src: keep per-Environment state out of thread_locals - #66411
Open
codebytere wants to merge 4 commits into
Open
codebytere wants to merge 4 commits into
codebytere wants to merge 4 commits into
Conversation
The root cert store and the certificates set through tls.setDefaultCACertificates() were thread_local, with a cleanup hook on whichever Environment used TLS first. When several Environments share a thread, setting the default CA certificates in one of them replaced the trusted CAs of the others. Keep both on the Environment, next to its other OpenSSL state. Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
The ngtcp2 and nghttp3 allocators shared one thread_local state whose BindingData pointer was set by the last BindingData that handed out an allocator. With several Environments on a thread, memory allocated for a session in one Environment was accounted against another's BindingData and failed a CHECK when freed. Give each BindingData its own heap-allocated state. nghttp3 buffers backing external strings can be freed after the BindingData is gone, so the state counts live allocations and is deleted once the BindingData has been destroyed and the last of them is freed. Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
Several Environments can share a thread, so state in src/ that belongs to one of them cannot be kept in a thread_local. Add a cpplint rule that rejects thread_local in src/ unless the declaration is marked with NOLINTNEXTLINE(runtime/thread_local), and mark the existing uses, which are per-thread by design. Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
Collaborator
|
Review requested:
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #66411 +/- ##
==========================================
- Coverage 90.39% 90.37% -0.02%
==========================================
Files 792 792
Lines 275580 275574 -6
Branches 52840 52839 -1
==========================================
- Hits 249104 249058 -46
- Misses 16897 16943 +46
+ Partials 9579 9573 -6
🚀 New features to boost your workflow:
|
addaleax
approved these changes
Sep 30, 2026
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
addaleax
approved these changes
Sep 30, 2026
Collaborator
Contributor
Failed to start CIFull Auto Start CI output |
Collaborator
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs: #66239
Two
thread_locals insrc/hold state that belongs to one Environment, so they break when several Environments share a thread:tls.setDefaultCACertificates()in one Environment replaced the trusted CAs of every other Environment on the thread. It now lives on the Environment, next to its other OpenSSL state.BindingDatapointer came from whicheverBindingDatalast handed out an allocator, so a session in one Environment freed memory against another's counter and failed aCHECK. EachBindingDatanow owns its allocator state. nghttp3 buffers backing external strings can outlive theBindingData, so the state is deleted once theBindingDatais gone and the last allocation made through it is freed.A new cpplint rule rejects
thread_localinsrc/unless the declaration is marked withNOLINTNEXTLINE(runtime/thread_local). The 11 remaining uses are marked: re-entrancy guards, debug counters,dlopenbookkeeping, the context setupBuiltinLoaderand the handle cleanup depth, all per-thread by design.Both fixes come with a cctest in
test_environment_shared_isolate.ccthat fails without them.Disclosure: the code, tests and this description were written by Claude Code, directed and reviewed by @codebytere.