Files
orca/src/main/opencode/opencode-session-binder.ts
T
Jinwoo Hong b06f40f3ba fix(opencode): read the binder's session store off the main thread; ship the reader worker in orcad (#24638)
* fix(opencode): read the binder's session store on the foreign SQLite reader worker (STA-9122)

Before: the OpenCode session binder listed new sessions from opencode.db with
node:sqlite on the main thread every 60 s (and on SessionStart kicks), so a
large or contended store could stall the app the same way Cursor's did.

After: the read is a pure openCodeBinderSessions reader in
foreign-sqlite-readers/readers/, run only on the worker. The binder's
correlation, pane snapshot and process sweep stay where they were.

- The binder round awaits listSessions and re-checks its generation right
  after, so a stop() during the read discards the round before it touches the
  unbound map or the watermark.
- The client's in-flight dedupe key now includes the cursor, so a stale round
  from before a restart cannot hand its rows to the restarted round.
- Idle teardown is per reader. The binder lane keeps its thread for 120 s,
  longer than its 60 s poll, so the thread is not respawned every round.
- A timeout, crash, malformed reply or unstartable worker resolves to [] (no
  sessions), the value the old read already returned on failure.
- An absent store still reads as [] without a log line, and a permission or
  corrupt-file failure still logs (kept from #24577, now in the reader: it
  stats the path and throws anything but ENOENT/ENOTDIR to the client's log).
- The binder lane inherits #24572's limits from the shared lane: no respawn
  until a timed-out worker has exited, 2 consecutive deaths, a queue cap of
  8. Its timeout stays 60 s, matching its poll.
- dispatch switches on the destructured kind, so a new kind without a case
  still fails to compile.

orcad: the hook server runs there too, so orcad now ships
foreign-sqlite-reader-entry.js beside orcad.js (ORCAD_ARTIFACTS, built as an
orcad child). build-orcad runs a smoke check that starts the built worker
under the build's Node and under the pinned runtime, and does a real binder
read on a fixture DB, a Cursor read of a missing file and an OpenCode history
list. The OpenCode history scanner uses the same entry and was bundled into
orcad without it, so on orcad it always failed closed; it can now run.

Tests: reader (cursor, same-ms ids, OpenCode 2 rows, missing then created,
corrupt, inaccessible directory), retirement gate for the binder lane, dispatch
routing, client lane (rows, failure -> [], dedupe per cursor, own thread, idle
teardown default and override), binder loop with an async listSessions
(failure -> [], stop during the read), orcad path resolution through orcad's
host adapters, artifact list, and the smoke check against good, missing and
non-reading entries.

* test(opencode): cover the binder read deadline with fake timers and name the failure test accurately (STA-9122)
2026-10-02 19:58:29 -04:00

261 lines
9.0 KiB
TypeScript

import { resolveOpenCodeDataDirectory } from './opencode-data-directory'
import {
bindOpenCodeSession,
type OpenCodeSessionBinding
} from '../../shared/agent-hook-listener/opencode-session-registry'
import {
correlateOpenCodeSessionOwners,
type CorrelatedClient,
type CorrelatedPane,
type CorrelatedSession,
type SessionOwnership
} from '../../shared/agent-hook-listener/opencode-session-correlation'
import type {
BinderSessionRow,
OpenCodeSessionCursor
} from '../foreign-sqlite-readers/opencode-binder-sessions-result'
import { splitWorktreeIdForFilesystem } from '../../shared/worktree/id'
import { listRegisteredPtys } from '../memory/pty-registry'
import { isOpenCodeClientProcess, type ProcessIdentityRow } from './opencode-client-sweep'
import type { HookListenerState } from '../../shared/agent-hook-listener/listener-state'
/**
* Main-process binder feeding the session→pane registry (#21359), for OpenCode 1
* `serve` + `attach` only (see isOpenCodeSharedServerPost).
*
* Each round: read new sessions from the shared server's SQLite store,
* snapshot panes, sweep for live clients, correlate, bind. Everything the
* round needs is injected so the decision core stays unit-testable; the
* store read runs on the foreign SQLite reader worker
* (foreign-sqlite-readers/readers/opencode-binder-sessions.ts).
*/
/** One pane snapshot feeding a binder round. */
export type BinderPaneSnapshot = {
paneKey: string
/** Worktree root backing the pane (null when unknown); sessions beneath it are candidates. */
directory: string | null
worktreeId: string | null
shellPid: number | null
}
/** Everything one binder round needs, injected for tests. */
export type BinderRoundDeps = {
nowMs: number
sessions: readonly BinderSessionRow[]
panes: readonly BinderPaneSnapshot[]
processes: readonly ProcessIdentityRow[]
knownOwners: ReadonlyMap<string, string>
parentBySessionId: ReadonlyMap<string, string | null>
}
/** Ownership decisions from one binder round. */
export type BinderRoundResult = {
ownerships: SessionOwnership[]
}
/** Cursor before anything was ever read. */
export const OPENCODE_SESSION_CURSOR_START: OpenCodeSessionCursor = { ms: 0, id: '' }
/** Order cursors the way the store lists rows: oldest first, id as tiebreak. */
function compareSessionRows(left: OpenCodeSessionCursor, right: OpenCodeSessionCursor): number {
return left.ms - right.ms || (left.id < right.id ? -1 : left.id > right.id ? 1 : 0)
}
/**
* Advance the store cursor past handled rows only. `fresh` arrives in store
* order; handling is prefix-closed (the unbound-cap break only ever skips the
* tail), so the first unhandled row freezes the cursor and every row at or
* past it is re-listed next round instead of silently dropped.
*/
export function advanceBinderCursor(args: {
fresh: readonly BinderSessionRow[]
isHandled: (sessionId: string) => boolean
current: OpenCodeSessionCursor
}): OpenCodeSessionCursor {
let cursor = args.current
for (const session of args.fresh) {
if (!args.isHandled(session.id)) {
break
}
const candidate: OpenCodeSessionCursor = { ms: session.createdAtMs, id: session.id }
if (compareSessionRows(candidate, cursor) > 0) {
cursor = candidate
}
}
return cursor
}
/** pid→ppid index for one sweep; first row wins on duplicate pids. */
function childrenIndex(processes: readonly ProcessIdentityRow[]): Map<number, number> {
const ppidByPid = new Map<number, number>()
for (const row of processes) {
if (!ppidByPid.has(row.pid)) {
ppidByPid.set(row.pid, row.ppid)
}
}
return ppidByPid
}
/** Nearest pane shell at or above this pid; external terminals stay unattributed. */
function owningPane(
ppidByPid: Map<number, number>,
shellPidByPid: Map<number, string>,
pid: number
): string | null {
const seen = new Set<number>()
let current: number | undefined = pid
while (current !== undefined && !seen.has(current)) {
seen.add(current)
const owner = shellPidByPid.get(current)
if (owner) {
return owner
}
current = ppidByPid.get(current)
}
return null
}
/** Attribute opencode client rows to panes via shell-subtree walks. */
function toCorrelatedClients(
processes: readonly ProcessIdentityRow[],
panes: readonly BinderPaneSnapshot[],
nowMs: number
): CorrelatedClient[] {
const ppidByPid = childrenIndex(processes)
const shellPidByPid = new Map<number, string>()
for (const pane of panes) {
if (pane.shellPid !== null && !shellPidByPid.has(pane.shellPid)) {
shellPidByPid.set(pane.shellPid, pane.paneKey)
}
}
const clients: CorrelatedClient[] = []
for (const row of processes) {
if (!isOpenCodeClientProcess(row)) {
continue
}
const paneKey = owningPane(ppidByPid, shellPidByPid, row.pid)
if (!paneKey) {
continue
}
// Why lastSeenAlive = now: the sweep just observed it. Bracketing uses
// startedAt for the lower bound and this observation for the upper.
clients.push({ paneKey, startedAtMs: row.startedAtMs, lastSeenAliveMs: nowMs, argv: row.argv })
}
return clients
}
/** Pure round core: correlate unbound sessions against panes and clients. */
export function runOpenCodeBinderRound(deps: BinderRoundDeps): BinderRoundResult {
// Why dedupe by key, newest wins: remints and reattachments can leave a
// stale registry row beside the live one; counting rows instead of panes
// would turn every same-pane tie into a false ambiguous and nothing would
// ever bind, while the oldest row would point the candidate set at a dead
// worktree.
const paneByKey = new Map<string, CorrelatedPane>()
for (const pane of deps.panes) {
paneByKey.set(pane.paneKey, { paneKey: pane.paneKey, directory: pane.directory })
}
const panes = [...paneByKey.values()]
const clients = toCorrelatedClients(deps.processes, deps.panes, deps.nowMs)
const sessions: CorrelatedSession[] = deps.sessions.map((row) => ({
id: row.id,
directory: row.directory,
createdAtMs: row.createdAtMs,
parentId: row.parentId
}))
// Why resolve inheritance here: the SQLite round only carries new rows, so
// an old root is invisible to the correlator; the binder's parent map walks
// the chain and the registry supplies the known root owner. Resolved heirs
// are emitted as binds (the registry lacks them) and fed back as known so
// the correlator skips what is already decided.
const knownOwners = new Map(deps.knownOwners)
const inherited: SessionOwnership[] = []
for (const session of sessions) {
if (knownOwners.has(session.id) || !session.parentId) {
continue
}
let parent: string | null | undefined = session.parentId
const seen = new Set<string>([session.id])
while (parent && !seen.has(parent)) {
seen.add(parent)
const owner = knownOwners.get(parent)
if (owner) {
knownOwners.set(session.id, owner)
inherited.push({ sessionId: session.id, paneKey: owner, basis: 'creation-correlation' })
break
}
parent = deps.parentBySessionId.get(parent)
}
}
const ownerships = [
...inherited,
...correlateOpenCodeSessionOwners({
sessions,
panes,
clients,
knownOwners
})
]
return { ownerships }
}
/** Default database path for the local shared server. */
export function defaultOpenCodeDbPath(): string {
return `${resolveOpenCodeDataDirectory()}/opencode.db`
}
/**
* Live local panes from the PTY registry: pane key, worktree root and shell
* pid. Panes without a key or pid (hydrated gaps, remote panes) cannot own a
* client subtree, so they are skipped — their sessions stay unbound rather
* than guessed.
*/
export function listBinderPaneSnapshots(): BinderPaneSnapshot[] {
const snapshots: BinderPaneSnapshot[] = []
for (const pty of listRegisteredPtys()) {
if (!pty.paneKey || pty.pid === null) {
continue
}
const parsed = pty.worktreeId ? splitWorktreeIdForFilesystem(pty.worktreeId) : null
snapshots.push({
paneKey: pty.paneKey,
directory: parsed?.worktreePath ?? null,
worktreeId: pty.worktreeId,
shellPid: pty.pid
})
}
return snapshots
}
/** Apply one round's decisions to the listener registry. */
export function applyBinderOwnerships(
state: HookListenerState,
panes: readonly BinderPaneSnapshot[],
ownerships: readonly SessionOwnership[],
nowMs: number
): number {
const worktreeByPane = new Map<string, string | null>()
for (const pane of panes) {
// Why overwrite: matching the round's newest-wins pane dedupe, so a
// remint's live row wins over a stale row with a different worktree.
worktreeByPane.set(pane.paneKey, pane.worktreeId)
}
let applied = 0
for (const ownership of ownerships) {
const binding: OpenCodeSessionBinding = {
paneKey: ownership.paneKey,
boundAt: nowMs,
basis: ownership.basis
}
const worktreeId = worktreeByPane.get(ownership.paneKey)
if (worktreeId) {
binding.worktreeId = worktreeId
}
if (bindOpenCodeSession(state, ownership.sessionId, binding)) {
applied += 1
}
}
return applied
}