)]}'
{"id":"openstack%2Fswift~270234","triplet_id":"openstack%2Fswift~stable%2Fkilo~I9b617bfc152dca40d1750131d1d814d85c0a88dd","project":"openstack/swift","branch":"stable/kilo","topic":"bug/1493303","hashtags":[],"change_id":"I9b617bfc152dca40d1750131d1d814d85c0a88dd","subject":"Fix memory/socket leak in proxy on truncated SLO/DLO GET","status":"MERGED","created":"2016-01-20 15:00:17.000000000","updated":"2016-01-22 03:39:56.000000000","submitted":"2016-01-22 03:39:56.000000000","submitter":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"42bc7622f53ad6b7cd2ab47737b06127ccd13c88","_number":270234,"virtual_id_number":270234,"owner":{"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"all":[{"value":2,"date":"2016-01-22 03:39:56.000000000","post_submit":true,"_account_id":3,"name":"Jenkins","username":"jenkins"},{"value":0,"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"},"all":[{"value":0,"_account_id":3,"name":"Jenkins","username":"jenkins"},{"value":2,"date":"2016-01-20 15:01:11.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"},"all":[{"value":0,"_account_id":3,"name":"Jenkins","username":"jenkins"},{"value":1,"date":"2016-01-20 15:01:11.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":3,"name":"Jenkins","username":"jenkins"},{"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2016-01-22 03:39:56.000000000","updated_by":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"reviewer":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"state":"REVIEWER"}],"messages":[{"id":"96a32d1e3d96866691973ea6d182d3cea48e73eb","author":{"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"},"date":"2016-01-20 15:00:17.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"12ce342c77d2ef8d7818ea5012c6565fbd18f941","author":{"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"},"date":"2016-01-20 15:01:11.000000000","message":"Patch Set 1: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":1},{"id":"a9bccb3c3230f952c4ad620d4ca00eff9b9cee00","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2016-01-20 17:03:58.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- gate-swift-pep8 http://logs.openstack.org/34/270234/1/check/gate-swift-pep8/a194b03/ : SUCCESS in 3m 23s\n- gate-swift-docs http://docs-draft.openstack.org/34/270234/1/check/gate-swift-docs/0d1758c//doc/build/html/ : SUCCESS in 3m 11s\n- gate-swift-python27 http://logs.openstack.org/34/270234/1/check/gate-swift-python27/23f2ca2/ : SUCCESS in 4m 50s\n- gate-swift-tox-func http://logs.openstack.org/34/270234/1/check/gate-swift-tox-func/7419882/ : SUCCESS in 5m 24s\n- gate-tempest-dsvm-full http://logs.openstack.org/34/270234/1/check/gate-tempest-dsvm-full/897611e/ : SUCCESS in 36m 01s\n- gate-swift-dsvm-functional http://logs.openstack.org/34/270234/1/check/gate-swift-dsvm-functional/4af2170/ : SUCCESS in 25m 36s","accounts_in_message":[],"_revision_number":1},{"id":"0039e153b94e7d69ec2bf35267eabc9c82206cf6","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2016-01-20 17:04:04.000000000","message":"Patch Set 1: -Verified\n\nStarting gate jobs.\nhttp://status.openstack.org/zuul/","accounts_in_message":[],"_revision_number":1},{"id":"321342ae4407aac0786dfc10666eaa31b5931045","author":{"_account_id":13052,"name":"SwiftStack Cluster CI","email":"openstack-ci@swiftstack.com","username":"swiftstack-cluster-ci","tags":["SERVICE_USER"]},"date":"2016-01-21 10:51:19.000000000","message":"Patch Set 1:\n\nBuild succeeded \n\n* cluster-swift-tox-func-ec https://8b86aea46fb38e6450f2-0e5f4c086da474abc1df58826577db2f.ssl.cf1.rackcdn.com/270234/1830/ : SUCCESS\n\n* vm-saio-probe https://8b86aea46fb38e6450f2-0e5f4c086da474abc1df58826577db2f.ssl.cf1.rackcdn.com/270234/1549/probetests/ : SUCCESS\n\n* cluster-swift-ssbench https://8b86aea46fb38e6450f2-0e5f4c086da474abc1df58826577db2f.ssl.cf1.rackcdn.com/270234/2426/ssbench : SUCCESS\n\n* cluster-swift-tox-func https://8b86aea46fb38e6450f2-0e5f4c086da474abc1df58826577db2f.ssl.cf1.rackcdn.com/270234/3789/ : SUCCESS","accounts_in_message":[],"_revision_number":1},{"id":"09076c0c7065ef711c1c940fe3523016bc586926","date":"2016-01-22 03:39:56.000000000","message":"Change has been successfully merged into the git repository by Jenkins","accounts_in_message":[],"_revision_number":1},{"id":"e9ef552ceca1144007386f3ba646df8372f4b92a","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2016-01-22 03:39:56.000000000","message":"Patch Set 1: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- gate-swift-docs http://docs-draft.openstack.org/34/270234/1/gate/gate-swift-docs/937e170//doc/build/html/ : SUCCESS in 3m 17s\n- gate-swift-pep8 http://logs.openstack.org/34/270234/1/gate/gate-swift-pep8/b8aaf2d/ : SUCCESS in 2m 38s\n- gate-swift-python27 http://logs.openstack.org/34/270234/1/gate/gate-swift-python27/baf286e/ : SUCCESS in 4m 39s\n- gate-swift-tox-func http://logs.openstack.org/34/270234/1/gate/gate-swift-tox-func/17f0d18/ : SUCCESS in 5m 22s\n- gate-tempest-dsvm-full http://logs.openstack.org/34/270234/1/gate/gate-tempest-dsvm-full/715fa28/ : SUCCESS in 40m 17s\n- gate-swift-dsvm-functional http://logs.openstack.org/34/270234/1/gate/gate-swift-dsvm-functional/b3b29ff/ : SUCCESS in 27m 36s","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"a4c1825a026655b7ed21d779824ae7c25318fd52","revisions":{"a4c1825a026655b7ed21d779824ae7c25318fd52":{"kind":"REWORK","_number":1,"created":"2016-01-20 15:00:17.000000000","uploader":{"_account_id":330,"name":"John Dickinson","email":"me@not.mn","username":"notmyname"},"ref":"refs/changes/34/270234/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/swift","ref":"refs/changes/34/270234/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/swift refs/changes/34/270234/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/swift refs/changes/34/270234/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/swift refs/changes/34/270234/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/swift refs/changes/34/270234/1"}}},"commit":{"parents":[{"commit":"036c2f348d24c01c7a4deba3e44889c45270b46d","subject":"Get better at closing WSGI iterables.","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/swift/commit/036c2f348d24c01c7a4deba3e44889c45270b46d"}]}],"author":{"name":"Samuel Merritt","email":"sam@swiftstack.com","date":"2015-12-09 00:36:05.000000000","tz":-480},"committer":{"name":"John Dickinson","email":"me@not.mn","date":"2016-01-20 14:55:43.000000000","tz":-480},"subject":"Fix memory/socket leak in proxy on truncated SLO/DLO GET","message":"Fix memory/socket leak in proxy on truncated SLO/DLO GET\n\nWhen a client disconnected while consuming an SLO or DLO GET response,\nthe proxy would leak a socket. This could be observed via strace as a\nsocket that had shutdown() called on it, but was never closed. It\ncould also be observed by counting entries in /proc/\u003cpid\u003e/fd, where\n\u003cpid\u003e is the pid of a proxy server worker process.\n\nThis is due to a memory leak in SegmentedIterable. A SegmentedIterable\nhas an \u0027app_iter\u0027 attribute, which is a generator. That generator\nreferences \u0027self\u0027 (the SegmentedIterable object). This creates a\ncyclic reference: the generator refers to the SegmentedIterable, and\nthe SegmentedIterable refers to the generator.\n\nPython can normally handle cyclic garbage; reference counting won\u0027t\nreclaim it, but the garbage collector will. However, objects with\nfinalizers will stop the garbage collector from collecting them* and\nthe cycle of which they are part.\n\nFor most objects, \"has finalizer\" is synonymous with \"has a __del__\nmethod\". However, a generator has a finalizer once it\u0027s started\nrunning and before it finishes: basically, while it has stack frames\nassociated with it**.\n\nWhen a client disconnects mid-stream, we get a memory leak. We have\nour SegmentedIterable object (call it \"si\"), and its associated\ngenerator. si.app_iter is the generator, and the generator closes over\nsi, so we have a cycle; and the generator has started but not yet\nfinished, so the generator needs finalization; hence, the garbage\ncollector won\u0027t ever clean it up.\n\nThe socket leak comes in because the generator *also* refers to the\nrequest\u0027s WSGI environment, which contains wsgi.input, which\nultimately refers to a _socket object from the standard\nlibrary. Python\u0027s _socket objects only close their underlying file\ndescriptor when their reference counts fall to 0***.\n\nThis commit makes SegmentedIterable.close() call\nself.app_iter.close(), thereby unwinding its generator\u0027s stack and\nmaking it eligible for garbage collection.\n\n* in Python \u003c 3.4, at least. See PEP 442.\n\n** see PyGen_NeedsFinalizing() in Objects/genobject.c and also\n   has_finalizer() in Modules/gcmodule.c in Python.\n\n*** see sock_dealloc() in Modules/socketmodule.c in Python. See\n    sock_close() in the same file for the other half of the sad story.\n\nThis closes CVE-2016-0738.\n\nCloses-Bug: 1493303\n\nChange-Id: I9b617bfc152dca40d1750131d1d814d85c0a88dd\nCo-Authored-By: Kota Tsuyuzaki \u003ctsuyuzaki.kota@lab.ntt.co.jp\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/swift/commit/a4c1825a026655b7ed21d779824ae7c25318fd52"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/swift/commit/a4c1825a026655b7ed21d779824ae7c25318fd52"}]},"branch":"refs/heads/stable/kilo"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
