Skip to content

fix(runtime): close callback admission during shutdown - #10290

Merged
ReubenBond merged 5 commits into
dotnet:mainfrom
ReubenBond:reubenbond-fix-transaction-test-hang
Jul 21, 2026
Merged

ReubenBond merged 5 commits into
dotnet:mainfrom
ReubenBond:reubenbond-fix-transaction-test-hang

Conversation

@ReubenBond

@ReubenBond ReubenBond commented Jul 20, 2026 •

Copy link
Copy Markdown
Member

Hard-killing an in-process silo can deadlock host disposal when stateless workers have transaction calls in flight.

The CI dumps show host disposal waiting on StatelessWorkerGrainContext.DisposeAsyncInternal. Faulting the original callbacks resumes transaction cleanup, which can issue follow-up requests after the shutdown sweep and register callbacks that can never receive responses.

Close callback admission before draining outstanding calls in both silo and client runtimes. Requests check the stopping state before insertion and again afterward, ensuring each callback is completed by either the shutdown sweep or the admitting thread. Callback cancellation registration now uses a nonblocking publication/disposal handshake so synchronous cancellation or concurrent completion cannot leak a registration.

The regression coverage includes multiple blocked silo workers which retry after shutdown, a client call which retries after shutdown, cancellation during registration, and registration attempted after callback completion.

Hard-killed silos can cancel callback timer shutdown before outstanding callbacks are faulted, leaving stateless worker disposal blocked forever. Complete callbacks before the cancellation-sensitive wait and exercise the path with multiple in-flight workers.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 10faef46-7323-49a5-bd75-9235f99dcf8f
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@ReubenBond ReubenBond changed the title Fix callback shutdown race during hard silo kills fix(runtime): fault callbacks before canceled shutdown wait Jul 20, 2026
Faulting outstanding transaction callbacks can resume code which issues follow-up calls after the shutdown sweep. Close callback registration when runtime shutdown begins so those calls fail immediately instead of blocking host disposal.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 10faef46-7323-49a5-bd75-9235f99dcf8f
@ReubenBond ReubenBond changed the title fix(runtime): fault callbacks before canceled shutdown wait fix(runtime): reject requests during silo shutdown Jul 20, 2026
Close callback admission before draining outstanding calls in silo and client runtimes. Use pre- and post-insertion checks so every callback is completed by either the shutdown sweep or the admitting thread, and safely publish cancellation registrations across concurrent completion.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 10faef46-7323-49a5-bd75-9235f99dcf8f
@ReubenBond ReubenBond changed the title fix(runtime): reject requests during silo shutdown fix(runtime): close callback admission during shutdown Jul 21, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 10faef46-7323-49a5-bd75-9235f99dcf8f
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 10faef46-7323-49a5-bd75-9235f99dcf8f
@ReubenBond
ReubenBond merged commit db18df9 into dotnet:main Jul 21, 2026
61 of 62 checks passed
@ReubenBond
ReubenBond deleted the reubenbond-fix-transaction-test-hang branch July 21, 2026 04:04
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 20, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant