Skip to content

Fix stdin relay for pipes in IsoSession - #1450

Draft
Dom Giandinoto (daamenik) wants to merge 1 commit into
mainfrom
user/dgiandinoto/fix-stdin-relay-handle-leak
Draft

Dom Giandinoto (daamenik) wants to merge 1 commit into
mainfrom
user/dgiandinoto/fix-stdin-relay-handle-leak

Conversation

@daamenik

@daamenik Dom Giandinoto (daamenik) commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

📖 Description

For a given sandbox, relays copy stdin bytes to the sandbox and stdout/stderr bytes back. There are two stdin relay types: a console-oriented one that listens for a stop event, and a pipe-oriented one that runs until EOF or until a cancel switch is fired.

The isolation_session backend chose the stdin relay type from the interactivity of stdout, not stdin. So piped input was handed the stop-aware console relay instead of the pipe-friendly one. Two consequences:

  • Delivery failure (user-visible): the console relay's first console read fails on a pipe handle, so piped input was never read at all — the workload blocked waiting for input it never received.
  • Latent handle leak: at teardown the console relay can't be cancelled, so its thread stays blocked and never releases the duplicated write handle to the agent's stdin.

This change classifies the stdin handle at runtime and routes pipe/file stdin to the cancellable pipe relay, so piped I/O works and the destination handle is released on teardown.

🔗 References

🔍 Validation

Manual repro (console stdout + piped stdin): before = no output, ~30s hang, non-zero exit; after = input echoed, prompt exit 0

  • Config's command line read a line from stdin, echoed it back in the format "SANDBOX_STDIN="
  • 'HELLO FROM CALLER' | .\wxc-exec.exe --experimental $config 2>&1 ; "EXIT=$LASTEXITCODE"

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task

GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See pull request builds.

If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See pull request builds
for the steps.

… changed from just relying on interactive trait of stdout
@daamenik
Dom Giandinoto (daamenik) requested a review from a team as a code owner October 8, 2026 08:05
Copilot AI balanced review requested due to automatic review settings October 8, 2026 08:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Natural stdin EOF is not propagated to workloads that read until EOF, potentially causing an indefinite wait.

1 open finding
What changed in this PR

Fixes IsolationSession stdin relay selection for redirected pipe/file input.

Changes:

  • Classifies stdin by its actual Windows handle type.
  • Uses cancellable relays for pipe/file stdin.
  • Adds cancellation and destination-handle release coverage.
File Description
pipe_relay.rs Documents redirected-stdin behavior and tests cancellation cleanup.
manager.rs Selects and tears down stdin relays by handle type.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment on lines +599 to +605
StdinRelayKind::CancellablePipe => {
let (thread, canceller) = unsafe {
create_relay_thread(
wxc_stdin,
HANDLE(stdin_handle_val as *mut core::ffi::c_void),
)
}

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants