion perf (0.0.62) - #69
Merged
Merged
Conversation
…aper claims survive teardown
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes #57
closes #62
closes #64
closes #66
closes #68
summary
curl --unix-socket ~/.orbstack/run/docker.sock http://localhost/_pingreturnedOK: orbstack's non-admin socket is missing from upstream's deny list and the macos strict profile allows network-outbound. a managed write run now fails assandboxbefore spawn while that socket exists; consult and review proceed, and/grok:setupreportswriteReady: false. codex's sandbox blocks the same connect (curl exit 7)ENOENTcounted as a lost race. claims now live beside the lock, and every teardown error is a lost race. the concurrent reapers case failed 3 of 100 loaded runs before and passes 100 of 100 after, in each pluginreserveWorkspaceresolving the workspace root with agitspawn per job record under the workspace lock (17.1s of a 17.7s run at 600 records), not the flagship stat. git probes are cached briefly and the own identity and boot marker once per process (grok mirrors the identity cache). at 600 records atask --writewent from 6260ms, 32psand 612gitspawns to 544ms, 8 and 2kill(pid, 0)while its identity read as gone, so waiters never reclaimed the lock. a zombie owner now counts as dead, proven both sides with a linux regression test. theinherited-pipecase now gets a 2000ms budget instead of 50ms, the fake grok leaves the companion 5000ms instead of 1000ms to kill it after a warning, flaky: grok-state-lock 'concurrent reapers serialize after a lock owner is killed' fails under load #62 covers the grok case, and a linux case was already fixed by 0.0.60. the smoke engine probes take their model from the lane defaults and pass--cwdtest plan
already verified
npm test-> 1316 tests, 1315 pass, 0 fail, 1 skippednpm testwith one busy loop per core, three rounds -> 0 failures each (166 to 178s; at 0.0.61codex-companion.test.mjsalone was still running after 200s)npm testtask --write --model gpt-6-astraagainst the fake codex with 0, 100 and 600 seeded records -> 381, 429 and 544ms, always 8psand 2gitspawnsOK), codex's sandbox does not (curl exit 7)claude plugin validateon plugins/codex, plugins/grok, plugins/fusion and the marketplace root -> all passreviewer should verify
/grok:setup --jsonshowsready: trueandwriteReady: false, a/grok:task --writefails assandboxbefore spawn, and a consult still answerstest (macos-latest, 22)stays green across repeated runs of this headnotes
test (macos-latest, 22)runs) is met on the final head bff6e03: ten consecutive attempts of its CI run passed every matrix job, 40 of 40, and the squash leaves main with the same tree