render: interrupting with Ctrl+C (SIGINT/SIGTERM) leaks Function containers, the render container, and the network
I maintainer di solito rispondono entro 2 giorni
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 68/100
Direzione di ricerca
Read the deferred cleanup paths in xr/cmd.go and op/cmd.go, then inspect the signal handling in internal/terminal/spinner.go and the render command entry points. Reproduce the issue with the supplied hanging Function and Ctrl+C, and verify that the existing containers, render container, and temporary network are removed before the command exits.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
What happened?
Interrupting crossplane render with Ctrl+C while a render is in progress leaves every Function container it
started, the crossplane internal render engine container, and the temporary crossplane-render-* network
all still running. This happens with the default runtime-docker-cleanup policy (Remove), with or
without a TTY.
All cleanup in the render commands is defer-based
(xr/cmd.go L270-L281,
op/cmd.go L210-L221),
and nothing turns SIGINT/SIGTERM into context cancellation, so the process exits before any deferred
cleanup runs. The only signal handler in the CLI is the terminal spinner's
(internal/terminal/spinner.go L291-L300),
which calls os.Exit(130) — and that skips deferred cleanup too.
Expected: an interrupted render cleans up what it created before exiting.
How can we reproduce it?
Use a Function that accepts a connection but never responds, so the render blocks long enough to interrupt:
# tagged fnlc-hang:test
FROM alpine:3.20
ENTRYPOINT ["sh","-c","exec nc -lk -p 9443 -e cat","hang"]
xr.yaml:
apiVersion: example.org/v1
kind: XThing
metadata:
name: test-xr
spec:
coolField: hello
comp-hang.yaml:
apiVersion: apiextensions.crossplane.io/v1
kind: Composition
metadata:
name: xthings.example.org
spec:
compositeTypeRef: {apiVersion: example.org/v1, kind: XThing}
mode: Pipeline
pipeline:
- step: templating
functionRef: {name: function-go-templating}
input:
apiVersion: gotemplating.fn.crossplane.io/v1beta1
kind: GoTemplate
source: Inline
inline:
template: |
apiVersion: nop.crossplane.io/v1alpha1
kind: NopResource
metadata:
annotations: {gotemplating.fn.crossplane.io/composition-resource-name: nop}
spec: {forProvider: {}}
- step: hang
functionRef: {name: function-hang}
functions-hang.yaml (names set only to make leftovers easy to find):
apiVersion: pkg.crossplane.io/v1
kind: Function
metadata:
name: function-go-templating
annotations: {render.crossplane.io/runtime-docker-name: fnlc-sigint-gotmpl}
spec: {package: xpkg.crossplane.io/crossplane-contrib/function-go-templating:v0.11.0}
---
apiVersion: pkg.crossplane.io/v1
kind: Function
metadata:
name: function-hang
annotations:
render.crossplane.io/runtime-docker-name: fnlc-sigint-hang
render.crossplane.io/runtime-docker-image: fnlc-hang:test
render.crossplane.io/runtime-docker-pull-policy: Never
spec: {package: example.org/unused:v0.0.0}
Run it, press Ctrl+C after a few seconds, then look:
$ crossplane render xr.yaml comp-hang.yaml functions-hang.yaml
^C
$ echo $?
130
$ docker ps --filter name=fnlc-sigint --format '{{.Names}} {{.Status}}'
fnlc-sigint-hang Up 7 seconds
fnlc-sigint-gotmpl Up 8 seconds
$ docker network inspect crossplane-render-wxjbqjcj --format '{{range .Containers}}{{.Name}} {{end}}'
musing_lamport
$ docker inspect musing_lamport --format '{{.Config.Image}} {{.State.Status}} cmd={{json .Config.Cmd}}'
xpkg.crossplane.io/crossplane/crossplane:stable running cmd=["internal","render"]
(Transcript lightly abridged: the reproduction was scripted, sending SIGINT 6s after start. It gives the
same result under a pseudo-TTY, where the spinner's handler is the one that exits.)
Possible fix: wrap the command context in signal.NotifyContext(ctx, os.Interrupt, syscall.SIGTERM) so an
interrupt cancels in-flight work and lets the existing deferred cleanup run, and have the spinner cooperate
with that instead of calling os.Exit. Cleanup already runs on a detached context.Background(), so it
still works after cancellation. A second signal could force-exit immediately, as is conventional.
Some interruptions (kill -9, a crash, a CI job timeout) can never be handled in-process; #401 proposes
labels so leftovers from those can be found and swept.
What environment did it happen in?
- Crossplane CLI version: built from
main@29316fea54f2ede9d2c039d9c54f0c29cbad4b65 - Platform (e.g., linux/amd64): darwin/arm64, Docker Engine 29.5.3 (Rancher Desktop)
- Crossplane version (if applicable): render engine image
xpkg.crossplane.io/crossplane/crossplane:stable
- Lingua principale
- Go
- Stelle
- 19
- Fork
- 33
- Merge medio
- 3g 4h
- PR unite (30g)
- 40
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di crossplane/cli
-
`credsStore` in docker config causes unit test failuresForse già presa @sujeito-operator l’ha presa 47 giorni fa. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
crossplane/cli#282 ·
I maintainer di solito rispondono entro 2 giorni
-
render: label the Docker containers and networks render createsForse già presa @jcogilvie l’ha presa 3 giorni fa. Apertaenhancement
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
crossplane/cli#401 ·
I maintainer di solito rispondono entro 2 giorni
-
render: Function cleanup failures are invisible without --verboseForse già presa @jcogilvie l’ha presa 3 giorni fa. Apertabug
Difficoltà 3/5 1-2 giorni Idoneità per principianti 70/100
crossplane/cli#399 ·
I maintainer di solito rispondono entro 2 giorni
-
render: docker engine discards the network-removal error, so crossplane-render-* networks leak silentlyForse già presa @jcogilvie l’ha presa 3 giorni fa. Apertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
crossplane/cli#398 ·
I maintainer di solito rispondono entro 2 giorni
-
render: stopping Function runtimes aborts on the first error, and the shared 5s budget skips container removalForse già presa @jcogilvie l’ha presa 3 giorni fa. Apertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 66/100
crossplane/cli#397 ·
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di crossplane/cli
Issue simili
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AOSSIE-Org/DebateAI#611 ·
I maintainer di solito rispondono entro 3 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
MHSanaei/3x-ui#6737 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
terraform-provider
Difficoltà 2/5 1-3 ore Idoneità per principianti 73/100
ClickHouse/terraform-provider-clickhousedbops#281 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
open-telemetry/opentelemetry-go-compile-instrumentation#1450 ·
I maintainer di solito rispondono entro 2 giorni