fix(db): defer process.exit(0) by a macrotask on graceful shutdown (#13306) - #13778
Merged
diegosouzapw merged 3 commits intoSep 16, 2026
Merged
Conversation
…13306) sql.js's Emscripten WASM build leaves pending libuv async-handle teardown work in flight after a statement has run. gracefulShutdown.ts's shutdown closure called process.exit(0) in the same tick as the cleanup promise resolving, tearing the event loop down before that teardown settled. On Windows, libuv's async-handle close path asserts !(handle->flags & UV_HANDLE_CLOSING) when this happens, aborting the process (exit 127); Linux's unix backend has no equivalent assertion, which is why this was invisible on CI. Deferring process.exit(0) by one macrotask (setTimeout(..., 0)) mirrors the pattern already used throughout 9router's own shutdown call sites and gives sql.js's pending libuv work a chance to settle first. Regression test: tests/unit/graceful-shutdown-deferred-exit-13306.test.ts pins the ordering contract (process.exit(0) must not fire in the same microtask turn cleanup() resolves in). The Windows abort itself cannot be reproduced on Linux CI — see the PR body for the required live Windows validation.
…6-windows-libuv-abort-sqljs-exit
…exit (base-red fix #13747)
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…iegosouzapw#13306) (diegosouzapw#13778) Merged in the 2026-09-16 sweep of the maintainer's own open PRs, at the owner's explicit instruction. No push was made to the PR branch: the merge took the head as the owning session left it (verified OPEN, non-draft and MERGEABLE against the release tip immediately before merging).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #13306
Root cause (short)
sql.jsis an Emscripten WASM build; once a statement has run (db.run()/adapter.exec()), Emscripten leaves async cleanup/teardown work registered with libuv.gracefulShutdown.ts'sshutdownclosure calledprocess.exit(0)in the same tick the cleanup promise resolved, tearing the event loop down synchronously before that teardown work settled. On Windows, libuv's async-handle close path (src/win/async.c) asserts!(handle->flags & UV_HANDLE_CLOSING)when this happens, aborting the process (exit 127). Linux's unix backend has no equivalent assertion, which is why CI (Linux-only) never caught it and it stayed invisible until a Windows contributor hit it locally.Fix
Defer
process.exit(0)by one macrotask (setTimeout(() => process.exit(0), 0)) instead of calling it synchronously right after the cleanup promise resolves. This mirrors the pattern already used throughout 9router's own shutdown call sites (appUpdater.js:199,cli/cli.js:675etc.) and gives sql.js's pending libuv teardown work a chance to run before the event loop tears down. The delay is unconditional (applies to every driver, not just sql.js) since a 0mssetTimeoutis a no-op-cost change when sql.js isn't involved.Regression test (path + RED output excerpt on unfixed code + GREEN excerpt)
tests/unit/graceful-shutdown-deferred-exit-13306.test.ts— pins the ordering contract the fix depends on (this cannot reproduce the Windows libuv abort itself; Linux has no equivalent assertion, see "Live check" below):RED (before the fix):
GREEN (after the fix):
Gates run
npx eslint --suppressions-location config/quality/eslint-suppressions.json src/lib/gracefulShutdown.ts tests/unit/graceful-shutdown-deferred-exit-13306.test.ts→ clean, exit 0npm run typecheck:core→ clean, no errorsnode scripts/check/check-file-size.mjs→ no ✗ on touched files (one pre-existing ✗ onopen-sse/utils/stream.ts, a file this PR does not touch — confirmed identical toorigin/release/v3.8.51, base drift)node scripts/check/check-complexity.mjs→ OK, no violation on the touched functionnode scripts/check/check-cognitive-complexity.mjs→OK — 1276 violações (baseline 1437), no regressionnode scripts/check/check-test-discovery.mjs→OK — 5780 arquivos de teste, new test file discoveredgracefulShutdown.tstests:tests/unit/graceful-shutdown-sighup-8045.test.ts→ both cases pass unchangedExisting tests aligned
None needed — no existing test encoded the old synchronous-exit behavior.
Live check (required before merge)
This fix cannot be verified on Linux CI (no libuv assertion equivalent on the unix backend). A live Windows run is required before merge:
better-sqlite3prebuilt binary available, sopreInitSqlJs()is used).src/lib/db/) so a sql.js statement has executed at least once.SIGHUP, fix(startup): Windows restart fails with "Database closed" / SQLite driver detection (500) #8045),taskkill /PID <pid>without/F(SIGTERM), or Ctrl+C (SIGINT).[Shutdown] Bye.+ exit 0) and stderr does not containAssertion failed: !(handle->flags & UV_HANDLE_CLOSING), file src\win\async.c, line 94.Not covered here
needs-vpsverdict, and the live-check above is the outstanding validation step.driverFactory.test.tsis unrelated to this trigger (confirmed by the reporter's own follow-up) and is untouched.