Skip to content

fix(runtime): avoid service resolution after silo shutdown - #10289

Merged
ReubenBond merged 4 commits into
dotnet:mainfrom
ReubenBond:reubenbond-fix-runtime-client-disposal
Jul 21, 2026
Merged

ReubenBond merged 4 commits into
dotnet:mainfrom
ReubenBond:reubenbond-fix-runtime-client-disposal

Conversation

@ReubenBond

@ReubenBond ReubenBond commented Jul 20, 2026 •

Copy link
Copy Markdown
Member

#10290 closes callback admission and establishes _isStopping before the shutdown callback sweep, but InsideRuntimeClient still lazily resolves several dependencies from runtime paths. A late rejection can therefore reach ReceiveResponse after the silo service provider has been disposed and throw ObjectDisposedException while resolving GrainLocator.

This follow-up mirrors OutsideRuntimeClient.ConsumeServices: InsideRuntimeClient eagerly consumes its dependencies when it participates in the silo lifecycle, after construction but before lifecycle startup. This avoids constructor cycles and eliminates lazy DI resolution from runtime paths without adding shutdown-state reads to hot paths.

Regression coverage delivers an unrecoverable rejection after ungraceful silo shutdown and provider disposal.

Fixes #10282

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Mark the inside runtime client stopped before teardown, drain callbacks even when shutdown is canceled, and bypass disposed runtime services for late responses.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0341b5a4-918f-42ef-9a09-3eae7070127b
@ReubenBond
ReubenBond force-pushed the reubenbond-fix-runtime-client-disposal branch from 63913ae to b0a3656 Compare July 21, 2026 04:07
Mirror the client runtime startup pattern so InsideRuntimeClient does not resolve dependencies from hot paths or after provider disposal. Keep shutdown checks only on response paths which can invoke disposed services.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0341b5a4-918f-42ef-9a09-3eae7070127b
Keep InsideRuntimeClient service consumption self-contained in Participate instead of coordinating it from Silo.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0341b5a4-918f-42ef-9a09-3eae7070127b
Rely on eager service consumption and the existing callback admission boundary instead of checking shutdown state in inbound message paths.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0341b5a4-918f-42ef-9a09-3eae7070127b
@ReubenBond
ReubenBond merged commit 9617577 into dotnet:main Jul 21, 2026
172 of 176 checks passed
@ReubenBond
ReubenBond deleted the reubenbond-fix-runtime-client-disposal branch July 21, 2026 14:47
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 21, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Avoid resolving services from InsideRuntimeClient after provider disposal

1 participant