fix(tools): revalidate systemd scope availability

This commit is contained in:
KoNit-K
2026-09-14 19:46:45 +08:00
committed by Teknium
parent 979576d938
commit c143ec4d88
2 changed files with 66 additions and 9 deletions
+17 -9
View File
@@ -81,16 +81,17 @@ WATCH_GLOBAL_COOLDOWN_SECONDS = 30
# Under a systemd gateway with MemoryMax, local background commands inherit the gateway's
# cgroup, so a memory-heavy executor can get the ENTIRE gateway killed by systemd-oomd;
# ``systemd-run --user --scope`` gives the worker its own transient cgroup. Usability is
# probed once (binary present but user D-Bus absent in system services/containers).
# probed with a bounded cache (binary present but user D-Bus absent in system services/containers).
# A memory-heavy executor (Codex, tests, Node) can push the whole cgroup past MemoryMax and trigger
# systemd-oomd to kill the ENTIRE gateway — taking down the messaging control plane and silently losing the
# active turn. We probe *once* whether ``systemd-run --user --scope`` is actually usable (the binary can
# active turn. We probe whether ``systemd-run --user --scope`` is actually usable (the binary can
# exist on the PATH while the user D-Bus session is unavailable — common for system services and
# containers), and cache the result for the process lifetime. See #70716.
# containers), and cache the result briefly. See #70716.
_SYSTEMD_SCOPE_AVAILABLE: Optional[bool] = None
_SYSTEMD_SCOPE_PROBE_LOCK = threading.Lock()
_SYSTEMD_SCOPE_PROBED_AT = 0.0
_SYSTEMD_SCOPE_FAILURE_TTL_SECONDS = 60.0
_SYSTEMD_SCOPE_SUCCESS_TTL_SECONDS = 60.0
_MIN_WORKER_MEMORY_MAX_BYTES = 64 * 1024 * 1024
_DEFAULT_WORKER_MEMORY_MAX_BYTES = 1024 * 1024 * 1024
_WORKER_MEMORY_MAX_CAP_BYTES = 4 * 1024 * 1024 * 1024
@@ -204,12 +205,19 @@ def systemd_user_bus_env(base_env: Optional[Dict[str, str]] = None) -> Dict[str,
def _systemd_scope_cached() -> Optional[bool]:
"""Cached probe verdict, or None when a (re)probe is due. True is permanent; False
expires after ``_SYSTEMD_SCOPE_FAILURE_TTL_SECONDS`` so a D-Bus blip isn't sticky."""
if _SYSTEMD_SCOPE_AVAILABLE is True:
return True
stale = time.monotonic() - _SYSTEMD_SCOPE_PROBED_AT >= _SYSTEMD_SCOPE_FAILURE_TTL_SECONDS
return None if _SYSTEMD_SCOPE_AVAILABLE is None or stale else False
"""Cached probe verdict, or None when a (re)probe is due.
Both verdicts expire: a user D-Bus can disappear after a successful probe,
while a failed probe can recover after linger or a login session starts.
"""
if _SYSTEMD_SCOPE_AVAILABLE is None:
return None
ttl = (
_SYSTEMD_SCOPE_SUCCESS_TTL_SECONDS
if _SYSTEMD_SCOPE_AVAILABLE
else _SYSTEMD_SCOPE_FAILURE_TTL_SECONDS
)
return None if time.monotonic() - _SYSTEMD_SCOPE_PROBED_AT >= ttl else _SYSTEMD_SCOPE_AVAILABLE
def _systemd_run_user_scope_available() -> bool: