git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v4 10/12] unix-socket: create `unix_stream_server__listen_with_lock()`

From
Jeff King <peff@peff.net>
Date
Mar 4, 2021, 15:13 UTC
Message-ID
<YED5N1QnnVQ6qbE6@coredump.intra.peff.net>
In-Reply-To
<d29f0f18-a292-8090-fe69-70576aa10506@jeffhostetler.com>
On Tue, Mar 02, 2021 at 06:50:51PM -0500, Jeff Hostetler wrote:
Show 5 quoted lines
> I was thinking that the "ping" is just to see if a server is listening
> or not.  (And I viewed that as kind of a hack, but it works.)  If we
> start sending data back and forth, we get into protocols and blocking
> and stuff that this layer (even if we move it up a level) doesn't know
> about.

Right. Definitely the higher up the stack the ping happens, the more value it has. But I also see the appeal of keeping this as its own layer.

Show 16 quoted lines
> > > +	if (hold_lock_file_for_update_timeout(&lock, path, 0,
> > > +					      opts->timeout_ms) < 0) {
> > > +		error_errno(_("could not lock listener socket '%s'"), path);
> > > +		return NULL;
> > > +	}
> > 
> > Would you want to ping to see if it's alive before creating the lock?
> > That would be the fast-path if we assume that a server will usually be
> > there once started. Or is that supposed to happen in the caller (in
> > which case I'd again wonder if this really should be happening in the
> > simple-ipc code).
> 
> Starting a server should not happen that often, so I'm not sure it
> matters.  And yes, a server once started should run for a long time.
> Pinging without the lock puts us back in another race, so we might as
> well lock first.

Definitely you need to ping under lock to avoid races. But I was thinking of an additional optimistic ping before we take the lock. I agree that starting the server should be rare, which is why I think there's value in seeing "is it up" before taking any lock.

But I suspect your thinking is that this ping happens in the caller anyway, before we hit any of this unix_socket_listen() code at all. And that makes sense to me. In fact, I guess it has to happen that way, because "try to connect" and "try to spin up a server" are likely happening in two separate processes entirely (we only spawn the second one if the first one failed its ping).

Show 17 quoted lines
> > I'd think in those three cases you'd want:
> > 
> >    - if lock contention, pause a moment and wait for the winner to spin
> >      up and serve requests
> > 
> >    - if another server is live while we hold the lock, then we raced them
> >      and they won. Release the lock and start using them.
> > 
> >    - if we really tried to call unix_stream_listen() and that failed,
> >      give up now. There is some system error that is not likely to be
> >      fixed by trying anything more (e.g., ENAMETOOLONG).
> 
> Yes, I want to move the error messages out of these library layers.
> 
> And yes, if another server is running, our server instance should
> shutdown gracefully.  Other client processes can just talk to them
> rather than us.

Right, that makes sense. Again, I was thinking earlier of the whole "try to connect, but spin up a server otherwise" thing happening in a single process. But by the time we get to the listen code, we have probably already spawned a server process, and have redirected its stderr somewhere. And likewise the caller doesn't even care that much if the server reports an error because it somebody else won the race. It only cares that after a few connect attempts it manages to talk to _somebody_.

Show 17 quoted lines
> > > +	lstat(path, &server_socket->st_socket);
> > 
> > This lstat I guess is part of your "periodically check to see if we're
> > still the one holding the socket" strategy. We _shouldn't_ need that
> > anymore, with the dotlocking, but I'm OK with it as a
> > belt-and-suspenders check. But why are we filling in the lstat here?
> > This seems like something that the unix-socket code doesn't really need
> > to know about (though you do at least provide the complementary
> > "was_stolen" function here, so that part makes sense).
> 
> The dotlock is only on disk for the duration of the socket setup.
> We do the rollback (to delete the lockfile) once we have the socket
> open and ready for business.
> 
> The lstat gives me the inode of the socket on disk and we can watch
> it with future lstat's in the event loop and see if it changes and
> detect theft and auto-shutdown.

Right, I gradually came to the understanding of what your extra layer was trying to accomplish while reading (sometimes I'll go back and edit earlier comments in my review before sending out the mail, but in this case it seemed less confusing to leave my train of thought in place. That might not have been correct, though. ;) ).

I think if everybody is abiding by the lock system to create the socket, we probably don't strictly _need_ the theft detection. But it might not hurt as a belt-and-suspenders, or for cases where somebody thinks the socket is stale but it isn't (perhaps due to listen backlog or something while trying to do the connect() ping).

Show 29 quoted lines
> > > +void unix_stream_server__free(
> > > +	struct unix_stream_server_socket *server_socket)
> > > +{
> > > +	if (!server_socket)
> > > +		return;
> > > +
> > > +	if (server_socket->fd_socket >= 0) {
> > > +		if (!unix_stream_server__was_stolen(server_socket))
> > > +			unlink(server_socket->path_socket);
> > > +		close(server_socket->fd_socket);
> > > +	}
> > > +
> > > +	free(server_socket->path_socket);
> > > +	free(server_socket);
> > > +}
> > 
> > OK, this makes sense. We only remove it if we're still the ones holding
> > it. That's not done under lock, though, so it's possibly racy (somebody
> > steals from us while _they_ hold the lock; we check and see "not stolen"
> > right before they steal it, and then we unlink their stolen copy).
> 
> Right, I didn't bother with the lock here.  I don't think we need it.
> 
> We technically still have the socket open and are listening on it when
> we lstat and unlink it.  The other process should create the lock and
> try to connect.  That should hang in the kernel because of the accept()
> grace period.  Then we close the socket and the client's connection
> request errors because we didn't accept it.  They will see the error
> as no one is listening and then create their own socket.

I think there are still some races (at least if we believe that anything can be stolen in the first place). Something like:

  - process A holds the socket but plans to exit
  - process B takes the lock
  - process B tries to ping us, but it doesn't work for some reason
    (this part is vague, but it's also the thing that makes stealing
    possible at all)
  - process A calls was_stolen(), which says "no"
  - process B decides nobody is there, so it unlinks the socket and
    creates its own
  - process A calls unlink(), removing B's socket

A is OK with this; it was exiting anyway. But it just stranded B, who _thinks_ it owns the socket, but doesn't.

Again, there's a vagueness to "B somehow doesn't see A as listening" in the middle step. But without that step, I don't see how you'd really have stealing in the first place.

-Peff
Previous: Jeff HostetlerNext: Jeff Hostetler via GitGitGadget
Message 122 of 178 in “[RFC] Simple IPC Mechanism”
  1. 00/10 [RFC] Simple IPC MechanismJeff Hostetler via GitGitGadget, Jan 12, 2021
  2. 01/10 pkt-line: use stack rather than static buffer in packet_write_gently()Jeff Hostetler via GitGitGadget, Jan 12, 2021
  3. Jeff KingJan 13, 2021
  4. Jeff HostetlerJan 25, 2021
  5. 04/10 pkt-line: accept additional options in read_packetized_to_strbuf()Johannes Schindelin via GitGitGadget, Jan 12, 2021
  6. 02/10 pkt-line: (optionally) libify the packet readersJohannes Schindelin via GitGitGadget, Jan 12, 2021
  7. 05/10 simple-ipc: design documentation for new IPC mechanismJeff Hostetler via GitGitGadget, Jan 12, 2021
  8. Ævar Arnfjörð BjarmasonJan 12, 2021
  9. 03/10 pkt-line: optionally skip the flush packet in write_packetized_from_buf()Johannes Schindelin via GitGitGadget, Jan 12, 2021
  10. 10/10 simple-ipc: add Unix domain socket implementationJeff Hostetler via GitGitGadget, Jan 12, 2021
  11. 08/10 unix-socket: add no-chdir option to unix_stream_listen_gently()Jeff Hostetler via GitGitGadget, Jan 12, 2021
  12. 09/10 simple-ipc: add t/helper/test-simple-ipc and t0052Jeff Hostetler via GitGitGadget, Jan 12, 2021
  13. 07/10 unix-socket: create gentle version of unix_stream_listen()Jeff Hostetler via GitGitGadget, Jan 12, 2021
  14. Jeff KingJan 13, 2021
  15. Chris TorekJan 14, 2021
  16. 06/10 simple-ipc: add win32 implementationJeff Hostetler via GitGitGadget, Jan 12, 2021
  17. Ævar Arnfjörð BjarmasonJan 12, 2021
  18. Jeff HostetlerJan 12, 2021
  19. Junio C HamanoJan 12, 2021
  20. Jeff HostetlerJan 12, 2021
  21. Junio C HamanoJan 13, 2021
  22. Jeff HostetlerJan 13, 2021
  23. Jeff KingJan 13, 2021
  24. Ævar Arnfjörð BjarmasonJan 13, 2021
  25. 00/14 Simple IPC MechanismJeff Hostetler via GitGitGadget, Feb 1, 2021
  26. 01/14 ci/install-depends: attempt to fix "brew cask" stuffJunio C Hamano via GitGitGadget, Feb 1, 2021
  27. 04/14 pkt-line: optionally skip the flush packet in write_packetized_from_buf()Johannes Schindelin via GitGitGadget, Feb 1, 2021
  28. Jeff KingFeb 2, 2021
  29. Johannes SchindelinFeb 2, 2021
  30. Jeff HostetlerFeb 5, 2021
  31. 05/14 pkt-line: (optionally) libify the packet readersJohannes Schindelin via GitGitGadget, Feb 1, 2021
  32. 06/14 pkt-line: accept additional options in read_packetized_to_strbuf()Johannes Schindelin via GitGitGadget, Feb 1, 2021
  33. Taylor BlauFeb 11, 2021
  34. 13/14 unix-socket: do not call die in unix_stream_connect()Jeff Hostetler via GitGitGadget, Feb 1, 2021
  35. 11/14 unix-socket: add options to unix_stream_listen()Jeff Hostetler via GitGitGadget, Feb 1, 2021
  36. Jeff KingFeb 2, 2021
  37. Jeff HostetlerFeb 5, 2021
  38. Jeff KingFeb 9, 2021
  39. Jeff HostetlerFeb 9, 2021
  40. Jeff KingFeb 10, 2021
  41. Jeff HostetlerFeb 10, 2021
  42. 07/14 simple-ipc: design documentation for new IPC mechanismJeff Hostetler via GitGitGadget, Feb 1, 2021
  43. 14/14 simple-ipc: add Unix domain socket implementationJeff Hostetler via GitGitGadget, Feb 1, 2021
  44. 08/14 simple-ipc: add win32 implementationJeff Hostetler via GitGitGadget, Feb 1, 2021
  45. 10/14 unix-socket: elimiate static unix_stream_socket() helper functionJeff Hostetler via GitGitGadget, Feb 1, 2021
  46. Jeff KingFeb 2, 2021
  47. Jeff KingFeb 2, 2021
  48. 09/14 simple-ipc: add t/helper/test-simple-ipc and t0052Jeff Hostetler via GitGitGadget, Feb 1, 2021
  49. SZEDER GáborFeb 2, 2021
  50. Jeff KingFeb 3, 2021
  51. Jeff HostetlerFeb 9, 2021
  52. SZEDER GáborFeb 5, 2021
  53. 12/14 unix-socket: add no-chdir option to unix_stream_listen()Jeff Hostetler via GitGitGadget, Feb 1, 2021
  54. Jeff KingFeb 2, 2021
  55. 03/14 pkt-line: add write_packetized_from_buf2() that takes scratch bufferJeff Hostetler via GitGitGadget, Feb 1, 2021
  56. Jeff KingFeb 2, 2021
  57. 02/14 pkt-line: promote static buffer in packet_write_gently() to callersJeff Hostetler via GitGitGadget, Feb 1, 2021
  58. Jeff KingFeb 2, 2021
  59. Jeff HostetlerFeb 2, 2021
  60. Johannes SchindelinFeb 2, 2021
  61. Jeff KingFeb 3, 2021
  62. Junio C HamanoFeb 1, 2021
  63. Jeff HostetlerFeb 1, 2021
  64. Johannes SchindelinFeb 2, 2021
  65. Junio C HamanoFeb 4, 2021
  66. candidate branches for `maint`, was Re: [PATCH v2 00/14] Simple IPC MechanismJohannes Schindelin, Feb 5, 2021
  67. Junio C HamanoFeb 5, 2021
  68. 00/12 Simple IPC MechanismJeff Hostetler via GitGitGadget, Feb 13, 2021
  69. 01/12 pkt-line: eliminate the need for static buffer in packet_write_gently()Jeff Hostetler via GitGitGadget, Feb 13, 2021
  70. 02/12 pkt-line: do not issue flush packets in write_packetized_*()Johannes Schindelin via GitGitGadget, Feb 13, 2021
  71. 03/12 pkt-line: (optionally) libify the packet readersJohannes Schindelin via GitGitGadget, Feb 13, 2021
  72. 04/12 pkt-line: add options argument to read_packetized_to_strbuf()Johannes Schindelin via GitGitGadget, Feb 13, 2021
  73. 05/12 simple-ipc: design documentation for new IPC mechanismJeff Hostetler via GitGitGadget, Feb 13, 2021
  74. 06/12 simple-ipc: add win32 implementationJeff Hostetler via GitGitGadget, Feb 13, 2021
  75. 07/12 unix-socket: elimiate static unix_stream_socket() helper functionJeff Hostetler via GitGitGadget, Feb 13, 2021
  76. 08/12 unix-socket: add backlog size option to unix_stream_listen()Jeff Hostetler via GitGitGadget, Feb 13, 2021
  77. 10/12 unix-socket: create `unix_stream_server__listen_with_lock()`Jeff Hostetler via GitGitGadget, Feb 13, 2021
  78. 09/12 unix-socket: disallow chdir() when creating unix domain socketsJeff Hostetler via GitGitGadget, Feb 13, 2021
  79. 12/12 t0052: add simple-ipc tests and t/helper/test-simple-ipc toolJeff Hostetler via GitGitGadget, Feb 13, 2021
  80. SZEDER GáborFeb 13, 2021
  81. Jeff HostetlerFeb 16, 2021
  82. 11/12 simple-ipc: add Unix domain socket implementationJeff Hostetler via GitGitGadget, Feb 13, 2021
  83. 00/12 Simple IPC MechanismJeff Hostetler via GitGitGadget, Feb 17, 2021
  84. 01/12 pkt-line: eliminate the need for static buffer in packet_write_gently()Jeff Hostetler via GitGitGadget, Feb 17, 2021
  85. Jeff KingFeb 26, 2021
  86. Jeff HostetlerFeb 26, 2021
  87. Jeff KingFeb 26, 2021
  88. Junio C HamanoMar 3, 2021
  89. Jeff HostetlerMar 4, 2021
  90. Junio C HamanoMar 4, 2021
  91. 02/12 pkt-line: do not issue flush packets in write_packetized_*()Johannes Schindelin via GitGitGadget, Feb 17, 2021
  92. 03/12 pkt-line: (optionally) libify the packet readersJohannes Schindelin via GitGitGadget, Feb 17, 2021
  93. Junio C HamanoMar 3, 2021
  94. Jeff HostetlerMar 4, 2021
  95. Jeff KingMar 4, 2021
  96. Junio C HamanoMar 4, 2021
  97. 04/12 pkt-line: add options argument to read_packetized_to_strbuf()Johannes Schindelin via GitGitGadget, Feb 17, 2021
  98. 05/12 simple-ipc: design documentation for new IPC mechanismJeff Hostetler via GitGitGadget, Feb 17, 2021
  99. Junio C HamanoMar 3, 2021
  100. 06/12 simple-ipc: add win32 implementationJeff Hostetler via GitGitGadget, Feb 17, 2021
  101. 07/12 unix-socket: elimiate static unix_stream_socket() helper functionJeff Hostetler via GitGitGadget, Feb 17, 2021
  102. Jeff KingFeb 26, 2021
  103. Junio C HamanoMar 3, 2021
  104. 08/12 unix-socket: add backlog size option to unix_stream_listen()Jeff Hostetler via GitGitGadget, Feb 17, 2021
  105. Jeff KingFeb 26, 2021
  106. Junio C HamanoMar 3, 2021
  107. 09/12 unix-socket: disallow chdir() when creating unix domain socketsJeff Hostetler via GitGitGadget, Feb 17, 2021
  108. Junio C HamanoMar 3, 2021
  109. Jeff KingMar 4, 2021
  110. Junio C HamanoMar 4, 2021
  111. Junio C HamanoMar 4, 2021
  112. Jeff KingMar 5, 2021
  113. Jeff KingMar 5, 2021
  114. Chris TorekMar 5, 2021
  115. Jeff HostetlerMar 5, 2021
  116. Junio C HamanoMar 5, 2021
  117. Jeff HostetlerMar 5, 2021
  118. Junio C HamanoMar 5, 2021
  119. 10/12 unix-socket: create `unix_stream_server__listen_with_lock()`Jeff Hostetler via GitGitGadget, Feb 17, 2021
  120. Jeff KingFeb 26, 2021
  121. Jeff HostetlerMar 2, 2021
  122. Jeff KingMar 4, 2021
  123. 12/12 t0052: add simple-ipc tests and t/helper/test-simple-ipc toolJeff Hostetler via GitGitGadget, Feb 17, 2021
  124. Jeff KingMar 2, 2021
  125. Jeff HostetlerMar 3, 2021
  126. 11/12 simple-ipc: add Unix domain socket implementationJeff Hostetler via GitGitGadget, Feb 17, 2021
  127. Junio C HamanoFeb 25, 2021
  128. Jeff KingFeb 26, 2021
  129. Jeff HostetlerFeb 26, 2021
  130. Jeff KingFeb 26, 2021
  131. Junio C HamanoMar 3, 2021
  132. 00/12 Simple IPC MechanismJeff Hostetler via GitGitGadget, Mar 9, 2021
  133. 01/12 pkt-line: eliminate the need for static buffer in packet_write_gently()Jeff Hostetler via GitGitGadget, Mar 9, 2021
  134. Junio C HamanoMar 9, 2021
  135. Jeff KingMar 11, 2021
  136. Junio C HamanoMar 11, 2021
  137. Jeff KingMar 11, 2021
  138. 05/12 simple-ipc: design documentation for new IPC mechanismJeff Hostetler via GitGitGadget, Mar 9, 2021
  139. 07/12 unix-socket: eliminate static unix_stream_socket() helper functionJeff Hostetler via GitGitGadget, Mar 9, 2021
  140. 06/12 simple-ipc: add win32 implementationJeff Hostetler via GitGitGadget, Mar 9, 2021
  141. 11/12 simple-ipc: add Unix domain socket implementationJeff Hostetler via GitGitGadget, Mar 9, 2021
  142. Junio C HamanoMar 10, 2021
  143. Jeff HostetlerMar 15, 2021
  144. 03/12 pkt-line: add PACKET_READ_GENTLE_ON_READ_ERROR optionJohannes Schindelin via GitGitGadget, Mar 9, 2021
  145. 02/12 pkt-line: do not issue flush packets in write_packetized_*()Johannes Schindelin via GitGitGadget, Mar 9, 2021
  146. 04/12 pkt-line: add options argument to read_packetized_to_strbuf()Johannes Schindelin via GitGitGadget, Mar 9, 2021
  147. 08/12 unix-socket: add backlog size option to unix_stream_listen()Jeff Hostetler via GitGitGadget, Mar 9, 2021
  148. 12/12 t0052: add simple-ipc tests and t/helper/test-simple-ipc toolJeff Hostetler via GitGitGadget, Mar 9, 2021
  149. 10/12 unix-stream-server: create unix domain socket under lockJeff Hostetler via GitGitGadget, Mar 9, 2021
  150. Junio C HamanoMar 10, 2021
  151. 09/12 unix-socket: disallow chdir() when creating unix domain socketsJeff Hostetler via GitGitGadget, Mar 9, 2021
  152. Junio C HamanoMar 9, 2021
  153. 00/12 Simple IPC MechanismJeff Hostetler via GitGitGadget, Mar 15, 2021
  154. 01/12 pkt-line: eliminate the need for static buffer in packet_write_gently()Jeff Hostetler via GitGitGadget, Mar 15, 2021
  155. 03/12 pkt-line: add PACKET_READ_GENTLE_ON_READ_ERROR optionJohannes Schindelin via GitGitGadget, Mar 15, 2021
  156. 02/12 pkt-line: do not issue flush packets in write_packetized_*()Johannes Schindelin via GitGitGadget, Mar 15, 2021
  157. 05/12 simple-ipc: design documentation for new IPC mechanismJeff Hostetler via GitGitGadget, Mar 15, 2021
  158. 08/12 unix-socket: add backlog size option to unix_stream_listen()Jeff Hostetler via GitGitGadget, Mar 15, 2021
  159. 04/12 pkt-line: add options argument to read_packetized_to_strbuf()Johannes Schindelin via GitGitGadget, Mar 15, 2021
  160. 10/12 unix-stream-server: create unix domain socket under lockJeff Hostetler via GitGitGadget, Mar 15, 2021
  161. 09/12 unix-socket: disallow chdir() when creating unix domain socketsJeff Hostetler via GitGitGadget, Mar 15, 2021
  162. 06/12 simple-ipc: add win32 implementationJeff Hostetler via GitGitGadget, Mar 15, 2021
  163. 07/12 unix-socket: eliminate static unix_stream_socket() helper functionJeff Hostetler via GitGitGadget, Mar 15, 2021
  164. 11/12 simple-ipc: add Unix domain socket implementationJeff Hostetler via GitGitGadget, Mar 15, 2021
  165. 12/12 t0052: add simple-ipc tests and t/helper/test-simple-ipc toolJeff Hostetler via GitGitGadget, Mar 15, 2021
  166. 00/12 Simple IPC MechanismJeff Hostetler via GitGitGadget, Mar 22, 2021
  167. 01/12 pkt-line: eliminate the need for static buffer in packet_write_gently()Jeff Hostetler via GitGitGadget, Mar 22, 2021
  168. 03/12 pkt-line: add PACKET_READ_GENTLE_ON_READ_ERROR optionJohannes Schindelin via GitGitGadget, Mar 22, 2021
  169. 02/12 pkt-line: do not issue flush packets in write_packetized_*()Johannes Schindelin via GitGitGadget, Mar 22, 2021
  170. 05/12 simple-ipc: design documentation for new IPC mechanismJeff Hostetler via GitGitGadget, Mar 22, 2021
  171. 04/12 pkt-line: add options argument to read_packetized_to_strbuf()Johannes Schindelin via GitGitGadget, Mar 22, 2021
  172. 08/12 unix-socket: add backlog size option to unix_stream_listen()Jeff Hostetler via GitGitGadget, Mar 22, 2021
  173. 09/12 unix-socket: disallow chdir() when creating unix domain socketsJeff Hostetler via GitGitGadget, Mar 22, 2021
  174. 07/12 unix-socket: eliminate static unix_stream_socket() helper functionJeff Hostetler via GitGitGadget, Mar 22, 2021
  175. 10/12 unix-stream-server: create unix domain socket under lockJeff Hostetler via GitGitGadget, Mar 22, 2021
  176. 12/12 t0052: add simple-ipc tests and t/helper/test-simple-ipc toolJeff Hostetler via GitGitGadget, Mar 22, 2021
  177. 11/12 simple-ipc: add Unix domain socket implementationJeff Hostetler via GitGitGadget, Mar 22, 2021
  178. 06/12 simple-ipc: add win32 implementationJeff Hostetler via GitGitGadget, Mar 22, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.