Repository navigation
Worker: bound output capture, upload fan-out, precondition scripts and orphaned action directories - #2810
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
amankrx
force-pushed
the
pr/worker-output-bounds
branch
from
September 29, 2026 00:16
bc8e798 to
bc87a36
Compare
corcillo
reviewed
Sep 29, 2026
corcillo
reviewed
Sep 29, 2026
corcillo
reviewed
Sep 29, 2026
corcillo
reviewed
Sep 29, 2026
… directories (cherry picked from commit 1b9928224cc63039b6cb7d1201f2232978ea3d8c)
(cherry picked from commit fac377f4d9f32a61ebc8ef0c13668189d031f78d)
…ks, and log a quiet sweep at debug
amankrx
force-pushed
the
pr/worker-output-bounds
branch
from
September 29, 2026 04:58
aa19021 to
93f213e
Compare
corcillo
approved these changes
Sep 29, 2026
MarcusSorealheis
approved these changes
Sep 29, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Four places where a worker had no bound. An action's stdout or stderr was captured in memory without limit; past
max_captured_output_bytesthe rest now spills to a file under the action directory, with the head kept for the log; the spill handle sits outside the open-file budget, since it lives as long as the child's stream. Output uploads fanned out one task per file; one semaphore of 64 permits, taken around each file from open to upload, now bounds the whole output tree, so nested directories cannot multiply it. A precondition script that hung held the action forever; it is now refused as backpressure afterprecondition_timeout_ms(default 30 s). Action directories left behind by a crash were never removed; a sweep onorphan_sweep_interval_snow clears them, detached so it outlives its spawn handle. The sweep skips symlinks rather than following them, takes the same cleanup mark a retry of the operation waits on before it removes anything, and a directory it cannot remove is logged and counted while the rest are still swept. The failed-command log line cuts its stdout and stderr excerpt by bytes, so a multibyte character on the boundary no longer panics.How was this verified?
running_actions_manager_testcovers the capture spilling past the cap and the spill file uploading whole, a 256-file tree uploading through a gated store with never more than 64 files open (258 without the shared bound), and the orphan sweep removing a stale directory, leaving a live one, and leaving a symlink and its target alone (that one fails without the change);local_worker_testcovers the hanging precondition script timing out, and the excerpt helper is tested on a cut through a multibyte character and on bytes that were never text. On a test cluster a target that printed 2 GiB to stderr no longer took the worker down, and a build with 3,000 outputs uploaded without the file-descriptor spike. The two captured-output uploads are boxed: inlined, the debug test binary overflowed its thread stack. The sweep carrying on past a directory it cannot remove is reviewed but not unit-tested: the removal helper repairs permissions before deleting, so a stuck directory cannot be staged without root.Risk
One default changes: a precondition script now has 30 s where it had forever, and a deployment with slower scripts should set
precondition_timeout_ms. The other knobs are off or unbounded unless set. Spill files live under the action directory and go with it.AI assistance
An agent drafted the change and I reviewed every line.
This change is