Skip to content

Contain sandbox process descendants in delegated cgroups - #614

Merged
SaladDay merged 2 commits into
aos/cutoverfrom
aos/contain-sandbox-process-descendants
Oct 9, 2026
Merged

SaladDay merged 2 commits into
aos/cutoverfrom
aos/contain-sandbox-process-descendants

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Sandbox process cancellation now contains descendants that fork, double-fork or call setsid when the existing ScopeCgroupV2 capability is selected. SandboxIO verifies delegation, creates an operation subgroup, and places its trusted trampoline there before target execution. Cancellation kills that subtree and confirms kernel emptiness independently of leader exit and output drain; failed kills continue retrying even while the leader remains alive.

The implementation reuses the process protocol, launch gate, reaper and scope observer. It adds no dependency or public field. Normal background work survives leader exit, and unsupported delegation remains an explicit capability distinction. The existing backend runtime CI job now exercises real delegated cgroups with missing support treated as a failure; the owning English and Chinese documentation is updated.

Validation: real delegated full-package race tests, repeated cancellation/signal/cgroup race tests, focused SandboxIO/process-contract tests, build/vet, naming/docs/CI checks and translation checks. Provider delegation and public stdio cancellation settlement are integrated separately.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit f908bfe into aos/cutover Oct 9, 2026
23 checks passed
@SaladDay
SaladDay deleted the aos/contain-sandbox-process-descendants branch October 9, 2026 08:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant