Corral is a Linux utility that runs a command with a wall-clock time limit and guarantees no descendant process remains alive when it returns. It achieves this by controlling the full process tree: in enforced mode it places the job in a delegated cgroup v2 and can atomically kill the group; in fallback mode it becomes a child subreaper, discovers orphaned processes via /proc, and signals them using pidfds. Runs end when the command itself exits (not when pipes close), and corral verifies no processes remain - if it cannot prove that, it exits with code 120. It supports limits for time, memory, number of PIDs, and combined stdout/stderr size, emits a JSON audit record, and requires Linux 5.11+ (5.14+ for enforced mode). It is explicitly not a security sandbox.
Benchmarks test ten fault programs against corral (enforced/fallback), a timeout tool, and a naive Python runner. Corral left no processes alive in any test and enforced mode enforced memory limits (e.g., stopped a 256 MiB test at 64 MiB quickly), while other runners sometimes left daemons or large numbers of children running. Measured overheads are small (single-digit ms to tens of ms). Limitations include inability to control work started outside the process tree (systemd-run, D-Bus, at), possible group escape if a process manipulates cgroupfs, fallback inability to signal setuid children, no PTY or CPU-time limits, and Linux-only operation. Licensed MIT.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.