Fix segfault caused by socket I/O on a closed io_service#168
Merged
RobertIndie merged 1 commit intoapache:mainfrom Jan 13, 2023
Merged
Conversation
Fixes apache#167 ### Motivation Here are some debugging info when the segfault happened in `testCloseClient`. The outputs have been trimmed to make them clear. An example crash at `async_write`: ``` #12 0x00007ffff7496dad in basic_stream_socket<...>::boost::asio::async_write /usr/include/boost/asio/impl/write.hpp:512 #13 0x00007ffff748e003 in ClientConnection::asyncWrite lib/ClientConnection.h:245 #14 0x00007ffff746e0b6 in ClientConnection::handleHandshake (this=0x555555e689d0) lib/ClientConnection.cc:502 ``` Another example crash at `async_receive`: ``` #6 0x00007ffff7497247 in basic_stream_socket<...>::async_receive /usr/include/boost/asio/basic_stream_socket.hpp:677 #7 0x00007ffff748e647 in ClientConnection::asyncReceive lib/ClientConnection.h:258 #8 0x00007ffff746fa5d in ClientConnection::readNextCommand lib/ClientConnection.cc:606 ``` The frame where it crashed: ``` 245 if (descriptor_data->shutdown_) (gdb) p descriptor_data $2 = (boost::asio::detail::epoll_reactor::per_descriptor_data &) @0x555555e4a780: 0x0 ``` We can see the socket descriptor is `nullptr`. The root cause is when `async_receive` or `async_write` is called, the `io_service` object might be closed. This case happened when `createProducerAsync` is called, the actual producer creation continues in another thread, while the `client.close()` happens in the current thread. ### Modifications Check if the `ClientConnection` is closed before `async_receive` or `async_write`. To avoid the use of lock, changing the `state_` field to atomic. ### Verifications ```bash ./tests/pulsar-tests --gtest_filter='ClientTest.testCloseClient' --gtest_repeat=20 ``` It never crashed after applying this patch.
shibd
approved these changes
Jan 7, 2023
Member
|
@RobertIndie Can you take a look? This error occurs frequently. |
RobertIndie
approved these changes
Jan 13, 2023
merlimat
pushed a commit
that referenced
this pull request
Jan 19, 2023
Fixes #167 ### Motivation Here are some debugging info when the segfault happened in `testCloseClient`. The outputs have been trimmed to make them clear. An example crash at `async_write`: ``` #12 0x00007ffff7496dad in basic_stream_socket<...>::boost::asio::async_write /usr/include/boost/asio/impl/write.hpp:512 #13 0x00007ffff748e003 in ClientConnection::asyncWrite lib/ClientConnection.h:245 #14 0x00007ffff746e0b6 in ClientConnection::handleHandshake (this=0x555555e689d0) lib/ClientConnection.cc:502 ``` Another example crash at `async_receive`: ``` #6 0x00007ffff7497247 in basic_stream_socket<...>::async_receive /usr/include/boost/asio/basic_stream_socket.hpp:677 #7 0x00007ffff748e647 in ClientConnection::asyncReceive lib/ClientConnection.h:258 #8 0x00007ffff746fa5d in ClientConnection::readNextCommand lib/ClientConnection.cc:606 ``` The frame where it crashed: ``` 245 if (descriptor_data->shutdown_) (gdb) p descriptor_data $2 = (boost::asio::detail::epoll_reactor::per_descriptor_data &) @0x555555e4a780: 0x0 ``` We can see the socket descriptor is `nullptr`. The root cause is when `async_receive` or `async_write` is called, the `io_service` object might be closed. This case happened when `createProducerAsync` is called, the actual producer creation continues in another thread, while the `client.close()` happens in the current thread. ### Modifications Check if the `ClientConnection` is closed before `async_receive` or `async_write`. To avoid the use of lock, changing the `state_` field to atomic. ### Verifications ```bash ./tests/pulsar-tests --gtest_filter='ClientTest.testCloseClient' --gtest_repeat=20 ``` It never crashed after applying this patch.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #167
Motivation
Here are some debugging info when the segfault happened in
testCloseClient. The outputs have been trimmed to make them clear.An example crash at
async_write:Another example crash at
async_receive:The frame where it crashed:
We can see the socket descriptor is
nullptr. The root cause is whenasync_receiveorasync_writeis called, theio_serviceobject might be closed. This case happened whencreateProducerAsyncis called, the actual producer creation continues in another thread, while theclient.close()happens in the current thread.Modifications
Check if the
ClientConnectionis closed beforeasync_receiveorasync_write. To avoid the use of lock, changing thestate_field to atomic.Verifications
./tests/pulsar-tests --gtest_filter='ClientTest.testCloseClient' --gtest_repeat=20It never crashed after applying this patch.