github.com

Show HN: Corral – Kill every command your agent starts

CG144 · 17 points · 4 comments · 昨天 · 打开原文

This summer I got to intern on the backend of an AI agent and I noticed that it would run commands like tail -f or some random background jobs and exit without terminating any of these. I got curious and looked up how Claude Code handles stuff like this, and it turns out they have similar problems. There are issues about background processes from the Bash tool not getting cleaned up when the session ends, and one where a timeout sends SIGTERM to the whole process group and ends up killing Claude Code itself. Most runners only kill the process they started, so anything that double forks, runs in the background, or keeps stdout open either survives or makes the runner hang. Corral was me attempting to make a fix for this problem, while also trying to learn about processes and signals in Linux. You run corral --wall 30s -- yourcommand and by the time it's done, nothing it started should be running. The command gets its own session so killing it can't kill you, and there's a mode where it runs in its own cgroup so the whole tree gets killed at once, including processes that may have changed sessions or process groups. If there's no cgroup available it tracks the tree through /proc instead (this is a bit weaker, it still catches processes that changed sessions once their parent dies, but it can't kill anything running as a different user or anything handed off to another service like systemd), and if it can't confirm everything is dead it exits with 120. Would love any feedback and more stuff along these lines i can do to learn more

评论

3 条预览评论 · 正在加载完整讨论
pmoriarty20小时前

Why not the timeout[1] command? [1] - https://www.man7.org/linux/man-pages/man1/timeout.1.html

Retr0id52分钟前

A trivial bypass I can imagine is spawning a new process via `ssh localhost foo` - the new process forks from sshd, not the client. This is simple enough that an LLM could come up with it all on its own, if it feels that you're getting in its way. It's a broad class of bypasses that can apply to just about any "long running daemon can be instructed to spawn a new child" situation.

ethanj801119小时前

slop core