1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
//! Shared fixtures for the `trusty-memory` integration tests.
//!
//! Why: each file under `tests/` compiles as its own binary, so a fixture used
//! by more than one of them has to live in a module they all declare. This is
//! that module.
//! What: [`DaemonGuard`], the owning handle for a spawned
//! `trusty-memory serve --foreground`.
//! Test: exercised by every test that spawns a daemon —
//! `serve_stdio_concurrent_e2e`, `serve_stdio_e2e`, `codex_stdio_e2e_5265`;
//! the parent-death guarantee itself by
//! `guard_spawned_daemon_exits_when_its_spawner_is_sigkilled`.
// Each `tests/` file compiles this module into its OWN binary, and no single
// binary uses every fixture in it — `pid` is only wanted by `orphan_reap_7085`.
// Without this the unused half is a `dead_code` warning, which `-D warnings`
// turns into a build failure in the other three.
use Path;
use ;
/// Owns a spawned `serve --foreground` daemon and kills it on drop.
///
/// Why (#5188): the spawn helpers returned a raw `Child` and relied on an
/// explicit `.kill()` at the end of the test body. Every `assert!` between
/// those two points — including the readiness-poll assert inside the spawn
/// helper itself — orphans the daemon on failure. An orphan re-parents to PID
/// 1, keeps its dream loop running against the temp data dir, and on the
/// reporting machine six of them accumulated from one `cargo test` run and
/// went on calling a local model. `Drop` runs on the panic unwind, so the
/// daemon dies with the test that spawned it.
/// What: kills and reaps in `Drop`. Both results are discarded — the child may
/// already have exited, and a teardown error must not mask the test's own
/// failure.
///
/// #7085: `Drop` is not enough on its own. SIGKILL this test binary — a `cargo
/// test` timeout, an interrupted run, a torn-down process tree — and no
/// destructor runs at all, which is how 102 orphaned daemons accumulated. The
/// daemon therefore also carries
/// `trusty_common::parent_death::exit_with_parent`, so it watches the test
/// process and self-exits on its own. The two are complementary: `Drop` is the
/// immediate reap on the ordinary path, the stamp is the backstop.
///
/// Why [`DaemonGuard::spawn`] and no `new` (#7085 recurrence): the stamp used
/// to be applied by each call site, three of which hand-copied the same
/// `exit_with_parent(...)` block beside a `DaemonGuard::new(child)`. A guard
/// that accepts an already-spawned `Child` cannot tell a stamped one from an
/// unstamped one, so the linkage was a convention a fourth call site — or one
/// edit to an existing one — could drop without any gate noticing. Owning the
/// spawn is what makes the stamp unskippable.
/// Test: `orphan_reap_7085::guard_spawned_daemon_exits_when_its_spawner_is_sigkilled`
/// kills a spawner outright and requires the guard's daemon to follow;
/// `stdio_serve_concurrent_two_bridges_both_work` and the other daemon tests
/// cover the ordinary path.
/// The socket `serve --foreground` binds under `data_dir` — the readiness
/// signal every caller polls for.
/// The `trusty-memory` binary Cargo built for this test run.