srv, ibus: a note the daemon lives through keeps its endpoints

srvnote and addrnote unlinked on any note at all, and plan9port marks
SIGPIPE Ignore: notify.c:59 lists it, and signotify runs the handler
chain first and only then finds the Ignore flag and returns.  So one
broken pipe took the IPC socket and the IBus address file away from a
daemon that went on running -- measured on a private runtime dir, a
single kill -PIPE left the process in state Ssl with both files gone,
so every client that focused a widget afterwards silently had no input
method and only a restart brought it back.

libxcb writes with writev, so the note is a broken X connection away;
today xim.c's die() masks it by taking the daemon down on the same
event, which is exactly why the two must not depend on each other.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-18 13:59:13 +09:00
parent dab80b3a77
commit 997e4c8d93
4 changed files with 47 additions and 5 deletions

7
dat.h
View File

@@ -7,6 +7,13 @@
#define min(a, b) ((a) < (b) ? (a) : (b))
#define max(a, b) ((a) > (b) ? (a) : (b))
/*
* plan9port runs the note handlers for a note it goes on to ignore, and
* the process lives through it, so what strans announced must outlive
* such a note. A daemon that forks nothing gets only the one.
*/
#define notefatal(note) (strcmp(note, "sys: write on closed pipe") != 0)
/* A language id is the control code of the Ctrl key that selects it. */
enum
{

3
ibus.c
View File

@@ -83,8 +83,9 @@ unlinkaddr(void)
}
static int
addrnote(void*, char*)
addrnote(void*, char *note)
{
if(notefatal(note))
unlinkaddr();
return 0;
}

2
srv.c
View File

@@ -26,7 +26,7 @@ static int
srvnote(void *v, char *note)
{
USED(v);
USED(note);
if(notefatal(note))
srvunlink();
return 0;
}

View File

@@ -140,6 +140,38 @@ openpersistent(Test *t)
return 1;
}
/*
* plan9port ignores a broken pipe: the note handlers run and the daemon
* goes on serving, so the endpoints it announced must still be there.
*/
static int
survivenote(Test *t)
{
struct stat st;
int fd, ok;
if(kill(t->firstpid, SIGPIPE) < 0)
return fail("send a broken pipe to the first daemon: %s",
strerror(errno));
pausems(200);
if(!daemonalive(&t->first))
return fail("first daemon died of a broken pipe");
if(lstat(t->l.socket, &st) < 0)
return fail("IPC socket taken by a note the daemon survived: %s",
strerror(errno));
if(lstat(t->l.addrfile, &st) < 0)
return fail("IBus address taken by a note the daemon survived: %s",
strerror(errno));
fd = connectsocket(t->l.socket, nowms() + Calltimeout);
if(fd < 0)
return fail("connect after a broken pipe: %s", strerror(errno));
ok = ipcprobe(fd, "after a broken pipe");
if(close(fd) < 0)
return fail("close the client opened after a broken pipe: %s",
strerror(errno));
return ok;
}
static int
hardcrash(Test *t)
{
@@ -329,6 +361,8 @@ runrestart(Test *t, char *program, char *mapdir)
if(!waitready(&t->l, &t->first, t->firstaddress, sizeof t->firstaddress) ||
!privateaddress(t->firstaddress, t->firstpid) || !openpersistent(t))
return 0;
if(!survivenote(t))
return 0;
if(!hardcrash(t) || !waitipcclosed(t) || !waitbusclosed(t) ||
!checkstale(t) || !rejectold(t, "after hard crash"))
return 0;
@@ -367,6 +401,6 @@ main(int argc, char **argv)
showerrors(&test.second);
return 1;
}
printf("daemon hard-crash endpoint recovery: ok\n");
printf("daemon endpoints across a note and a hard crash: ok\n");
return 0;
}