Problem
A request cancelled in the window between dependency analysis claiming it (validated → batched) and promoting its batch out of creating reaches speculation anyway. The result is a live batch carrying a request the user cancelled; it will build, and it can merge.
Interleaving
dependency analysis: request validated → batched (claimRequestsForBatch)
cancel: request batched → cancelling (markCancelling)
cancel: findBatches sees only a creating batch — not cancellable
cancel: request cancelling → cancelled (no applicable batch → cancelRequest)
dependency analysis: batch creating → created (batch-only compare-and-swap)
dependency analysis: publish to speculate
Why the existing guards miss it
- The halted-request check in dependency analysis runs before the claim.
- The claim's re-read and version check reject a cancel that lands before or during the claim, but this window opens after the claim succeeds.
creating is not cancellable, so cancel's batch loop matches nothing and falls through to cancelRequest.
- Neither speculate's admission of
created batches nor conclude checks for halted requests.
Found in review of #590. As of 6c050082 the code paths above are unchanged.
Constraint
From #817: a batch abandoned in creating must stay unreachable, and created must remain dependency-eligible.
Problem
A request cancelled in the window between dependency analysis claiming it (
validated → batched) and promoting its batch out ofcreatingreaches speculation anyway. The result is a live batch carrying a request the user cancelled; it will build, and it can merge.Interleaving
Why the existing guards miss it
creatingis not cancellable, so cancel's batch loop matches nothing and falls through tocancelRequest.createdbatches nor conclude checks for halted requests.Found in review of #590. As of
6c050082the code paths above are unchanged.Constraint
From #817: a batch abandoned in
creatingmust stay unreachable, andcreatedmust remain dependency-eligible.