Skip to content

stop() racing a REBUILD's connectAndBind has no cell; the guard is proven for start() only #1028

Description

@davidfarah2003

Follow-up to #981, which fixed the stop-versus-bind races on connectAndBind and proved them for the start() caller. This files the one gap that PR discloses deliberately, so it is on record as known rather than an oversight.

The stopped guard before the readiness emit (and the transport seed guard in watchStatus) is a single unbranched statement both callers await. The broker suite proves it for start(): the mid-bind cell gates armPlane3 and the pending-dial cell holds a real dial open, and both mutations kill red-and-named. Nothing races a stop against doRebuild's call of the same method. That path is covered today by shared-line reasoning, recorded in a comment at the guard site in packages/core/src/endpoint.ts, together with the condition that voids it.

The condition that turns this issue from optional into mandatory: if connectAndBind's tail ever becomes caller-aware, or the readiness emit splits per path, the shared-line reasoning expires and the rebuild race needs its own cell. Whoever makes such a change should treat this issue as part of its acceptance.

Why it was not built in #981: a rebuild-race cell needs to force a terminal close and then land stop() inside the rebuild's bind window, which is timing-heavy on a CI shard, while proving only that doRebuild awaits connectAndBind, which tearDownIfStopped sitting beside it already shows. The review panel on #981 examined the trade and endorsed disclose-not-build (its condition is the sentence above).

Scope if built: deterministic control of the stop-versus-rebuild-bind window in the broker companion suite, one cell, one mutation with a code-only anchor.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:corePrimary affected area: core.enhancementNew feature or requestseverity:lowConfirmed low-impact defect or security issue.triage:confirmedReported defect reproduces, or requested non-bug gap is independently verified.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions