Skip to content

fix(render): stop already-started function runtimes when a later one fails to start - #403

Draft
jcogilvie wants to merge 1 commit into
crossplane:mainfrom
jcogilvie:jco/render-start-rollback
Draft

jcogilvie wants to merge 1 commit into
crossplane:mainfrom
jcogilvie:jco/render-start-rollback

Conversation

@jcogilvie

@jcogilvie jcogilvie commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Description of your changes

StartFunctionRuntimes starts Functions in order; if Function N fails to get or start its runtime, it returned nil, err and the runtimes for Functions 1..N-1 were leaked, since callers only defer StopFunctionRuntimes after a successful start.

Now, on failure, every runtime already started is stopped via its own RuntimeContext.Stop (so each runtime's cleanup policy is honoured). The stop uses a 5s timeout on a context detached from the caller's cancellation (context.WithoutCancel), mirroring StopFunctionRuntimes. All runtimes are attempted, and stop errors are joined after the original start error so it stays primary. No exported signatures change. StartFunctionRuntimes now delegates to an unexported startFunctionRuntimes that takes the runtime getter as a parameter, so the test injects a fake without package-level state.

Tested with a new unit test (TestStartFunctionRuntimesStopsStartedOnFailure) that fails the third of three Functions and asserts the first two were stopped. ./nix.sh flake check could not be run (nix isn't available in my environment); instead I ran go build ./..., go test ./cmd/crossplane/render/..., and golangci-lint run ./cmd/crossplane/render/..., all clean.

Fixes #396

I have:

Need help with this checklist? See the cheat sheet.

🤖 Generated with Claude Code

@jcogilvie
jcogilvie force-pushed the jco/render-start-rollback branch from 96fede9 to e931f12 Compare October 1, 2026 21:39
…fails to start

StartFunctionRuntimes starts Functions in order. When Function N failed to
get or start a runtime it returned nil and an error, dropping the
RuntimeContexts of Functions 1..N-1. Callers only defer
StopFunctionRuntimes after a successful start, so those runtimes (e.g.
Docker containers) were leaked.

On failure, stop every runtime already started via its own Stop (honouring
its cleanup policy), using a bounded context detached from the caller's
cancellation. All are attempted; stop errors are joined after the original
start error so it stays primary.

Fixes crossplane#396

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Jonathan Ogilvie <jonathan.ogilvie@sumologic.com>
@jcogilvie
jcogilvie force-pushed the jco/render-start-rollback branch from e931f12 to 44b6388 Compare October 1, 2026 22:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

render: StartFunctionRuntimes leaks already-started Function containers when a later Function fails to start

1 participant