Reap dead outbound connection slots; strike disconnected peers from discovery. Two related connection-lifecycle fixes on top of the SIGPIPE fix.
Reclaim outbound slots on peer disconnect: - TcpClient_ThreadProc fired on_disconnect but never cleared the outbound slot, closed the fd, joined the io thread, or freed the connection, so a dead peer permanently held its outboundClients[] slot. After MAX_CONS (32) churned connections the node could make no new outbound connections, and leaked fds/threads/memory. (The inbound side already self-reclaimed.) - Add a reaper (Node_ReapDeadOutbound) on the maintenance thread: under outboundLock it detaches dead (disconnect-notified) slots, then joins the io thread and destroys/frees each connection outside the lock. - Guard against use-after-free with a pin count on tcp_connection_t (TcpConnection_Pin/Unpin). The only cross-thread consumer holding a raw connection pointer across a blocking op is the `sync` command (via Node_GetBestOutboundPeer); it now pins the peer and unpins when done, and the reaper skips pinned connections. Discovery's snapshots run on the reaper's own thread, so they need no pin. - Node_GetBestOutboundPeer/GetClientList/GetPeerEndpoints skip disconnect-notified connections so a dead peer is never handed out. - Node_Destroy stops+joins the maintenance thread before tearing down outbound clients, so the reaper can't race shutdown. Strike disconnected peers from the discovery peer list: - Add NodeDiscovery_RemovePeer + Node_HandlePeerDisconnect: on disconnect, remove the peer from the known-peer table once no live connection (inbound or outbound) to its listen endpoint remains (Node_HasLiveConnectionTo; disconnect-notified conns don't count, so both directions dropping at once is handled). Wired into Node_Server_OnDisconnect and Node_Client_OnDisconnect.
This commit is contained in:
@@ -3,6 +3,7 @@
|
||||
|
||||
#include <arpa/inet.h>
|
||||
#include <pthread.h>
|
||||
#include <stdatomic.h>
|
||||
#include <stdbool.h>
|
||||
#include <stddef.h>
|
||||
#include <stdint.h>
|
||||
@@ -37,6 +38,11 @@ struct tcp_connection_t {
|
||||
bool closing;
|
||||
bool disconnectedNotified;
|
||||
|
||||
// Non-zero while another thread holds a raw pointer to this connection taken from a
|
||||
// lock-protected snapshot and used after releasing the lock. The reaper must not free a
|
||||
// pinned connection. See TcpConnection_Pin/Unpin.
|
||||
atomic_int pinCount;
|
||||
|
||||
unsigned char* dataBuf;
|
||||
size_t dataBufLen;
|
||||
size_t dataBufCap;
|
||||
@@ -75,4 +81,9 @@ void TcpConnection_RequestClose(tcp_connection_t* conn);
|
||||
void TcpConnection_MarkDisconnectNotified(tcp_connection_t* conn);
|
||||
bool TcpConnection_IsDisconnectNotified(tcp_connection_t* conn);
|
||||
|
||||
// Pin/unpin a connection so a background reaper won't free it while a caller still holds a raw
|
||||
// pointer to it (e.g. across a blocking operation after releasing the collection lock).
|
||||
void TcpConnection_Pin(tcp_connection_t* conn);
|
||||
void TcpConnection_Unpin(tcp_connection_t* conn);
|
||||
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user