fix(backend): robustness pass — spawn leak, timeouts, workspace fail-loud, 409 order, respond guard

Audit findings 4.1-4.6.

- spawnFor: a rejected configure/start no longer leaks a registered runtime
  with a live Pi child (identity-checked teardown + rethrow); every later
  start used to hit "session runtime already active".
- ThtRunner.run: default 60s timeout on every tht child (SIGKILL backstop),
  120s for DWH-touching calls (sql preview/export, search pack); a dropped
  VPN mid-call no longer wedges the HTTP request forever.
- configArg: a NAMED workspace whose yaml is missing now throws instead of
  silently falling back to the default config (operations were silently
  targeting the wrong workspace).
- resume: the finalized/archived 409 is evaluated BEFORE the alreadyActive
  fast-path — the manifest is the truth even with a lingering runtime.
- ollamaEnsure: exit-0 with non-JSON stdout is a failed check, not ok:true.
- SessionBridge.respond: only the response matching the pending descriptor
  is forwarded to Pi; stale/duplicate submissions return 409 instead of
  being sent with the current gate's RPC id.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-20 01:37:20 +02:00
co-authored by Claude Fable 5
parent 2958b32fd5
commit f772ef9dca
7 changed files with 92 additions and 34 deletions
+9 -2
View File
@@ -176,8 +176,15 @@ export class PiProcessManager {
async spawnFor(sessionId: string, o: RuntimeOptions = {}): Promise<SessionRuntime> {
const rt = this.createFor(sessionId, o);
await this.configure(rt, o);
this.start(sessionId, rt, o);
try {
await this.configure(rt, o);
this.start(sessionId, rt, o);
} catch (error) {
// A rejected configure/start must not leak a registered runtime with a live
// child: every later start would see "session runtime already active".
this.teardownIfCurrent(sessionId, rt);
throw error;
}
return rt;
}