Skip to content

Fix txPubSub subscriber release interrupts after hub shutdown - #7117

Merged
tim-smart merged 2 commits into
mainfrom
audit/repro-b206fa5d76-txpubsub-release-after-shutdown
Aug 7, 2026
Merged

Fix txPubSub subscriber release interrupts after hub shutdown#7117
tim-smart merged 2 commits into
mainfrom
audit/repro-b206fa5d76-txpubsub-release-after-shutdown

Conversation

@fubhy

@fubhy fubhy commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

TxPubSub.shutdown first calls TxQueue.shutdown on the subscriber. Its scope finalizer later calls releaseSubscriber, which calls TxQueue.shutdown again. clear observes the queue's interrupt Done cause; Effect.ignore does not recover interruption, so the finalizer and Scope.close exit with interruption. The minimal public sequence TxQueue.shutdown(queue) twice likewise yields Success(true) then an interrupt Exit rather than a boolean result.

Important

This PR includes the focused regression test and the implementation fix in TxQueue.shutdown.

TxPubSub subscriber release interrupts after hub shutdown

Module: packages/effect/src/TxPubSub.ts
Audit ID: relsem-txpubsub-release-after-shutdown
Severity / confidence: medium / high

What happens

TxPubSub.shutdown first calls TxQueue.shutdown on the subscriber. Its scope finalizer later calls releaseSubscriber, which calls TxQueue.shutdown again. clear observes the queue's interrupt Done cause; Effect.ignore does not recover interruption, so the finalizer and Scope.close exit with interruption. The minimal public sequence TxQueue.shutdown(queue) twice likewise yields Success(true) then an interrupt Exit rather than a boolean result.

Why it happens

TxQueue.shutdown attempts to tolerate clear failure with Effect.ignore, but clear can fail by interruption when the queue is already interrupt-completed. Effect.ignore handles the typed failure channel, not the full interruption cause, so repeated shutdown is not total and TxPubSub's release finalizer inherits that interruption.

Expected behavior

A scoped TxPubSub subscription release must unregister and shut down its queue without turning ordinary scope closure into interruption, including when hub shutdown already terminated that queue.

Relevant implementation

These links and excerpts are pinned to audit base b206fa5d7655c1634c9993410a9203f6616a5ca2.

View problematic code at packages/effect/src/TxPubSub.ts:582
export const releaseSubscriber: {

View exact lines on GitHub

Reproduction

pnpm test --run packages/effect/test/TxPubSub.test.ts -t "releases a subscriber after hub shutdown without interruption"

Validation: The reproduction failed before the implementation change and passes after it.

Implementation

TxQueue.shutdown now ignores the full cause from clear before interrupting the queue, making repeated shutdown safe when the queue is already interrupted.

The focused regression, full effect test project, repository lint, and type checks all pass.

Audit provenance

  • Audit base: b206fa5d7655c1634c9993410a9203f6616a5ca2
  • Reproduction base: b206fa5d7655c1634c9993410a9203f6616a5ca2
  • Findings: relsem-txpubsub-release-after-shutdown
  • Implementation: focused reproduction test plus interruption-tolerant TxQueue.shutdown

Closes EFF-552

@fubhy fubhy added the audit Findings originating from the Effect runtime correctness audit label Aug 7, 2026
@changeset-bot

changeset-bot Bot commented Aug 7, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfa0903

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 30 packages
Name Type
effect Patch
@effect/ai-anthropic Patch
@effect/ai-openai Patch
@effect/ai-openai-compat Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/docgen Patch
@effect/doctest Patch
@effect/openapi-generator Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node Patch
@effect/platform-node-shared Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/vitest Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@effect-slopcop effect-slopcop Bot added 4.0 bug Something isn't working labels Aug 7, 2026

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

This PR adds a focused regression test, but the implementation fix described in the title and commit message is not present in the diff. CI will fail until TxQueue.shutdown is made tolerant of repeated interruption.

Reviewed changes

  • Added one regression test in packages/effect/test/TxPubSub.test.ts that reproduces Scope.close exiting with interruption when a TxPubSub subscriber is released after hub shutdown.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | Fix all ➔Fix 👍s ➔View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

Comment thread packages/effect/test/TxPubSub.test.ts

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

This run reviewed the delta since the prior Pullfrog review.

  • Added a changeset describing the TxQueue.shutdown idempotency fix.
  • Changed TxQueue.shutdown to use Effect.ignoreCause(clear(self)) instead of Effect.ignore(clear(self)), so repeated shutdown after an interruption cause no longer propagates that interruption through the finalizer.
  • The regression test added in the prior commit now passes: Scope.close on a subscriber scope succeeds after hub shutdown.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 6.92 KB 6.92 KB 0.00 KB (0.00%)
batching.ts 9.72 KB 9.72 KB 0.00 KB (0.00%)
brand.ts 6.60 KB 6.60 KB 0.00 KB (0.00%)
cache.ts 10.59 KB 10.59 KB 0.00 KB (0.00%)
config.ts 20.83 KB 20.83 KB 0.00 KB (0.00%)
differ.ts 19.67 KB 19.67 KB 0.00 KB (0.00%)
http-client.ts 21.50 KB 21.50 KB 0.00 KB (0.00%)
logger.ts 10.81 KB 10.81 KB 0.00 KB (0.00%)
metric.ts 8.86 KB 8.86 KB 0.00 KB (0.00%)
optic.ts 6.68 KB 6.68 KB 0.00 KB (0.00%)
pubsub.ts 14.86 KB 14.86 KB 0.00 KB (0.00%)
queue.ts 11.54 KB 11.54 KB 0.00 KB (0.00%)
schedule.ts 10.71 KB 10.71 KB 0.00 KB (0.00%)
schema-class.ts 19.38 KB 19.38 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 29.24 KB 29.24 KB 0.00 KB (0.00%)
schema-representation-roundtrip.ts 25.51 KB 25.51 KB 0.00 KB (0.00%)
schema-string-transformation.ts 13.49 KB 13.49 KB 0.00 KB (0.00%)
schema-string.ts 11.03 KB 11.03 KB 0.00 KB (0.00%)
schema-template-literal.ts 15.30 KB 15.30 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.43 KB 21.43 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 23.87 KB 23.87 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 18.64 KB 18.64 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 18.47 KB 18.47 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.32 KB 18.32 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.09 KB 22.09 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.01 KB 19.01 KB 0.00 KB (0.00%)
schema.ts 18.62 KB 18.62 KB 0.00 KB (0.00%)
stm.ts 12.59 KB 12.59 KB 0.00 KB (0.00%)
stream.ts 9.67 KB 9.67 KB 0.00 KB (0.00%)

@tim-smart
tim-smart merged commit c2071b1 into main Aug 7, 2026
20 checks passed
@tim-smart
tim-smart deleted the audit/repro-b206fa5d76-txpubsub-release-after-shutdown branch August 7, 2026 21:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 audit Findings originating from the Effect runtime correctness audit bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants