deepseek-harness/packages/experimental/code-runtime-python/README.i18n.yaml

7 lines
451 B
YAML
Raw Normal View History

# Bilingual-pair consistency record (docs/i18n/README.md): the git blob hash of each
# side as of the last confirmed-consistent state. Both languages carry equal authority;
# after editing either side, bring the other along and re-record with:
# pnpm run verify-translation-pairing --write packages/experimental/code-runtime-python/README.md
fix(code-runtime-python): bound reply and call backlogs, snapshot binding metadata, and compact the reply queue Review findings on the CPython backend: a child that never reads fd 3 leaves the reply pipe full forever, so the drain loop waits on 'drain' while every call frame it keeps sending resolves a binding and queues another reply — the backlog (and the binding results it pins) would grow until the wall clock. sendReply now caps the pending backlog at MAX_PENDING_REPLIES and settles the run as worker-exit past it, mirroring the frame cap; a child flooding calls against a binding that never settles would otherwise bypass that cap (pendingReplies grows only after the await), so the dispatcher counts in-flight binding calls before dispatch and releases the slot in the async body's finally, capping outstanding closures at the same bound. The drain also compacts its consumed prefix (replyQueue.splice(0, head)) once head reaches the bound, so a drain that stays alive without emptying cannot grow the backing store linearly with cumulative throughput. The completion-value meter counted lone surrogates with _SURROGATE.findall(folded), materializing one single-character string per surrogate: a surrogate-dense value near the budget (millions of surrogates, each serializing to six bytes) allocated millions of objects before the meter returned, defeating the meter's counting-without-building contract. The count is now the length difference between folded and the without string the meter already computes; a standalone equivalence check confirms it matches findall across lone-high, lone-low, paired, astral, and mixed cases. validateBindings read namespace.global/errorClass.name/memberNameProperty several times and retained the original errorClass object for the boot frame, whose JSON.stringify re-read it after validation: a stateful getter could throw or change between the two stages, turning the seam-misuse rejection into a worker-exit or injecting an unvalidated name. Each field is now read once into a plain value and the bindings map stores a plain { name, memberNameProperty } copy, so validation and the boot frame see identical values. Regression tests: a hostile child floods 5000 sequential valid calls without reading fd 3 and the run settles worker-exit with the reply-queue message before maxWallMs; a 3,000,000-surrogate completion succeeds at an 18,000,002-byte budget and reports output-limit one byte under; a 5000-call flood against a never-settling binding settles worker-exit with the call-backlog message; getter-backed namespace metadata that throws or changes on a second read boots and runs with each field read exactly once; a two-wave flood whose replies exceed the writable high-water mark drives the drain past the compaction bound mid-delivery and verifies all 1524 replies arrive. README Known Limitations gains the reply-backlog and call-backlog bounds (en/zh, pairing re-recorded); a new Agent Note registers the findings.
2026-08-29 23:51:17 +08:00
README.md: 1009c150a320e23811bae01e989e82cefeb9b907
README.zh.md: b3dd8803855b9f579f2d1cfdd155ff3691b4573b