agent-substrate / agent-substrate/substrate

[Bug]: Lifecycle finalizers can overwrite a concurrent worker-deletion crash

Aberta
#1,443 0 comentários 0 reações 1 responsável Reivindicada por @EItanya Ver no GitHub
area/api-machinery area/reliability kind/bug
Linguagem predominante
Go
Estrelas
1.8k
Forks
316
Merge médio
2d 43min
PRs com merge (30d)
287

Descrição

### What happened?

When a worker disappears during ResumeActor or SuspendActor, DeleteWorker marks the actor
CRASHED and clears its worker assignment. The lifecycle workflow can subsequently re-read that
updated actor and unconditionally finalize it:

- Resume changes CRASHED to RUNNING, leaving a running actor without a worker.
- Suspend changes CRASHED to SUSPENDED, potentially without a valid snapshot.

Optimistic version checks do not prevent this because the finalizers read and update the new
CRASHED version.

### Expected Behavior

finalization should require the actor to remain RESUMING or SUSPENDING. If worker deletion has already crashed it, the workflow should preserve CRASHED and return FailedPrecondition.

### Steps to Reproduce

Regression tests can reproduce both cases by deleting the worker from the fake atelet
immediately after restore/checkpoint completes.

### Sandbox Runtime

Both / Runtime Agnostic

### Agent Substrate Version / Commit SHA

main

### Kubernetes Version & Environment

_No response_

### Host OS & Architecture

_No response_

### Relevant Logs and Diagnostic Output

```shell

```

### Additional Context

_No response_

### Confirmation

- [x] I have searched existing issues and verified that this is not a duplicate.
- [x] I have verified that this issue occurs on the latest commit on `main`.

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.