Go to file
Dominik Csapak dc9531d302 fix #5868: rest-server: handshake detection: avoid infinite loop on connections abort
When a connection is closed by the client before we have enough data
to determine if it contains a TLS Handshake or not, the socket stays
in a readable state.
While we setup a tokio backed timeout of 10s for the connection
build-up here, this timeout does not trigger on said early connection
abort from the client side, causing then the async_io loop to
endlessly loop around peeking into the client, which always returns
the last available bytes before the connection was closed. This in
turn causes 100% CPU usage for one of the PBS threads.
The timeout not triggering is rather odd, and does indicate some
potential for further improvement in tokio itself, but our
questionable use of the WouldBlock error does violate the API
contract, so this is not a clear cut.

Such an early connection abort is often triggered by monitoring
solutions, which use it to relatively cheaply check if TCP on a port
still works as "is service up" heuristic.

To fix this, save the amount of bytes peek returned and if they did
not change between invocations of the callback, we can assume that the
connection was closed and thus exit the connection attempt with an
error.

Signed-off-by: Dominik Csapak <d.csapak@proxmox.com>
 [ TL: reword commit message and change error to ConnectionAborted ]
Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
2024-11-14 14:31:47 +01:00
.cargo move .cargo/config to .cargo/config.toml 2024-06-20 12:29:30 +02:00
proxmox-access-control tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-acme acme: bump to 0.5.3 2024-10-03 09:52:46 +02:00
proxmox-acme-api tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-api-macro api-marcro: throw compiler error if description for enums is empty 2024-10-22 15:14:43 +02:00
proxmox-apt apt: bump version to 0.11.5-1 2024-11-11 21:10:23 +01:00
proxmox-apt-api-types apt-api-types: bump version to 1.0.2 2024-11-10 18:45:57 +01:00
proxmox-async tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-auth-api tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-borrow tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-client tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-compression tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-config-digest tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-daemon tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-dns-api tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-http http: update d/control 2024-10-30 12:20:36 +01:00
proxmox-http-error tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-human-byte tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-io tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-lang tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-ldap tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-log log: only print error level to syslog/stderr 2024-10-18 18:28:37 +02:00
proxmox-login login: bump to 0.1.3-1 2024-09-30 11:48:12 +02:00
proxmox-metrics tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-network-api tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-notify notify: bump version to 0.5.0-1 2024-11-10 18:58:59 +01:00
proxmox-openid tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-product-config tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-rest-server fix #5868: rest-server: handshake detection: avoid infinite loop on connections abort 2024-11-14 14:31:47 +01:00
proxmox-router cli: format: switch some format strings to inline template variables 2024-10-18 17:29:17 +02:00
proxmox-rrd tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-rrd-api-types tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-schema schema: property description: output indentation where its required 2024-10-22 14:51:19 +02:00
proxmox-section-config tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-serde tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-shared-cache tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-shared-memory tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-simple-config tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-sortable-macro tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-subscription subscription: use correct debian release name 2024-11-07 13:35:00 +01:00
proxmox-sys tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-syslog-api tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-systemd tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-tfa tfa: clean up unused 'use' statements 2024-10-15 15:19:03 +02:00
proxmox-time time: bump version to 2.0.2-1 2024-10-17 16:16:56 +02:00
proxmox-time-api tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-uuid tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
proxmox-worker-task tree-wide: unify workspace inherited attributes 2024-09-20 08:42:45 +02:00
.gitignore git: ignore top level *-deb make target files 2022-08-26 12:18:44 +02:00
build.sh buildsys: add targets for raw installation and sysexts 2024-09-05 14:15:11 +02:00
bump.sh add bump.sh 2022-12-07 10:36:27 +01:00
Cargo.toml apt: add support for Ceph Squid repositories 2024-11-10 18:48:03 +01:00
Makefile buildsys: add a 'make list-packages' target 2024-09-20 08:43:08 +02:00
README.md README: extend Adding Cates section, convert to markdown 2024-09-30 10:26:56 +02:00
rustfmt.toml bump edition in rustfmt.toml 2022-10-13 15:00:28 +02:00

Local cargo config

This repository ships with a .cargo/config.toml that replaces the crates.io registry with packaged crates located in /usr/share/cargo/registry.

A similar config is also applied building with dh_cargo. Cargo.lock needs to be deleted when switching between packaged crates and crates.io, since the checksums are not compatible.

To reference new dependencies (or updated versions) that are not yet packaged, the dependency needs to point directly to a path or git source.

Quickly installing all packages from apt

To a void too many manual installations when mk-build-deps etc. fail, a quick way to install all the main packages of this workspace is to run:

# apt install $(make list-packages)

Steps for Releases

  • Run ./bump.sh <CRATE> [patch|minor|major|<VERSION>]
    • Fill out changelog
    • Confirm bump commit
  • Build packages with make <crate>-deb.
    • Don't forget to commit updated d/control!

Adding Crates

  1. At the top level:

    • Generate the crate: cargo new --lib the-name
    • Sort the crate into Cargo.toml's workspace.members
  2. In the new crate's Cargo.toml:

    • In [package] set:

      authors.workspace = true
      edition.workspace = true
      exclude.workspace = true
      homepage.workspace = true
      license.workspace = true
      repository.workspace = true
      rust-version.workspace = true
      

      If a separate exclude is need it, separate it out as its own block above the inherited fields.

    • Add a meaningful description

    • Copy debian/copyright and debian/debcargo.toml from another subcrate.

  3. In the new crate's lib.rs, add the following preamble on top:

    #![cfg_attr(docsrs, feature(doc_cfg, doc_auto_cfg))]
    
  4. Ideally (but optionally) in the new crate's lib.rs, add the following preamble on top as well:

    #![deny(unsafe_op_in_unsafe_fn)]
    #![deny(missing_docs)]
    

Adding a new Dependency

  1. At the top level:
    • Add it to [workspace.dependencies] specifying the version and any features that should be enabled throughout the workspace
  2. In each member's Cargo.toml:
    • Add it to the desired dependencies section with workspace = true and no version specified.
    • If this member requires additional features, add only the extra features to the member dependency.

Updating a Dependency's Version

  1. At the top level:
    • Bump the version in [workspace.dependencies] as desired.
    • Check for deprecations or breakage throughout the workspace.

Notes on Workspace Inheritance

Common metadata (like authors, license, ..) are inherited throughout the workspace. If new fields are added that are identical for all crates, they should be defined in the top-level Cargo.toml file's [workspace.package] section, and inherited in all members explicitly by setting FIELD.workspace = true in the member's [package] section.

Dependency information is also inherited throughout the workspace, allowing a single dependency specification in the top-level Cargo.toml file to be used by all members.

Some restrictions apply:

  • features can only be added in members, never removed (this includes default_features = false!)
    • the base feature set at the workspace level should be the minimum (possibly empty!) set required by all members
  • workspace dependency specifications cannot include optional
    • if needed, the optional flag needs to be set at the member level when using a workspace dependency