Stop pending actor startup before shutdown - #79
Merged
Merged
Conversation
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stopping an actor during recovery could return before startup ended. Recovery could then create background work after the actor became terminal. Stop also lost errors from recovery cleanup.
Give startup a child fiber and shutdown one shared owner. Shutdown cancels startup, waits for its cleanup, and then closes the runtime. Each external stop caller can cancel its own wait. Owner creation and cache publication finish before caller cancellation can take effect. Self-stop marks the startup fiber interrupted, so recovery fallbacks cannot swallow the stop. Protected recovery regions finish before shutdown completes.
A patch changeset records the fix. The full gate passes type checks, lint, formatting, build, examples, and 379 tests with 828 assertions. Regression tests cover delayed recovery, cause fallbacks, external waiters, protected self-stop, and cleanup errors. Existing synchronous send and Atom behavior tests pass. The state stream test now waits for the initial value and each transition explicitly.
Two Counsel rounds are complete. The final finding has a failing regression on the prior candidate and passes after the repair. The full gate passed again after that repair.