Line data Source code
1 : #define _GNU_SOURCE
2 : #include "utils/fd_ssarchive.h"
3 : #include "utils/fd_ssctrl.h"
4 : #include "utils/fd_sshttp.h"
5 : #include "utils/fd_sspeer_selector.h"
6 :
7 : #include "../../disco/topo/fd_topo.h"
8 : #include "../../disco/metrics/fd_metrics.h"
9 :
10 : #include <sys/mman.h> /* memfd_create */
11 : #include <errno.h>
12 : #include <fcntl.h>
13 : #include <unistd.h>
14 : #include <sys/socket.h>
15 :
16 : #include "generated/fd_snapld_tile_seccomp.h"
17 :
18 : #define NAME "snapld"
19 :
20 : /* download progress in each 10 second window must be at
21 : min_download_speed_mibs * 10 seconds or higher. Catches extremely
22 : slow download speeds where we may not get to 100 MiB downloaded for a
23 : while. */
24 0 : #define FD_SNAPLD_DOWNLOAD_WINDOW_NS (10L*1000L*1000L*1000L) /* 10 seconds */
25 :
26 : /* The snapld tile is responsible for loading data from the local file
27 : or from an HTTP/TCP connection and sending it to the snapdc tile
28 : for later decompression. */
29 :
30 : typedef struct fd_snapld_tile {
31 :
32 : struct {
33 : char path[ PATH_MAX ];
34 : uint min_download_speed_mibs;
35 : } config;
36 :
37 : int state;
38 : int load_full;
39 : int load_file;
40 : int sent_meta;
41 : int is_redirect;
42 : ulong gossip_slot;
43 : ulong file_sz;
44 :
45 : ulong bytes_in_batch;
46 : double download_speed_mibs;
47 : long start_batch;
48 : long end_batch;
49 :
50 : ulong bytes_in_window;
51 : ulong min_bytes_in_window;
52 : long window_deadline;
53 :
54 : int local_full_fd;
55 : int local_incr_fd;
56 : int sockfd;
57 :
58 : fd_sshttp_t * sshttp;
59 :
60 : struct {
61 : void const * base;
62 : } in_rd;
63 :
64 : struct {
65 : fd_wksp_t * mem;
66 : ulong chunk0;
67 : ulong wmark;
68 : ulong chunk;
69 : ulong mtu;
70 : } out_dc;
71 :
72 : } fd_snapld_tile_t;
73 :
74 : static ulong
75 0 : scratch_align( void ) {
76 0 : ulong a = alignof(fd_snapld_tile_t);
77 0 : a = fd_ulong_max( a, fd_sshttp_align() );
78 0 : a = fd_ulong_max( a, fd_alloc_align() );
79 0 : return a;
80 0 : }
81 :
82 : static ulong
83 0 : scratch_footprint( fd_topo_tile_t const * tile FD_PARAM_UNUSED ) {
84 0 : ulong l = FD_LAYOUT_INIT;
85 0 : l = FD_LAYOUT_APPEND( l, alignof(fd_snapld_tile_t), sizeof(fd_snapld_tile_t) );
86 0 : l = FD_LAYOUT_APPEND( l, fd_sshttp_align(), fd_sshttp_footprint() );
87 0 : l = FD_LAYOUT_APPEND( l, fd_alloc_align(), fd_alloc_footprint() );
88 0 : return FD_LAYOUT_FINI( l, scratch_align() );
89 0 : }
90 :
91 :
92 : static void
93 : privileged_init( fd_topo_t const * topo,
94 0 : fd_topo_tile_t const * tile ) {
95 0 : void * scratch = fd_topo_obj_laddr( topo, tile->tile_obj_id );
96 0 : FD_SCRATCH_ALLOC_INIT( l, scratch );
97 0 : fd_snapld_tile_t * ctx = FD_SCRATCH_ALLOC_APPEND( l, alignof(fd_snapld_tile_t), sizeof(fd_snapld_tile_t) );
98 0 : void * _sshttp = FD_SCRATCH_ALLOC_APPEND( l, fd_sshttp_align(), fd_sshttp_footprint() );
99 :
100 0 : ctx->sshttp = fd_sshttp_join( fd_sshttp_new( _sshttp ) );
101 0 : FD_TEST( ctx->sshttp );
102 :
103 0 : ulong full_slot = ULONG_MAX;
104 0 : ulong incr_slot = ULONG_MAX;
105 0 : int full_is_zstd = 0;
106 0 : int incr_is_zstd = 0;
107 0 : char full_path[ PATH_MAX ] = { 0 };
108 0 : char incr_path[ PATH_MAX ] = { 0 };
109 0 : uchar full_snapshot_hash[ FD_HASH_FOOTPRINT ] = { 0 };
110 0 : uchar incr_snapshot_hash[ FD_HASH_FOOTPRINT ] = { 0 };
111 0 : ctx->local_full_fd = -1;
112 0 : ctx->local_incr_fd = -1;
113 : /* fd_ssarchive_latest_pair needs to be invoked here, irrespective
114 : of whether snapct may do the same, because this information is
115 : needed here during privileged_init. */
116 0 : if( FD_LIKELY( -1!=fd_ssarchive_latest_pair( tile->snapld.snapshots_path,
117 0 : tile->snapld.incremental_snapshots,
118 0 : &full_slot, &incr_slot,
119 0 : full_path, incr_path,
120 0 : &full_is_zstd, &incr_is_zstd,
121 0 : full_snapshot_hash, incr_snapshot_hash ) ) ) {
122 0 : FD_TEST( full_slot!=ULONG_MAX );
123 :
124 0 : ctx->local_full_fd = open( full_path, O_RDONLY|O_CLOEXEC|O_NONBLOCK );
125 0 : if( FD_UNLIKELY( -1==ctx->local_full_fd ) ) FD_LOG_ERR(( "open() failed `%s` (%i-%s)", full_path, errno, fd_io_strerror( errno ) ));
126 0 : posix_fadvise( ctx->local_full_fd, 0L, 0L, POSIX_FADV_SEQUENTIAL );
127 :
128 0 : if( FD_LIKELY( incr_slot!=ULONG_MAX ) ) {
129 0 : ctx->local_incr_fd = open( incr_path, O_RDONLY|O_CLOEXEC|O_NONBLOCK );
130 0 : if( FD_UNLIKELY( -1==ctx->local_incr_fd ) ) FD_LOG_ERR(( "open() failed `%s` (%i-%s)", incr_path, errno, fd_io_strerror( errno ) ));
131 0 : posix_fadvise( ctx->local_incr_fd, 0L, 0L, POSIX_FADV_SEQUENTIAL );
132 0 : }
133 0 : }
134 :
135 : /* Load CA trust store while we still have filesystem access
136 : (before seccomp sandbox locks down). */
137 0 : fd_sshttp_load_ca_store( ctx->sshttp );
138 :
139 : /* Create a temporary file descriptor for our socket file descriptor.
140 : It is closed later in unprivileged init so that the sandbox sees
141 : an existent file descriptor. */
142 0 : ctx->sockfd = memfd_create( "snapld.sockfd", 0 );
143 0 : if( FD_UNLIKELY( -1==ctx->sockfd ) ) FD_LOG_ERR(( "memfd_create() failed (%i-%s)", errno, fd_io_strerror( errno ) ));
144 0 : }
145 :
146 : static ulong
147 : populate_allowed_fds( fd_topo_t const * topo,
148 : fd_topo_tile_t const * tile,
149 : ulong out_fds_cnt,
150 0 : int * out_fds ) {
151 0 : if( FD_UNLIKELY( out_fds_cnt<5UL ) ) FD_LOG_ERR(( "out_fds_cnt %lu", out_fds_cnt ));
152 :
153 0 : ulong out_cnt = 0;
154 0 : out_fds[ out_cnt++ ] = 2UL; /* stderr */
155 0 : if( FD_LIKELY( -1!=fd_log_private_logfile_fd() ) ) {
156 0 : out_fds[ out_cnt++ ] = fd_log_private_logfile_fd();
157 0 : }
158 :
159 0 : void * scratch = fd_topo_obj_laddr( topo, tile->tile_obj_id );
160 0 : FD_SCRATCH_ALLOC_INIT( l, scratch );
161 0 : fd_snapld_tile_t * ctx = FD_SCRATCH_ALLOC_APPEND( l, alignof(fd_snapld_tile_t), sizeof(fd_snapld_tile_t) );
162 0 : if( FD_LIKELY( -1!=ctx->local_full_fd ) ) out_fds[ out_cnt++ ] = ctx->local_full_fd;
163 0 : if( FD_LIKELY( -1!=ctx->local_incr_fd ) ) out_fds[ out_cnt++ ] = ctx->local_incr_fd;
164 0 : out_fds[ out_cnt++ ] = ctx->sockfd;
165 :
166 0 : return out_cnt;
167 0 : }
168 :
169 : static ulong
170 : populate_allowed_seccomp( fd_topo_t const * topo,
171 : fd_topo_tile_t const * tile,
172 : ulong out_cnt,
173 0 : struct sock_filter * out ) {
174 0 : void * scratch = fd_topo_obj_laddr( topo, tile->tile_obj_id );
175 0 : FD_SCRATCH_ALLOC_INIT( l, scratch );
176 0 : fd_snapld_tile_t * ctx = FD_SCRATCH_ALLOC_APPEND( l, alignof(fd_snapld_tile_t), sizeof(fd_snapld_tile_t) );
177 :
178 0 : populate_sock_filter_policy_fd_snapld_tile( out_cnt, out, (uint)fd_log_private_logfile_fd(), (uint)ctx->local_full_fd, (uint)ctx->local_incr_fd, (uint)ctx->sockfd );
179 0 : return sock_filter_policy_fd_snapld_tile_instr_cnt;
180 0 : }
181 :
182 : static void
183 : unprivileged_init( fd_topo_t const * topo,
184 0 : fd_topo_tile_t const * tile ) {
185 0 : void * scratch = fd_topo_obj_laddr( topo, tile->tile_obj_id );
186 0 : FD_SCRATCH_ALLOC_INIT( l, scratch );
187 0 : fd_snapld_tile_t * ctx = FD_SCRATCH_ALLOC_APPEND( l, alignof(fd_snapld_tile_t), sizeof(fd_snapld_tile_t) );
188 0 : FD_SCRATCH_ALLOC_APPEND( l, fd_sshttp_align(), fd_sshttp_footprint() );
189 0 : FD_SCRATCH_ALLOC_APPEND( l, fd_alloc_align(), fd_alloc_footprint() );
190 :
191 0 : fd_memcpy( ctx->config.path, tile->snapld.snapshots_path, PATH_MAX );
192 0 : ctx->config.min_download_speed_mibs = tile->snapld.min_download_speed_mibs;
193 :
194 0 : ctx->state = FD_SNAPSHOT_STATE_IDLE;
195 :
196 0 : ctx->download_speed_mibs = 0.0;
197 0 : ctx->bytes_in_batch = 0UL;
198 0 : ctx->start_batch = 0L;
199 0 : ctx->end_batch = 0L;
200 0 : ctx->bytes_in_window = 0UL;
201 0 : ctx->window_deadline = LONG_MAX;
202 0 : ctx->min_bytes_in_window = ((ulong)ctx->config.min_download_speed_mibs * (FD_SNAPLD_DOWNLOAD_WINDOW_NS / (ulong)1e9))<<20UL;
203 :
204 0 : FD_TEST( tile->in_cnt==1UL );
205 0 : fd_topo_link_t const * in_link = &topo->links[ tile->in_link_id[ 0 ] ];
206 0 : FD_TEST( 0==strcmp( in_link->name, "snapct_ld" ) );
207 0 : ctx->in_rd.base = fd_topo_obj_wksp_base( topo, in_link->dcache_obj_id );
208 :
209 0 : FD_TEST( tile->out_cnt==1UL );
210 0 : fd_topo_link_t const * out_link = &topo->links[ tile->out_link_id[ 0 ] ];
211 0 : FD_TEST( 0==strcmp( out_link->name, "snapld_dc" ) );
212 0 : ctx->out_dc.mem = fd_topo_obj_wksp_base( topo, out_link->dcache_obj_id );
213 0 : ctx->out_dc.chunk0 = fd_dcache_compact_chunk0( ctx->out_dc.mem, out_link->dcache );
214 0 : ctx->out_dc.wmark = fd_dcache_compact_wmark ( ctx->out_dc.mem, out_link->dcache, out_link->mtu );
215 0 : ctx->out_dc.chunk = ctx->out_dc.chunk0;
216 0 : ctx->out_dc.mtu = out_link->mtu;
217 :
218 0 : FD_TEST( sizeof(fd_ssctrl_meta_t)<=ctx->out_dc.mtu );
219 :
220 : /* We can only close the temporary socket file descriptor after
221 : entering the sandbox because the sandbox checks all file
222 : descriptors are existent. */
223 0 : if( -1==close( ctx->sockfd ) ) FD_LOG_ERR((" close() failed (%i-%s)", errno, fd_io_strerror( errno ) ));
224 :
225 0 : ulong scratch_top = FD_SCRATCH_ALLOC_FINI( l, scratch_align() );
226 0 : if( FD_UNLIKELY( scratch_top > (ulong)scratch + scratch_footprint( tile ) ) )
227 0 : FD_LOG_ERR(( "scratch overflow %lu %lu %lu", scratch_top - (ulong)scratch - scratch_footprint( tile ), scratch_top, (ulong)scratch + scratch_footprint( tile ) ));
228 0 : }
229 :
230 : static int
231 0 : should_shutdown( fd_snapld_tile_t * ctx ) {
232 0 : return ctx->state==FD_SNAPSHOT_STATE_SHUTDOWN;
233 0 : }
234 :
235 : static void
236 0 : metrics_write( fd_snapld_tile_t * ctx ) {
237 0 : FD_MGAUGE_SET( SNAPLD, STATE, (ulong)(ctx->state) );
238 0 : }
239 :
240 : static void
241 : transition_malformed( fd_snapld_tile_t * ctx,
242 0 : fd_stem_context_t * stem ) {
243 0 : if( FD_UNLIKELY( ctx->state==FD_SNAPSHOT_STATE_ERROR ) ) return;
244 0 : ctx->state = FD_SNAPSHOT_STATE_ERROR;
245 0 : fd_stem_publish( stem, 0UL, FD_SNAPSHOT_MSG_CTRL_ERROR, 0UL, 0UL, 0UL, 0UL, 0UL );
246 0 : }
247 :
248 : static int
249 : check_download_progress( fd_snapld_tile_t * ctx,
250 : fd_stem_context_t * stem,
251 : int downloading,
252 0 : long now ) {
253 0 : if( FD_UNLIKELY( ctx->window_deadline==LONG_MAX && downloading ) ) {
254 0 : ctx->window_deadline = now + FD_SNAPLD_DOWNLOAD_WINDOW_NS;
255 0 : ctx->bytes_in_window = 0UL;
256 0 : }
257 :
258 0 : if( FD_UNLIKELY( now>ctx->window_deadline ) ) {
259 0 : if( FD_UNLIKELY( ctx->bytes_in_window<ctx->min_bytes_in_window ) ) {
260 : /* cancel the download if the download progress speed in the last
261 : window is less than the minimum download speed. */
262 0 : double download_speed_mibs = (double)ctx->bytes_in_window / (double)(FD_SNAPLD_DOWNLOAD_WINDOW_NS / 1e9) / (double)(1<<20UL);
263 0 : FD_LOG_WARNING(( "download progress of %.2f MiB/s in the last %lu seconds for %s snapshot "
264 0 : "is below the minimum download speed %u MiB/s, cancelling download",
265 0 : download_speed_mibs, FD_SNAPLD_DOWNLOAD_WINDOW_NS / (ulong)1e9,
266 0 : ctx->load_full ? "full" : "incremental", ctx->config.min_download_speed_mibs ));
267 0 : transition_malformed( ctx, stem );
268 0 : fd_sshttp_cancel( ctx->sshttp );
269 0 : return -1;
270 0 : }
271 0 : ctx->window_deadline = now + FD_SNAPLD_DOWNLOAD_WINDOW_NS;
272 0 : ctx->bytes_in_window = 0UL;
273 0 : }
274 0 : return 0;
275 0 : }
276 :
277 : static void
278 : after_credit( fd_snapld_tile_t * ctx,
279 : fd_stem_context_t * stem,
280 : int * opt_poll_in FD_PARAM_UNUSED,
281 0 : int * charge_busy ) {
282 0 : if( ctx->state!=FD_SNAPSHOT_STATE_PROCESSING ) {
283 0 : fd_log_sleep( (long)1e6 );
284 0 : return;
285 0 : }
286 :
287 0 : uchar * out = fd_chunk_to_laddr( ctx->out_dc.mem, ctx->out_dc.chunk );
288 :
289 0 : if( ctx->load_file ) {
290 0 : if( FD_UNLIKELY( !ctx->sent_meta ) ) {
291 0 : FD_TEST( sizeof(fd_ssctrl_meta_t)<=ctx->out_dc.mtu );
292 0 : fd_ssctrl_meta_t * meta = (fd_ssctrl_meta_t *)out;
293 0 : meta->total_sz = ctx->file_sz;
294 0 : meta->resolved_slot = ULONG_MAX;
295 0 : fd_memset( meta->resolved_hash, 0, FD_HASH_FOOTPRINT );
296 0 : meta->resolved_name[0] = '\0';
297 0 : ctx->sent_meta = 1;
298 0 : fd_stem_publish( stem, 0UL, FD_SNAPSHOT_MSG_META, ctx->out_dc.chunk, sizeof(fd_ssctrl_meta_t), 0UL, 0UL, 0UL );
299 0 : ctx->out_dc.chunk = fd_dcache_compact_next( ctx->out_dc.chunk, sizeof(fd_ssctrl_meta_t), ctx->out_dc.chunk0, ctx->out_dc.wmark );
300 0 : return;
301 0 : }
302 0 : long result = read( ctx->load_full ? ctx->local_full_fd : ctx->local_incr_fd, out, ctx->out_dc.mtu );
303 0 : if( FD_UNLIKELY( result<=0L ) ) {
304 0 : if( result==0L ) {
305 0 : FD_LOG_INFO(( "finished reading %s snapshot from local file", ctx->load_full ? "full" : "incremental" ));
306 0 : ctx->state = FD_SNAPSHOT_STATE_FINISHING;
307 0 : fd_stem_publish( stem, 0UL, FD_SNAPSHOT_MSG_LOAD_COMPLETE, 0UL, 0UL, 0UL, 0UL, 0UL );
308 0 : } else if( FD_UNLIKELY( errno!=EAGAIN && errno!=EINTR ) ) {
309 0 : FD_LOG_WARNING(( "read() failed on %s snapshot file (%i-%s)", ctx->load_full ? "full" : "incremental", errno, fd_io_strerror( errno ) ));
310 0 : transition_malformed( ctx, stem );
311 0 : return; /* verbose return */
312 0 : }
313 0 : } else {
314 0 : fd_stem_publish( stem, 0UL, FD_SNAPSHOT_MSG_DATA, ctx->out_dc.chunk, (ulong)result, 0UL, 0UL, 0UL );
315 0 : ctx->out_dc.chunk = fd_dcache_compact_next( ctx->out_dc.chunk, (ulong)result, ctx->out_dc.chunk0, ctx->out_dc.wmark );
316 0 : *charge_busy = 1;
317 0 : return; /* verbose return */
318 0 : }
319 0 : } else {
320 0 : int downloading = 0;
321 0 : ulong data_len = ctx->out_dc.mtu;
322 0 : long now = fd_log_wallclock();
323 0 : int result = fd_sshttp_advance( ctx->sshttp, &data_len, out, &downloading, now );
324 0 : switch( result ) {
325 0 : case FD_SSHTTP_ADVANCE_AGAIN:
326 : /* Return value ignored: on failure, check_download_progress
327 : already calls transition_malformed and fd_sshttp_cancel. */
328 0 : check_download_progress( ctx, stem, downloading, now );
329 0 : break;
330 0 : case FD_SSHTTP_ADVANCE_DATA: {
331 0 : ctx->bytes_in_window += data_len;
332 0 : if( FD_UNLIKELY( -1==check_download_progress( ctx, stem, downloading, now ) ) ) break;
333 0 : if( FD_UNLIKELY( !ctx->sent_meta ) ) {
334 : /* On the first DATA return, the HTTP headers are available
335 : for use. We need to send this metadata downstream, but
336 : need to do so before any data frags. So, we copy any data
337 : we received with the headers (if any) to the next dcache
338 : chunk and then publish both in order. */
339 0 : ctx->start_batch = fd_log_wallclock();
340 0 : FD_TEST( sizeof(fd_ssctrl_meta_t)<=ctx->out_dc.mtu );
341 0 : fd_ssctrl_meta_t * meta = (fd_ssctrl_meta_t *)out;
342 0 : ulong next_chunk = fd_dcache_compact_next( ctx->out_dc.chunk, sizeof(fd_ssctrl_meta_t), ctx->out_dc.chunk0, ctx->out_dc.wmark );
343 0 : memmove( fd_chunk_to_laddr( ctx->out_dc.mem, next_chunk ), out, data_len );
344 0 : meta->total_sz = fd_sshttp_content_len( ctx->sshttp );
345 0 : if( FD_UNLIKELY( meta->total_sz==ULONG_MAX ) ) {
346 0 : FD_LOG_WARNING(( "HTTP response for %s snapshot is missing Content-Length header", ctx->load_full ? "full" : "incremental" ));
347 0 : transition_malformed( ctx, stem );
348 0 : fd_sshttp_cancel( ctx->sshttp );
349 0 : break;
350 0 : }
351 :
352 : /* Populate resolved redirect fields in META */
353 0 : meta->resolved_slot = ULONG_MAX;
354 0 : meta->resolved_name[0] = '\0';
355 0 : fd_memset( meta->resolved_hash, 0, FD_HASH_FOOTPRINT );
356 :
357 0 : if( ctx->is_redirect ) {
358 0 : char const * resolved_name = fd_sshttp_snapshot_name( ctx->sshttp );
359 0 : if( FD_UNLIKELY( !resolved_name || resolved_name[0]=='\0' ) ) {
360 0 : FD_LOG_WARNING(( "redirect-based download did not resolve to a snapshot filename for %s snapshot",
361 0 : ctx->load_full ? "full" : "incremental" ));
362 0 : transition_malformed( ctx, stem );
363 0 : fd_sshttp_cancel( ctx->sshttp );
364 0 : break;
365 0 : }
366 0 : int is_full_filename = !strncmp( resolved_name, "snapshot-", 9 );
367 0 : if( FD_UNLIKELY( is_full_filename!=ctx->load_full ) ) {
368 0 : FD_LOG_WARNING(( "resolved snapshot type mismatch: expected %s but got %s filename `%s`",
369 0 : ctx->load_full ? "full" : "incremental", is_full_filename ? "full" : "incremental", resolved_name ));
370 0 : transition_malformed( ctx, stem );
371 0 : fd_sshttp_cancel( ctx->sshttp );
372 0 : break;
373 0 : }
374 0 : ulong resolved_slot = fd_sshttp_resolved_slot( ctx->sshttp );
375 0 : if( FD_UNLIKELY( resolved_slot<ctx->gossip_slot ) ) {
376 0 : FD_LOG_WARNING(( "resolved snapshot slot %lu is older than gossip slot %lu for %s snapshot, rejecting",
377 0 : resolved_slot, ctx->gossip_slot, ctx->load_full ? "full" : "incremental" ));
378 0 : transition_malformed( ctx, stem );
379 0 : fd_sshttp_cancel( ctx->sshttp );
380 0 : break;
381 0 : }
382 0 : if( FD_UNLIKELY( resolved_slot>=FD_SSPEER_PLAUSIBLE_MAX_SLOT ) ) {
383 0 : FD_LOG_WARNING(( "resolved snapshot slot %lu exceeds plausibility bound for %s snapshot, rejecting",
384 0 : resolved_slot, ctx->load_full ? "full" : "incremental" ));
385 0 : transition_malformed( ctx, stem );
386 0 : fd_sshttp_cancel( ctx->sshttp );
387 0 : break;
388 0 : }
389 0 : meta->resolved_slot = resolved_slot;
390 0 : fd_memcpy( meta->resolved_hash, fd_sshttp_resolved_hash( ctx->sshttp ), FD_HASH_FOOTPRINT );
391 0 : fd_cstr_ncpy( meta->resolved_name, resolved_name, PATH_MAX );
392 0 : FD_LOG_INFO(( "redirect resolved to `%s` (slot %lu) for %s snapshot",
393 0 : resolved_name, resolved_slot, ctx->load_full ? "full" : "incremental" ));
394 0 : }
395 :
396 0 : ctx->sent_meta = 1;
397 0 : fd_stem_publish( stem, 0UL, FD_SNAPSHOT_MSG_META, ctx->out_dc.chunk, sizeof(fd_ssctrl_meta_t), 0UL, 0UL, 0UL );
398 0 : ctx->out_dc.chunk = next_chunk;
399 0 : }
400 0 : if( FD_LIKELY( data_len!=0UL ) ) {
401 0 : fd_stem_publish( stem, 0UL, FD_SNAPSHOT_MSG_DATA, ctx->out_dc.chunk, data_len, 0UL, 0UL, 0UL );
402 0 : ctx->out_dc.chunk = fd_dcache_compact_next( ctx->out_dc.chunk, data_len, ctx->out_dc.chunk0, ctx->out_dc.wmark );
403 0 : ctx->bytes_in_batch += data_len;
404 :
405 : /* measure download speed every 100 MiB */
406 0 : if(ctx->bytes_in_batch>=100<<20UL) {
407 0 : ctx->end_batch = fd_log_wallclock();
408 : /* as a precaution, make sure elapsed_batch is positive
409 : and larger than zero (to avoid division by zero). */
410 0 : long elapsed_batch = fd_long_if( ctx->end_batch > ctx->start_batch, ctx->end_batch - ctx->start_batch, 1L );
411 : /* download speed in MiB/s = bytes/nanoseconds * 1e9/(1 second) * 1/(1MiB = 1<<20UL) = 1e9/(1024*1024) ~= 954 */
412 0 : ctx->download_speed_mibs = (double)(ctx->bytes_in_batch*954) / (double)elapsed_batch;
413 0 : if( FD_UNLIKELY( ctx->download_speed_mibs<ctx->config.min_download_speed_mibs ) ) {
414 : /* cancel the snapshot load if the download speed is less
415 : than the minimum download speed. */
416 0 : FD_LOG_WARNING(( "download speed %.2f MiB/s on a batch of %lu MiB for %s snapshot is below the minimum threshold %.2f MiB/s. "
417 0 : "cancelling snapshot download",
418 0 : ctx->download_speed_mibs, ctx->bytes_in_batch>>20UL, ctx->load_full ? "full" : "incremental",
419 0 : (double)(ctx->config.min_download_speed_mibs) ));
420 0 : transition_malformed( ctx, stem );
421 0 : fd_sshttp_cancel( ctx->sshttp );
422 0 : break;
423 0 : }
424 0 : ctx->start_batch = ctx->end_batch;
425 0 : ctx->bytes_in_batch = 0UL;
426 0 : }
427 0 : }
428 0 : *charge_busy = 1;
429 0 : break;
430 0 : }
431 0 : case FD_SSHTTP_ADVANCE_DONE:
432 0 : if( FD_UNLIKELY( !ctx->sent_meta ) ) {
433 0 : FD_LOG_WARNING(( "zero-length HTTP response for %s snapshot", ctx->load_full ? "full" : "incremental" ));
434 0 : transition_malformed( ctx, stem );
435 0 : fd_sshttp_cancel( ctx->sshttp );
436 0 : break;
437 0 : }
438 0 : FD_LOG_INFO(( "finished downloading %s snapshot", ctx->load_full ? "full" : "incremental" ));
439 0 : ctx->state = FD_SNAPSHOT_STATE_FINISHING;
440 0 : fd_stem_publish( stem, 0UL, FD_SNAPSHOT_MSG_LOAD_COMPLETE, 0UL, 0UL, 0UL, 0UL, 0UL );
441 0 : break;
442 0 : case FD_SSHTTP_ADVANCE_ERROR:
443 0 : FD_LOG_WARNING(( "HTTP advance error during %s snapshot download, entering error state",
444 0 : ctx->load_full ? "full" : "incremental" ));
445 0 : transition_malformed( ctx, stem );
446 0 : fd_sshttp_cancel( ctx->sshttp );
447 0 : break;
448 0 : default: FD_LOG_ERR(( "unexpected fd_sshttp_advance result %d for %s snapshot",
449 0 : result, ctx->load_full ? "full" : "incremental" ));
450 0 : }
451 0 : }
452 0 : }
453 :
454 : static int
455 : returnable_frag( fd_snapld_tile_t * ctx,
456 : ulong in_idx FD_PARAM_UNUSED,
457 : ulong seq FD_PARAM_UNUSED,
458 : ulong sig,
459 : ulong chunk,
460 : ulong sz,
461 : ulong ctl FD_PARAM_UNUSED,
462 : ulong tsorig FD_PARAM_UNUSED,
463 : ulong tspub FD_PARAM_UNUSED,
464 0 : fd_stem_context_t * stem ) {
465 0 : if( ctx->state==FD_SNAPSHOT_STATE_ERROR && sig!=FD_SNAPSHOT_MSG_CTRL_FAIL ) {
466 : /* Control messages move along the snapshot load pipeline. Since
467 : error conditions can be triggered by any tile in the pipeline,
468 : it is possible to be in error state and still receive otherwise
469 : valid messages. Only a fail message can revert this. */
470 0 : return 0;
471 0 : };
472 :
473 0 : int forward_msg = 1;
474 :
475 0 : switch( sig ) {
476 :
477 0 : case FD_SNAPSHOT_MSG_CTRL_INIT_FULL:
478 0 : case FD_SNAPSHOT_MSG_CTRL_INIT_INCR: {
479 0 : FD_TEST( ctx->state==FD_SNAPSHOT_STATE_IDLE );
480 0 : ctx->state = FD_SNAPSHOT_STATE_PROCESSING;
481 0 : FD_TEST( sz==sizeof(fd_ssctrl_init_t) && sz<=ctx->out_dc.mtu );
482 0 : fd_ssctrl_init_t const * msg_in = fd_chunk_to_laddr_const( ctx->in_rd.base, chunk );
483 0 : ctx->load_full = sig==FD_SNAPSHOT_MSG_CTRL_INIT_FULL;
484 0 : ctx->load_file = msg_in->file;
485 0 : ctx->sent_meta = 0;
486 0 : ctx->gossip_slot = msg_in->slot;
487 0 : ctx->is_redirect = msg_in->is_redirect;
488 0 : ctx->file_sz = msg_in->file_sz;
489 :
490 0 : ctx->window_deadline = LONG_MAX;
491 0 : ctx->bytes_in_window = 0UL;
492 0 : long now = fd_log_wallclock();
493 0 : if( ctx->load_file ) {
494 0 : if( FD_UNLIKELY( 0!=lseek( ctx->load_full ? ctx->local_full_fd : ctx->local_incr_fd, 0, SEEK_SET ) ) )
495 0 : FD_LOG_ERR(( "lseek(0) failed on %s snapshot file (%i-%s)",
496 0 : ctx->load_full ? "full" : "incremental", errno, fd_io_strerror( errno ) ));
497 0 : } else {
498 0 : if( FD_UNLIKELY( fd_sshttp_init( ctx->sshttp, msg_in->addr, msg_in->hostname, msg_in->is_https, msg_in->path, msg_in->path_len, 4UL, now ) ) ) {
499 0 : transition_malformed( ctx, stem );
500 0 : forward_msg = 0;
501 0 : break;
502 0 : }
503 0 : }
504 0 : fd_ssctrl_init_t * msg_out = fd_chunk_to_laddr( ctx->out_dc.mem, ctx->out_dc.chunk );
505 0 : fd_memcpy( msg_out, msg_in, sz );
506 0 : fd_stem_publish( stem, 0UL, sig, ctx->out_dc.chunk, sz, 0UL, 0UL, 0UL );
507 0 : ctx->out_dc.chunk = fd_dcache_compact_next( ctx->out_dc.chunk, ctx->out_dc.mtu, ctx->out_dc.chunk0, ctx->out_dc.wmark );
508 0 : forward_msg = 0; // we are forwarding the control message in the `fd_sstrl_init_t` message
509 0 : break;
510 0 : }
511 :
512 0 : case FD_SNAPSHOT_MSG_CTRL_FINI: {
513 0 : FD_TEST( ctx->state==FD_SNAPSHOT_STATE_FINISHING );
514 0 : break;
515 0 : }
516 :
517 0 : case FD_SNAPSHOT_MSG_CTRL_NEXT:
518 0 : case FD_SNAPSHOT_MSG_CTRL_DONE: {
519 0 : FD_TEST( ctx->state==FD_SNAPSHOT_STATE_FINISHING );
520 0 : ctx->state = FD_SNAPSHOT_STATE_IDLE;
521 0 : break;
522 0 : }
523 :
524 0 : case FD_SNAPSHOT_MSG_CTRL_ERROR: {
525 0 : FD_TEST( ctx->state!=FD_SNAPSHOT_STATE_SHUTDOWN );
526 0 : fd_sshttp_cancel( ctx->sshttp );
527 0 : ctx->state = FD_SNAPSHOT_STATE_ERROR;
528 0 : break;
529 0 : }
530 :
531 0 : case FD_SNAPSHOT_MSG_CTRL_FAIL:
532 0 : FD_TEST( ctx->state!=FD_SNAPSHOT_STATE_SHUTDOWN );
533 0 : fd_sshttp_cancel( ctx->sshttp );
534 0 : ctx->state = FD_SNAPSHOT_STATE_IDLE;
535 0 : break;
536 :
537 0 : case FD_SNAPSHOT_MSG_CTRL_SHUTDOWN: {
538 0 : FD_TEST( ctx->state==FD_SNAPSHOT_STATE_IDLE );
539 0 : ctx->state = FD_SNAPSHOT_STATE_SHUTDOWN;
540 0 : break;
541 0 : }
542 :
543 : /* FD_SNAPSHOT_MSG_DATA is not possible */
544 0 : default: {
545 0 : FD_LOG_ERR(( "unexpected control frag %s (%lu) in state %s (%lu)",
546 0 : fd_ssctrl_msg_ctrl_str( sig ), sig,
547 0 : fd_ssctrl_state_str( (ulong)ctx->state ), (ulong)ctx->state ));
548 0 : break;
549 0 : }
550 0 : }
551 :
552 : /* Forward the control message down the pipeline */
553 0 : if( FD_LIKELY( forward_msg ) ) {
554 0 : fd_stem_publish( stem, 0UL, sig, 0UL, 0UL, 0UL, 0UL, 0UL );
555 0 : }
556 :
557 0 : return 0;
558 0 : }
559 :
560 : /* Up to two frags from after_credit plus one from returnable_frag */
561 0 : #define STEM_BURST 3UL
562 :
563 0 : #define STEM_LAZY (128L*3000L)
564 :
565 0 : #define STEM_CALLBACK_CONTEXT_TYPE fd_snapld_tile_t
566 0 : #define STEM_CALLBACK_CONTEXT_ALIGN alignof(fd_snapld_tile_t)
567 :
568 : #define STEM_CALLBACK_SHOULD_SHUTDOWN should_shutdown
569 0 : #define STEM_CALLBACK_METRICS_WRITE metrics_write
570 0 : #define STEM_CALLBACK_AFTER_CREDIT after_credit
571 0 : #define STEM_CALLBACK_RETURNABLE_FRAG returnable_frag
572 :
573 : #include "../../disco/stem/fd_stem.c"
574 :
575 : fd_topo_run_tile_t fd_tile_snapld = {
576 : .name = NAME,
577 : .populate_allowed_seccomp = populate_allowed_seccomp,
578 : .populate_allowed_fds = populate_allowed_fds,
579 : .scratch_align = scratch_align,
580 : .scratch_footprint = scratch_footprint,
581 : .privileged_init = privileged_init,
582 : .unprivileged_init = unprivileged_init,
583 : .run = stem_run,
584 : .keep_host_networking = 1,
585 : .allow_connect = 1,
586 : .rlimit_file_cnt = 5UL, /* stderr, log, http, full/incr local files */
587 : };
588 :
589 : #undef NAME
|