Repository navigation
pool, license: close the shutdown race, warn when the pool ignores a tier change; release v1.0.5 - #32
Merged
Conversation
…ier change WorkerPool.Get checked an atomic flag and then sent on the job channel, while Shutdown set the flag and then closed it; a Get between the two sent on a closed channel and panicked, and a second Shutdown closed it twice. Normal shutdown never got there only because GracefulStop drains handlers before the deferred Shutdown — an ordering the pool did not own, and one serve.GRPC skipped when Serve itself failed. The check and the send now share a read lock, Shutdown is idempotent, and a failed Serve drains its handlers too. The pool reads its licence ceilings once at startup. A licence lapsing past grace moved audit and the plugin cap at once and the pool only on the next restart, silently. The licence manager now logs a Warn when that gap opens, counts MaxGenerations as a change, and the README and AGENTS.md say so. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
WorkerPool shutdown no longer panics on a racing Get or a second Shutdown; the licence manager warns when a tier change will reach the pool only on restart. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ZergsLaw
enabled auto-merge
October 1, 2026 14:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WorkerPool shutdown race
Getchecked an atomicclosedflag and then sent on the job channel;Shutdownset the flag and then closed the channel. AGetbetween the two panicked with send on closed channel (recovered by the gRPC interceptor asINTERNAL), and a secondShutdownclosed the channel twice.Shutdowntakes the write lock and is idempotent.serve.GRPCalso callsGracefulStopwhenServereturns an error, so live handlers drain beforerun()closes the pool and the database.TestGetRacingShutdownNeverPanicsandTestShutdownIsIdempotentboth failed on the old code (6 panics in one run) and pass 30× under-racenow.Licence ceilings are read only at startup
worker_pool.workersandmax_concurrent_generationsare capped once, ininitApp. A licence lapsing past grace switched audit and the plugin cap immediately but left the pool at its Enterprise capacity until the next restart, which then lowered it silently.license.Managerremembers the startup claims and logs one Warn per transition when the pool ceilings no longer match.MaxGenerationsnow counts as a licence change.cappedByLicencegodoc describe the behaviour.Release
Bumps the chart, compose defaults and docs to v1.0.5.
Verification
go test -race ./...— greenserve.GRPCfailure branch:internal/servehas no tests, and forcingServeto fail needs listener plumbing.🤖 Generated with Claude Code