fix(peer): stop QUIC promptly after application tasks drain

Cancelled handshakes can remain in transport state after their application
owners return. Waiting for client idleness before signaling endpoint stop
added a measured three-second grace timeout to shutdown.

Stop and join the owned endpoint directly after application scopes drain.
Keep supervisor joining and isolated runtime teardown, which also finish
s2n's adapter workers and release their socket clones. Use this normal cleanup
for rejected-handshake tests instead of their former special shutdown path.

Test Plan:
- A loopback silent-peer handshake reproduced a 3.001-second wait before the fix.
- New supervisor regression verifies wait_stopped completes within one second
  and releases the client UDP socket after cancelling an in-flight handshake.
- just test: all 796 workspace tests passed, including the new regression.
- just fmt and just clippy: passed.
- Actual native window-close timing was not manually measured.
This commit is contained in:
ddidderr committed 2026-09-12 20:01:56 +02:00
1 parent 1a394d2825
commit 276a919f46
4 files changed
+68 -51

No files matched your search

+3
View File
@@ -166,6 +166,9 @@ encoded author snapshot at 4 MiB, with reserved capacity for terminal actions.
- Cancellation stops admission, drains all lexically owned connection, stream,
state-sync, operation, and mDNS children, closes the shared endpoints, and
joins the supervisor.
- After application children drain, endpoint tasks stop and join immediately;
exit does not wait for cancelled handshakes or closed connections to exhaust
their transport timers.
- There is no `Goodbye` control message. Pinned liveness failure and stale
generation-conditional removal are authoritative for departure.