Publish exit events to subscribers; the VFS releases dead clients' handles (M17.3)

process_subscribe adds an endpoint to a bounded, ref-counted subscriber
table; every death posts the same badge encoding a supervisor's exit
notification uses, equally late, so subscribers observe a fully-released
child. A dying subscriber's own subscriptions are removed first — it never
hears about itself. The VFS is the first subscriber: open handles now
record their owner and are swept when the owner dies, because a service
must never depend on clients cleaning up after themselves
(docs/process-lifecycle.md). Proven by the vfs-client-death scenario.
This commit is contained in:
Daniel Samson
2026-07-12 23:41:44 +01:00
parent 2ebfb0c3b0
commit d8c55c6f2f
8 changed files with 202 additions and 7 deletions
+4 -1
View File
@@ -35,7 +35,10 @@ only when its definition of green holds.
- [x] **M17.2** — exit reasons (`ExitReason` recorded at exit/fault/kill before
the notification; `process_exit_reason` supervisor-gated;
`runtime.process.exitReason`; kernel + ring-3 assertions; suite 49/49)
- [ ] **M17.3** — published exit events + VFS subscriber
- [x] **M17.3** — published exit events + VFS subscriber (`process_subscribe`,
bounded ref-counted table, publish on every death;
`runtime.process.subscribeExits`; VFS handles carry owners and are swept on
the owner's death; `vfs-client-death` test; suite 50/50)
- [ ] **M17.4** — signals, timer notifications, `runtime.process`, the service harness
- [ ] **merge** `feat/process-lifecycle` → main, push
- [ ] **M18.1** — device-manager protocol: hello + restart policy (branch `feat/device-manager`)