The review of #766 (celeris#711) found no blocking defect. It left two nits. The first needs no change; the second is a test gap.
1. The len(liveConns) == 0 guard before sweepRetract is always true at the park (nit, no action)
Under the park predicate, connCount and liveConns change together at every site, so the guard never skips the retraction. It is harmless and documents the intent, so it stays.
The sites where they change together:
- epoll:
adopt.go:199-200, loop.go:995-996, 1742-1748, 2591-2592, 3370-3372, transplant.go:235-239;
- io_uring:
worker.go:2051-2052, 2281-2283, 3984-3986, 4104-4106, transplant.go:171-172, transplant_source.go:179-181.
The retraction sits at the only park site in each engine (suspended.Store(true): epoll/loop.go:792, iouring/worker.go:1532 in the merged tree). So it covers every close that follows sweep(), whichever close site a test happens to exercise.
To do: nothing.
2. The epoll post-sweep arm reaches the defect only through a test-disarmed timer (nit)
engine/epoll/park_retracts_residue_test.go:127-131 disarms every loop's timerfd from the test goroutine (unix.TimerfdSettime(l.timerFD, 0, &unix.ItimerSpec{}, nil)) so that the last close lands after sweep() in the parking iteration. The io_uring arm needs no such step.
The PR body says openly that the production paths on epoll that close after sweep() in that iteration are argued, not shown:
- the tick-gate
checkTimeouts;
- the detach queue;
- the dirty flush;
- the H2 queue.
To do: add an epoll arm that drives one of those production paths into the parking iteration without touching the timerfd, for example a detached connection closed through the detach queue on a paused loop. It must fail with loop.go's park retraction removed (#766's negative control) and pass on the head.
Refs: #766, celeris#711. Review evidence: evidence/lanes-20260927/EP-2/ (lane) and the reviewer's review-EP-2-evidence/logs/m8/n766.log (negative control: both post-sweep tests FAIL 10/10, busy_parked=1 busy_hold=1).
The review of #766 (celeris#711) found no blocking defect. It left two nits. The first needs no change; the second is a test gap.
1. The
len(liveConns) == 0guard beforesweepRetractis always true at the park (nit, no action)Under the park predicate,
connCountandliveConnschange together at every site, so the guard never skips the retraction. It is harmless and documents the intent, so it stays.The sites where they change together:
adopt.go:199-200,loop.go:995-996,1742-1748,2591-2592,3370-3372,transplant.go:235-239;worker.go:2051-2052,2281-2283,3984-3986,4104-4106,transplant.go:171-172,transplant_source.go:179-181.The retraction sits at the only park site in each engine (
suspended.Store(true):epoll/loop.go:792,iouring/worker.go:1532in the merged tree). So it covers every close that followssweep(), whichever close site a test happens to exercise.To do: nothing.
2. The epoll post-sweep arm reaches the defect only through a test-disarmed timer (nit)
engine/epoll/park_retracts_residue_test.go:127-131disarms every loop's timerfd from the test goroutine (unix.TimerfdSettime(l.timerFD, 0, &unix.ItimerSpec{}, nil)) so that the last close lands aftersweep()in the parking iteration. The io_uring arm needs no such step.The PR body says openly that the production paths on epoll that close after
sweep()in that iteration are argued, not shown:checkTimeouts;To do: add an epoll arm that drives one of those production paths into the parking iteration without touching the timerfd, for example a detached connection closed through the detach queue on a paused loop. It must fail with
loop.go's park retraction removed (#766's negative control) and pass on the head.Refs: #766, celeris#711. Review evidence:
evidence/lanes-20260927/EP-2/(lane) and the reviewer'sreview-EP-2-evidence/logs/m8/n766.log(negative control: both post-sweep tests FAIL 10/10,busy_parked=1 busy_hold=1).