Daemon/plugin exit hardening: deferred review items from v0.32.2 #305

Open
opened 2026-09-26 17:03:28 +02:00 by buildagent · 0 comments
Member

These were found by the independent review of the v0.32.2 daemon-robustness lane. The lane was stopped before it fixed them, and none of them blocked the release.

  1. Panic-hook cost. The exit-reason panic hook runs for every panic, including caught panics inside the plugin host. Measure its cost on a plugin that panics often, and skip the file write for caught panics.
  2. Windows parent-death watchdog. Every OpenProcess/WaitForSingleObject error is treated as "parent gone". Only ERROR_INVALID_PARAMETER means gone. Other errors, such as access denied, should keep the worker alive and log the error.
  3. Signal exit codes. A daemon stopped by SIGTERM or SIGINT should exit 128+signo and record the signal in daemon.exit, not exit 0 or 1.
  4. Docs. docs/ needs one line on daemon.exit and on CODE_INDEX_TOOL_CALL_BUDGET_SECS.
  5. Deferred transactions. Check the remaining BEGIN (DEFERRED) sites that later write. They can still fail SQLITE_BUSY on the lock upgrade without the new backoff.
  6. Review nits: log wording and duplicate tracing fields.

Each fix needs a test whose mutation has actually been run.

These were found by the independent review of the v0.32.2 daemon-robustness lane. The lane was stopped before it fixed them, and none of them blocked the release. 1. **Panic-hook cost.** The exit-reason panic hook runs for every panic, including caught panics inside the plugin host. Measure its cost on a plugin that panics often, and skip the file write for caught panics. 2. **Windows parent-death watchdog.** Every `OpenProcess`/`WaitForSingleObject` error is treated as "parent gone". Only `ERROR_INVALID_PARAMETER` means gone. Other errors, such as access denied, should keep the worker alive and log the error. 3. **Signal exit codes.** A daemon stopped by SIGTERM or SIGINT should exit 128+signo and record the signal in `daemon.exit`, not exit 0 or 1. 4. **Docs.** `docs/` needs one line on `daemon.exit` and on `CODE_INDEX_TOOL_CALL_BUDGET_SECS`. 5. **Deferred transactions.** Check the remaining `BEGIN` (DEFERRED) sites that later write. They can still fail `SQLITE_BUSY` on the lock upgrade without the new backoff. 6. **Review nits:** log wording and duplicate `tracing` fields. Each fix needs a test whose mutation has actually been run.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
h-dv/code-index#305
No description provided.