Prevent telemetry workers reopening after cleanup - #127
Open
Brian Krabach (bkrabach) wants to merge 1 commit into
Open
Brian Krabach (bkrabach) wants to merge 1 commit into
Brian Krabach (bkrabach) wants to merge 1 commit into
Conversation
Brian Krabach (bkrabach)
marked this pull request as ready for review
September 23, 2026 03:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A hook event delivered after cleanup could start a new telemetry worker and HTTP client. Dispatcher closure is now terminal: it refuses new admissions, shares one bounded cleanup task across callers, and shields that task from caller cancellation. Late dispatcher replacements are closed and rejected. Local event persistence, disk-loss warnings and existing drain/abandonment bounds remain intact.
Coordinate adoption with Core #114, which delivers the natural terminal event before module cleanup. On older Core versions that emit it afterward, this defensive fix preserves it locally but does not deliver it remotely. The pair has not been deployed.
Validation at
72f1fb68a1409d0c07f77245f154dbffc7a55707:3654f7d, actual backend43973967, static fixture authentication and Neo4j 5.26.22 passed accepted delivery, bad authentication and an unavailable endpoint. The public Rust session and normally loaded modules emitted exactly one naturalsession:endduring cleanup. Its202/queuedresponse preceded client closure; later Neo4j readback matched retained HTTP/local/server-spool payloads. Failure cases retained their local terminal event, indexed none and closed clients/workers without reopening. This used no model calls or manually emitted terminal event. All owned processes/services/VM closed; existing host state was preserved.scripts/validate-full.sh, using Foundation validator v3.16.1, passed independent review of the complete recipe state: full mode, tested successful build, 12/12 bundles good, 0 ERROR findings, fresh diagrams and unchanged source. Two advisory warnings remain: navigation defines three tools and the server-data-ops description is long. The ordinary validator used published Core 1.6.1; the candidate-Core lifecycle proof above is separate.This verifies the tested static-auth lifecycle boundary. It does not establish every authentication mode, model-driven lifecycle behavior, or the cause of the earlier Spark shutdown timeout. Keep the pair's Core release/adoption requirement explicit before rollout.