fleetd #561: harden the completion/session TurnListener fan-out #570
Reference in New Issue
Block a user
Delete Branch "worker/561-listener-fanout-survives-a-throw-61d538-2"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes fleetd #561.
What changed
Fleetd.java'sTurnListenerfan-out (the composed listener that hands eachlifecycle event to both
CompletionResolverandSessionManager) had fourcallbacks —
onTurnComplete,onTurnCompleteWithPostAction, and bothonTurnFailedoverloads — built from two bare, unguarded statements each.onDelivered's registration hazard was already fixed structurally by #556(moved off the fan-out entirely); these four callbacks have the identical
shape and were still untested per comment 17041 on #561 (which supersedes the
ticket body — the body's
onDeliveredexample is already fixed and alreadypinned by
InjectorTest, not touched here).Extracted the composition into a package-private static factory,
Fleetd.turnListener(CompletionResolver completion, TurnListener sessions),and hardened it (rather than only asserting call order) with two small
helpers:
bothMustRunandbothMustRunKeepingSecondResult. Both callbackhalves are always attempted regardless of whether the other one throws;
whatever escapes (from one half or both) is rethrown once both have run —
never swallowed — so it still reaches
StatusPoller'scatch (Throwable)and logs at ERROR.
onTurnCompleteWithPostActionis documented as the one exception: orderthere is a functional requirement (
completion.resolveBeforePostActionmustrun before the session half's context-reset housekeeping can erase the
pane), not just fault tolerance, so it is not reorder-symmetric like the
other three — see the javadoc on
Fleetd.turnListener.Tests
New
FleetdTurnListenerCompositionTest(5 tests) builds the real productioncomposition from a real
CompletionResolverand a throwing fakesessionshalf:
half's effect (the captured
Rendezvouswaiter resolving/failing) stillhappened;
ConcurrentHashMap.get(null), a real code path, not a contrived one — theproduction
CompletionResolveris otherwise too defensive to throwsynchronously in normal operation), and the session half still ran.
Mutation proof
relevant tests red with their own assertion messages, confirming the
tests are not vacuous.
of the three symmetric call sites) left the full suite green —
confirming the hardening actually decouples the invariant from call
order, as intended. Reported as intentional successes, not gaps.
shasum -a 256onFleetd.javamatchedthe pristine file byte-for-byte before moving to the next.
Build
mvn -o clean installfromfleetd/: BUILD SUCCESS, exit 0.Maven's own count:
Tests run: 1755, Failures: 0, Errors: 0, Skipped: 0.Independent sum over
fleetd/target/surefire-reports/*.txt: 1755 tests, 0failures/errors — agrees with Maven's count. 131 report files (baseline 130
Out of scope
Injector.javais being edited by another worker for #551 — untouched here.