Skip to content

Trunk bugfixes: heap race crash, graceful restart fix, event-thread spin - #13

Open
xl32 wants to merge 3 commits into
machine-moon:trunkfrom
xl32:trunk-bugfixes
Open

xl32 wants to merge 3 commits into
machine-moon:trunkfrom
xl32:trunk-bugfixes

Conversation

@xl32

@xl32 xl32 commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

@machine-moon, as soon as you decided not to go with ngtcp2, please find the fixes (I previously submitted them as a part of ngtcp2 0-RTT work) I found during extensive user testing of httpd 2.4.69 with mod_http3 (which exist in vanilla variant). Last one fired GHA tests sometimes.

  • Fixed an event-thread spin while a client holds its flow-control window shut: a blocked stream is now blocked again each time nghttp3 offers it.
  • Fixed a graceful restart that never ended: a handshake still pending when the child started to drain did not finish or time out, so the old child kept its connection count and the port.
  • Fixed a heap race that crashed the child: worker threads and the event thread allocated from one session allocator that had no mutex.

xl32 added 3 commits October 9, 2026 11:01
Worker threads allocate from stream subpools while the event thread
allocates from the session pool. All of them use one allocator, which
had no mutex, so concurrent allocations corrupted the heap and crashed
the child under load. Set a mutex on the allocator, as mod_http2 does.
A pending handshake counts as an MPM connection. The event thread
advanced pending handshakes only when not draining, so a handshake in
flight at a graceful restart did not finish or time out. The old child
then never reached zero connections and kept the port.
nghttp3_conn_resume_stream puts a blocked stream back in the write
queue. The module blocked the stream only on the first refusal, so
when the peer kept its window shut, nghttp3 offered the stream again
and again and the event thread used 100% CPU.
@machine-moon

Copy link
Copy Markdown
Owner

Hi, this looks easier to review, can you bump to 0.0.71 and I'll take a closer look and merge this week.

Cheers

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants