actions / actions/runner

Run Service renewal throws NullReferenceException after a post-success failure and abandons the active job

Open
#4,635 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C#
Stars
6.3k
Forks
1.4k
Avg merge
1d 16h
Merged PRs (30d)
24

Description

Describe the bug

For Run Service jobs, if lease renewal succeeds at least once and a later renewal throws a non-terminal exception, the renewal task can fail with NullReferenceException. The active worker is then cancelled and the job is reported as Abandoned, even though the most recently acquired lease is still valid.

In the Run Service overload of RenewJobRequestAsync, request is initialized to null and never assigned:

TaskAgentJobRequest request = null;

var renewResponse = await runServer.RenewJobAsync(planId, jobId, token);

After the first successful renewal, the exception path reads:

remainingTime = request.LockedUntil.Value + TimeSpan.FromMinutes(5) - DateTime.UtcNow;

The successful response is stored in renewResponse, but the retry path reads request.LockedUntil. Therefore, a generic renewal exception after the first success causes a NullReferenceException.

Relevant source:

The same implementation is present in v2.336.0 and in main as of 2026-08-14.

To Reproduce

This can be reproduced at unit level:

  1. Configure IRunServer.RenewJobAsync to return a successful RenewJobResponse with a future LockedUntil.
  2. Allow the next renewal cycle to start.
  3. Configure the next call to throw HttpRequestException or another generic exception.
  4. Observe that RenewJobRequestAsync throws NullReferenceException instead of entering the lease-window retry path.
  5. The completed/faulted renewal task causes RunAsync to cancel the worker and report the job as Abandoned.

Expected behavior

After a successful renewal, a later retriable exception should use the most recent LockedUntil value and continue retrying within the existing lease window, including the configured five-minute buffer. The active worker should not be cancelled while that retry window remains valid.

Runner Version and Platform

  • Runner version: 2.336.0
  • Platform: Linux x64
  • Environment: self-hosted runner in a Kubernetes Pod

What's not working?

The issue was observed twice on the same runner during a period of TLS/network instability.

First occurrence:

[2026-08-14 05:23:22Z] Successfully renew job <job-id>,
    job is valid till 08/14/2026 05:33:22

[2026-08-14 05:26:45Z] Back off ... before next retry. 1 attempt left.

[2026-08-14 05:26:55Z] Catch exception during renew runner job <job-id>.
System.Net.Http.HttpRequestException: The SSL connection could not be established.
System.IO.IOException: Received an unexpected EOF or 0 bytes from the transport stream.

[2026-08-14 05:26:55Z] Send job cancellation message to worker for job <job-id>.
[2026-08-14 05:29:31Z] Job completed with result: Abandoned
[2026-08-14 05:29:37Z] System.NullReferenceException:
    Object reference not set to an instance of an object.
    at GitHub.Runner.Listener.JobDispatcher.RenewJobRequestAsync(IRunServer runServer, ...)

The RunServer request layer made five total attempts—one initial attempt and four retries—before the exception reached JobDispatcher.

A second job showed the same sequence:

05:51:45  Last successful renewal; valid until 06:01:45
05:55:27  Renewal exception and immediate worker cancellation
06:00:26  Job reported as Abandoned
06:08:48  NullReferenceException surfaced

The delayed NullReferenceException is surfaced when the already-faulted renewal task is later awaited; worker cancellation begins as soon as that task becomes completed.

Job Log Output

The active workflow step was cancelled without a workflow cancellation request.

Runner and Worker's Diagnostic Logs

The worker received the cancellation at the same time as the renewal failure:

[2026-08-14 05:26:55Z] Cancellation/Shutdown message received.
[2026-08-14 05:26:55Z] Cancel current running step.
[2026-08-14 05:26:55Z] Sending SIGINT to process <pid>.
[2026-08-14 05:27:03Z] Sending SIGTERM to process <pid>.
[2026-08-14 05:27:05Z] Kill entire process tree since both cancel and terminate signal have been ignored.

Full diagnostic logs contain environment-specific information and can be provided privately if needed.

Possible fix direction

One option would be to retain the most recent renewResponse.LockedUntil value and use it in the exception path instead of reading the unassigned request.

A regression test could cover the Run Service sequence:

successful renewal -> generic exception -> retry/recovery

The existing Run Service test covers the terminal TaskOrchestrationJobNotFoundException case, but not a generic exception after a successful renewal:

https://github.com/actions/runner/blob/main/src/Test/L0/Listener/JobDispatcherL0.cs#L219-L285

The affected Run Service renewal overload was introduced in https://github.com/actions/runner/pull/2461.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in src/Runner.Listener/JobDispatcher.cs at the Run Service RenewJobRequestAsync overload, then read the renewal tests in src/Test/L0/Listener/JobDispatcherL0.cs, especially the existing terminal-exception case. Reproduce the successful-renewal followed by generic-exception sequence and add regression coverage showing that the latest lease window is used and the worker is not abandoned while retries remain valid.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
backend, ci-cd
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
78/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.