Expected behavior
Committed shutdown must close new effectful control admission, settle or explicitly preserve uncertainty for already-admitted operations, and await their durable result writes before releasing the state-process lock. Completion receipts required by that drain must remain writable.
Confirmed source seam
At 115e26fc9c67316a3b0b1b4318f47f7a2bea3606, createControlHost.dispose() synchronously retires waits/window registrations and IPC handlers. It does not join executor work or the private FileControlHistory append tail. Stopping an HTTP transport or disposing a renderer bridge is not evidence that the operation and its result persistence ended.
The executor's active map is populated only after the serialized received-intent append. Draining that map alone would miss pre-registration admission work. Nested observations/waits/batches call the executor directly, and the private main operations.start/operations.finish port must retain the ability to record results during shutdown.
Sources: main composition, executor, durable history.
Acceptance and scope
Add a composed regression with an intent write still queued at commit, a dispatched effect awaiting completion, and delayed/rejected result persistence. Assert new effects cannot enter, existing results are still recorded, required failures hold the exit/lock boundary, and transport timeout does not authorize repeating a mutation. Cover nested waits/batches and internal completion receipts.
This is source-grounded follow-up work discovered during #919. The first disposal PR (fix/quit-service-lifecycle, source e9b88bf5) records the gap but does not implement this contract. No application crash/OS-exit reproduction has been run. Keep this issue and the complete B02 acceptance open after that PR.
Refs #919 and #918; coordinate with B05 mutation uncertainty and B02's revision-bound editor preparation.
Expected behavior
Committed shutdown must close new effectful control admission, settle or explicitly preserve uncertainty for already-admitted operations, and await their durable result writes before releasing the state-process lock. Completion receipts required by that drain must remain writable.
Confirmed source seam
At
115e26fc9c67316a3b0b1b4318f47f7a2bea3606,createControlHost.dispose()synchronously retires waits/window registrations and IPC handlers. It does not join executor work or the private FileControlHistory append tail. Stopping an HTTP transport or disposing a renderer bridge is not evidence that the operation and its result persistence ended.The executor's
activemap is populated only after the serialized received-intent append. Draining that map alone would miss pre-registration admission work. Nested observations/waits/batches call the executor directly, and the private main operations.start/operations.finish port must retain the ability to record results during shutdown.Sources: main composition, executor, durable history.
Acceptance and scope
Add a composed regression with an intent write still queued at commit, a dispatched effect awaiting completion, and delayed/rejected result persistence. Assert new effects cannot enter, existing results are still recorded, required failures hold the exit/lock boundary, and transport timeout does not authorize repeating a mutation. Cover nested waits/batches and internal completion receipts.
This is source-grounded follow-up work discovered during #919. The first disposal PR (
fix/quit-service-lifecycle, sourcee9b88bf5) records the gap but does not implement this contract. No application crash/OS-exit reproduction has been run. Keep this issue and the complete B02 acceptance open after that PR.Refs #919 and #918; coordinate with B05 mutation uncertainty and B02's revision-bound editor preparation.