Skip to content

core: prevent RetriableStream registry leak on cancel race - #13083

Open
014-code wants to merge 1 commit into
grpc:masterfrom
014-code:fix/retriable-stream-registration-race
Open

014-code wants to merge 1 commit into
grpc:masterfrom
014-code:fix/retriable-stream-registration-race

Conversation

@014-code

Copy link
Copy Markdown

When ClientCall.cancel() races ClientCall.start() on a retry-enabled channel, RetriableStream.cancel() can commit the stream before start() calls prestart().

The commit callback then removes nothing because the stream has not been registered yet. prestart() subsequently registers the already-committed stream, and the one-shot commit prevents any later removal. This permanently retains the stream in UncommittedRetriableStreamsRegistry and can delay channel shutdown.

This change makes RetriableStream.start() check whether the stream was committed after prestart(). If so, it runs postCommit() again after registration, allowing the registry to remove the stream.

Added regression coverage for:

  • retry streams;
  • hedging streams;
  • streams without retry or hedging policy.

Related issue: #13034

Testing:

  • git diff --check

  • Attempted:

    ./gradlew :grpc-core:test --tests io.grpc.internal.RetriableStreamTest -PskipAndroid=true -PskipCodegen=true
    

@linux-foundation-easycla

linux-foundation-easycla Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: 014-code / name: Donson (8ace0ad)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant