1 # Copyright (C) all contributors <meta@public-inbox.org>
2 # License: AGPL-3.0+ <https://www.gnu.org/licenses/agpl-3.0.txt>
4 # Like most Perl modules in public-inbox, this is internal and
5 # NOT subject to any stability guarantees! It is only documented
8 # This is used to limit the number of processes spawned by the
9 # PSGI server, so it acts like a semaphore and queues up extra
10 # commands to be run if currently at the limit. Multiple "limiters"
11 # may be configured which give inboxes different channels to
12 # operate in. This can be useful to ensure smaller inboxes can
13 # be cloned while cloning of large inboxes is maxed out.
15 # This does not depend on the PublicInbox::DS::event_loop or any
16 # other external scheduling mechanism, you just need to call
17 # start() and finish() appropriately. However, public-inbox-httpd
18 # (which uses PublicInbox::DS) will be able to schedule this
19 # based on readability of stdout from the spawned process.
20 # See GitHTTPBackend.pm and SolverGit.pm for usage examples.
21 # It does not depend on any form of threading.
23 # This is useful for scheduling CGI execution of both long-lived
24 # git-http-backend(1) process (for "git clone") as well as short-lived
25 # processes such as git-apply(1).
27 package PublicInbox::Qspawn;
29 use PublicInbox::Spawn qw(popen_rd);
30 use PublicInbox::GzipFilter;
31 use Scalar::Util qw(blessed);
33 # n.b.: we get EAGAIN with public-inbox-httpd, and EINTR on other PSGI servers
34 use Errno qw(EAGAIN EINTR);
38 # declares a command to spawn (but does not spawn it).
39 # $cmd is the command to spawn
40 # $cmd_env is the environ for the child process (not PSGI env)
41 # $opt can include redirects and perhaps other process spawning options
42 # {qsp_err} is an optional error buffer callers may access themselves
44 my ($class, $cmd, $cmd_env, $opt) = @_;
45 bless { args => [ $cmd, $cmd_env, $opt ] }, $class;
49 my ($self, $start_cb, $limiter) = @_;
51 my ($cmd, $cmd_env, $opt) = @{delete $self->{args}};
52 my %o = %{$opt || {}};
53 $self->{limiter} = $limiter;
54 foreach my $k (@PublicInbox::Spawn::RLIMITS) {
55 if (defined(my $rlimit = $limiter->{$k})) {
59 $self->{cmd} = $o{quiet} ? undef : $cmd;
61 # popen_rd may die on EMFILE, ENFILE
62 $self->{rpipe} = popen_rd($cmd, $cmd_env, \%o);
64 die "E: $!" unless defined($self->{rpipe});
66 $limiter->{running}++;
67 $start_cb->($self); # EPOLL_CTL_ADD may ENOSPC/ENOMEM
69 finish($self, $@) if $@;
73 my ($child_error) = @_; # typically $?
74 my $exitstatus = ($child_error >> 8) or return;
75 my $sig = $child_error & 127;
76 my $msg = "exit status=$exitstatus";
77 $msg .= " signal=$sig" if $sig;
82 my ($self, $err) = @_;
84 my ($env, $qx_cb, $qx_arg, $qx_buf) =
85 delete @$self{qw(psgi_env qx_cb qx_arg qx_buf)};
87 # done, spawn whatever's in the queue
88 my $limiter = $self->{limiter};
89 my $running = --$limiter->{running};
91 if ($running < $limiter->{max}) {
92 if (my $next = shift(@{$limiter->{run_queue}})) {
93 _do_spawn(@$next, $limiter);
99 if (my $dst = $self->{qsp_err}) {
100 $$dst .= $$dst ? " $err" : "; $err";
102 warn "@{$self->{cmd}}: $err" if $self->{cmd};
105 eval { $qx_cb->($qx_buf, $qx_arg) };
107 warn "E: $@"; # hope qspawn.wcb can handle it
109 return if $self->{passed}; # another command chained it
110 if (my $wcb = delete $env->{'qspawn.wcb'}) {
111 # have we started writing, yet?
112 my $code = delete $env->{'qspawn.fallback'} // 500;
113 require PublicInbox::WwwStatic;
114 $wcb->(PublicInbox::WwwStatic::r($code));
118 # callback for dwaitpid or ProcessPipe
119 sub waitpid_err { finalize($_[0], child_err($?)) }
122 my ($self, $err) = @_;
123 my $tied_pp = delete($self->{rpipe}) or return finalize($self, $err);
124 my PublicInbox::ProcessPipe $pp = tied *$tied_pp;
125 @$pp{qw(cb arg)} = (\&waitpid_err, $self); # for ->DESTROY
129 my ($self, $limiter, $start_cb) = @_;
130 if ($limiter->{running} < $limiter->{max}) {
131 _do_spawn($self, $start_cb, $limiter);
133 push @{$limiter->{run_queue}}, [ $self, $start_cb ];
137 sub psgi_qx_init_cb { # this may be PublicInbox::HTTPD::Async {cb}
139 my $async = delete $self->{async}; # PublicInbox::HTTPD::Async
141 my $qx_fh = $self->{qx_fh};
143 $r = sysread($self->{rpipe}, $buf, 65536);
145 $async->async_pass($self->{psgi_env}->{'psgix.io'},
147 } elsif (defined $r) {
148 $r ? (print $qx_fh $buf) : event_step($self, undef);
150 return if $! == EAGAIN; # try again when notified
151 goto reread if $! == EINTR;
152 event_step($self, $!);
158 if (my $async = $self->{psgi_env}->{'pi-httpd.async'}) {
159 # PublicInbox::HTTPD::Async->new(rpipe, $cb, cb_arg, $end_obj)
160 $self->{async} = $async->($self->{rpipe},
161 \&psgi_qx_init_cb, $self, $self);
162 # init_cb will call ->async_pass or ->close
163 } else { # generic PSGI
164 psgi_qx_init_cb($self) while $self->{qx_fh};
168 # Similar to `backtick` or "qx" ("perldoc -f qx"), it calls $qx_cb with
169 # the stdout of the given command when done; but respects the given limiter
170 # $env is the PSGI env. As with ``/qx; only use this when output is small
173 my ($self, $env, $limiter, $qx_cb, $qx_arg) = @_;
174 $self->{psgi_env} = $env;
176 open(my $qx_fh, '+>', \$qx_buf) or die; # PerlIO::scalar
177 $self->{qx_cb} = $qx_cb;
178 $self->{qx_arg} = $qx_arg;
179 $self->{qx_fh} = $qx_fh;
180 $self->{qx_buf} = \$qx_buf;
181 $limiter ||= $def_limiter ||= PublicInbox::Qspawn::Limiter->new(32);
182 start($self, $limiter, \&psgi_qx_start);
185 # this is called on pipe EOF to reap the process, may be called
186 # via PublicInbox::DS event loop OR via GetlineBody for generic
189 my ($self, $err) = @_; # $err: $!
190 warn "psgi_{return,qx} $err" if defined($err);
192 my ($fh, $qx_fh) = delete(@$self{qw(qfh qx_fh)});
193 $fh->close if $fh; # async-only (psgi_return)
198 # typically used for reading CGI headers
199 # We also need to check EINTR for generic PSGI servers.
202 my $hdr_buf = $self->{hdr_buf};
203 my ($ph_cb, $ph_arg) = @{$self->{parse_hdr}};
204 until (defined($ret)) {
205 my $r = sysread($self->{rpipe}, $$hdr_buf, 4096,
209 eval { $ret = $ph_cb->($total_rd, $hdr_buf, $ph_arg) };
211 warn "parse_hdr: $@";
212 $ret = [ 500, [], [ "Internal error\n" ] ];
213 } elsif (!defined($ret) && !$r) {
214 my $cmd = $self->{cmd} // [ '(?)' ];
215 my $env = $self->{psgi_env};
217 EOF parsing headers from @$cmd ($self->{psgi_env}->{REQUEST_URI})
219 $ret = [ 500, [], [ "Internal error\n" ] ];
222 # caller should notify us when it's ready:
223 return if $! == EAGAIN;
224 next if $! == EINTR; # immediate retry
225 warn "error reading header: $!";
226 $ret = [ 500, [], [ "Internal error\n" ] ];
229 delete $self->{parse_hdr}; # done parsing headers
233 sub psgi_return_init_cb { # this may be PublicInbox::HTTPD::Async {cb}
235 my $r = rd_hdr($self) or return;
236 my $env = $self->{psgi_env};
239 # this is for RepoAtom since that can fire after parse_cgi_headers
240 if (ref($r) eq 'ARRAY' && blessed($r->[2]) && $r->[2]->can('attach')) {
243 $filter //= delete($env->{'qspawn.filter'}) // (ref($r) eq 'ARRAY' ?
244 PublicInbox::GzipFilter::qsp_maybe($r->[1], $env) : undef);
246 my $wcb = delete $env->{'qspawn.wcb'};
247 my $async = delete $self->{async}; # PublicInbox::HTTPD::Async
248 if (ref($r) ne 'ARRAY' || scalar(@$r) == 3) { # error
249 if ($async) { # calls rpipe->close && ->event_step
250 $async->close; # PublicInbox::HTTPD::Async::close
251 } else { # generic PSGI:
252 delete($self->{rpipe})->close;
256 if (ref($r) eq 'ARRAY') { # error
258 } elsif (ref($r) eq 'CODE') { # chain another command
264 # done reading headers, handoff to read body
265 my $fh = $wcb->($r); # scalar @$r == 2
266 $fh = $filter->attach($fh) if $filter;
268 $async->async_pass($env->{'psgix.io'}, $fh,
269 delete($self->{hdr_buf}));
270 } else { # for synchronous PSGI servers
271 require PublicInbox::GetlineBody;
272 my $buf = delete $self->{hdr_buf};
273 $r->[2] = PublicInbox::GetlineBody->new($self->{rpipe},
274 \&event_step, $self, $$buf, $filter);
279 sub psgi_return_start { # may run later, much later...
281 if (my $cb = $self->{psgi_env}->{'pi-httpd.async'}) {
282 # PublicInbox::HTTPD::Async->new(rpipe, $cb, $cb_arg, $end_obj)
283 $self->{async} = $cb->($self->{rpipe},
284 \&psgi_return_init_cb, $self, $self);
285 } else { # generic PSGI
286 psgi_return_init_cb($self) while $self->{parse_hdr};
290 # Used for streaming the stdout of one process as a PSGI response.
292 # $env is the PSGI env.
293 # optional keys in $env:
294 # $env->{'qspawn.wcb'} - the write callback from the PSGI server
295 # optional, use this if you've already
296 # captured it elsewhere. If not given,
297 # psgi_return will return an anonymous
298 # sub for the PSGI server to call
300 # $env->{'qspawn.filter'} - filter object, responds to ->attach for
301 # pi-httpd.async and ->translate for generic
304 # $limiter - the Limiter object to use (uses the def_limiter if not given)
306 # $parse_hdr - Initial read function; often for parsing CGI header output.
307 # It will be given the return value of sysread from the pipe
308 # and a string ref of the current buffer. Returns an arrayref
309 # for PSGI responses. 2-element arrays in PSGI mean the
310 # body will be streamed, later, via writes (push-based) to
311 # psgix.io. 3-element arrays means the body is available
312 # immediately (or streamed via ->getline (pull-based)).
314 my ($self, $env, $limiter, $parse_hdr, $hdr_arg) = @_;
315 $self->{psgi_env} = $env;
316 $self->{hdr_buf} = \(my $hdr_buf = '');
317 $self->{parse_hdr} = [ $parse_hdr, $hdr_arg ];
318 $limiter ||= $def_limiter ||= PublicInbox::Qspawn::Limiter->new(32);
320 # the caller already captured the PSGI write callback from
321 # the PSGI server, so we can call ->start, here:
322 $env->{'qspawn.wcb'} and
323 return start($self, $limiter, \&psgi_return_start);
325 # the caller will return this sub to the PSGI server, so
326 # it can set the response callback (that is, for
327 # PublicInbox::HTTP, the chunked_wcb or identity_wcb callback),
328 # but other HTTP servers are supported:
330 $env->{'qspawn.wcb'} = $_[0];
331 start($self, $limiter, \&psgi_return_start);
335 package PublicInbox::Qspawn::Limiter;
339 my ($class, $max) = @_;
341 # 32 is same as the git-daemon connection limit
345 # RLIMIT_CPU => undef,
346 # RLIMIT_DATA => undef,
347 # RLIMIT_CORE => undef,
352 my ($self, $name, $cfg) = @_;
353 foreach my $rlim (@PublicInbox::Spawn::RLIMITS) {
356 $k = "publicinboxlimiter.$name.$k";
357 defined(my $v = $cfg->{$k}) or next;
358 my @rlimit = split(/\s*,\s*/, $v);
359 if (scalar(@rlimit) == 1) {
360 push @rlimit, $rlimit[0];
361 } elsif (scalar(@rlimit) != 2) {
362 warn "could not parse $k: $v\n";
364 eval { require BSD::Resource };
366 warn "BSD::Resource missing for $rlim";
369 foreach my $i (0..$#rlimit) {
370 next if $rlimit[$i] ne 'INFINITY';
371 $rlimit[$i] = BSD::Resource::RLIM_INFINITY();
373 $self->{$rlim} = \@rlimit;