Skip to content

Prevent coalesced libuv wakes from stranding inbound reads - #8498

Merged
Amaury Chamayou (achamayou) merged 6 commits into
mainfrom
copilot/investigate-missed-admission-resumption
Oct 5, 2026
Merged

Amaury Chamayou (achamayou) merged 6 commits into
mainfrom
copilot/investigate-missed-admission-resumption

Conversation

Copilot AI commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

On libuv before 1.53, an admission wake can be coalesced after the callback has consumed its recheck flag, potentially leaving paused reads idle until another event. This is a portable liveness risk, not a reproduced failure or lost response data.

  • Ordering: Publish and consume the recheck flag under the existing queue mutex. The callback either sees the request, or its mutex release orders libuv's pending-bit clear before the next send.
    {
      ccf::ds::MutexGuard g(self->out_mutex);
      self->recheck_read_interest = true;
    }
    self->wake();
  • Regression: Extend the real-socket test so one interface releases the inbound budget and another resumes without new client traffic.
  • Documentation: Record the reduced ordering argument and update the release note.

Verified libuv versions

Checked on 2026-10-05 against Microsoft's official x86_64 package repositories:

Platform libuv version Published RPM version-release
Azure Linux 3.0 1.48.0 1.48.0-1.azl3
Azure Linux 4.0 (beta repository) 1.52.0 1.52.0-2.azl4

For Azure Linux 3, the downloaded RPM header was queried with rpm -qp. For Azure Linux 4, the installed libuv and libuv-devel RPM versions, pkg-config --modversion libuv, and the loaded library's uv_version_string() all agreed with the published package. CCF's setup scripts install the distribution's libuv-devel without an exact version pin, so this table records the verified packages rather than a guarantee for every installed system.

Both versions are below the 1.53 threshold discussed above. Their version-tagged upstream documentation explicitly warns that multiple uv_async_send() calls before a callback can yield only one callback (libuv 1.48.0, libuv 1.52.0). Coalesced notifications are therefore relevant to both environments; this does not claim that the stalled-read failure has been reproduced.

Closes #8436

Co-authored-by: achamayou <4016369+achamayou@users.noreply.github.com>
Copilot AI changed the title [WIP] Investigate missed admission-resumption wakeup with libuv Prevent coalesced libuv wakes from stranding inbound reads Oct 2, 2026
@achamayou
Amaury Chamayou (achamayou) marked this pull request as ready for review October 5, 2026 10:59
Copilot AI balanced review requested due to automatic review settings October 5, 2026 10:59
@achamayou
Amaury Chamayou (achamayou) requested a review from a team as a code owner October 5, 2026 10:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The concurrency-sensitive ordering around older libuv versions warrants final human review.

Review effort: Balanced
Findings: None

What changed in this PR

Prevents older libuv notification coalescing from leaving inbound reads paused.

Changes:

  • Protects admission rechecks with the output queue mutex.
  • Adds cross-interface socket regression coverage.
  • Documents the ordering and prepares release 7.0.19.

Custom instructions used

  • .github/copilot-instructions.md
  • .github/instructions/reviewing.instructions.md
  • .github/instructions/changelog.instructions.md
  • .github/skills/testing/SKILL.md
File Description
src/​tls/​openssl_server.h Synchronizes recheck publication and consumption.
src/​tls/​test/​openssl_server_test.cpp Tests cross-interface budget resumption.
doc/​architecture/​tls_internals.rst Documents the mutex ordering argument.
CHANGELOG.md Adds the 7.0.19 fix entry.
python/​pyproject.toml Bumps the SDK version to 7.0.19.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Initialize recheck_all to false to satisfy cppcoreguidelines-init-variables. The queue-mutex-protected exchange still supplies its value before use, so admission wake ordering and runtime behavior are unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@achamayou
Amaury Chamayou (achamayou) merged commit 8a152f6 into main Oct 5, 2026
12 checks passed
@achamayou
Amaury Chamayou (achamayou) deleted the copilot/investigate-missed-admission-resumption branch October 5, 2026 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Investigate possible missed admission-resumption wakeup with libuv before 1.53

4 participants