Skip to content

Reap orphaned workers without weakening fleet shutdown - #7

Merged
philcunliffe merged 1 commit into
mainfrom
codex/reap-orphan-processes
Sep 11, 2026
Merged

philcunliffe merged 1 commit into
mainfrom
codex/reap-orphan-processes

Conversation

@philcunliffe

Copy link
Copy Markdown
Collaborator

Long-running loops accumulated thousands of zombies because the Node safety controller ran as PID 1 without reaping adopted worker descendants. Package tini as PID 1 and run the controller as its direct child, retaining whole-container termination when the controller exits or crashes. Reject unmanaged startup and a second external init. LLP 0076 extends the existing PID 1 requirement without changing admission limits or operator holds.

Validation: 295 unit tests and typecheck pass. The local Docker smoke uses fake services and proves orphan reaping, bounded recovery, persistent holds, detached-worker termination, and fail-closed startup. The new orphan check fails against the previous implementation and passes with this change. CPU/memory review found no unbounded polling or allocation added; tini reaps on child exit.

The production fleet remains stopped with automatic restart disabled. This PR does not deploy or restart it.

@philcunliffe
philcunliffe marked this pull request as ready for review September 11, 2026 21:04
@philcunliffe
philcunliffe merged commit 9cf2b97 into main Sep 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant