Bound slow native architecture startup with the existing UID window

This commit is contained in:
dh
2026-10-05 06:18:38 +02:00
parent 4b7fd160ef
commit 2e2d702e29
3 changed files with 10 additions and 1 deletions
+3 -1
View File
@@ -22,6 +22,8 @@ Run 4193 at `9164fe4` successfully derived the same current-file version in both
Run 4194 at `81a3b9c` stopped the same single query after 606 seconds without output. StorageKit exists but was not running and had never started in the before/live snapshots; the live snapshot covers approximately 103–160 seconds of the query, not its entire lifetime. `sample` hit its own watchdog without even its sampling-start message or report. This does not establish symbolication as the cause. The observed `1T` is a current Timeshare priority, not a thread count or proof of background policy. Neither installation nor tests ran.
Run 4195 at `4b7fd16` did not reach the new observer: the required `uname -m` timed out at its 45-second limit, was sent TERM at 51 seconds and exited 143 at 55 seconds without output. Later `id`, `sysctl` and targeted `ps` completed, but `uname -a` also timed out. No new QEMU fatal/reset, container OOM, swap or CPU throttling was recorded. The cause remains unknown. The next bounded run changes only the architecture command's limit to the existing UID command's 180 seconds; a successful native `uname -m` result is still mandatory.
## Entry points and dependencies
Orchestration remains the .NET 10 file-based app `tools/ci/MacOsNativeDiagnostic.cs`. Existing Bash/Python boot integration is necessary before a guest SDK exists. NASM assembles the CPU probe in the disposable image build, without host/runner installation. No new runner, device, capability, secret or service is used.
@@ -57,7 +59,7 @@ Native readiness requires x86_64, UID 0, macOS 14+, successful launchd service q
The raw file, exact source path, length, SHA256 and parsing receipt are retained and bound to the current token. This version evidence travels only from guest to host and requires no reply. The guest uses its existing Bash before any SDK exists; authoritative XML logic stays in C#/.NET. A Bash candidate alone cannot authorize installation or qualify readiness. This method establishes the current guest version, not successful execution of `sw_vers`.
Required commands retain 45 seconds and UID 180 seconds. The single disk query retains its 600-second diagnostic window under the existing 90-minute Recovery deadline. An optional no-target `sample` CLI control precedes it. The owned observer takes an early native process snapshot, requests an ordinary one-second/100-ms `sample` without eager `-mayDie` symbol loading, and records live StorageKit state. After a cancelable 180-second builtin pause it takes a late snapshot of the same live disk child and expected parent. Each observation retains its own 60-second watchdog and two-second TERM/KILL grace. Missing tools, denied reads, failures and timed-out samples remain explicit missing evidence. Stack output is captured directly from the owned state with a 512-KiB bound, without another native copy command. Observation failure passes no gate. Owned children are stopped on query completion/cancellation; output remains 512 KiB per command and 4 MiB proof. No service is started or restarted by the observer.
Ordinary commands retain 45 seconds; architecture and UID use 180 seconds. The single disk query retains its 600-second diagnostic window under the existing 90-minute Recovery deadline. An optional no-target `sample` CLI control precedes it. The owned observer takes an early native process snapshot, requests an ordinary one-second/100-ms `sample` without eager `-mayDie` symbol loading, and records live StorageKit state. After a cancelable 180-second builtin pause it takes a late snapshot of the same live disk child and expected parent. Each observation retains its own 60-second watchdog and two-second TERM/KILL grace. Missing tools, denied reads, failures and timed-out samples remain explicit missing evidence. Stack output is captured directly from the owned state with a 512-KiB bound, without another native copy command. Observation failure passes no gate. Owned children are stopped on query completion/cancellation; output remains 512 KiB per command and 4 MiB proof. No service is started or restarted by the observer.
The container retains 6 GiB memory/swap, two-CPU limit, 512 MiB shared memory and a 4-GiB/two-vCPU guest. One fresh anonymous /storage volume holds the sparse 64-GiB target. Inspection rejects devices, capabilities, binds, ports, host networking and privileged mode. KVM is disabled with no /dev/kvm mapping; guest networking stays slirp.