Skip to content

Add broker-coordinated child process startup - #1391

Merged
Weidong Cui (wdcui) merged 30 commits into
uliteboxfrom
wdcui/ulitebox/child-start
Sep 20, 2026
Merged

Weidong Cui (wdcui) merged 30 commits into
uliteboxfrom
wdcui/ulitebox/child-start

Conversation

@wdcui

@wdcui Weidong Cui (wdcui) commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

This PR adds broker-coordinated dynamic child process startup for userland runners by introducing broker-owned process and thread identities, inherited object references, bounded startup data, and a portable process-launcher contract. Root and child runners use the same precreated-process negotiation, authenticated association, startup deadline, supervision, and retirement path across Linux and Windows, while parent requests synchronously receive the child identity after association activation and broker shutdown waits for all launched processes to finish.

Weidong Cui (wdcui) and others added 18 commits September 19, 2026 07:17
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Converge child startup publication, acknowledgement, failure, shutdown, and finalization across Linux and Windows while preserving process identity safety.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Use one mutex-serialized std::process::Child lifecycle for Linux and Windows exit observation, termination, and final waiting.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Replace the parallel startup-thread pin with explicit StartReady and StartCommitted process states completed after acknowledgement publication.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Model every out-of-process runner with RunnerInstance and represent parent-issued startup through RunnerStartup and ProcessStart coordination. Move the process-start state machine into its own module and share one association-serving path across initial and started runners.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Name the module after RunnerProcessManager and represent each in-progress StartProcess operation as a transaction with explicit state. Clarify started-runner configuration and simplify the non-Linux exit-signal helper.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Make StartProcess block until the new runner reports ready and broker startup completes. Remove acknowledgement tokens, receipt state, watchdog workers, and the intermediate committed process state while preserving bounded startup, teardown, and runner finalization.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Allocate process and initial thread identities before launch, commit startup when the broker association activates, and remove the separate readiness protocol.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Weidong Cui (wdcui) and others added 10 commits September 19, 2026 07:24
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Launch the root and dynamically created processes through the same precreated broker process, deadline, association, supervision, and retirement path. Also resolve the related lifecycle review findings and remove the test shared-buffer leak.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
Return the detailed runner completion error when root association startup fails, while retaining the broker failure as a safe fallback. Add regression coverage for a runner that exits before connecting.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
@wdcui Weidong Cui (wdcui) changed the title Add dynamic child process startup Add broker-coordinated child process startup Sep 20, 2026
Update the macOS loader test to accept the optional process startup data returned by BrokerLocal negotiation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05547201-01e0-4ff2-87c6-27739e6cc816
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure inherent_method_missing: pub method removed or renamed ---

Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
        ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/inherent_method_missing.ron

Failed in:
  BrokerProcess::parent_id, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-ulitebox/7515d7c16b81514e19b90fb58c9c48ac859bc3a0/litebox_broker_core/src/process.rs:160
  BrokerProcess::finish, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-ulitebox/7515d7c16b81514e19b90fb58c9c48ac859bc3a0/litebox_broker_core/src/process.rs:230

--- failure method_parameter_count_changed: pub method parameter count changed ---

Description:
A publicly-visible method now takes a different number of parameters, not counting the receiver (self) parameter.
        ref: https://doc.rust-lang.org/cargo/reference/semver.html#fn-change-arity
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/method_parameter_count_changed.ron

Failed in:
  litebox_broker_core::BrokerCore::create_process takes 1 parameters in /home/runner/work/litebox/litebox/target/semver-checks/git-ulitebox/7515d7c16b81514e19b90fb58c9c48ac859bc3a0/litebox_broker_core/src/lib.rs:310, but now takes 2 parameters in /home/runner/work/litebox/litebox/litebox_broker_core/src/lib.rs:334

--- failure function_parameter_count_changed: pub fn parameter count changed ---

Description:
A publicly-visible function now takes a different number of parameters.
        ref: https://doc.rust-lang.org/cargo/reference/semver.html#fn-change-arity
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/function_parameter_count_changed.ron

Failed in:
  litebox_broker_host::setup_connection now takes 8 parameters instead of 5, in /home/runner/work/litebox/litebox/litebox_broker_host/src/lib.rs:223

--- failure type_mismatched_generic_lifetimes: type now takes a different number of generic lifetimes ---

Description:
A type now takes a different number of generic lifetime parameters. Uses of this type that name the previous number of parameters will be broken.
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/type_mismatched_generic_lifetimes.ron
Failed in:
  Struct BrokerHostAssociation (1 -> 0 lifetime params) in /home/runner/work/litebox/litebox/litebox_broker_host/src/lib.rs:86

--- failure enum_struct_variant_field_added: pub enum struct variant field added ---

Description:
An enum's exhaustive struct variant has a new field, which has to be included when constructing or matching on this variant.
        ref: https://doc.rust-lang.org/reference/attributes/type_system.html#the-non_exhaustive-attribute
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/enum_struct_variant_field_added.ron

Failed in:
  field initial_thread_id of variant BrokerHandshakeResponse::Negotiated in /home/runner/work/litebox/litebox/litebox_broker_protocol/src/message.rs:152
  field startup of variant BrokerHandshakeResponse::Negotiated in /home/runner/work/litebox/litebox/litebox_broker_protocol/src/message.rs:154

--- failure enum_variant_added: enum variant added on exhaustive enum ---

Description:
A publicly-visible enum without #[non_exhaustive] has a new variant.
        ref: https://doc.rust-lang.org/cargo/reference/semver.html#enum-variant-new
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/enum_variant_added.ron

Failed in:
  variant BrokerResult:ProcessStarted in /home/runner/work/litebox/litebox/litebox_broker_protocol/src/message.rs:246
  variant BrokerOperation:StartChildProcess in /home/runner/work/litebox/litebox/litebox_broker_protocol/src/message.rs:69

--- failure function_missing: pub fn removed or renamed ---

Description:
A publicly-visible function cannot be imported by its prior path. A `pub use` may have been removed, or the function itself may have been renamed or removed entirely.
        ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/function_missing.ron

Failed in:
  function litebox_broker_userland::runtime::serve_association, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-ulitebox/7515d7c16b81514e19b90fb58c9c48ac859bc3a0/litebox_broker_userland/src/runtime.rs:61

--- failure struct_missing: pub struct removed or renamed ---

Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
        ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/struct_missing.ron

Failed in:
  struct litebox_broker_userland::runner::RunnerInstance, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-ulitebox/7515d7c16b81514e19b90fb58c9c48ac859bc3a0/litebox_broker_userland/src/runner.rs:72

--- failure method_parameter_count_changed: pub method parameter count changed ---

Description:
A publicly-visible method now takes a different number of parameters, not counting the receiver (self) parameter.
        ref: https://doc.rust-lang.org/cargo/reference/semver.html#fn-change-arity
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.50.0/src/lints/method_parameter_count_changed.ron

Failed in:
  litebox_shim_linux::LinuxShim::load_program takes 4 parameters in /home/runner/work/litebox/litebox/target/semver-checks/git-ulitebox/7515d7c16b81514e19b90fb58c9c48ac859bc3a0/litebox_shim_linux/src/lib.rs:263, but now takes 5 parameters in /home/runner/work/litebox/litebox/litebox_shim_linux/src/lib.rs:262

Merged via the queue into ulitebox with commit 09ff508 Sep 20, 2026
10 checks passed
@wdcui
Weidong Cui (wdcui) deleted the wdcui/ulitebox/child-start branch September 20, 2026 06:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant