Skip to content

fix(core): reject execution waits when a VM is disposed - #2030

Draft
DevEverything01 wants to merge 2 commits into
rivet-dev:mainfrom
DevEverything01:fix/sdk-execution-disposal
Draft

DevEverything01 wants to merge 2 commits into
rivet-dev:mainfrom
DevEverything01:fix/sdk-execution-disposal

Conversation

@DevEverything01

@DevEverything01 DevEverything01 commented Oct 10, 2026 •

Copy link
Copy Markdown
  • Disposing a VM can leave SDK execution admission, completion, or result waits unresolved while the shared sidecar remains live.
  • Reject those waits and new execution waits with ERR_AGENTOS_VM_DISPOSED when disposal starts. Keep native teardown and its errors observable, preserve sibling VMs, and avoid reconciling an already-exited process through a disposed public wait.
  • Mirror shutdown behavior in the Rust SDK, including background language-process waits. Add a configurable bounded wait budget, typed capacity errors, near-capacity warnings, and documentation.
  • Add 11 TypeScript disposal cases covering every wait phase, busy retries, background waits, sibling isolation, and teardown races; add Rust guard tests and a real shared-sidecar lifecycle/capacity regression. Build, type checks, changed-file Biome, 108 Rust client contract cases, and secure-exec tests pass on macOS arm64. Full Core/Runtime Core lanes retain 8/1 failures also reproduced on clean main; publish-helper tests, global Biome, and workspace Clippy have main-baseline failures.

Related: shared sidecars #1531 and guest-fetch disposal #2014. This changes SDK wait settlement; shared-sidecar callback routing is prepared separately.

Also release the TypeScript shared-sidecar lease hold in a finally block when native VM disposal rejects. Preserve the disposal error and keep sibling VMs usable. A real subprocess regression injects a rejection after successful native cleanup, runs a sibling VM timer, and verifies that the host exits naturally after the final lease is disposed. Include both success and failure exit cases in the Core PR test lane. This closes SDK event-loop reference cleanup; it does not prove native cleanup after a real teardown failure. Validation ran on macOS arm64, not upstream Linux CI.

🤖 Generated with Claude Code

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant