Skip to content

fix(computer): never execute or overwrite a dead command - #111

Open
kvnloo wants to merge 3 commits into
CopilotKit:mainfrom
kvnloo:fix/computer-dead-command-guards
Open

kvnloo wants to merge 3 commits into
CopilotKit:mainfrom
kvnloo:fix/computer-dead-command-guards

Conversation

@kvnloo

@kvnloo kvnloo commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Problem

There are two races after a computer command row is created:

  1. If Stop quarantines the command before the executor re-checks its lease, the executor currently overwrites the existing interrupted receipt with a blind put().
  2. If Stop or lease recovery marks the command interrupted immediately after the lease check, the executor can still invoke Docker. Its final completion CAS then loses, leaving an interrupted receipt even though side effects actually ran.

That second case is particularly dangerous because it can invite a retry of side effects whose outcome is already unknown.

Change

  • Replace the stopped-before-execution blind write with a CAS on status: "running"; if another path already quarantined the row, return that receipt unchanged.
  • Re-read the command row after the lease check and return immediately if it is no longer running.

Tests

Two race regressions pin both boundaries:

  • a Stop quarantine that lands before lease re-check keeps its original "Stopped by the user" receipt and Docker is never invoked;
  • a command marked interrupted after lease validation is never executed.

No command schema, timeout, or successful execution behavior changes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant