Files
orca/src/main/ipc/runtime-watcher-pending-assignment.ts
T
Brennan Benson 64be819790 fix(runtime): harden watcher and PTY teardown ownership (#8661)
* fix(runtime): retain watcher and PTY teardown ownership

* fix(runtime): restore watchers after interrupted cleanup

* fix(runtime): prevent stale watcher revival

* test(runtime): cover watcher shutdown ownership

* test(daemon): model physical PTY exit

* fix(daemon): keep shutdown terminating when disposal cannot prove exit

A rejecting host.dispose() (unreapable child past its exit deadline) left
the shutdown RPC without its process.nextTick(shutdown) and skipped socket
cleanup in shutdown(), stranding the daemon as an unreachable orphan after
the stale-daemon replacement flow unlinks its socket. Log and continue:
daemon exit reparents the child to init instead of blocking on it.

* fix(runtime): keep local watching alive after an idle-kill deadline miss

An idle child that outlived the exit deadline set shutdownRequested on the
shared desktop supervisor, which has no retire-and-replace path — every
later subscribe rejected supervisor_disposed and the roots were cached
unwatchable, silently ending local file watching for the session. The idle
path owns zero records, so there is no double-watch hazard; the zombie
keeps its capacity reservation until physical exit and the next subscribe
gets a fresh child.

* fix(renderer): resync replayed paired-web file watches

Transparent replay removed the implicit resync the old close-and-rebuild
path provided: a replayed files.watch only reports changes from its own
native setup, so changes during the reconnect gap were silently lost.
Deliver a conservative overflow to consumers once the replayed watch is
ready, matching the overflow-after-interruption contract everywhere else.

* fix(runtime): address teardown review findings

* fix(runtime): retry watches after teardown deadlines

* Fix PTY descendant leaks on forced teardown

* Fix jitter-sensitive terminal lifecycle test
2026-07-15 15:23:35 -07:00

65 lines
2.0 KiB
TypeScript

import { WatcherProcessFailure } from './parcel-watcher-process-failure'
import type { WatcherProcessHooks } from './parcel-watcher-process-subscription'
import { PromiseSettlementWaiters } from '../../shared/promise-settlement-waiters'
const DEFAULT_QUARANTINE_WAIT_TIMEOUT_MS = 60_000
export class RuntimeWatcherPendingAssignment<T> {
private readonly settlementWaiters: PromiseSettlementWaiters<T>
private settledNotified = false
constructor(
basePromise: Promise<T>,
private readonly onNoWaiters: () => void,
private readonly onSettled: () => void
) {
this.settlementWaiters = new PromiseSettlementWaiters(basePromise, () => this.notifySettled())
}
get waiterCount(): number {
return this.settlementWaiters.waiterCount
}
wait(hooks: WatcherProcessHooks, onGranted: (assignment: T) => void): Promise<T> {
return this.settlementWaiters.wait({
signal: hooks.signal,
timeoutMs: hooks.subscribeTimeoutMs ?? DEFAULT_QUARANTINE_WAIT_TIMEOUT_MS,
createAbortError: createAssignmentAbortError,
createTimeoutError: createAssignmentTimeoutError,
onFulfilled: onGranted,
onAbandon: () => {
if (this.settlementWaiters.waiterCount === 0) {
// Why: delete the logically abandoned assignment synchronously so a
// same-turn replacement cannot join its soon-to-reject promise.
this.notifySettled()
this.onNoWaiters()
}
}
})
}
private notifySettled(): void {
if (this.settledNotified) {
return
}
this.settledNotified = true
this.onSettled()
}
}
function createAssignmentAbortError(): WatcherProcessFailure {
return new WatcherProcessFailure(
'file watcher subscription aborted',
'subscription',
'subscribe_aborted'
)
}
function createAssignmentTimeoutError(): WatcherProcessFailure {
return new WatcherProcessFailure(
'file watcher subscription timed out waiting for quarantine capacity',
'subscription',
'subscribe_timeout'
)
}