runtime: only count an in-flight timer send as pending once - #80762
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
unlockAndRun increments isSending and publishes when=0 while holding t.mu, but acquires t.sendLock only after releasing t.mu. If the firing goroutine is descheduled between the two locks, both a Stop and a Reset can complete inside the gap. Stop observes isSending>0, voids the send by incrementing seq, and correctly returns true: the send will never be delivered. But a subsequent Reset (or Stop) observes isSending still >0 and counts the same voided send again, so Reset reports an active timer immediately after Stop reported having stopped it. Pooled timers check exactly this invariant and break. Record the seq value that unlockAndRun snapshots for the send, and have stop and modify treat the in-flight send as pending only while that snapshot still matches t.seq. Once a stop or reset voids the send, later calls see the seq mismatch and no longer count it. Fixes golang#80760
3acd3e0 to
810bc43
Compare
|
This PR (HEAD: 810bc43) has been imported to Gerrit for code review. Please visit Gerrit at https://go-review.googlesource.com/c/go/+/811520. Important tips:
|
|
Message from Gopher Robot: Patch Set 1: Congratulations on opening your first change. Thank you for your contribution! Next steps: Most changes in the Go project go through a few rounds of revision. This can be During May-July and Nov-Jan the Go project is in a code freeze, during which Please don’t reply on this GitHub thread. Visit golang.org/cl/811520. |
|
Message from Ian Lance Taylor: Patch Set 1: Commit-Queue+1 Please don’t reply on this GitHub thread. Visit golang.org/cl/811520. |
|
Message from golang-scoped@luci-project-accounts.iam.gserviceaccount.com: Patch Set 1: Dry run: CV is trying the patch. Bot data: {"action":"start","triggered_at":"2026-08-06T17:46:23Z","revision":"5141137119a863a866ee7dc94a2d42e813f4fc1b"} Please don’t reply on this GitHub thread. Visit golang.org/cl/811520. |
|
Message from Ian Lance Taylor: Patch Set 1: -Commit-Queue (Performed by <GERRIT_ACCOUNT_60063> on behalf of <GERRIT_ACCOUNT_5206>) Please don’t reply on this GitHub thread. Visit golang.org/cl/811520. |
|
Message from golang-scoped@luci-project-accounts.iam.gserviceaccount.com: Patch Set 1: This CL has passed the run Please don’t reply on this GitHub thread. Visit golang.org/cl/811520. |
|
Message from golang-scoped@luci-project-accounts.iam.gserviceaccount.com: Patch Set 1: LUCI-TryBot-Result+1 Please don’t reply on this GitHub thread. Visit golang.org/cl/811520. |
unlockAndRun increments isSending and publishes when=0 while holding
t.mu, but acquires t.sendLock only after releasing t.mu. If the firing
goroutine is descheduled between the two locks, both a Stop and a Reset
can complete inside the gap. Stop observes isSending>0, voids the send
by incrementing seq, and correctly returns true: the send will never
be delivered. But a subsequent Reset (or Stop) observes isSending
still >0 and counts the same voided send again, so Reset reports an
active timer immediately after Stop reported having stopped it.
Pooled timers check exactly this invariant and break.
Record the seq value that unlockAndRun snapshots for the send, and
have stop and modify treat the in-flight send as pending only while
that snapshot still matches t.seq. Once a stop or reset voids the
send, later calls see the seq mismatch and no longer count it.
Fixes #80760