Skip to content

fix: close durable runtime stores after shutdown drains writers - #732

Merged
imran-siddique merged 1 commit into
agentrust-io:mainfrom
soyeladice-svg:worknet-cmcp-676-durable-shutdown
Oct 6, 2026
Merged

imran-siddique merged 1 commit into
agentrust-io:mainfrom
soyeladice-svg:worknet-cmcp-676-durable-shutdown

Conversation

@soyeladice-svg

Copy link
Copy Markdown
Contributor

What

Closes #676.

Pass the three CLI-owned durable stores explicitly to MCPServer and close them during server shutdown only after MCPProxy has confirmed that all admitted calls have drained. Reuse the existing admission gate and drain logic.

Shutdown is serialized. Every owned store gets an independent close attempt; successful closes are not repeated, failed closes can be retried, and an earlier proxy shutdown error remains the primary error. Kill-switch store close uses its existing lock. Embedded servers retain ownership of stores they have not explicitly transferred.

Why

The production runtime creates persistent audit, kill-switch, and sensitivity stores but did not close their handles in the server lifespan. Closing them before a cancellation-resistant call has drained would instead break its final durable writes.

Security impact

No policy, receipt format, audit-chain, or TEE behavior changes. Durable handles remain open when draining fails, so an admitted tool can still persist its audit outcome and state before a later shutdown retry closes them.

Test plan

  • Focused production wiring/lifecycle suite: 11 passed, including five new regression tests using real SQLite stores.
  • Unit suite exercised: initial run 2,310 passed, 6 skipped, 9 failed because the environment's SOCKS proxy required the missing optional socksio package. After installing socksio in the test environment, all 9 failed cases passed on rerun.
  • Ruff check passed.
  • Mypy passed (77 source files).
  • Bandit passed with no findings.
  • git diff --check passed.

Regression coverage: normal closure; one close failure does not stop other stores and retries only the failed close; original proxy cleanup errors are preserved; incomplete drain permits real durable audit/state writes, rejects new admissions and then closes on retry; borrowed stores are not closed.
No manual deployment test was performed.

AI assistance: prepared and tested with Codex for Burs-IA.

DCO sign-off

Signed-off-by: Héctor Alejandro Flórez Díaz <327943577+soyeladice-svg@users.noreply.github.com>
Signed-off-by: Alejandro Florez <soyeladice@gmail.com>
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

🔴 Contributor Check: HIGH

Check Result
Profile HIGH
Credential LOW
Overall HIGH

Automated check by AgenTrust Contributor Check.

@github-actions github-actions Bot added the needs-review:HIGH Contributor check flagged HIGH risk label Oct 6, 2026
@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This meets #676 and the September 24 constraint: the stores close only once shutdown_drained is set, stay open when draining fails so a late call can still write its outcome, and each close is attempted independently with the original shutdown error kept as primary. All 18 checks pass, fuzzing included. Thanks @soyeladice-svg.

@imran-siddique
imran-siddique merged commit fb3e4b5 into agentrust-io:main Oct 6, 2026
18 of 19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review:HIGH Contributor check flagged HIGH risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Durable stores are never closed on shutdown

3 participants