Severity: P2
Verified at v4.10.0, 55c15761845b00931ab2ea4aa184a7797dfd0614.
Locations
src/tools/process_manager.py:57-157,187-200,250-266
Failure scenario and affected installations
Remote Linux/macOS jobs whose descendant setsid escapes original group. Supervisor/controller signal/inspect onlyoriginalPGID and can emit empty=true while escaped child survives completion/kill/deadline.
Verification
Independently traced embedded supervision ownership/group checks and absence of ancestry/adoption. Reviewer real embedded code with mocked operations emitted emptytrue/exit0 for absentgroup plus survivingescapedchild.
Correction and regression coverage
Contain/track all owned descendants or report limited group-only evidence honestly; add harmless escaped-descendant model fixture.
Duplicate screening
Checked open/closed inventory and GitHub title/body search; no matching root. Harmless mocked operations/temporary data and complete source traces; no live processes killed, remote calls or service actions.
Severity: P2
Verified at v4.10.0,
55c15761845b00931ab2ea4aa184a7797dfd0614.Locations
src/tools/process_manager.py:57-157,187-200,250-266Failure scenario and affected installations
Remote Linux/macOS jobs whose descendant setsid escapes original group. Supervisor/controller signal/inspect onlyoriginalPGID and can emit empty=true while escaped child survives completion/kill/deadline.
Verification
Independently traced embedded supervision ownership/group checks and absence of ancestry/adoption. Reviewer real embedded code with mocked operations emitted emptytrue/exit0 for absentgroup plus survivingescapedchild.
Correction and regression coverage
Contain/track all owned descendants or report limited group-only evidence honestly; add harmless escaped-descendant model fixture.
Duplicate screening
Checked open/closed inventory and GitHub title/body search; no matching root. Harmless mocked operations/temporary data and complete source traces; no live processes killed, remote calls or service actions.