tailcat: let proxied gVisor TCP connections finish teardown - #83
Merged
Conversation
ProxyConns propagates EOF in each direction with CloseWrite, then used to call Close on both connections as soon as its copy loops returned. For a gonet.TCPConn, that changes the gVisor endpoint to application-closed immediately after its FIN was queued. If the FIN is lost around that transition, the peer can wait forever for EOF. When the peer FIN has already arrived, subscribe to gVisor’s hangup event and give the local FIN up to five seconds to be acknowledged before the final Close. The wait happens entirely inside ProxyConns, is bounded if the peer disappears, and preserves its simple ownership contract: it closes both connections before returning. Together with the outstanding tailscale.com netcheck race fix (tailscale/tailscale#21086), this completed 12,203 TestServeExitNode runs over 30 minutes without a failure. The netcheck fix prevents spurious rebinds; this change independently prevents a lost teardown FIN from wedging the client. Updates #71 Updates #73 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ProxyConns propagates EOF in each direction with CloseWrite, then used to
call Close on both connections as soon as its copy loops returned. For a
gonet.TCPConn, that changes the gVisor endpoint to application-closed
immediately after its FIN was queued. If the FIN is lost around that
transition, the peer can wait forever for EOF.
When the peer FIN has already arrived, subscribe to gVisor’s hangup event
and give the local FIN up to five seconds to be acknowledged before the
final Close. The wait happens entirely inside ProxyConns, is bounded if
the peer disappears, and preserves its simple ownership contract: it
closes both connections before returning.
Together with the outstanding tailscale.com netcheck race fix
(tailscale/tailscale#21086), this completed 12,203 TestServeExitNode runs
over 30 minutes without a failure. The netcheck fix prevents spurious
rebinds; this change independently prevents a lost teardown FIN from
wedging the client.
Updates #71
Updates #73