3d3dc8
From 51210a849ea7f163a1760de989756206c01dd758 Mon Sep 17 00:00:00 2001
3d3dc8
From: Michal Sekletar <msekleta@redhat.com>
3d3dc8
Date: Mon, 4 Oct 2021 19:44:06 +0200
3d3dc8
Subject: [PATCH] sd-event: introduce callback invoked when event source
3d3dc8
 ratelimit expires
3d3dc8
3d3dc8
(cherry picked from commit fd69f2247520b0be3190ded96d646a415edc97b7)
3d3dc8
3d3dc8
Related: #2036608
3d3dc8
---
3d3dc8
 src/libsystemd/libsystemd.sym        |  5 +++
3d3dc8
 src/libsystemd/sd-event/sd-event.c   | 61 +++++++++++++++++++++++-----
3d3dc8
 src/libsystemd/sd-event/test-event.c | 12 ++++++
3d3dc8
 src/systemd/sd-event.h               |  1 +
3d3dc8
 4 files changed, 68 insertions(+), 11 deletions(-)
3d3dc8
3d3dc8
diff --git a/src/libsystemd/libsystemd.sym b/src/libsystemd/libsystemd.sym
3d3dc8
index 149d2e7b82..f4a1426248 100644
3d3dc8
--- a/src/libsystemd/libsystemd.sym
3d3dc8
+++ b/src/libsystemd/libsystemd.sym
3d3dc8
@@ -579,3 +579,8 @@ global:
3d3dc8
         sd_event_source_get_ratelimit;
3d3dc8
         sd_event_source_is_ratelimited;
3d3dc8
 } LIBSYSTEMD_239;
3d3dc8
+
3d3dc8
+LIBSYSTEMD_250 {
3d3dc8
+global:
3d3dc8
+        sd_event_source_set_ratelimit_expire_callback;
3d3dc8
+} LIBSYSTEMD_248;
3d3dc8
diff --git a/src/libsystemd/sd-event/sd-event.c b/src/libsystemd/sd-event/sd-event.c
3d3dc8
index 47cf93b3f4..0adfdd9e1a 100644
3d3dc8
--- a/src/libsystemd/sd-event/sd-event.c
3d3dc8
+++ b/src/libsystemd/sd-event/sd-event.c
3d3dc8
@@ -125,6 +125,7 @@ struct sd_event_source {
3d3dc8
         uint64_t prepare_iteration;
3d3dc8
 
3d3dc8
         sd_event_destroy_t destroy_callback;
3d3dc8
+        sd_event_handler_t ratelimit_expire_callback;
3d3dc8
 
3d3dc8
         LIST_FIELDS(sd_event_source, sources);
3d3dc8
 
3d3dc8
@@ -2734,7 +2735,7 @@ fail:
3d3dc8
         return r;
3d3dc8
 }
3d3dc8
 
3d3dc8
-static int event_source_leave_ratelimit(sd_event_source *s) {
3d3dc8
+static int event_source_leave_ratelimit(sd_event_source *s, bool run_callback) {
3d3dc8
         int r;
3d3dc8
 
3d3dc8
         assert(s);
3d3dc8
@@ -2766,6 +2767,23 @@ static int event_source_leave_ratelimit(sd_event_source *s) {
3d3dc8
         ratelimit_reset(&s->rate_limit);
3d3dc8
 
3d3dc8
         log_debug("Event source %p (%s) left rate limit state.", s, strna(s->description));
3d3dc8
+
3d3dc8
+        if (run_callback && s->ratelimit_expire_callback) {
3d3dc8
+                s->dispatching = true;
3d3dc8
+                r = s->ratelimit_expire_callback(s, s->userdata);
3d3dc8
+                s->dispatching = false;
3d3dc8
+
3d3dc8
+                if (r < 0) {
3d3dc8
+                        log_debug_errno(r, "Ratelimit expiry callback of event source %s (type %s) returned error, disabling: %m",
3d3dc8
+                                        strna(s->description),
3d3dc8
+                                        event_source_type_to_string(s->type));
3d3dc8
+
3d3dc8
+                        sd_event_source_set_enabled(s, SD_EVENT_OFF);
3d3dc8
+                }
3d3dc8
+
3d3dc8
+                return 1;
3d3dc8
+        }
3d3dc8
+
3d3dc8
         return 0;
3d3dc8
 
3d3dc8
 fail:
3d3dc8
@@ -2966,6 +2984,7 @@ static int process_timer(
3d3dc8
                 struct clock_data *d) {
3d3dc8
 
3d3dc8
         sd_event_source *s;
3d3dc8
+        bool callback_invoked = false;
3d3dc8
         int r;
3d3dc8
 
3d3dc8
         assert(e);
3d3dc8
@@ -2981,9 +3000,11 @@ static int process_timer(
3d3dc8
                          * again. */
3d3dc8
                         assert(s->ratelimited);
3d3dc8
 
3d3dc8
-                        r = event_source_leave_ratelimit(s);
3d3dc8
+                        r = event_source_leave_ratelimit(s, /* run_callback */ true);
3d3dc8
                         if (r < 0)
3d3dc8
                                 return r;
3d3dc8
+                        else if (r == 1)
3d3dc8
+                                callback_invoked = true;
3d3dc8
 
3d3dc8
                         continue;
3d3dc8
                 }
3d3dc8
@@ -2998,7 +3019,7 @@ static int process_timer(
3d3dc8
                 event_source_time_prioq_reshuffle(s);
3d3dc8
         }
3d3dc8
 
3d3dc8
-        return 0;
3d3dc8
+        return callback_invoked;
3d3dc8
 }
3d3dc8
 
3d3dc8
 static int process_child(sd_event *e) {
3d3dc8
@@ -3698,15 +3719,15 @@ _public_ int sd_event_wait(sd_event *e, uint64_t timeout) {
3d3dc8
         if (r < 0)
3d3dc8
                 goto finish;
3d3dc8
 
3d3dc8
-        r = process_timer(e, e->timestamp.realtime, &e->realtime);
3d3dc8
+        r = process_inotify(e);
3d3dc8
         if (r < 0)
3d3dc8
                 goto finish;
3d3dc8
 
3d3dc8
-        r = process_timer(e, e->timestamp.boottime, &e->boottime);
3d3dc8
+        r = process_timer(e, e->timestamp.realtime, &e->realtime);
3d3dc8
         if (r < 0)
3d3dc8
                 goto finish;
3d3dc8
 
3d3dc8
-        r = process_timer(e, e->timestamp.monotonic, &e->monotonic);
3d3dc8
+        r = process_timer(e, e->timestamp.boottime, &e->boottime);
3d3dc8
         if (r < 0)
3d3dc8
                 goto finish;
3d3dc8
 
3d3dc8
@@ -3718,16 +3739,27 @@ _public_ int sd_event_wait(sd_event *e, uint64_t timeout) {
3d3dc8
         if (r < 0)
3d3dc8
                 goto finish;
3d3dc8
 
3d3dc8
+        r = process_timer(e, e->timestamp.monotonic, &e->monotonic);
3d3dc8
+        if (r < 0)
3d3dc8
+                goto finish;
3d3dc8
+        else if (r == 1) {
3d3dc8
+                /* Ratelimit expiry callback was called. Let's postpone processing pending sources and
3d3dc8
+                 * put loop in the initial state in order to evaluate (in the next iteration) also sources
3d3dc8
+                 * there were potentially re-enabled by the callback.
3d3dc8
+                 *
3d3dc8
+                 * Wondering why we treat only this invocation of process_timer() differently? Once event
3d3dc8
+                 * source is ratelimited we essentially transform it into CLOCK_MONOTONIC timer hence
3d3dc8
+                 * ratelimit expiry callback is never called for any other timer type. */
3d3dc8
+                r = 0;
3d3dc8
+                goto finish;
3d3dc8
+        }
3d3dc8
+
3d3dc8
         if (e->need_process_child) {
3d3dc8
                 r = process_child(e);
3d3dc8
                 if (r < 0)
3d3dc8
                         goto finish;
3d3dc8
         }
3d3dc8
 
3d3dc8
-        r = process_inotify(e);
3d3dc8
-        if (r < 0)
3d3dc8
-                goto finish;
3d3dc8
-
3d3dc8
         if (event_next_pending(e)) {
3d3dc8
                 e->state = SD_EVENT_PENDING;
3d3dc8
 
3d3dc8
@@ -4054,7 +4086,7 @@ _public_ int sd_event_source_set_ratelimit(sd_event_source *s, uint64_t interval
3d3dc8
 
3d3dc8
         /* When ratelimiting is configured we'll always reset the rate limit state first and start fresh,
3d3dc8
          * non-ratelimited. */
3d3dc8
-        r = event_source_leave_ratelimit(s);
3d3dc8
+        r = event_source_leave_ratelimit(s, /* run_callback */ false);
3d3dc8
         if (r < 0)
3d3dc8
                 return r;
3d3dc8
 
3d3dc8
@@ -4062,6 +4094,13 @@ _public_ int sd_event_source_set_ratelimit(sd_event_source *s, uint64_t interval
3d3dc8
         return 0;
3d3dc8
 }
3d3dc8
 
3d3dc8
+_public_ int sd_event_source_set_ratelimit_expire_callback(sd_event_source *s, sd_event_handler_t callback) {
3d3dc8
+        assert_return(s, -EINVAL);
3d3dc8
+
3d3dc8
+        s->ratelimit_expire_callback = callback;
3d3dc8
+        return 0;
3d3dc8
+}
3d3dc8
+
3d3dc8
 _public_ int sd_event_source_get_ratelimit(sd_event_source *s, uint64_t *ret_interval, unsigned *ret_burst) {
3d3dc8
         assert_return(s, -EINVAL);
3d3dc8
 
3d3dc8
diff --git a/src/libsystemd/sd-event/test-event.c b/src/libsystemd/sd-event/test-event.c
3d3dc8
index e3ee4cd5c3..9135b22839 100644
3d3dc8
--- a/src/libsystemd/sd-event/test-event.c
3d3dc8
+++ b/src/libsystemd/sd-event/test-event.c
3d3dc8
@@ -506,6 +506,11 @@ static int ratelimit_time_handler(sd_event_source *s, uint64_t usec, void *userd
3d3dc8
         return 0;
3d3dc8
 }
3d3dc8
 
3d3dc8
+static int expired = -1;
3d3dc8
+static int ratelimit_expired(sd_event_source *s, void *userdata) {
3d3dc8
+        return ++expired;
3d3dc8
+}
3d3dc8
+
3d3dc8
 static void test_ratelimit(void) {
3d3dc8
         _cleanup_close_pair_ int p[2] = {-1, -1};
3d3dc8
         _cleanup_(sd_event_unrefp) sd_event *e = NULL;
3d3dc8
@@ -568,12 +573,19 @@ static void test_ratelimit(void) {
3d3dc8
 
3d3dc8
         assert_se(sd_event_source_set_ratelimit(s, 1 * USEC_PER_SEC, 10) >= 0);
3d3dc8
 
3d3dc8
+        /* Set callback that will be invoked when we leave rate limited state. */
3d3dc8
+        assert_se(sd_event_source_set_ratelimit_expire_callback(s, ratelimit_expired) >= 0);
3d3dc8
+
3d3dc8
         do {
3d3dc8
                 assert_se(sd_event_run(e, UINT64_MAX) >= 0);
3d3dc8
         } while (!sd_event_source_is_ratelimited(s));
3d3dc8
 
3d3dc8
         log_info("ratelimit_time_handler: called 10 more times, event source got ratelimited");
3d3dc8
         assert_se(count == 20);
3d3dc8
+
3d3dc8
+        /* Dispatch the event loop once more and check that ratelimit expiration callback got called */
3d3dc8
+        assert_se(sd_event_run(e, UINT64_MAX) >= 0);
3d3dc8
+        assert_se(expired == 0);
3d3dc8
 }
3d3dc8
 
3d3dc8
 int main(int argc, char *argv[]) {
3d3dc8
diff --git a/src/systemd/sd-event.h b/src/systemd/sd-event.h
3d3dc8
index a17a9b3488..c2e9c9614d 100644
3d3dc8
--- a/src/systemd/sd-event.h
3d3dc8
+++ b/src/systemd/sd-event.h
3d3dc8
@@ -147,6 +147,7 @@ int sd_event_source_get_destroy_callback(sd_event_source *s, sd_event_destroy_t
3d3dc8
 int sd_event_source_set_ratelimit(sd_event_source *s, uint64_t interval_usec, unsigned burst);
3d3dc8
 int sd_event_source_get_ratelimit(sd_event_source *s, uint64_t *ret_interval_usec, unsigned *ret_burst);
3d3dc8
 int sd_event_source_is_ratelimited(sd_event_source *s);
3d3dc8
+int sd_event_source_set_ratelimit_expire_callback(sd_event_source *s, sd_event_handler_t callback);
3d3dc8
 
3d3dc8
 /* Define helpers so that __attribute__((cleanup(sd_event_unrefp))) and similar may be used. */
3d3dc8
 _SD_DEFINE_POINTER_CLEANUP_FUNC(sd_event, sd_event_unref);