-
Notifications
You must be signed in to change notification settings - Fork 1
fix: seven correctness and lifecycle findings from the bidi-streaming review #5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 3 commits
Commits
Show all changes
6 commits
Select commit
Hold shift + click to select a range
6de9f6b
fix: apply the run retry policy to runAsync
qcodr 945a8c8
fix: cancel only in-flight children and release run proposals on close
qcodr 102aa02
fix: make amphp server limits configurable and fix worker lifecycle
qcodr 38e1fea
test: replace type-tautology assertions with behavioural ones
qcodr 90f0c94
fix: exit a forked worker even when its server throws
qcodr 6c37a09
chore: drop the unused Codacy badge placeholder
qcodr File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -9,3 +9,4 @@ | |
| .DS_Store | ||
| /coverage/ | ||
| /build/ | ||
| /graphify-out/ | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,39 @@ | ||
| <?php | ||
|
|
||
| declare(strict_types=1); | ||
|
|
||
| namespace Qcodr\Restate\Sdk\Protocol\Message; | ||
|
|
||
| use Qcodr\Restate\Sdk\Protocol\Protobuf\Reader; | ||
|
|
||
| /** | ||
| * `ProposeRunCompletionAckMessage` (0x0007, service protocol V7): the runtime's | ||
| * confirmation that a `ProposeRunCompletion` was durably stored. | ||
| * | ||
| * Over bidirectional streaming the runtime acks a proposal with this control frame | ||
| * instead of echoing the value back as a notification, so the SDK promotes the result it | ||
| * stashed at propose time (see {@see \Qcodr\Restate\Sdk\Vm\StateMachine}). It is its own | ||
| * message type, not a notification: `completion_id` (field 1) is all it carries. | ||
| */ | ||
| final class ProposeRunCompletionAck | ||
| { | ||
| public function __construct(public readonly ?int $completionId) | ||
| { | ||
| } | ||
|
|
||
| public static function decode(string $bytes): self | ||
| { | ||
| $reader = new Reader($bytes); | ||
| $completionId = null; | ||
| while (!$reader->atEnd()) { | ||
| [$field, $wire] = $reader->readTag(); | ||
| if ($field === 1) { | ||
| $completionId = $reader->readVarint(); | ||
| } else { | ||
| $reader->skip($wire); | ||
| } | ||
| } | ||
|
|
||
| return new self($completionId); | ||
| } | ||
| } | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,81 @@ | ||
| <?php | ||
|
|
||
| declare(strict_types=1); | ||
|
|
||
| namespace Qcodr\Restate\Sdk\Server; | ||
|
|
||
| use RuntimeException; | ||
|
|
||
| /** | ||
| * Connection, concurrency and idle ceilings for {@see AmpStreamingServer}. | ||
| * | ||
| * The defaults are deliberately far above amphp's own (1000 connections, 10 per IP, | ||
| * 1000 concurrent, 15 s stream / 60 s connection idle), because the Restate runtime is a | ||
| * single trusted peer that opens one long-lived bidi connection per in-flight invocation, | ||
| * all from the same IP, and legitimately keeps that stream open and idle while the handler | ||
| * is parked awaiting a completion, a signal, or a cancel the runtime may deliver much | ||
| * later. The runtime never half-closes the request (so amphp never `suspend()`s the stream | ||
| * timer) and its HTTP/2 keep-alive PINGs only refresh the connection timer: at amphp's | ||
| * 15 s the driver would `releaseStream(..., "Closing stream due to inactivity")`, making | ||
| * the body read throw mid-invocation and silently dropping a pending cancel. At ~10 | ||
| * connections per IP the runtime is denied new connections ("too many existing | ||
| * connections"), surfacing as broken-pipe / unexpected-frame errors under load. | ||
| * | ||
| * Those defaults suit an endpoint reachable only by the runtime. They are NOT a general | ||
| * hardening posture: with a per-IP ceiling this high, an endpoint exposed beyond the | ||
| * runtime — especially one built without | ||
| * {@see \Qcodr\Restate\Sdk\Endpoint\EndpointBuilder::identityKey} — can be held at many | ||
| * idle connections for an hour each. Pass tightened values in that case; a dead peer is | ||
| * still detected immediately by the socket closing. | ||
| * | ||
| * Every ceiling is validated to be positive: amphp's own signatures require `int<1, max>`, | ||
| * and a zero or negative ceiling would silently mean "accept nothing". The constructor | ||
| * takes plain ints so values may come from configuration or the environment, and fails | ||
| * fast naming the offending field. | ||
| */ | ||
| final class ServerLimits | ||
| { | ||
| /** @var int<1, max> */ | ||
| public readonly int $connectionLimit; | ||
|
|
||
| /** @var int<1, max> */ | ||
| public readonly int $connectionLimitPerIp; | ||
|
|
||
| /** @var int<1, max> */ | ||
| public readonly int $concurrencyLimit; | ||
|
|
||
| /** @var int<1, max> */ | ||
| public readonly int $streamIdleTimeoutSeconds; | ||
|
|
||
| /** @var int<1, max> */ | ||
| public readonly int $connectionIdleTimeoutSeconds; | ||
|
|
||
| public function __construct( | ||
| int $connectionLimit = 100_000, | ||
| int $connectionLimitPerIp = 100_000, | ||
| int $concurrencyLimit = 100_000, | ||
| int $streamIdleTimeoutSeconds = 3600, | ||
| int $connectionIdleTimeoutSeconds = 3600, | ||
| ) { | ||
| $this->connectionLimit = self::positive('connectionLimit', $connectionLimit); | ||
| $this->connectionLimitPerIp = self::positive('connectionLimitPerIp', $connectionLimitPerIp); | ||
| $this->concurrencyLimit = self::positive('concurrencyLimit', $concurrencyLimit); | ||
| $this->streamIdleTimeoutSeconds = self::positive('streamIdleTimeoutSeconds', $streamIdleTimeoutSeconds); | ||
| $this->connectionIdleTimeoutSeconds = self::positive( | ||
| 'connectionIdleTimeoutSeconds', | ||
| $connectionIdleTimeoutSeconds, | ||
| ); | ||
| } | ||
|
|
||
| /** | ||
| * @return int<1, max> | ||
| */ | ||
| private static function positive(string $name, int $value): int | ||
| { | ||
| if ($value < 1) { | ||
| throw new RuntimeException("ServerLimits::\${$name} must be positive, got {$value}"); | ||
| } | ||
|
|
||
| return $value; | ||
| } | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.