Outcome
Cancel in-flight chain-event poll work promptly when shutdown begins, so a slow RPC or callback cannot hold the agent retirement drain until its outer timeout.
This extracts the live shutdown requirement from PR #2044 onto the current lifecycle, chain-event poller, and RPC cancellation boundaries.
Current state
Current shutdown correctly fences new work, stops the chain poller, waits for physical agent work, and quarantines backing-store teardown on a retirement timeout. DKGNode.stopSignal also cancels protocol reads.
The remaining seam is narrower: ChainEventPoller.stop() waits for the active poll, while event dispatch callbacks such as the KA-to-CG nudge do not receive a poll-generation shutdown signal. A slow chain read inside that callback can therefore consume most or all of the retirement budget.
Related current work:
This issue must reuse those ownership boundaries rather than introduce a parallel cancellation model.
Requirements
- Close new poll/event admission synchronously before the first shutdown await.
- Give the active poll generation an abort signal composed with existing RPC/read cancellation.
- Thread cancellation through event dispatch only as far as required; do not make every domain callback own infrastructure policy.
- An aborted or partially dispatched page must not advance a durable chain-event cursor past uncompleted work.
- Preserve atomic verified store operations once their existing non-cancellable commit boundary has begun.
- Keep timeout quarantine as the final fail-stop guard for adapters that ignore cancellation.
Acceptance criteria
Provenance
Outcome
Cancel in-flight chain-event poll work promptly when shutdown begins, so a slow RPC or callback cannot hold the agent retirement drain until its outer timeout.
This extracts the live shutdown requirement from PR #2044 onto the current lifecycle, chain-event poller, and RPC cancellation boundaries.
Current state
Current shutdown correctly fences new work, stops the chain poller, waits for physical agent work, and quarantines backing-store teardown on a retirement timeout.
DKGNode.stopSignalalso cancels protocol reads.The remaining seam is narrower:
ChainEventPoller.stop()waits for the active poll, while event dispatch callbacks such as the KA-to-CG nudge do not receive a poll-generation shutdown signal. A slow chain read inside that callback can therefore consume most or all of the retirement budget.Related current work:
This issue must reuse those ownership boundaries rather than introduce a parallel cancellation model.
Requirements
Acceptance criteria
Provenance