Skip to content

[Accepted risk] Enforce bounded-worker memory containment on macOS #510

Description

@Anionix

Risk

Issue #301 adds pre-import Unix resource caps, but Darwin rejects every tested finite RLIMIT_AS value with ValueError: current limit exceeds maximum limit. The harness therefore records address_space_bytes as unsupported on macOS while still enforcing file-size, open-file, real-user process, timeout, output-retention, and artifact-budget bounds.

This is an explicit accepted risk, not evidence that memory is bounded on macOS.

Owner and expiry

  • Owner: maintainers
  • Review by: 2026-08-07
  • Priority: P2

Exit criteria

  • Select a primary-source-backed macOS containment mechanism that works before heavyweight worker imports.
  • Add a deterministic regression proving a worker cannot exceed the selected memory ceiling.
  • Record requested, effective, and unsupported memory containment in run and per-case evidence.
  • Keep unsupported/failed setup non-rankable under the lifecycle contract.
  • Run exact-SHA CI and resolve every review thread before closeout.

Evidence

  • Python documents resource as Unix-only and resource availability as system-dependent: https://docs.python.org/3.12/library/resource.html
  • Local aarch64-darwin probes rejected finite RLIMIT_AS values from 8 GiB through 256 GiB; RLIMIT_FSIZE, RLIMIT_NOFILE, and RLIMIT_NPROC were accepted.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    audit:2026-07-19Strict audit finding from 2026-07-19enhancementNew feature or requestpriority:p2Important audit follow-upready-for-agentReady for implementation

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions