fix: a re-offered sentinel is not data loss
139bfbb made the channel refuse a sentinel offered while one was still
pending — correct, and the reason is a data race: overwriting wrote
eof_value_ while the consumer could be moving the previous one out of it,
which ThreadSanitizer reports as a torn refcount and a heap-use-after-free.
That part stands.
What was wrong was the accounting. The refusal recorded a drop, and PoolNode
reported it through the overflow event callback, on the theory that two
control tokens on one channel means the stream ended twice and is a caller
protocol error.
It is not. A source that has reached the end of its input keeps being polled
and keeps returning EOF — that is the normal steady state, not an error — so
the token is re-offered on every firing. Refusing a re-offer loses nothing:
the pending token carries the same meaning and is already on its way.
Found by running it. scene-actor-extraction on a 14 s clip reported
[main] ERROR: frames were dropped (channel overflow):
frame_source: 2
scene_annotate: 1
[main] The output would describe footage that was never analysed.
Refusing to report success.
and exited 2, on a run where nothing had been dropped and every frame was
analysed. frame_source emits EOF once and then returns it forever
(frame_source_node.hpp:76), so the count grows with however many times the
source is polled after the end. The pipeline's own loss detector — which
exists because a dropped frame silently corrupts the output — was being
tripped by a clean run, which is the one thing a loss detector must not do.
So SlotBusy now records nothing and reports nothing. The cost, stated
plainly: a genuinely distinct second token would also be refused silently,
and the channel cannot tell a re-offer from a distinct token. Re-offering is
the case that actually occurs; the delivery guarantee that matters — the
first token arrives — holds either way.
The test asserting the old behaviour is inverted rather than deleted, and now
also checks that the token which was accepted is the one delivered. 148/148.
This commit is contained in:
+16
-5
@@ -271,15 +271,26 @@ TEST_CASE("a second sentinel is refused, not swallowed", "[channel][sentinel]")
|
||||
CHECK(out == 3);
|
||||
}
|
||||
|
||||
TEST_CASE("a refused sentinel is counted as a drop", "[channel][sentinel]") {
|
||||
// Visibility matters more here than for a dropped value: the refusal means
|
||||
// a control token went nowhere, and the only alternative to a counter is
|
||||
// for it to vanish.
|
||||
TEST_CASE("a refused sentinel is not counted as a drop", "[channel][sentinel]") {
|
||||
// A refusal means a token arrived while an equivalent one was already
|
||||
// pending — not that anything was lost. Counting it as a drop was wrong in
|
||||
// a way that showed up immediately on real content: a source at the end of
|
||||
// its input keeps being polled and keeps returning EOF, so the token is
|
||||
// re-offered on every firing, and the pipeline reported hundreds of dropped
|
||||
// frames on a clean run and exited non-zero.
|
||||
//
|
||||
// The delivery guarantee is unaffected: the first token is pending and will
|
||||
// arrive. Only the accounting changed.
|
||||
Channel<int> ch(4);
|
||||
REQUIRE(ch.push_sentinel(1));
|
||||
const auto before = ch.stats().drops.load();
|
||||
REQUIRE_FALSE(ch.push_sentinel(2));
|
||||
CHECK(ch.stats().drops.load() == before + 1);
|
||||
CHECK(ch.stats().drops.load() == before);
|
||||
|
||||
// And the one that was accepted is still the one delivered.
|
||||
int out = 0;
|
||||
REQUIRE(ch.try_pop_now(out));
|
||||
CHECK(out == 1);
|
||||
}
|
||||
|
||||
TEST_CASE("try_push_sentinel leaves a refused value untouched", "[channel][sentinel]") {
|
||||
|
||||
Reference in New Issue
Block a user