Repository navigation
fix(agentos): queue concurrent WebAssembly and Python launches per VM #2025
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1100,6 +1100,10 @@ struct VmExecutionEnginesInner { | |
| javascript: RefCell<JavascriptExecutionEngine>, | ||
| python: RefCell<PythonExecutionEngine>, | ||
| wasm: RefCell<WasmExecutionEngine>, | ||
| /// Launches that hold an engine across an await take turns here, so a second launch | ||
| /// waits instead of failing with an execution conflict. | ||
| python_launch: tokio::sync::Mutex<()>, | ||
| wasm_launch: tokio::sync::Mutex<()>, | ||
| } | ||
|
|
||
| impl VmExecutionEngines { | ||
|
|
@@ -1120,6 +1124,8 @@ impl VmExecutionEngines { | |
| javascript: RefCell::new(javascript), | ||
| python: RefCell::new(python), | ||
| wasm: RefCell::new(wasm), | ||
| python_launch: tokio::sync::Mutex::new(()), | ||
| wasm_launch: tokio::sync::Mutex::new(()), | ||
| }), | ||
| } | ||
| } | ||
|
|
@@ -1143,6 +1149,14 @@ impl VmExecutionEngines { | |
| .map_err(|_| execution_engine_conflict_error(&self.inner.vm_id, "Python", operation)) | ||
| } | ||
|
|
||
| pub(crate) async fn python_launch_turn(&self) -> tokio::sync::MutexGuard<'_, ()> { | ||
|
Comment on lines
1149
to
+1152
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟠 Medium · Engine admission remains bypassable The queue is independent of
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. not introduced by this pr. but need to look into this deeper
eersnington marked this conversation as resolved.
|
||
| self.inner.python_launch.lock().await | ||
| } | ||
|
|
||
| pub(crate) async fn wasm_launch_turn(&self) -> tokio::sync::MutexGuard<'_, ()> { | ||
| self.inner.wasm_launch.lock().await | ||
| } | ||
|
|
||
| pub(crate) fn wasm( | ||
| &self, | ||
| operation: &'static str, | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔴 High · Queue before creating an unregistered process
This await happens after the duplicate-ID check and after
spawn_trusted_root_process. If a queued request is cancelled, droppingKernelProcessHandledoes not finish or reap that process, so it remains in the VM kernel without anactive_processesentry. Two same-runtime requests with the sameprocess_idcan also both pass the check; the queue then lets both start, and the lateractive_processes.insertsilently replaces the first. Acquire the runtime turn before creating/reserving the process and hold it through registration, or add a cancellation-safe pending reservation that claims the ID and rolls back the kernel process.