fix(runtime): exclude stale process resources during authority intersection

Catch ResourceIdentityError during intersection so that normal process exit
or background job termination does not crash child authority creation.
Stale or unverifiable observations are conservatively excluded from the
resulting authority while maintaining identity verification and preventing
PID reuse or renewal.
This commit is contained in:
Alexandre Teixeira
2026-10-02 18:54:09 +01:00
parent 525ae76df3
commit ab89e3274a
4 changed files with 145 additions and 7 deletions
+18 -3
View File
@@ -181,9 +181,24 @@ def seal_jobs(authority):
def intersect_observed(parent, child, validate):
# Validate both sides before equality. Seeing a replacement cannot renew a
# stale parent observation, even when the child has just sealed it.
for resource in (*parent, *child):
validate(resource)
return tuple(resource for resource in parent if resource in child)
# Stale/dead/unverifiable resources on EITHER side are conservatively
# excluded from the resulting authority — a normal process exit must not
# crash child authority intersection.
live_parent = []
for resource in parent:
try:
validate(resource)
live_parent.append(resource)
except ResourceIdentityError:
continue
live_child = set()
for resource in child:
try:
validate(resource)
live_child.add(resource)
except ResourceIdentityError:
continue
return tuple(resource for resource in live_parent if resource in live_child)
def intersect_launch_scopes(parent, child):