Terminate timed-out Git process trees (#36793)

## Why

Timing out a Git metadata command must not leave helper processes running after
the command wrapper exits.

## What changed

- Run Git metadata commands in a dedicated process group on Unix and a Job
  Object on Windows so timeout cleanup terminates their full process trees.
- Start Windows commands suspended, assign them to the Job Object, and then
  resume them so immediate descendants cannot escape containment.
- Preserve descendants when a Git command completes normally, and retain the
  existing direct-spawn fallback if Windows Job Object setup fails.

## Testing

Added cross-platform regression tests for cleanup both while the command wrapper
is running and after it exits, plus Windows coverage for immediate-child Job
Object containment.

GitOrigin-RevId: 351851708e23ff06b89fe1894bd09a3558f67293
This commit is contained in:
Colin Young
2026-08-03 19:55:19 +00:00
committed by copyberry
parent e4e0c7070e
commit 3149fa4b99
9 changed files with 337 additions and 18 deletions

1
codex-rs/Cargo.lock generated
View File

@@ -3230,6 +3230,7 @@ dependencies = [
"codex-protocol",
"codex-utils-absolute-path",
"codex-utils-path-uri",
"codex-utils-pty",
"futures",
"gix",
"once_cell",