Skip to content

Prevent telemetry workers reopening after cleanup - #127

Open
Brian Krabach (bkrabach) wants to merge 1 commit into
mainfrom
fix/dispatcher-close-lifecycle
Open

Brian Krabach (bkrabach) wants to merge 1 commit into
mainfrom
fix/dispatcher-close-lifecycle

Conversation

@bkrabach

@bkrabach Brian Krabach (bkrabach) commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

A hook event delivered after cleanup could start a new telemetry worker and HTTP client. Dispatcher closure is now terminal: it refuses new admissions, shares one bounded cleanup task across callers, and shields that task from caller cancellation. Late dispatcher replacements are closed and rejected. Local event persistence, disk-loss warnings and existing drain/abandonment bounds remain intact.

Coordinate adoption with Core #114, which delivers the natural terminal event before module cleanup. On older Core versions that emit it afterward, this defensive fix preserves it locally but does not deliver it remotely. The pair has not been deployed.

Validation at 72f1fb68a1409d0c07f77245f154dbffc7a55707:

  • CI: all 11 jobs and CLA passed. Root tests passed 932 cases on each Python 3.11–3.13; hook tests passed 709 with 2 skipped; the remaining module suites and lint passed. The 11 new regressions reproduced 9 failures on unchanged upstream.
  • Real lifecycle acceptance with candidate Core 3654f7d, actual backend 43973967, static fixture authentication and Neo4j 5.26.22 passed accepted delivery, bad authentication and an unavailable endpoint. The public Rust session and normally loaded modules emitted exactly one natural session:end during cleanup. Its 202/queued response preceded client closure; later Neo4j readback matched retained HTTP/local/server-spool payloads. Failure cases retained their local terminal event, indexed none and closed clients/workers without reopening. This used no model calls or manually emitted terminal event. All owned processes/services/VM closed; existing host state was preserved.
  • The unmodified scripts/validate-full.sh, using Foundation validator v3.16.1, passed independent review of the complete recipe state: full mode, tested successful build, 12/12 bundles good, 0 ERROR findings, fresh diagrams and unchanged source. Two advisory warnings remain: navigation defines three tools and the server-data-ops description is long. The ordinary validator used published Core 1.6.1; the candidate-Core lifecycle proof above is separate.

This verifies the tested static-auth lifecycle boundary. It does not establish every authentication mode, model-driven lifecycle behavior, or the cause of the earlier Spark shutdown timeout. Keep the pair's Core release/adoption requirement explicit before rollout.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant