Describe the bug
Native hostname resolution and selected TLS or QUIC credential-file reads can
remain blocked after the caller cancels session construction. Because the blocked
work does not join, the caller cannot prove synchronous ownership cleanup without
terminating the process.
To reproduce
Resolver
Configure a client TCP endpoint with a hostname, hold name resolution in a
controlled resolver fixture, begin session open, then cancel the owning operation
and request shutdown. In our packaged test, the five-second cancellation-to-drain
gate expired while the native resolver remained blocked.
Credential file
Configure root_ca_certificate_file for TLS or QUIC as a FIFO with no writer,
then begin session construction and cancel it. Neither Open returned within the
20-second test watchdog, so both test processes required termination. The normal
10-second per-link open budget did not advance while the synchronous file read was
blocking the polled future.
System info
- Zenoh Rust crates: 1.9.0
- zenoh-c: 1.9.0, revision
8858e129271f4e05bb34d8ae6df3f3d221ef5299
- zenoh-go: Go module
github.com/eclipse-zenoh/zenoh-go v1.9.0,
checksum h1:OKjUYd3foYsp7NY5B9aH+yFLUba9caUDmJSUOXqBLkI=
- Linux x86_64, reproduced through the packaged native library
Expected behavior
Cancellation or close should either join the native operation within a documented
bound or return an ownership handle that lets the caller prove when it has drained.
Actual behavior and downstream decision
The caller's bounded wait expires while native work remains outstanding. TiCOS is
retaining stock Zenoh and narrowing its supported deployment profile to numeric
IPv4 TCP locators with no native TLS or QUIC credential files. A finite systemd
cgroup stop timeout provides process containment; we do not claim graceful
in-process cancellation for the reproductions above.
We can provide standalone redacted fixtures if maintainers confirm the preferred
repository and test location.
Describe the bug
Native hostname resolution and selected TLS or QUIC credential-file reads can
remain blocked after the caller cancels session construction. Because the blocked
work does not join, the caller cannot prove synchronous ownership cleanup without
terminating the process.
To reproduce
Resolver
Configure a client TCP endpoint with a hostname, hold name resolution in a
controlled resolver fixture, begin session open, then cancel the owning operation
and request shutdown. In our packaged test, the five-second cancellation-to-drain
gate expired while the native resolver remained blocked.
Credential file
Configure
root_ca_certificate_filefor TLS or QUIC as a FIFO with no writer,then begin session construction and cancel it. Neither Open returned within the
20-second test watchdog, so both test processes required termination. The normal
10-second per-link open budget did not advance while the synchronous file read was
blocking the polled future.
System info
8858e129271f4e05bb34d8ae6df3f3d221ef5299github.com/eclipse-zenoh/zenoh-gov1.9.0,checksum
h1:OKjUYd3foYsp7NY5B9aH+yFLUba9caUDmJSUOXqBLkI=Expected behavior
Cancellation or close should either join the native operation within a documented
bound or return an ownership handle that lets the caller prove when it has drained.
Actual behavior and downstream decision
The caller's bounded wait expires while native work remains outstanding. TiCOS is
retaining stock Zenoh and narrowing its supported deployment profile to numeric
IPv4 TCP locators with no native TLS or QUIC credential files. A finite systemd
cgroup stop timeout provides process containment; we do not claim graceful
in-process cancellation for the reproductions above.
We can provide standalone redacted fixtures if maintainers confirm the preferred
repository and test location.