Defect
When a Leash-managed target exits during its bootstrap entrypoint, the runner immediately launches the sidecar. Docker then rejects the sidecar with cannot join network namespace of a non running container, and that secondary error is the only diagnostic surfaced to the orchestrator.
The primary target diagnostic remains only in docker logs <target> and is removed during normal cleanup.
Reproduction
- Walk
v0.2.2 (3b2431d)
- Leash CLI release tag
native-v0.3.2 (43e8715), using its Docker/container backend
- Target image
walk33-bmad-codex:v0.2.2
- Synthetic credential only
The target bootstrap exits with:
leash-error: update-ca-trust or update-ca-certificates not found
The caller instead receives:
cannot join network namespace of a non running container
Process tracing confirms the Docker/container runner launched the target first with --user 0 --entrypoint /leash/leash-entry-linux-amd64; this is independent of target Config.User handling and did not exercise Leash's host-process native runtime.
Expected
- Detect target exit before or while launching the sidecar.
- Surface the target bootstrap exit code and sanitized target diagnostic as the primary error.
- Keep the sidecar namespace error, if useful, as secondary context only.
- Preserve machine-output stdout purity and do not expose environment values, credential contents, or secrets.
- Cover an intentionally failing target bootstrap in a focused runner regression.
Relationship
Discovered while correcting Walk #64. Walk owns the incompatible generated image in Walk PR #66; Leash owns preservation of the primary bootstrap diagnostic.
Defect
When a Leash-managed target exits during its bootstrap entrypoint, the runner immediately launches the sidecar. Docker then rejects the sidecar with
cannot join network namespace of a non running container, and that secondary error is the only diagnostic surfaced to the orchestrator.The primary target diagnostic remains only in
docker logs <target>and is removed during normal cleanup.Reproduction
v0.2.2(3b2431d)native-v0.3.2(43e8715), using its Docker/container backendwalk33-bmad-codex:v0.2.2The target bootstrap exits with:
The caller instead receives:
Process tracing confirms the Docker/container runner launched the target first with
--user 0 --entrypoint /leash/leash-entry-linux-amd64; this is independent of targetConfig.Userhandling and did not exercise Leash's host-process native runtime.Expected
Relationship
Discovered while correcting Walk #64. Walk owns the incompatible generated image in Walk PR #66; Leash owns preservation of the primary bootstrap diagnostic.