fix(watchers): exempt runaway shells from protection to prevent host OOM

- update is_protected() in box-stability-watcher.py to revoke immunity from bash/zsh processes with RSS >= 2048MB
- update watchers/README.md to document the 2048MB interactive shell threshold
- add unit tests verifying shell protection vs runaway exemption in test_box_stability_watcher.py
This commit is contained in:
operator
2026-10-07 21:09:45 +00:00
parent 0a45133d28
commit 2a2a808778
3 changed files with 13 additions and 4 deletions
+3
View File
@@ -37,6 +37,9 @@ class TestConfigAndSafety(unittest.TestCase):
self.assertTrue(w.is_protected(777, "tailscaled", "/usr/sbin/tailscaled", cfg))
self.assertFalse(w.is_protected(1234, "muse-bin", "/home/super/.local/bin/muse-bin-1.4.3 resume abc", cfg))
self.assertFalse(w.is_protected(5678, "chromium", "/usr/lib/chromium/chromium --type=renderer", cfg))
# Shell protection & runaway exemption
self.assertTrue(w.is_protected(9999, "bash", "/bin/bash", {"protected_commands": ["bash"]}, rss_mb=50))
self.assertFalse(w.is_protected(9999, "bash", "bash test_script.sh", {"protected_commands": ["bash"]}, rss_mb=2500))
class TestStabilityEvaluation(unittest.TestCase):