fix: reclaim queued Pi parent capacity

This commit is contained in:
2026-08-23 13:53:28 +08:00
parent a10b98e484
commit 1727b75f30
3 changed files with 171 additions and 17 deletions

View File

@@ -8,7 +8,7 @@
- Worktree: D:\Datas\OthersProjects\makelore-pi-child-workers-5c8e2a71
- Base commit: b806c78139aa11e338c680d4c3fa92e076901aa2
- Owner: codex
- Status: Second planner corrections complete; re-review pending
- Status: Third planner correction complete; final re-review pending
## Scope
@@ -77,6 +77,16 @@
reservations race direct capacity against this cancellable event-driven
reclaim and always settle/release on reclaim rejection, parent abort, or any
other early exit. Parent `stop()` now releases its process lease in `finally`.
- Planner re-review of `a10b98e` confirmed both lease-lifecycle findings closed,
then reproduced the production-capacity shape `4 running + 4 queued`: queued
parent workers retained all eight process leases, leaving no ready/idle
worker for four children to reclaim. The pool now prefers ready/idle
eviction, then suspends the oldest queued parent process while retaining its
top-level FIFO entry, Conversation state, and session binding. When its turn
arrives, the same queue entry reopens that session as a new worker generation
before sending the original prompt. This closes the deadlock without
dropping queued work, reordering it, adding another queue, or exceeding the
shared eight-process cap.
- Added the managed ephemeral child opener. It resolves only enabled,
unarchived project Agents from `.niancode/project.json`, materializes their
exact model/prompt/skills, keeps credentials in the child environment and
@@ -113,7 +123,10 @@
unknown schema/version raw-payload suppression; first reclaim finding no
idle followed by delayed parent readiness and automatic child execution;
reclaim rejection/abort with zero queued lease; and stop rejection with zero
active/waiting lease.
active/waiting lease. A production-scale regression also covers four running
plus four queued parents dispatching four parallel children: all four queued
workers suspend, all children complete, and the queued parents then resume
FIFO with unchanged session bindings and generation 2.
- Locked real Pi 0.84.2 workspace smoke passed for both the parent worker and
an ephemeral read-only child launched through Electron Node with the child
extension role and `--no-session`. A probe extension reads Pi's actual
@@ -129,17 +142,18 @@
authenticated Main bridge; the active-tool process probes and bridge execute
test jointly cover visibility and tool invocation without an external
Provider.
- All cumulative Pi tests passed: 22 files, 110 passed and 1 staged-only
- All cumulative Pi tests passed: 22 files, 111 passed and 1 staged-only
skipped; the staged-only command passed separately as described above.
- `pnpm run typecheck`: passed.
- `pnpm run lint:check`: passed with 0 errors and 6 pre-existing frontend
warnings outside this task.
- `pnpm run build:vite`: passed for Renderer, Main, Preload, and utility
worker bundles; existing chunk-size/dynamic-import warnings remain.
- The final full-suite first pass hit the known Windows temporary JSON `rename`
`EPERM` in the unchanged conversation store. The failing runtime test passed
1/1 in isolation, and the single full-suite rerun passed: 202 files, 2213
passed and 1 staged-only skipped.
- An earlier full-suite pass hit the known Windows temporary JSON `rename`
`EPERM` in the unchanged conversation store; the failing runtime test passed
1/1 in isolation and the rerun passed. After the queued-parent correction,
the final full suite passed on its first run: 202 files, 2214 passed and 1
staged-only skipped.
- Real external Provider validation remains **Explicitly Waived / Accepted
Risk** with `realTurnVerified=false`. Provider concurrency, credential
isolation, protocol compatibility, and image-path risk are accepted rather
@@ -166,7 +180,10 @@
reservations ahead of normal parent-start waiters, and wire the scheduler's
cancellable capacity reclaimer to `PiWorkerPool.reclaimIdleWorker`. The pool
must notify an already waiting child when a spawning/running parent becomes
`ready`/`idle`, and stop/reclaim failure must never retain a lease. Semantic
conflicts: none with the accepted PI runtime specification; this makes its
parent/child cap executable. Human confirmation required: no, unless
integration changes the accepted process-cap policy.
`ready`/`idle`, and stop/reclaim failure must never retain a lease. If the
cap consists only of running and queued parents, it must suspend queued
parent processes in FIFO-safe/LRU order, retain their queue entries and
session bindings, and reopen them as a new generation when scheduled.
Semantic conflicts: none with the accepted PI runtime specification; this
makes its parent/child cap executable. Human confirmation required: no,
unless integration changes the accepted process-cap policy.