Skip to content

test(budget): give a Windows child spawn the cold-start headroom it measures - #4830

Merged
lidge-jun merged 1 commit into
devfrom
codex/2570-windows-spawn-budget
Sep 16, 2026
Merged

lidge-jun merged 1 commit into
devfrom
codex/2570-windows-spawn-budget

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Sep 16, 2026 •

Copy link
Copy Markdown
Owner

The failure

dev has been red for five consecutive Cross-platform CI runs. One of the two remaining Windows
failure classes is this:

error: Timed out waiting for a real port in ...\ocx-native-startup-BKiCqN\port; childExit=null; elapsedMs=45004
      at waitForPort (tests/codex-integration/native-profile-startup.test.ts:271:17)

Run 35118018849, job 104895935554, windows 1/6. The interesting line is three lines later in
the same log: [native-startup] port-published elapsedMs=50728. The child was not hung. It
published its port 5.7 seconds after the harness gave up, and the very next case in the same file
was ready in 1759ms.

Why raise the budget rather than the test

tests/helpers/test-budget.ts sets two conditions for raising a budget. Both hold here. The wait
is intrinsic: the spawned proxy child reaching its port file is the assertion, which is why the
file already carries two comments recording 8-19s and 10-18s spawns on loaded Windows shards.
And the ablation still fails: nothing about this change makes a child that never publishes pass —
it fails at 90s instead of 45s.

What 45s was measuring on Windows is runner contention. The leg runs four Bun pools on one runner
and the first spawn in a file pays a cold start the rest do not.

The change

SPAWN_BUDGET_MS becomes 90s on win32 and stays 45s everywhere else, following the shape
BULK_DURABLE_IO_BUDGET_MS already uses in this file for the same reason. Every other lane keeps
the shorter signal.

Validation

No local suite, typecheck or build was run. The evidence is the hosted run above: the measured
publish time, the passing sibling spawn, and the file's own recorded Windows spawn costs.

Summary by CodeRabbit

  • Bug Fixes
    • Adjusted test execution time limits by platform, allowing longer spawn operations on Windows while retaining the standard limit elsewhere.

…easures

The first proxy child in native-profile-startup.test.ts published its port at
50.7s against a 45s SPAWN_BUDGET_MS while the next spawn in the same file was
ready in 1.8s. Gate the budget to 90s on win32 only, the same way
BULK_DURABLE_IO_BUDGET_MS already is.
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 16, 2026 17:35
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-16T17:37:10.568477Z 605f0ba PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the chore Maintenance, CI, tests, refactors, or build changes (not a user-facing bug or feature). label Sep 16, 2026
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d612e7fd-f881-406b-941a-59ea5701138e

📥 Commits

Reviewing files that changed from the base of the PR and between d78be30 and 605f0ba.

📒 Files selected for processing (1)
  • tests/helpers/test-budget.ts

Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

SPAWN_BUDGET_MS now uses platform-specific values. Windows receives a 90-second budget. Other platforms retain the 45-second budget.

Changes

Spawn budget configuration

Layer / File(s) Summary
Platform-specific spawn budget
tests/helpers/test-budget.ts:34-50
SPAWN_BUDGET_MS now delegates to spawnBudgetMs(). The helper returns 90_000 milliseconds on Windows and 45_000 milliseconds on other platforms.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 605f0

No concrete merge-blocking risk is evident; Windows startup tests receive additional time while other platforms are unchanged.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the budget test change and the Windows-specific increase in child-spawn headroom. It accurately reflects the main change.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/2570-windows-spawn-budget

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lidge-jun

Copy link
Copy Markdown
Owner Author

리뷰 · 우선순위 74 / 80

이 PR은 제품 로직이 아니라 테스트 예산(숫자) 만 고친다. 지금 dev HEAD는 d78be30da(#4828 릴리스 트레인 문서)이고, package.json은 여전히 2.57.0이다. 릴리스 문서(010_dev_green.md)가 적어 둔 “다섯 번 연속 Cross-platform 빨강” 중 Windows 쪽 실패 한 종류가 바로 이것이다. tests/codex-integration/native-profile-startup.test.ts의 waitForPort가 SPAWN_BUDGET_MS(45초) 안에 자식이 쓴 port 파일을 못 보면 타임아웃인데, 호스트 런 35118018849 / job 104895935554(windows 1/6)에서는 하니스가 45초에 포기한 뒤 같은 자식이 50.7초에 port를 공개했고, 바로 다음 케이스는 1.8초에 통과했다. 즉 자식이 죽은 게 아니라, 파일 첫 spawn의 콜드 스타트가 예산보다 길었다.

고치는 파일은 하나다. tests/helpers/test-budget.ts에서 SPAWN_BUDGET_MS를 상수 45000에서 spawnBudgetMs()로 바꾸고, win32만 90000·그 외는 45000을 돌려준다. 같은 파일의 BULK_DURABLE_IO_BUDGET_MS/bulkDurableIoBudgetMs()가 이미 “Windows + 네 Bun 풀 경합이면 천장만 올린다”는 모양이라, 이번 패치는 그 규칙을 spawn 예산에도 그대로 옮긴 것이다. 파일 맨 위 주석의 예산 올리기 조건 두 개(대기가 assertion 자체인지, ablation 해도 여전히 실패하는지)를 PR 본문이 둘 다 짚는다. port를 영원히 안 쓰는 자식은 90초에도 실패하고, Linux/macOS 레인은 짧은 신호(45초)를 유지한다.

왜 지금 dev에 중요하냐면, 2.57.0 후보로 이름 붙인 2b19983bfd(#4821 Bun 1.4.0 핀) 위의 Cross-platform이 아직 초록으로 증명되지 않았고, 문서도 “하네스/런타임 flake”로 분류했다. 이 PR은 그 flake 중 측정된 spawn 콜드 스타트 한 칸을 예산으로 흡수한다. 제품 코드를 싣는 랜딩이 아니라 CI 신호 복구다. 직접 메인테이너(lidge-jun) 브랜치 codex/2570-windows-spawn-budget, 로컬 suite/typecheck/build는 돌리지 않았고 증거는 위 호스트 로그다.

부작용으로 native-profile-startup.test.ts의 CHILD_CASE_BUDGET_MS = 2 * SPAWN_BUDGET_MS도 Windows에서 90초→180초가 된다. waitForPort 기본값은 그대로 SPAWN_BUDGET_MS라 포트 대기는 90초 천장이고, 케이스 전체 예산만 같이 늘는다. 의도된 연동으로 보이지만, 다른 파일이 SPAWN_BUDGET_MS를 곱해 쓰면 Windows에서만 조용히 길어지니 소비처를 한 번 훑는 편이 안전하다.

라인 34 - SPAWN_BUDGET_MS가 함수 호출 결과로 바뀌면서 모듈 로드 시점의 process.platform에 고정된다. 테스트가 플랫폼을 런타임에 속이는 방식이면(드묾) 예전 상수와 다르게 동작한다. 지금 소비처는 실제 win32 CI를 전제로 하므로 실무상 문제는 작다.

경로 tests/helpers/test-budget.ts / spawnBudgetMs - 90초가 “측정 50.7초 + 여유”인지는 맞지만, 네 Bun 풀 경합이 더 심해지면 90초도 다시 깨질 수 있다. 다음 실패 때는 숫자를 또 올리기 전에 shard/풀 배치를 먼저 볼지 정해야 한다.

경로 tests/codex-integration/native-profile-startup.test.ts - 파일 주석에 이미 “Windows shard에서 10-18초 spawn”이 적혀 있는데, 이번 증거는 50.7초다. 주석과 예산이 어긋난 채로 남으면 나중에 읽는 사람이 45초를 다시 넣고 싶어질 수 있다. 예산 PR과 같은 랜딩이 아니어도, 주석의 상한을 한 줄 갱신할지 판단이 필요하다.

메인테이너의 판단이 필요한 지점

  • 릴리스 문서가 “2.57.0에 제품 PR을 더 싣지 않는다”고 했는데, 이 하네스 예산 패치를 후보 초록 증명 전에 dev에 넣을지(권장) 아니면 tip을 후보 SHA에 고정한 채 재실행만 할지.
  • PR 본문이 말한 “남은 Windows 실패 클래스 두 개 중 하나”의 다른 하나를 같은 트레인에서 막을지, 이 PR만 먼저 넣을지.
  • CHILD_CASE_BUDGET_MS가 180초로 늘어나는 부작용을 수용할지, 케이스 예산을 spawn과 분리할지.

너의 추천
머지해도 된다. 제품 freeze와 충돌하지 않는 CI 예산 패치이고, 기존 BULK_DURABLE_IO_BUDGET_MS 패턴과 증거가 맞다. 머지 후 같은 tip(또는 이 커밋이 쌓인 tip)에서 Cross-platform을 다시 돌려 초록 run id를 040_release.md에 적는 흐름이 릴리스 트레인과 맞다. 로컬 검증은 없어도 호스트 측정이 충분하다. 다만 남은 Windows 실패 클래스가 있으면 그 PR/이슈 번호를 이 PR 본문이나 후속 이슈에 한 줄로 박아 두라.

이 댓글은 grok-bot이 작성했습니다

@lidge-jun

Copy link
Copy Markdown
Owner Author

Maintainer integration into dev under the 2026-09-06 owner authorization in MAINTAINERS.md, not a self-approval.

Exact head 605f0bad2f4fc95c9d122a33b8ad895f7bb831a9, Cross-platform CI run 35129111694: success. Test-harness only; no product code changes. The Windows matrix is skipped on pull-request events, so the failure class this addresses is proven on the dev push run that follows this merge.

@lidge-jun
lidge-jun merged commit 1831193 into dev Sep 16, 2026
29 checks passed
@lidge-jun
lidge-jun deleted the codex/2570-windows-spawn-budget branch September 16, 2026 17:55
lidge-jun added a commit that referenced this pull request Sep 16, 2026
…sable port (#4834)

PR #4830 raised SPAWN_BUDGET_MS on win32 from 45s to 90s to fix one test
case. 31 test files read that constant and nine hand it to
setDefaultTimeout, so the edit reached 339 Windows cases: 315 went 45s to
90s, 22 more that multiply it went 90s to 180s, and one derivation chain
in codex-sync-api reached 265s. The detectors that now report twice as
late are the contention ones -- codex-write-lock, the cross-process
history-lock exclusions, the shim process cases -- and several of the
affected files never spawn anything.

The measurement behind #4830 was also contaminated. The child published
its port through atomicWriteFile, the production SECRET writer, which on
Windows runs hardenSecretPath(..., required: true) twice, each able to
spawn PowerShell for SID resolution and several 30s-budgeted icacls
passes. That ACL ceremony ran inside the window the parent measures as
"time to reach a port" -- on a disposable port number.

- SPAWN_BUDGET_MS returns to 45s on every platform.
- COLD_SPAWN_BUDGET_MS (90s, win32 only) is consumed exactly once, by the
  readiness wait of the first proxy child in native-profile-startup.
- The child publishes its port and settled markers with a plain temp-file
  rename, preserving the #1061 no-partial-read contract without the ACL
  ceremony.
- The child logs child-entry, start-server-begin, start-server-end and
  port-published, so the next slow run names its own phase.
- codex-sync-api owns its bounds instead of deriving them, which returns
  that case to 130s and makes it immune to the next edit of a shared
  constant. It also reports its measured preparation window on green runs.

Co-authored-by: lidge-jun <lidge-jun@users.noreply.github.com>
agentHits pushed a commit to agentHits/opencodex that referenced this pull request Sep 17, 2026
…easures (lidge-jun#4830)

The first proxy child in native-profile-startup.test.ts published its port at
50.7s against a 45s SPAWN_BUDGET_MS while the next spawn in the same file was
ready in 1.8s. Gate the budget to 90s on win32 only, the same way
BULK_DURABLE_IO_BUDGET_MS already is.

Co-authored-by: lidge-jun <lidge-jun@users.noreply.github.com>
agentHits pushed a commit to agentHits/opencodex that referenced this pull request Sep 17, 2026
…sable port (lidge-jun#4834)

PR lidge-jun#4830 raised SPAWN_BUDGET_MS on win32 from 45s to 90s to fix one test
case. 31 test files read that constant and nine hand it to
setDefaultTimeout, so the edit reached 339 Windows cases: 315 went 45s to
90s, 22 more that multiply it went 90s to 180s, and one derivation chain
in codex-sync-api reached 265s. The detectors that now report twice as
late are the contention ones -- codex-write-lock, the cross-process
history-lock exclusions, the shim process cases -- and several of the
affected files never spawn anything.

The measurement behind lidge-jun#4830 was also contaminated. The child published
its port through atomicWriteFile, the production SECRET writer, which on
Windows runs hardenSecretPath(..., required: true) twice, each able to
spawn PowerShell for SID resolution and several 30s-budgeted icacls
passes. That ACL ceremony ran inside the window the parent measures as
"time to reach a port" -- on a disposable port number.

- SPAWN_BUDGET_MS returns to 45s on every platform.
- COLD_SPAWN_BUDGET_MS (90s, win32 only) is consumed exactly once, by the
  readiness wait of the first proxy child in native-profile-startup.
- The child publishes its port and settled markers with a plain temp-file
  rename, preserving the lidge-jun#1061 no-partial-read contract without the ACL
  ceremony.
- The child logs child-entry, start-server-begin, start-server-end and
  port-published, so the next slow run names its own phase.
- codex-sync-api owns its bounds instead of deriving them, which returns
  that case to 130s and makes it immune to the next edit of a shared
  constant. It also reports its measured preparation window on green runs.

Co-authored-by: lidge-jun <lidge-jun@users.noreply.github.com>
lidge-jun added a commit that referenced this pull request Sep 17, 2026
… they now measure (#4843)

The first round added the instrumentation; this one uses it. Run
35141541461 measured the Windows preparation window at 2740ms and the
Linux/macOS one at 423-575ms, against a reserve that had been guessing at
52.7s. Boot drops 40s to 30s and the Windows preparation reserve 80s to
55s, which takes the case from 265s to 95s while still leaving room for
the 52.7s outlier the reserve was written for: that much preparation
still leaves the flip its full boot budget and its reap.

The same run also showed every readiness wait in native-profile-startup
at 2.0-4.9s on all six Windows shards, first child included, confirming
the 50.7s observation behind #4830 was the ACL ceremony rather than a
cold start. COLD_SPAWN_BUDGET_MS is kept as a bound against the part one
run cannot rule out, with a note to delete rather than raise it.

Co-authored-by: lidge-jun <lidge-jun@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance, CI, tests, refactors, or build changes (not a user-facing bug or feature).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant