Repository navigation
fix(h3): preserve responses under reactor backpressure - #411
Merged
Merged
Conversation
Contributor
CoverageTotal lines: 84.69% → 85.27% (+0.58 pp)
❌ Regression in touched files (> 1.0 pp drop)
Add |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A full reactor mailbox could discard a pooled HTTP/3 response while the worker logged 200 and the prepared body size, leaving the client waiting. The sender now preserves the wire and suspends its coroutine until capacity is available. Queue acceptance transfers ownership; accounting waits for the terminal transport outcome.
The reactor publishes one completion to the originating worker generation after the request snapshot is ready and all wire objects are released. Clean completion requires data and FIN acknowledgement. Failures before a confirmed status use
responses_undelivered_totalandresponse_undelivered; failures after confirmation retain the status and reportresponse_aborted. An independent preallocated control path handles cancellation, timeout and shutdown even when the data mailbox is full.Per-response writer ordering, retryable nonblocking first writes, waiter bailout cleanup and shutdown fences replace the old pending-wire TTL. The parent closes reload admission, sends STOP and joins worker tasks before destroying shared transport. The join retains completion events, runs the event loop through public
Async\protect, and waits for the current reload reservation to unwind. Partial worker submission stops and joins accepted tasks; recoverable worker start bailout completes clone cleanup before the task future can resolve. Arbitrary fatal/OOM inside a destructor does not acknowledge successful quiescence; progress through that failure is not guaranteed.The flow and ownership rules are documented in
docs/REACTOR_RESPONSE_DELIVERY.md.Validation:
tls/006andtls/007. Those and the two TLS/static tests that retried in the preceding full run all passed on a separate run on both the old and updated normal modules. The full run is not claimed retry-free. Of the skips, 24 require test hooks absent from that build; one depends on kernel SO_REUSEPORT behavior.reactor_pool_is_running; they now pass. The expanded ASAN attempt also crashed in three pre-existing core graceful-shutdown tests before the first server response. The same crashes reproduced on the previous PR module in the same ASAN environment; the three tests pass on the normal build.Remaining review items:
Closes #351.