fix(runtime): only named tenancies stamp the terminal record — anonymous churn must not evict it
Discovered wiring the bridge consult: with an unconditional stamp, the record for the very death being raced was the shortest-lived data in the runtime. Every green thread is a slot tenant, the free list is LIFO — so the slot a named server's death frees is the first one recycled, and the next throwaway exit (monitor holders, chain-runner work, anything) overwrote the record before a raced watch could consult it. Deterministic bridge repro: the corpse resolved fine, terminal_reason read None every time. register_with now flags the tenancy (ever_named, reset at reclaim) before the binding lands — set outside the registry lock, so no successfully registered actor can die unflagged and a failed register's overshoot is harmless — and finalize stamps only flagged tenancies. Watchable identities are exactly the named ones (the bridge's pid-identity path deliberately keeps Erlang's raw :noproc), so nothing consultable is lost. Contract test updated: the three death modes now self-register; a new anonymous control pins that unregistered deaths neither stamp nor evict.
This commit is contained in:
+7
-5
@@ -178,11 +178,13 @@ pub fn monitor<A>(target: Pid<A>) -> Monitor {
|
||||
}
|
||||
|
||||
/// The terminal [`DownReason`] of the tenancy `target` names, if that tenancy
|
||||
/// is the *most recent* death of its slot: finalize stamps the slot with
|
||||
/// `(generation, reason)`, and the record survives reclaim and the next
|
||||
/// tenant's install, until that next tenant itself dies. `None` means the pid
|
||||
/// never lived, is still alive, or its record was overwritten by a later
|
||||
/// tenancy's death — callers fall back to `NoProc` semantics.
|
||||
/// ever registered a name and is the *most recent named* death of its slot:
|
||||
/// finalize stamps the slot with `(generation, reason)` for once-registered
|
||||
/// tenancies (anonymous green-thread churn does not stamp — nor evict), and
|
||||
/// the record survives reclaim and the next tenant's install, until the next
|
||||
/// *named* tenant of the slot itself dies. `None` means the pid never lived,
|
||||
/// is still alive, never held a name, or its record was overwritten by a
|
||||
/// later named tenancy's death — callers fall back to `NoProc` semantics.
|
||||
///
|
||||
/// This exists for watch-installers that raced their target's death (bridge
|
||||
/// soak signature 4): a `NoProc` observed at install time can be upgraded to
|
||||
|
||||
Reference in New Issue
Block a user