feat(channel,runtime): off-runtime cross-thread wake for parked receivers and stop

Wakes issued from a non-scheduler OS thread were silent no-ops. Every
off-runtime wake primitive (unpark, unpark_at, request_stop) reaches the
runtime through the RUNTIME thread-local, which is unset on any foreign
thread — so a send from a plain std::thread enqueued its message but never
woke the parked receiver, and there was no way to drive a stop into a
runtime from an application thread (e.g. an OS-signal handler). The former
strands a parked recv forever; the latter is why a downstream server must
poll a shutdown flag instead of parking on it.

Generalize RFC 018's rule — a producer reaches the runtime through a Weak it
holds — from the IO backend to channel senders and to a new handle:

- A receiver captures a Weak<RuntimeInner> (provably live at that moment)
  alongside its (pid, epoch) when it parks. send() and the last-sender drop
  wake through scheduler::unpark_at_via, which takes the thread-local path
  when on a scheduler thread (preemption-gated, slot-eligible) and the
  captured Weak otherwise — the same cross-context wake the IO threads do.
- Runtime::handle() returns a Send + Sync RuntimeHandle carrying that Weak;
  RuntimeHandle::request_stop drives a cooperative stop from any thread and
  is a no-op once the runtime is dropped.

The in-runtime wake paths (recv/select timers) are unchanged; only the sites
reachable from a foreign thread route through the Weak. RuntimeHandle exposes
request_stop only: send-wake needs no user-facing handle, and off-runtime
unpark is covered because request_stop drives unpark on the upgraded inner.

tests/cross_thread_wake.rs: a foreign-thread send wakes a parked receiver; a
foreign-thread request_stop wakes and stops a parked actor; a RuntimeHandle
held across and beyond run never blocks all-done and degrades to a no-op.
This commit is contained in:
Claude (sandbox)
2026-08-19 05:50:54 +00:00
parent 8f2d513940
commit 1002777ef3
5 changed files with 238 additions and 24 deletions
+34 -21
View File
@@ -90,8 +90,9 @@
use crate::pid::Pid;
use crate::raw_mutex::RawMutex;
use crate::runtime::RuntimeInner;
use std::collections::VecDeque;
use std::sync::Arc;
use std::sync::{Arc, Weak};
/// Create a new channel and return its `(Sender, Receiver)` halves.
///
@@ -114,12 +115,15 @@ pub fn channel<T>() -> (Sender<T>, Receiver<T>) {
struct Inner<T> {
queue: VecDeque<T>,
/// The parked receiver's `(pid, park-epoch)`, if one is currently
/// The parked receiver's `(pid, park-epoch, runtime)`, if one is currently
/// waiting. The epoch identifies exactly which wait this is, so a waker
/// left over from a wait that already ended (a losing `select` arm, a
/// `recv_timeout` whose timer fired after it was already satisfied) is
/// inert and does nothing when it fires.
parked_receiver: Option<(Pid, u32)>,
/// inert and does nothing when it fires. The `Weak<RuntimeInner>` is the
/// receiver's runtime, captured while it parked (so provably alive then);
/// it lets a sender on a foreign OS thread wake the receiver without the
/// `RUNTIME` thread-local, which is unset off a scheduler thread.
parked_receiver: Option<(Pid, u32, Weak<RuntimeInner>)>,
senders: usize,
receiver_alive: bool,
}
@@ -206,8 +210,8 @@ impl<T> Drop for Sender<T> {
None
}
};
if let Some((pid, epoch)) = unpark {
crate::scheduler::unpark_at(pid, epoch);
if let Some((pid, epoch, rt)) = unpark {
crate::scheduler::unpark_at_via(pid, epoch, &rt);
}
}
}
@@ -254,13 +258,13 @@ impl<T> Sender<T> {
g.queue.push_back(value);
g.parked_receiver.take()
};
if let Some((pid, epoch)) = unpark {
if let Some((pid, epoch, rt)) = unpark {
crate::te!(crate::trace::Event::Send {
sender: crate::actor::current_pid()
.unwrap_or(crate::pid::Pid::new(u32::MAX, u32::MAX)),
receiver: Some(pid)
});
crate::scheduler::unpark_at(pid, epoch);
crate::scheduler::unpark_at_via(pid, epoch, &rt);
} else {
crate::te!(crate::trace::Event::Send {
sender: crate::actor::current_pid()
@@ -293,13 +297,17 @@ impl<T> Receiver<T> {
None => panic!("smarm: recv() called outside an actor"),
};
debug_assert!(
g.parked_receiver.is_none_or(|(p, _)| p == me),
g.parked_receiver.as_ref().is_none_or(|(p, _, _)| *p == me),
"channel has more than one receiver"
);
// begin_wait is lock-free, so it's legal under the Channel lock;
// registering in the same critical section makes the epoch
// atomic with the senders' view of the registration.
g.parked_receiver = Some((me, crate::scheduler::begin_wait()));
g.parked_receiver = Some((
me,
crate::scheduler::begin_wait(),
crate::scheduler::runtime_weak(),
));
crate::te!(crate::trace::Event::RecvPark(me));
}
// Release the lock before parking: the unparker will need it.
@@ -347,11 +355,11 @@ impl<T> Receiver<T> {
return Err(RecvTimeoutError::Disconnected);
}
debug_assert!(
g.parked_receiver.is_none_or(|(p, _)| p == me),
g.parked_receiver.as_ref().is_none_or(|(p, _, _)| *p == me),
"channel has more than one receiver"
);
epoch = crate::scheduler::begin_wait();
g.parked_receiver = Some((me, epoch));
g.parked_receiver = Some((me, epoch, crate::scheduler::runtime_weak()));
crate::te!(crate::trace::Event::RecvPark(me));
}
@@ -423,10 +431,14 @@ impl<T> Receiver<T> {
None => panic!("smarm: recv_match() called outside an actor"),
};
debug_assert!(
g.parked_receiver.is_none_or(|(p, _)| p == me),
g.parked_receiver.as_ref().is_none_or(|(p, _, _)| *p == me),
"channel has more than one receiver"
);
g.parked_receiver = Some((me, crate::scheduler::begin_wait()));
g.parked_receiver = Some((
me,
crate::scheduler::begin_wait(),
crate::scheduler::runtime_weak(),
));
crate::te!(crate::trace::Event::RecvPark(me));
}
// Release the lock before parking: the unparker will need it.
@@ -497,11 +509,12 @@ impl<T: Send + 'static> crate::timer::TimerTarget for RawMutex<Inner<T>> {
// keeps the registration bookkeeping exact.)
let unpark = {
let mut g = self.lock();
if g.parked_receiver == Some((pid, epoch)) {
g.parked_receiver = None;
true
} else {
false
match g.parked_receiver {
Some((p, e, _)) if p == pid && e == epoch => {
g.parked_receiver = None;
true
}
_ => false,
}
};
// Unpark outside the channel lock: it may take the run-queue lock;
@@ -562,10 +575,10 @@ impl<T> Selectable for Receiver<T> {
return Ok(false);
}
debug_assert!(
g.parked_receiver.is_none_or(|(p, _)| p == pid),
g.parked_receiver.as_ref().is_none_or(|(p, _, _)| *p == pid),
"channel has more than one receiver"
);
g.parked_receiver = Some((pid, epoch));
g.parked_receiver = Some((pid, epoch, crate::scheduler::runtime_weak()));
Ok(true)
}