Found in the PR #170 review.
Defect: aborting or dropping the task running MqttBroker::run() does not stop connection handlers that were already accepted. They keep serving their clients and keep writing to session storage.
Effect: code that stops a broker by aborting its task, rather than through graceful shutdown, leaves a half-running broker. In tests this made "crash" tests pass by ordering rather than by crash semantics (PR #170 moved those tests to a child process killed with SIGKILL). Graceful shutdown is not affected.
Evidence: a client connected before the abort still gets PINGRESP after it.
Fix: tie the connection handlers to the lifetime of run(), for example with a cancellation token or a JoinSet owned by run(), so aborting it stops them. Add a test.
Found in the PR #170 review.
Defect: aborting or dropping the task running
MqttBroker::run()does not stop connection handlers that were already accepted. They keep serving their clients and keep writing to session storage.Effect: code that stops a broker by aborting its task, rather than through graceful shutdown, leaves a half-running broker. In tests this made "crash" tests pass by ordering rather than by crash semantics (PR #170 moved those tests to a child process killed with SIGKILL). Graceful shutdown is not affected.
Evidence: a client connected before the abort still gets PINGRESP after it.
Fix: tie the connection handlers to the lifetime of
run(), for example with a cancellation token or aJoinSetowned byrun(), so aborting it stops them. Add a test.