Repository navigation
fix(runner): sweep detached exec sessions when an agent stops (RIG-4708) - #1805
Merged
trunk-io[bot] merged 3 commits intoOct 7, 2026
Conversation
The stop wrapper kills the exec process group, but SDK and shell children that called setsid escape it. Stop and Reload now run an optional backend sweep, as the agent uid, that kills every process outside PID 1 session, keeping the container keep-alive. Stop logs a sweep failure; Reload returns it so a relaunch never runs beside survivors. Co-authored-by: Matt Wilkinson <matt@rigel.build>
…IG-4708) The sweep now waits between rounds (10s bound), so a large process still exiting is not a failure. It reads whole stat files so a crafted comm cannot fake its session. A failed Reload sweep marks the session ERRORED. RefreshSecrets takes the container lock so a sweep cannot kill its execs. Co-authored-by: Matt Wilkinson <matt@rigel.build>
… (RIG-4708) Co-authored-by: Matt Wilkinson <matt@rigel.build>
|
Compass engineering docs preview: https://compass-agent-rig-4708-stop.compass-eng-docs.pages.dev Deployed from |
rigel-mintaka
marked this pull request as ready for review
October 6, 2026 20:39
mattwilkinsonn
added this pull request to stack #1819
October 7, 2026 00:17
mattwilkinsonn
approved these changes
Oct 7, 2026
Contributor
|
/trunk merge |
|
😎 Stack merged successfully - details. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR is part of a stack containing 2 PRs:
mainSummary
setsidescape it: shell commands run without a tty, and SDK-spawned MCP servers, debug adapters and eval kernels.runtime.SessionSweeper, implemented byPodmanCLIandAppleContainerCLI. As the agent uid, it runs a POSIX sh/procsweep that SIGKILLs every non-zombie process outside PID 1's session (and outside its own). It rescans every 100 ms until none remain, with a 10 s bound.statfiles and parses after the last), so a crafted comm cannot fake its session.agentHost.Stopsweeps after stopping the stream and logs a failure. Reload sweeps before relaunch; on failure it marks the session ERRORED and returns the error. Remove is unchanged.RefreshSecretsnow takes the container lock around the secret install and re-checks the session, so a sweep cannot kill its execs and a stale refresh cannot overwrite a newer session's secrets.Stacked on #1791.
Verification
go test ./internal/runtime/... ./internal/runner/...: pass.-race ./internal/runner/: pass.TestExecStreamingStopSweepsDetachedSession(podman, real agent image) runs a detached bun holding 300 MiB. It passes-count=5together with the existing exec-stop tests. With the kill removed, it fails. With the earlier no-wait sweep, it failed 1 of 3 runs.TestReloadSweepFailureMarksErrored: reported READY before the markErrored fix, and passes after it.TestStopAndReloadSweepExecSessionschecks the workload id and uid on both paths.).Risks
Compatibility
Documentation
Refs RIG-4708