Make the OIDC loopback wait cancellable so Ctrl+C exits #258
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/oidc-ctrlc-hang"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #257.
Fixed and Tested
Ctrl+C during
fj auth loginnow exits:LoopbackServer::wait_for_codemoved offspawn_blockingontotokio::net::TcpListener. The accept loop, the request-line read, and the response write are async, socli::run's SIGINT select actually cancels the wait and the runtime drops with nothing outstanding.tokio::time::timeoutaround the loop. Same semantics, and it now also covers connection handling.cancelling_wait_for_code_does_not_stall_runtime_shutdown.A stalled connection no longer wedges the sign-in:
REQUEST_LINE_TIMEOUT(10s), after which the connection is treated as a stray hit and the loop goes back to accepting.Cargo.toml: declared the tokionetandtimefeatures this code now uses directly. Both were already present through feature unification; naming them keeps the build honest if a dependency stops pulling them in.On the regression test
Asserting on runtime shutdown latency rather than on awaiting the future is deliberate. Awaiting
wait_for_codelooks identical either way, so a test that only awaits it would pass against the broken shape. Only runtime shutdown reveals a detached blocking task. I confirmed the assertion is not vacuous with a throwaway probe: with a livespawn_blockingtask,rt.shutdown_timeout(2s)blocks the full 2s, well past the test's 500ms bound.Verification
main(ba0f96a) against the real deployment: SIGINT during the sign-in wait printederror: interruptedand the process was still alive 10s later. After the fix it exits in 500ms.https://fjord.sh: held a stray socket open on the callback port, then hit/callback?code=...&state=.... The stray was dropped at the timeout, the real redirect was accepted, state was checked, the branded success page was served (HTTP 200), and the CLI went on to the token exchange (which correctly failedinvalid_granton the fake code).cargo fmt --allcargo clippy --all-targets --all-features -- -D warningscargo test: 764 passed, 0 failed, 2 ignored, plus the version integration test.Not Claimed
client::resolve::testswere skipped, not run. They read the real keychain, and the test binary's ad-hoc signature needs a fresh keychain grant that could not be presented in my session. They are untouched by this change; CI covers them.FJ_SKIP_PREPUSH=1for the same reason, with the fmt/clippy/test gate run by hand as above.