doc: clarify toolsrv lifecycle for local vs SSH-remote case

This commit is contained in:
Ollie Agent 2026-08-11 07:27:38 +02:00
parent 4b7d5cdd79
commit 41969ed4b2
2 changed files with 14 additions and 8 deletions

View File

@ -113,7 +113,7 @@ graph TB
AG[agent.Agent<br>loop · compaction<br>prompt assembly]
end
subgraph "toolsrv (child process, 9P)"
subgraph "toolsrv (local: child process / remote: SSH-spawned)"
TOOLS[9P Filesystem<br>ctl · tools · proc/]
EXEC[Tool Scripts<br>· shell, reasoning_think<br>· file_*, lsp_*, memory_*<br>· gui_*, subagent_*]
end

View File

@ -1073,7 +1073,9 @@ Excludes: backends (4,229), fsedsl (1,030), tests, KDE, tools, generated code.
## Phase 20: toolsrv 9P Migration & Process Isolation (Aug 10–11)
The tool server completed its evolution from an in-process library to a
**fully independent 9P server** running as a child process of olliesrv.
**fully independent 9P server**. Locally it runs as a child process of
olliesrv; for remote execution it runs on a remote host, connected via
SSH Unix socket forwarding.
### Before
@ -1123,13 +1125,17 @@ communicate over a socket.
Three-layer defense against orphaned toolsrv processes:
1. **Pdeathsig** — `SysProcAttr{Pdeathsig: SIGTERM}` on local spawn. When
olliesrv dies, the kernel terminates toolsrv immediately.
1. **Pdeathsig** (local only) — `SysProcAttr{Pdeathsig: SIGTERM}` on local
spawn. When olliesrv dies, the kernel terminates toolsrv immediately.
For SSH-spawned toolsrv, Pdeathsig is set on the `ssh` process itself —
when SSH dies, the remote shell receives SIGHUP which typically cascades
to toolsrv.
2. **Idle timeout** — toolsrv tracks active 9P connections. After the first
client connects and then all connections drop, a 30s timer starts.
If no new connection arrives, toolsrv exits cleanly. 60s startup grace
period for the initial connection.
2. **Idle timeout** (local + remote) — toolsrv tracks active 9P connections.
After the first client connects and then all connections drop, a 30s timer
starts. If no new connection arrives, toolsrv exits cleanly. 60s startup
grace period for the initial connection. This is the primary cleanup
mechanism for remote toolsrv where Pdeathsig doesn't apply directly.
3. **Kill-before-respawn** — `ProcessKeeper.Dial()` kills the old process
before spawning a replacement. Prevents accumulation during reconnect cycles.