Corral - Kill every command your agent starts
Show HN: Corral – Kill every command your agent starts
Corral is a Linux tool that runs a command with a time limit and guarantees no leftover processes when it returns. It solves a common problem for AI coding agents and CI jobs: processes that daemonize, ignore SIGTERM, or hold output pipes open. Corral controls the full process tree using cgroup v2 or subreaper fallback, ensuring a clean slate. Install via prebuilt binary or build from source. Use with options like --wall, --mem, and --json for audit records. Corral leaves no process alive, as benchmarked against timeout and naive runners.
When corral returns, no process that the command started is still alive. corral verifies this before it returns.
- Retr0id
A trivial bypass I can imagine is spawning a new process via `ssh localhost foo` - the new process forks from sshd, not the client. This is simple enough that an LLM could come up with it all on its own, if it feels that you're getting in its way.
It's a broad class of bypasses that can apply to just about any "long running daemon can be instructed to spawn a new child" situation.
- pmoriarty
Why not the timeout[1] command?
[1] - https://www.man7.org/linux/man-pages/man1/timeout.1.html
- ethanj8011
slop core