Repository navigation
Conversation
`handle_review` and the webhook's spawned review task both bracketed `run_review(...).await` with a bare `fetch_add` / `fetch_sub` pair. The decrement is skipped on two real exit paths: - the handler future is dropped when an HTTP client disconnects mid-review (axum drops the future; the `fetch_sub` line is never reached) - `run_review` panics, unwinding past the `fetch_sub` Either leaks a permanent +1 into `AppState::in_flight`, the gauge `GET /status` reports, for the life of the process. Reviews take ~37s median, so the disconnect window is wide. Both sites now take an `InFlightCountGuard` whose `Drop` decrements, matching the RAII discipline `InFlightGuard` already applies to the dedup slot in the same module. 🤖🤖🤖 Generated with trusty-mpm — https://github.com/bobmatnyc/trusty-tools
🤖🤖🤖 Generated with trusty-mpm — https://github.com/bobmatnyc/trusty-tools
Owner
Author
|
Closed as obsoleted. The fix is correct, but trusty-review's daemon removal (#5028) eliminates the code path this patches. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The defect
crates/trusty-review/src/service/handlers.rsandcrates/trusty-review/src/service/webhook.rsboth bracketedrun_review(...).awaitwith a barefetch_add/fetch_subpair onAppState::in_flight— the gaugeGET /statusreports. The decrement is aplain statement after the
.await, so it is skipped on two real exit paths:fetch_subline is never reachedhandle_reviewrun_reviewpanicsfetch_sub; on the webhook path the panic is swallowed into aJoinErrornobody reads and the daemon keeps runningEither leaks a permanent +1 for the life of the process. Reviews take a ~36.7s
median, so the disconnect window is wide.
Verified against
origin/mainbefore fixing — the shape was as reported and noguard existed.
The fix
InFlightCountGuardincrates/trusty-review/src/store/in_flight.rs:acquireincrements,Dropdecrements. That module already owns this exactidiom —
InFlightGuardreleases the dedup slot on drop, documented there as"so the slot is always released even if the review task panics." This extends
the existing pattern rather than adding a second one; there is no shared
counter-guard in
trusty-commonto route through.Both call sites now hold the guard. The increment has no spelling that does not
also arm the decrement —
acquireis the only constructor.Tests
Five new tests, all confirmed to go red with the guard removed:
review_handler_in_flight_returns_to_zero_when_future_dropped— parksrun_reviewinsidepreflight_contexton a never-resolving search probe,asserts the gauge reached 1, drops the future, asserts it is back to 0.
review_handler_in_flight_returns_to_zero_when_pipeline_panics— panicsinside the pipeline, runs the handler under
tokio::spawnso the unwind iscaught, asserts the task panicked and the gauge is 0.
count_guard_increments_then_decrements_on_drop,count_guard_decrements_on_panic_unwind,count_guard_nests_and_unwinds_in_order— guard-level unit tests.Break-and-watch, as required. Reverting
handlers.rsto the barefetch_add/fetch_subshape and re-running:The guard was then restored and the suite re-run green.
The webhook site has no end-to-end drop/panic test of its own — driving that
spawned task through
run_reviewneeds a GitHub PR-metadata fetch stub thecrate does not have. It is covered by the guard's own unit tests plus the
end-to-end handler tests, since it uses the same guard.
Also checked, deliberately not changed
in_flight_registry— already correct. Its PR- and SHA-level slots areRAII guards released on drop; that is the precedent this fix follows.
last_error— aMutex<Option<String>>written afterrun_reviewreturns, not an acquire/release pair. A panic means the error is not
recorded, which is a missed log line, not a leak.
InferenceProbe::consecutive_unknown— a streak counter with an explicitstore(0)reset, not a paired increment/decrement.claim, but
DEDUP_STALE_SECSalready reclaims abandoned claims, so itself-heals. Nothing to do.
Out of scope — NOT addressed by this PR
The scoping pass that found this counter leak also flagged two other
daemon-shape bugs in
trusty-review:resolve_index()running once at boot rather than per-invocation/healthblocking on a live Bedrock callNeither is touched here. They are entangled with an undecided question
about whether
trusty-reviewshould remain a daemon at all. Do not read thisPR as having addressed them.
Gates — rung 3, concurrency-shaped
cargo fmt --checkcargo check -p trusty-review --all-targetscargo clippy -p trusty-review --all-targets -- -D warningscargo test -p trusty-review --all-features1571 passed; 0 failed; 5 ignored+ 8 further suites all green, 0 failuresbash scripts/check_line_cap.sh3742 tracked .rs file(s); 0 violations — OKbash scripts/check_sld.sh56 spec doc(s) + 3115 code file(s); 0 error(s), 0 warning(s)bash scripts/check_test_pointers.sh22079 Test: citation(s) — 0 dangling pointers — OKCollision check
No other open PR touches
crates/trusty-review/— the open set is intrusty-installer (#5011,
#5018),
trusty-common/memory_core (#5013),
and trusty-mpm assets (#5019).
This PR stays entirely inside trusty-review.
Note on CI
GitHub Actions is in a major outage — jobs die at "Set up job" with
Failed to resolve action download info. Red or absent checks here are thatoutage, not this change. The local gates above are the evidence.
🤖🤖🤖 Generated with trusty-mpm — https://github.com/bobmatnyc/trusty-tools