writeonce/docs
shoney.arickathil 60414a1754 feat(runtime): the shutdown drain guarantee — iteration 40
A message sent before the stop flag is observed must be delivered and run
before the engine stops. One rule; a spin count could never express it.

- root cause in `shard_main` (runtime/src/vm.c): NEXT_RUNNABLE() already
  stated the contract — "a WORKER on stop keeps DRAINING ... so queued
  shutdown messages (close frames!) still run" — but the IDLE branch
  contradicted it, calling fib_reap_all and breaking on WO_IO_STOP,
  abandoning its inbox for wo_engine_stop() to free wholesale
- an actor between messages is exactly that idle case, which is why a WARM
  soak server hid it: warm shards held live fibers and took the right path
- fix: while the primary's drain window is open, an idle worker adopts its
  inbox and runs what arrives; sched_yield on an empty poll so a drain
  cannot burn a core per shard and starve the actors it exists to let run
- unreachable at WO_SHARDS=1: wo_engine_stop returns early at nshards <= 1

Measured:

- fresh-server SIGTERM drain: 5 of 16 failing before, 20 of 20 clean after
- `just chat` at the FULL 1000-client soak: 11 checks, 0 failures, both
  WO_IO backends, ASan clean with zero leaks
- the fd leg settled at scale too: 1000 connections left the count at 44,
  unchanged after 20 more — lazy per-shard init, not a leak
- runtime battery 36 suites (18 x both dispatch flavors) 0 fail;
  compiler 556 checks 0 fail

- story: docs/stories/language-runtime-database/40-shutdown-drain-guarantee.md
  (chain 3 with 31, status done), board row, slice marker updated
- outstanding and named: a pin below the gate needs new multithreaded test
  infrastructure — nothing in runtime/test/ drives wo_engine_start/stop and
  no corpus fixture can trigger a stop

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-27 23:43:45 +02:00
..
examples fix(chat gate): every leg starts its own server — and it found a real bug 2026-08-27 23:27:46 +02:00
guides docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
plan Merge branch 'master' into chat-ws-lifecycle 2026-08-27 23:11:49 +02:00
stories feat(runtime): the shutdown drain guarantee — iteration 40 2026-08-27 23:43:45 +02:00
superpowers docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-code-review.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-dependency-graph.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-doc-audit.md refactor(porch): name the web framework porch, fix the wo.toml identifier claim 2026-08-26 19:36:34 +02:00
00-link-audit.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-principles.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
01-problem.md docs: remove stale old-runtime docs; abandon the ##ui frontend track 2026-08-17 20:06:36 +02:00
08-project-structure.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
2026-08-27-chat-drain-finding.md fix(chat gate): every leg starts its own server — and it found a real bug 2026-08-27 23:27:46 +02:00
active-slice-2026-08-23-chat-ws-lifecycle.md feat(runtime): the shutdown drain guarantee — iteration 40 2026-08-27 23:43:45 +02:00