Follow-up from PR #692 (#673), left open under the maintainer's two-round review cap (2026-09-27). The round-2 independent review of #692 approved with no blocker or major. Its minors were handled before the merge: docs#73 rewrites graceful-shutdown.md, #692 carries the breaking label, and CodeRabbit reviewed 5a05c2e with no actionable comments. One nit is left, and it is tracked here.
A narrow window can still run the OnShutdown hooks twice.
What to do: either close the window (for example, take the snapshot under the same publication step that sets the engine), or add one sentence to the comment at server.go:865-869 that names the window and why the load sits where it does. The #703 lane edits the same function (it reuses #692's listen/watcher join), so it can pick this up.
Found by: the lane E round-2 review of #692 (nit), evidence root evidence/celeris-673-679-653-424/lane-20260926/673/.
Follow-up from PR #692 (#673), left open under the maintainer's two-round review cap (2026-09-27). The round-2 independent review of #692 approved with no blocker or major. Its minors were handled before the merge: docs#73 rewrites graceful-shutdown.md, #692 carries the
breakinglabel, and CodeRabbit reviewed 5a05c2e with no actionable comments. One nit is left, and it is tracked here.A narrow window can still run the OnShutdown hooks twice.
listenUntilCancelled(server.go:858 at 5a05c2e),callsBefore := s.shutdownCalls.Load()runs after the caller'spreparehas published the engine.Server.Shutdownthat racesStart*ContextbetweendoPrepareand that load is counted as "before". It runs the hooks, because the engine is already set.ctx, the watcher seesshutdownCalls == callsBeforeand callsShutdownagain, so every hook runs a second time.prepareis worse: aShutdownthat comes beforeStartwould then suppress the watcher'sShutdownand leak the settle re-opener (adaptive dispatch never re-times a settled route: a store-backed handler that turns slow runs inline on the engine worker forever (#493 item 4, measured) #592). The current placement is defensible.What to do: either close the window (for example, take the snapshot under the same publication step that sets the engine), or add one sentence to the comment at server.go:865-869 that names the window and why the load sits where it does. The #703 lane edits the same function (it reuses #692's listen/watcher join), so it can pick this up.
Found by: the lane E round-2 review of #692 (nit), evidence root
evidence/celeris-673-679-653-424/lane-20260926/673/.