check / check (push) Failing after 0s
The server ran os.Exit at the end of its own goroutine, which raced fx's teardown and could kill the process before reportbuf's OnStop flushed the buffer — losing up to a full flush window of telemetry on every restart, silently and with exit 0. The server now requests shutdown through fx.Shutdowner, so fx runs every OnStop in dependency order. The http.Server is built synchronously in OnStart before the serving goroutine starts, so shutdown can no longer race or nil-deref it; the field is never written and read from two goroutines without a happens-before edge. A listen failure now exits non-zero via fx.ExitCode(1). reportbuf's OnStop is guarded by sync.Once. writeTimeout now exceeds the chi per-request budget, with a comment, so that budget is reachable. Dead startupTime, exitCode, and cancelFunc fields are gone. A new test buffers a report and asserts it reaches disk after the fx lifecycle stops. Model: opus-4-8
63 lines
1.7 KiB
Go
63 lines
1.7 KiB
Go
package server
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
"net/http"
|
|
"time"
|
|
|
|
"go.uber.org/fx"
|
|
)
|
|
|
|
const (
|
|
readTimeout = 10 * time.Second
|
|
maxHeaderBytes = 1 << 20 // 1 MiB
|
|
|
|
// requestTimeout (routes.go) is the single per-request
|
|
// processing budget, enforced by chi's middleware.Timeout.
|
|
// writeTimeout must exceed that budget so a handler can write
|
|
// its 503 when the chi timeout fires; if it were shorter the
|
|
// server would abort the write first and the chi budget would
|
|
// be unreachable dead configuration.
|
|
writeTimeout = requestTimeout + 5*time.Second
|
|
)
|
|
|
|
// newHTTPServer constructs the http.Server. It performs no I/O
|
|
// and does not start listening.
|
|
func (s *Server) newHTTPServer() *http.Server {
|
|
listenAddr := fmt.Sprintf(":%d", s.params.Config.Port)
|
|
|
|
return &http.Server{
|
|
Addr: listenAddr,
|
|
Handler: s,
|
|
MaxHeaderBytes: maxHeaderBytes,
|
|
ReadTimeout: readTimeout,
|
|
WriteTimeout: writeTimeout,
|
|
}
|
|
}
|
|
|
|
// listenAndServe runs the listener until the server is shut
|
|
// down. A genuine listen failure (not the expected
|
|
// ErrServerClosed from a clean shutdown) requests process
|
|
// shutdown through fx with a non-zero exit code, so the failure
|
|
// is visible to any supervisor.
|
|
func (s *Server) listenAndServe() {
|
|
s.log.Info("http begin listen",
|
|
"listenaddr", s.httpServer.Addr,
|
|
"version", s.params.Globals.Version,
|
|
"buildarch", s.params.Globals.Buildarch,
|
|
)
|
|
|
|
err := s.httpServer.ListenAndServe()
|
|
if err == nil || errors.Is(err, http.ErrServerClosed) {
|
|
return
|
|
}
|
|
|
|
s.log.Error("listen error", "error", err)
|
|
|
|
shutdownErr := s.shutdowner.Shutdown(fx.ExitCode(1))
|
|
if shutdownErr != nil {
|
|
s.log.Error("request shutdown failed", "error", shutdownErr)
|
|
}
|
|
}
|