fix(runtime): avoid service resolution after silo shutdown - #10289
Merged
ReubenBond merged 4 commits intoJul 21, 2026
Merged
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Mark the inside runtime client stopped before teardown, drain callbacks even when shutdown is canceled, and bypass disposed runtime services for late responses. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0341b5a4-918f-42ef-9a09-3eae7070127b
ReubenBond
force-pushed
the
reubenbond-fix-runtime-client-disposal
branch
from
July 21, 2026 04:07
63913ae to
b0a3656
Compare
Mirror the client runtime startup pattern so InsideRuntimeClient does not resolve dependencies from hot paths or after provider disposal. Keep shutdown checks only on response paths which can invoke disposed services. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0341b5a4-918f-42ef-9a09-3eae7070127b
Keep InsideRuntimeClient service consumption self-contained in Participate instead of coordinating it from Silo. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0341b5a4-918f-42ef-9a09-3eae7070127b
Rely on eager service consumption and the existing callback admission boundary instead of checking shutdown state in inbound message paths. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0341b5a4-918f-42ef-9a09-3eae7070127b
This was referenced Jul 22, 2026
This was referenced Jul 29, 2026
This was referenced Jul 29, 2026
Merged
This was referenced Aug 18, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#10290 closes callback admission and establishes
_isStoppingbefore the shutdown callback sweep, butInsideRuntimeClientstill lazily resolves several dependencies from runtime paths. A late rejection can therefore reachReceiveResponseafter the silo service provider has been disposed and throwObjectDisposedExceptionwhile resolvingGrainLocator.This follow-up mirrors
OutsideRuntimeClient.ConsumeServices:InsideRuntimeClienteagerly consumes its dependencies when it participates in the silo lifecycle, after construction but before lifecycle startup. This avoids constructor cycles and eliminates lazy DI resolution from runtime paths without adding shutdown-state reads to hot paths.Regression coverage delivers an unrecoverable rejection after ungraceful silo shutdown and provider disposal.
Fixes #10282