Remove race condition during module host exit#5573
Open
joshua-spacetime wants to merge 1 commit into
Open
Conversation
joshua-spacetime
force-pushed
the
joshua/fix/module-host-exit
branch
from
July 21, 2026 01:31
1c42f31 to
90e13cf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of Changes
Previously
exit_module_hostremoved a replica'sHostCellbefore acquiring the write lock and shutting down the module/database. A concurrent access path could then create a second cell for the same replica while the old host was still exiting.This change keeps the existing cell registered during shutdown, marks it as
Exiting, and removes it from the map while still holding the write lock. Queued waiters on the old cell will then observe that it is no longer current and fail rather than initializing through stale state.exit_module_hoststill returns after the provided timeout, but the shutdown task continues in the background and keeps blocking new host creation until cleanup completes.API and ABI breaking changes
None.
Expected complexity level and risk
3
Testing
This should fix hangs/flakiness in pause/unpause and suspend/unsuspend smoketests such as
unpause_makes_database_accessible_again, where a pause-triggered host exit can race with a subsequent access or relaunch.