Skip to content

Optional birth probes can exhaust startup admission #966

Description

@bcdonadio

Observed behavior: At PR #965 candidate 63cd814220aa3eb8e4049c9a50a306c987e6e781, optional process-birth sampling for newly admitted daemon convergence can consume the remaining startup admission time before authenticated diagnostics run. On non-Linux platforms, processStartTime invokes a trusted ps or PowerShell helper synchronously with a timeout capped at 2 seconds, and lifecycle supplies the entire remaining startup budget. A child becoming healthy late or a slow helper can therefore exhaust the remaining deadline and cause otherwise healthy startup admission to fail. The after-authentication birth sample is also attempted when the first sample was null.

Expected behavior: Failure or slowness in optional convergence-evidence collection should disable child retry eligibility while preserving enough of the existing admission budget for authenticated startup diagnostics. Define a bounded reservation/cap and avoid unnecessary second sampling when the first evidence is already unusable.

Root cause: src/daemon/lifecycle.ts:1842-1853 calls processBirthProbe(..., {timeoutMs: Math.max(1, deadline - monotonicNow())}) before checkDaemonDiagnostics. src/private-mutation-lock.ts:143-160 bounds each non-Linux subprocess at min(2000, remaining) but does not reserve any authentication time.

How to reproduce safely: Use a complete hermetic lifecycle fixture with an injected monotonic clock and process-birth probe. Make the pre-authentication probe consume the simulated remaining deadline and return null; let fake endpoint diagnostics be healthy if invoked before that deadline. Assert the current operation refuses admission. No actual subprocess, daemon, install, network or host signaling is needed.

Environment:

  • Agent: Codex automated PR review and Astra owner adjudication
  • Connector: static source review
  • OS: Fedora Linux; affected slow synchronous helper paths are non-Linux

P2 reliability follow-up discovered in PR #965 review for #865. Outside immutable S1 cutoff. Tracked separately per the rule that accepted P2 findings do not block the issue-scoped increment. No operational reproduction occurred.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    Medium

    Effort

    None yet

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions