Repository navigation
fix(firecracker): a guest that dies fails its agent-ready waiters at once, with the console tail - #1610
Merged
Conversation
…once, with the console tail `wait_agent_ready` sat out its full 180 s deadline when the guest died first: the supervisor pruned the sandbox and deleted the jail, but the ready-dial listener kept the watch sender alive, so waiters saw neither "ready" nor "closed". A base capture whose guest panicked at boot hung with no diagnosis, and the console log was gone before anyone read it. The listener is now owned by the sandbox. Prune and destroy read the last 4 KiB of `firecracker.log` before the jail is removed, store it as the sandbox's death note, log it at WARN on an unexpected death, and abort the listener. A closed watch becomes "guest died before agentd dialed ready port" with the console tail attached. The ready fast path and the 180 s backstop for a hung guest are unchanged. Tests: two pending waiters receive the panic marker after the supervisor's real teardown callback; the same without a console file; explicit destroy; a tail that starts inside a UTF-8 character; pooled base capture propagates the death within one second and still destroys the VM; a KVM lifecycle test boots a fixture whose init exits and asserts the failure names the kernel panic within 15 s. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UHxL6gj4o8EvxYpgtwEWaM
nikhilunni
force-pushed
the
fix/fc-dead-vm-wait
branch
from
October 8, 2026 02:47
c489a7d to
7dda8c2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A Firecracker guest that dies before agentd dials ready now fails its waiters immediately, with the console tail in the error, instead of sitting out the 180 s deadline with a generic message.
The problem
Reproduced on a KVM host while debugging the swap snapshot test: the capture guest panicked 3 s after boot, the supervisor pruned the sandbox within 5 s and deleted the jail, but the ready-dial listener task kept the watch sender alive.
wait_agent_readysaw neither "ready" nor "closed", waited the full 180 s, and failed with "agentd did not dial ready port". The panic text was only recoverable by polling the jail before the prune.The change
LiveSandbox(AgentReadiness: receiver, task handle, death note).firecracker.logbefore removing the jail, store it as the death note, log it at WARN on an unexpected death, and abort the listener so the watch closes.guest died before agentd dialed ready portwith the console tail. The ready fast path and the 180 s backstop for a hung guest are unchanged.start_agentand base capture get the behaviour through their existing calls.read_tailis UTF-8 tolerant (a tail that starts mid-character no longer drops the rest).Tests
lifecycle.rs, already in the unprivileged FC lane): a fixture whose init exits immediately failswait_agent_readywithin 15 s with "Kernel panic" in the message.Validation
just checkgreen (2766 tests); Linux cross clippy for firecracker and host-agent clean; Codex adversarial review approved with no findings.🤖 Generated with Claude Code
https://claude.ai/code/session_01UHxL6gj4o8EvxYpgtwEWaM