Skip to content

Run a process broker per agent-host view - #371

Merged
SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/agenthost-broker
Oct 1, 2026
Merged

SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/agenthost-broker

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Plan row 9c, PR A (lane L5r, briefs/l5r-broker-cgroup.md). The agent host runs one process broker per view, so a Harness's shims run their programs in the sandbox. It also fixes the sessionview.Start hang that #348 names as a residual.

agenthost

  • One broker per view. own starts a processbroker with View.Relay() after sessionview.Start. The view's end path closes it after Wait and before the slot is released. The processBroker seam and the Session-level broker are gone.
  • Broker config:
    • Executables maps each shim name and shim path to itself.
    • Environment is the view's ForwardEnv plus the Session's Sandbox and Tool values.
    • CancelGrace is the launch's kill timeout.
    • Dial opens a Process stream on the Session's attachment.
    • Scope is the strongest scope the Process service declares (ScopeCgroupV2, then ScopePOSIXSession), read with Describe before each launch whose view declares shims. If neither is declared, the Session fails with ErrProcessBroker.
  • Relay loss. When the broker's Done fires while the view runs, the watcher sends the view Signal(0). A delivered signal means the relay was lost while the Harness ran, and the Session fails with ErrProcessBroker wrapping processbroker.ErrRelayLost. A failed signal means the view is already ending, because sessionview ends the relay connection only in its teardown. Wait then reports how.
  • Admission. A view that declares shim names needs PATH in the Environment's Sandbox or Tool values. Without it, admission rejects the Session with ErrInvalidSession, before any effect.
  • Incomplete teardown. sessionview.ErrCleanup from Start or Wait fails the Session as ErrTeardown. Teardown then keeps the Session directory and uid, as a failed Executor.Close already does, because the view's processes may still run.

sessionview

  • Start hang. A launcher killed while it waits on a FUSE request that the world already read cannot exit. It keeps its end of the control socket open, so the handshake could wait forever.
  • Fix. When Start's context ends, Start kills the launcher and also shuts the daemon's end of the control socket. The handshake returns at once, and the existing abort teardown stops the world, which answers the pending request. Start returns within its teardown bound even if the world never answers.

Checks

  • go build ./... and go vet ./....
  • The darwin and windows builds of ./apps/... ./internal/.... The windows build failure in services/core predates this branch.
  • go test -race -count=1 on agenthost, sessionview and processbroker.
  • Privileged suites:
    • OAC_TEST_AGENTHOST=1: all tests pass, including two new subtests. In one, a command run through the shim in the sandbox gives the Harness 42 and exit code 3. In the other, killing the relay fails the Session with ErrRelayLost.
    • OAC_TEST_SESSIONVIEW=1: all 8 tests pass, including TestCancelledStartStopsTheWorld, which fails without the fix.
    • The processbroker view suite passes.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit 74605ec into feature/agent-outside-sandbox Oct 1, 2026
2 checks passed
@SaladDay
SaladDay deleted the aos/agenthost-broker branch October 1, 2026 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant