-
Notifications
You must be signed in to change notification settings - Fork 150
Fixes a race condition in killing Sandboxes #959
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
ad6647c
to
96a6fce
Compare
Signed-off-by: Simon Davies <[email protected]>
96a6fce
to
d200c7c
Compare
Signed-off-by: James Sturtevant <[email protected]>
…sted by us Signed-off-by: James Sturtevant <[email protected]>
/// retrying until either: | ||
/// - The signal is successfully delivered (VCPU transitions from running to not running) | ||
/// - The VCPU stops running for another reason (e.g., call completes normally) | ||
/// - No call is active (call_active=false) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Does it block? I thought it would just return false?
/// - Set to true at the start of call_guest_function_by_name_no_reset() | ||
/// - Cleared at the end of call_guest_function_by_name_no_reset() | ||
/// - kill() only stamps cancel_requested if call_active is true | ||
/// - If kill() is called when call_active=false, it returns false and has no effect |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this actually the case? I don't see it returning early when call is not active.
target_generation = Some(generation); | ||
} | ||
|
||
// If not running, we've stamped the generation (if requested), so we're done |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
should there be a check that call_active
is false
so this exits early in the case that the call ins't active?
I think this is currently working due to the fact that when call_active
running
is also active. I think there is one case where the call might not be active but the vm is running (during initial set up) and i think it might hang in that scenario?
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
// The virtualization stack can use this function to return the control | ||
// of a virtual processor back to the virtualization stack in case it | ||
// needs to change the state of a VM or to inject an event into the processor | ||
debug!("Internal cancellation detected, returning Retry error"); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
Fixes a race condition where a sandbox kill arrives after a sandbox has successfully exited causing the subsequent run to fail.
There is a breaking change in this PR, previously if kill was called on an
InterruptHandle
before or while a guest call was not in progress the next guest call made on theSandbox
would be cancelled , now this scenario is a no-op. kill only takes effect if there is a guest call running.