Skip to content

feat(cli): add conductor stop command for background workflows - #12

Merged
Jason Robert (jrob5756) merged 1 commit into
mainfrom
feat/conductor-stop-command
Mar 3, 2026
Merged

feat(cli): add conductor stop command for background workflows#12
Jason Robert (jrob5756) merged 1 commit into
mainfrom
feat/conductor-stop-command

Conversation

@jrob5756

Copy link
Copy Markdown
Collaborator

Summary

  • Add conductor stop CLI command to manage background workflow processes launched with --web-bg
  • Add PID file tracking (~/.conductor/runs/) so background processes can be discovered and stopped
  • Add stop button to web dashboard UI that cancels the running workflow
  • Add POST /api/stop endpoint that races against the workflow engine to actually cancel execution

Details

Previously, stopping a background workflow required manually finding and killing the process (kill $(lsof -ti:PORT)). Now:

  • conductor stop — auto-stops if one running, lists if multiple
  • conductor stop --port 8080 — stop specific port
  • conductor stop --all — stop all background workflows
  • Dashboard stop button — visible when workflow is running, cancels via /api/stop

PID files are written on --web-bg launch and cleaned up on natural completion or explicit stop.

Test plan

  • 13 tests for PID file utilities (test_pid.py)
  • 7 tests for stop CLI command (test_stop.py)
  • 5 tests for /api/stop endpoint and stop signal (test_server.py)
  • All 1567 existing tests pass
  • make lint and make typecheck pass

🤖 Generated with Claude Code

Add PID file tracking and a `stop` CLI command to manage background
workflow processes launched with `--web-bg`. Previously, stopping a
background workflow required manually finding and killing the process.
- Add `pid.py` with PID file read/write/cleanup utilities (~/.conductor/runs/)
- Write PID file in `bg_runner.py` after background launch succeeds
- Clean up PID file on natural child process exit in `run.py`
- Add `conductor stop` command with `--port` and `--all` options
- Add `POST /api/stop` endpoint to web dashboard server
- Add stop button to web dashboard header (visible when workflow is running)
- Race engine.run() against dashboard stop signal so stop actually cancels the workflow
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@jrob5756
Jason Robert (jrob5756) merged commit d7599a1 into mainMar 3, 2026
5 of 6 checks passed
@jrob5756
Jason Robert (jrob5756) deleted the feat/conductor-stop-command branch March 3, 2026 17:48
Jason Robert (jrob5756) pushed a commit that referenced this pull request Aug 24, 2026
Blocking fixes (PR #484 review):
- _restart_spawned_runtime no longer publishes the rebuilt client until
it has actually started: _client/_started are invalidated first, so a
failed start() (e.g. OOM at spawn) leaves the provider correctly
believing no client is started, instead of silently disabling
dead-runtime recovery for the rest of the process.
- The consecutive-restart cap is now checked before incrementing the
counter and is never left stale: the cap can no longer be tripped
after zero actual restarts, the giving-up message reports the real
restart count, and close() resets the counter so a cached provider
isn't permanently wedged after a workflow crash-loops once.
- Replaced the unfalsifiable cap-message assertion in
test_copilot_runtime_recovery.py with one that pins the rendered
clause and asserts the cap actually prevents the next rebuild.
- Added tests/test_providers/conftest.py: an autouse fixture clearing
COPILOT_PROVIDER_RUNTIME_URL/TOKEN so the runtime-recovery tests pass
regardless of the developer's/CI runner's environment.
- Added a regression test covering the corrupted-state bug: when the
rebuilt client's start() raises, _started must end up False and a
later _ensure_client_started() must re-attempt start().
Recommendations applied:
- _runtime_unavailable_error now distinguishes a confirmed-dead process
(poll() returned an exit code) from a broken connection to a still-
alive process, instead of always claiming the process "died" and
suggesting NODE_OPTIONS.
- Client teardown during restart, and session.disconnect() in the
per-agent finally block, now log a warning on failure instead of
silently swallowing the exception (a leaked child / stranded session
is diagnostically useful, especially given this PR's own OOM focus).
- The session.error ProviderError path is now also routed through dead-
runtime classification when retryable, instead of always surfacing a
generic "Copilot SDK error" message that hides an exit-code 137 OOM
kill.
- Narrowed _spawned_runtime_process's return type from Any | None to
subprocess.Popen[bytes] | None, matching the isinstance check the
body already performs and the SDK's own annotation.
- Added a one-time warning when a spawned, started client has no usable
_cli_process handle, so a future SDK rename surfaces instead of
silently degrading recovery to a no-op.
- Fixed the inverted _FakeClient docstring/comments describing mock
auto-vivification as looking "live" when it in fact reads as dead.
- Scoped the restart-counter-reset comment to agent execution (several
auxiliary paths increment without resetting).
- Updated CHANGELOG.md, docs/configuration.md and AGENTS.md to name the
restart cap (2, fixed, non-configurable), correct the "endlessly
retrying" overstatement, and scope the SDK-boundary claim to
agent-execution; documented the _cli_process vs _process split.
Recommendations skipped (not applied): #5 (_interrupted_session reset +
disclosure wording), #6 (max_session pre-flight), #12 (Liveness enum),
#13 (_RestartBudget value type), #17 (per-generation client tracking
for parallel groups), #18 (additional missing tests beyond the one
added for finding #1), #19 (collapsing except clauses), #20 (extracting
shared helpers) -- all correctness-neutral hardening/refactors judged
to grow the diff beyond what this pass should touch; pyproject.toml
dependency cap was also left alone as an unrelated, broader change.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Jason Robert (jrob5756) pushed a commit that referenced this pull request Aug 24, 2026
Blocking fixes (PR #484 review):
- _restart_spawned_runtime no longer publishes the rebuilt client until
it has actually started: _client/_started are invalidated first, so a
failed start() (e.g. OOM at spawn) leaves the provider correctly
believing no client is started, instead of silently disabling
dead-runtime recovery for the rest of the process.
- The consecutive-restart cap is now checked before incrementing the
counter and is never left stale: the cap can no longer be tripped
after zero actual restarts, the giving-up message reports the real
restart count, and close() resets the counter so a cached provider
isn't permanently wedged after a workflow crash-loops once.
- Replaced the unfalsifiable cap-message assertion in
test_copilot_runtime_recovery.py with one that pins the rendered
clause and asserts the cap actually prevents the next rebuild.
- Added tests/test_providers/conftest.py: an autouse fixture clearing
COPILOT_PROVIDER_RUNTIME_URL/TOKEN so the runtime-recovery tests pass
regardless of the developer's/CI runner's environment.
- Added a regression test covering the corrupted-state bug: when the
rebuilt client's start() raises, _started must end up False and a
later _ensure_client_started() must re-attempt start().
Recommendations applied:
- _runtime_unavailable_error now distinguishes a confirmed-dead process
(poll() returned an exit code) from a broken connection to a still-
alive process, instead of always claiming the process "died" and
suggesting NODE_OPTIONS.
- Client teardown during restart, and session.disconnect() in the
per-agent finally block, now log a warning on failure instead of
silently swallowing the exception (a leaked child / stranded session
is diagnostically useful, especially given this PR's own OOM focus).
- The session.error ProviderError path is now also routed through dead-
runtime classification when retryable, instead of always surfacing a
generic "Copilot SDK error" message that hides an exit-code 137 OOM
kill.
- Narrowed _spawned_runtime_process's return type from Any | None to
subprocess.Popen[bytes] | None, matching the isinstance check the
body already performs and the SDK's own annotation.
- Added a one-time warning when a spawned, started client has no usable
_cli_process handle, so a future SDK rename surfaces instead of
silently degrading recovery to a no-op.
- Fixed the inverted _FakeClient docstring/comments describing mock
auto-vivification as looking "live" when it in fact reads as dead.
- Scoped the restart-counter-reset comment to agent execution (several
auxiliary paths increment without resetting).
- Updated CHANGELOG.md, docs/configuration.md and AGENTS.md to name the
restart cap (2, fixed, non-configurable), correct the "endlessly
retrying" overstatement, and scope the SDK-boundary claim to
agent-execution; documented the _cli_process vs _process split.
Recommendations skipped (not applied): #5 (_interrupted_session reset +
disclosure wording), #6 (max_session pre-flight), #12 (Liveness enum),
#13 (_RestartBudget value type), #17 (per-generation client tracking
for parallel groups), #18 (additional missing tests beyond the one
added for finding #1), #19 (collapsing except clauses), #20 (extracting
shared helpers) -- all correctness-neutral hardening/refactors judged
to grow the diff beyond what this pass should touch; pyproject.toml
dependency cap was also left alone as an unrelated, broader change.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Jason Robert (jrob5756) added a commit that referenced this pull request Aug 24, 2026
* fix(copilot): recover from a dead spawned Copilot runtime process
Detect when the nested Copilot runtime subprocess has died (broken
pipe/connection reset, or a check before sending an idle-recovery
prompt) and transparently restart it on the next attempt instead of
surfacing a confusing stuck-agent error. Externally-owned runtimes
(runtime_url) are never restarted here -- that failure is reported as
non-retryable so the owning orchestrator can act. A consecutive
restart counter (reset on any successful SDK call) caps restart
attempts so a runtime that keeps dying before ever succeeding fails
fast rather than looping forever.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* fix(copilot): address review findings on runtime restart state machine
Blocking fixes (PR #484 review):
- _restart_spawned_runtime no longer publishes the rebuilt client until
it has actually started: _client/_started are invalidated first, so a
failed start() (e.g. OOM at spawn) leaves the provider correctly
believing no client is started, instead of silently disabling
dead-runtime recovery for the rest of the process.
- The consecutive-restart cap is now checked before incrementing the
counter and is never left stale: the cap can no longer be tripped
after zero actual restarts, the giving-up message reports the real
restart count, and close() resets the counter so a cached provider
isn't permanently wedged after a workflow crash-loops once.
- Replaced the unfalsifiable cap-message assertion in
test_copilot_runtime_recovery.py with one that pins the rendered
clause and asserts the cap actually prevents the next rebuild.
- Added tests/test_providers/conftest.py: an autouse fixture clearing
COPILOT_PROVIDER_RUNTIME_URL/TOKEN so the runtime-recovery tests pass
regardless of the developer's/CI runner's environment.
- Added a regression test covering the corrupted-state bug: when the
rebuilt client's start() raises, _started must end up False and a
later _ensure_client_started() must re-attempt start().
Recommendations applied:
- _runtime_unavailable_error now distinguishes a confirmed-dead process
(poll() returned an exit code) from a broken connection to a still-
alive process, instead of always claiming the process "died" and
suggesting NODE_OPTIONS.
- Client teardown during restart, and session.disconnect() in the
per-agent finally block, now log a warning on failure instead of
silently swallowing the exception (a leaked child / stranded session
is diagnostically useful, especially given this PR's own OOM focus).
- The session.error ProviderError path is now also routed through dead-
runtime classification when retryable, instead of always surfacing a
generic "Copilot SDK error" message that hides an exit-code 137 OOM
kill.
- Narrowed _spawned_runtime_process's return type from Any | None to
subprocess.Popen[bytes] | None, matching the isinstance check the
body already performs and the SDK's own annotation.
- Added a one-time warning when a spawned, started client has no usable
_cli_process handle, so a future SDK rename surfaces instead of
silently degrading recovery to a no-op.
- Fixed the inverted _FakeClient docstring/comments describing mock
auto-vivification as looking "live" when it in fact reads as dead.
- Scoped the restart-counter-reset comment to agent execution (several
auxiliary paths increment without resetting).
- Updated CHANGELOG.md, docs/configuration.md and AGENTS.md to name the
restart cap (2, fixed, non-configurable), correct the "endlessly
retrying" overstatement, and scope the SDK-boundary claim to
agent-execution; documented the _cli_process vs _process split.
Recommendations skipped (not applied): #5 (_interrupted_session reset +
disclosure wording), #6 (max_session pre-flight), #12 (Liveness enum),
#13 (_RestartBudget value type), #17 (per-generation client tracking
for parallel groups), #18 (additional missing tests beyond the one
added for finding #1), #19 (collapsing except clauses), #20 (extracting
shared helpers) -- all correctness-neutral hardening/refactors judged
to grow the diff beyond what this pass should touch; pyproject.toml
dependency cap was also left alone as an unrelated, broader change.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Jason Robert <jasonrobert@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jrob5756