Apply backpressure when a worker stops reading
A stalled child leaves the supervisor buffering every request body until memory is exhausted.
- Focused work estimate
- 4h + prerequisites
- Priority in the scenario
- High
- Engineering practice
- Backpressure · Resource isolation
Estimated field mix
- Systems programming60%
- Performance engineering40%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Pattern topics
- BulkheadApply
Isolate each child process buffer and preserve global capacity so one stopped reader cannot consume every supervisor resource.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional document converter launches local sandbox substitutes as child processes. Its prototype parses newline-delimited output, leaks descriptors, and retries requests after ambiguous worker exits. Create a Rust supervisor and deterministic worker fixtures; no document content or production sandbox is supplied.
Setup prerequisites
- File descriptors
- Framing
- Process signals
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
Acceptance criteria
- Per-worker and global pending byte limits are enforced
- Admission reports overload before consuming the body
- Healthy workers can continue within their own capacity
Implementation constraints
- Do not solve the stall with an unbounded retry queue.
Verification to include
- Drive balanced workers to their declared capacity.
- Pause one reader and prove buffers remain bounded while another worker progresses.
Deliverables
- IPC admission controller and stalled-reader test
Rollout and recovery
Start with small limits and expose overload to callers.
Value of the work
For the engineer: Practice IPC contracts, resource inheritance, process supervision and ambiguous completion.
For the team: Review a local worker boundary that contains crashes and preserves request outcomes before connecting an isolated execution provider.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.