Skip to content

feat: own runtime process trees with a host-leased supervisor - #15

Merged
skevetter merged 3 commits into
mainfrom
codex/runtime-owned-supervisor
Oct 3, 2026
Merged

skevetter merged 3 commits into
mainfrom
codex/runtime-owned-supervisor

Conversation

@skevetter

@skevetter skevetter commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Plain go-plugin transport leaves a runtime child alive after plugin death and leaves the plugin alive after host death. Add an opt-in SDK runner and dedicated supervisor so an independent owner terminates the plugin, child, and grandchild when the host lease closes, the plugin exits, startup times out, or the client explicitly closes.

The supervisor inherits a host-lifetime pipe and forwards the existing handshake and diagnostics. Configuration stays on an inherited pipe and preserves Unix argument/environment bytes. Runtime environment inheritance remains the default; client-assigned transport metadata takes precedence over provider overrides. Buffered diagnostics survive reaping.

Linux and macOS use an isolated plugin process group, keeping its leader unreaped until group termination prevents PID reuse. Linux also adopts and reaps orphan descendants. On Windows, the supervisor joins a kill-on-close Job Object before creating the runtime, so descendants inherit ownership without a post-spawn assignment race.

This is a bounded process-ownership follow-up to #14. Existing plain-transport probes remain as baseline evidence. Unix descendants must stay in the owned process group and retain signalable privileges; detached sessions, elevated commands, and independently managed runtime services require their own owner. Executable verification remains the host's responsibility. No pooling policy or main Devsy adapter integration is introduced here.

Validation:

  • Full local race tests and vet passed on macOS.
  • Pre-commit, strict lint, formatting, and diff checks passed.
  • CI passed on Linux, macOS, and Windows: race tests, vet, spawn probes, generated bindings, Lint, and Pre-commit. Uploaded reports confirm all four ownership regressions and the supervisor tests passed on each OS.
  • Local CodeRabbit reviewed all 16 changed files with zero findings.
  • Release Please is intentionally skipped on pull requests; release automation runs after merge to main.
  • Real-process regressions cover abrupt host/plugin death, uncooperative child and grandchild cleanup, handshake timeout, configuration preservation, and diagnostic draining.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 527bd7b5-ede4-4bb1-92be-1d1bc52e1db2
📥 Commits

Reviewing files that changed from the base of the PR and between 076712a and 293c64b.

📒 Files selected for processing (16)
  • README.md
  • cmd/devsy-runtime-supervisor/main.go
  • go.mod
  • internal/processfixture/client.go
  • internal/processfixture/descendant.go
  • internal/processfixture/main.go
  • internal/processfixture/observer.go
  • internal/processprobe/owned_test.go
  • supervisor/exit_darwin.go
  • supervisor/exit_linux.go
  • supervisor/main.go
  • supervisor/runner.go
  • supervisor/runner_test.go
  • supervisor/tree_other.go
  • supervisor/tree_unix.go
  • supervisor/tree_windows.go
✨ Finishing Touches
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@skevetter
skevetter marked this pull request as ready for review October 3, 2026 17:04
@skevetter
skevetter merged commit 2df05ac into main Oct 3, 2026
10 of 11 checks passed
@skevetter
skevetter deleted the codex/runtime-owned-supervisor branch October 3, 2026 17:04
@devsy-app devsy-app Bot mentioned this pull request Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant