writeonce/docs/examples/writeonce-framework/internal/serve.wo
shoney.arickathil a32550d968 feat: iteration 35 — net seams + the serving slice (fiber-per-connection)
- runtime ids 91-95: net.read_dl/accept_dl/write_dl (per-call deadline,
  nil/false = the EXPECTED timeout; ms<=0 = old behavior bit for bit),
  net.listen_unix (unlink-before-bind, O_NONBLOCK on the listener —
  probe-found: accept4's flag covers accepted sockets only), net.peer
- plane: one-op-per-park stays law — deadlines ride one per-shard
  TIMEOUT tick (sentinel user_data) + post-CQE expiry sweep +
  POLL_REMOVE tombstone; epoll's deadline scan grew the fd-park case;
  fibers POOL instead of freeing mid-run (stale-CQE UAF); plain parks
  zero park_deadline (no stale sleep deadlines)
- probe: all five seams verified on BOTH WO_IO backends (timeout
  timing exact, peer round-trip, unix rebind)
- framework: parse_request grows first_ms/read_ms; serve_conn — the
  keep-alive loop with deadlines where parked idle conns are LEGAL
  (close-when-idle RETIRED); App.handle_conn exposes it; plain serve()
  unchanged for simple apps
- web-app: app-owned accept_dl loop + ConnWorker actor per connection
  (each builds its own App; cross-shard placement rides the DB actor);
  WA_IDLE_MS knob; gate grows to 41 checks — two slow requests served
  in PARALLEL, stalled client evicted at the idle deadline, slow-loris
  torn at the read deadline (400)
- docs: story 35 -> done with banner; SQE/CQE design spec LANDED (was
  the review doc); ledger rows (timeouts/unix/keep-alive/peer), graph
  (NETSEAM cleared, KEEPAL done), builtin-surface rows, runtime
  CODE-LOGIC section, board entry
- battery 13/13 fresh-built

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-23 08:04:32 +02:00

153 lines
5.8 KiB
Text

-- internal/serve.wo — response serialization + the blocking keep-alive serve
-- loop. The dispatch seam is the Dispatcher interface (the router's App
-- satisfies it, Task 3); it is wrapped in `try`, so a trapping handler
-- answers 500 and the loop lives — a bad request must never kill the
-- server. Every accept path closes its fd; `env.stopping()` is honored
-- between connections and between keep-alive requests (a SIGTERM landing
-- in a blocking call already unwinds cleanly — the runtime's stop story).
use net
use env
-- iteration 17: serve.wo moved under internal/, so Req/Resp and the response
-- builders are no longer same-module — they live in the public `http` module.
use http
use internal
pub interface Dispatcher {
fn dispatch(mut req: Req) -> Resp
}
fn status_text(code: Int) -> Text {
switch code {
case 200: return "OK";
case 201: return "Created";
case 302: return "Found";
case 400: return "Bad Request";
case 401: return "Unauthorized";
case 404: return "Not Found";
case 405: return "Method Not Allowed";
case 409: return "Conflict";
case 500: return "Internal Server Error";
default: return "Status";
}
}
-- head_only: HEAD answers — full status line + headers (Content-Length of
-- the body a GET would have sent) with the body itself suppressed.
pub fn serialize(resp: Resp, keep: Bool, head_only: Bool) -> Text {
let head = "HTTP/1.1 ${resp.status} ${status_text(resp.status)}\r\n";
for k, v in resp.headers {
head = head .. "${k}: ${v}\r\n";
}
if keep {
head = head .. "Connection: keep-alive\r\n";
} else {
head = head .. "Connection: close\r\n";
}
head = head .. "Content-Length: ${len(resp.body)}\r\n\r\n";
if head_only { return head; }
return head .. resp.body;
}
-- iteration 35, the serving slice: ONE connection served to completion —
-- the keep-alive loop with per-read deadlines. Meant to run INSIDE an
-- app-spawned per-connection actor (fiber): a parked idle connection is
-- legal there (it blocks nobody), so keep-alive stays OPEN until the
-- idle deadline evicts it — close-when-idle retires. read_ms bounds a
-- slow peer mid-request (torn = 400-and-close); idle_ms bounds the wait
-- for a request's first bytes (expiry = clean close). ms <= 0 = forever.
-- Closes the fd on every path except a WS hijack (status 101).
pub fn serve_conn(c: net.Conn, d: Dispatcher, read_ms: Int, idle_ms: Int) {
let carry = "";
let alive = true;
let hijacked = false;
while alive {
if env.stopping() { alive = false; continue; }
let p = try parse_request(c, carry, idle_ms, read_ms) catch (e) nil;
if p == nil { alive = false; continue; }
if p.closed { alive = false; continue; }
if p.ok == false {
try net.write(c, serialize(bad_request("malformed request"), false, false)) catch (e) {}
alive = false;
continue;
}
let r = p.req;
if r == nil { alive = false; continue; }
carry = p.rest;
let is_head = r.method == "HEAD";
if is_head { r.method = "GET"; }
-- fiber-per-connection: keep-alive stays OPEN (the idle deadline is
-- the eviction policy), unless the client asks to close
let keep = true;
let conn = r.headers["connection"];
if conn != nil {
if to_lower(conn) == "close" { keep = false; }
}
let resp = try d.dispatch(r) catch (e) server_error();
if resp.status == 101 {
hijacked = true;
alive = false;
continue;
}
try net.write(c, serialize(resp, keep, is_head)) catch (e) { alive = false; }
if keep == false { alive = false; }
}
if hijacked == false {
net.close(c);
}
}
pub fn serve(host: Text, port: Int, d: Dispatcher) -> Int {
let srv = net.listen(host, port);
print("listening on ${host}:${port}");
while true {
if env.stopping() { net.close(srv); return 0; }
let c = net.accept(srv);
let carry = "";
let alive = true;
let hijacked = false;
while alive {
if env.stopping() { alive = false; continue; }
let p = try parse_request(c, carry, 0, 0) catch (e) nil; -- an IO trap = gone
if p == nil { alive = false; continue; }
if p.closed { alive = false; continue; }
if p.ok == false {
try net.write(c, serialize(bad_request("malformed request"), false, false)) catch (e) {}
alive = false;
continue;
}
let r = p.req;
if r == nil { alive = false; continue; }
carry = p.rest;
-- HEAD is GET with the body suppressed: route and dispatch as GET,
-- serialize with head_only so Content-Length still names the body a
-- GET would have carried (RFC 9110 §9.3.2).
let is_head = r.method == "HEAD";
if is_head { r.method = "GET"; }
-- Connection policy for a single-threaded server: serve PIPELINED
-- requests on one connection (bytes already buffered), but close when
-- the client would idle — a parked keep-alive connection would block
-- `accept` and starve every other client. A proxy in front simply
-- reconnects; this is the honest shape until shards/fibers (8/11).
let keep = len(carry) > 0;
let conn = r.headers["connection"];
if conn != nil {
if to_lower(conn) == "close" { keep = false; }
}
let resp = try d.dispatch(r) catch (e) server_error();
-- iteration 24: status 101 is the hijack sentinel (http/ws.wo).
-- The handler completed a WebSocket upgrade and now OWNS the fd
-- through its own actors: no serialization, no close — the loop
-- forgets this connection and returns to accept.
if resp.status == 101 {
hijacked = true;
alive = false;
continue;
}
try net.write(c, serialize(resp, keep, is_head)) catch (e) { alive = false; }
if keep == false { alive = false; }
}
if hijacked == false {
net.close(c);
}
}
}