Skip to content

fix: prevent Docker network resource exhaustion with improved cleanup - #41

Merged
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup
Sep 13, 2025
Merged

fix: prevent Docker network resource exhaustion with improved cleanup#41
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup

Conversation

@ammario

@ammarioammario commented Sep 13, 2025

Copy link
Copy Markdown
Member

Problem

CI instance experiencing network interface pool exhaustion due to orphaned Docker networks accumulating over time. Investigation found 105+ stale networks.

Additionally identified a race condition where concurrent jail initialization could delete networks before their canary files were created.

Solution

  1. Comprehensive orphan cleanup: Added cleanup_all_orphaned_docker_networks() to remove networks without canary files
  2. Race condition fix: Create canary files BEFORE network setup to prevent concurrent deletion
  3. Cleanup ordering: Ensure canaries are deleted LAST, only after successful cleanup
  4. Persistent canaries: Moved from /tmp to user data directory to survive reboots
  5. DRY refactoring: Extracted common patterns to reduce code duplication

Key Changes

Cleanup Improvements

  • Scan and remove orphaned Docker networks at jail setup
  • Only delete canary files after successful resource cleanup
  • Move canary files to ~/.local/share/httpjail/canaries/ for persistence

Race Condition Fix

  • Create canary BEFORE jail.setup() to protect resources during creation
  • Prevents concurrent jails from deleting each other's networks

Code Quality (DRY)

  • Extract network/table name generation with constants
  • Add is_not_found_error() and is_already_exists_error() helpers
  • Consolidate Docker flag handling with FLAGS_WITH_VALUES constant
  • Reduce code duplication while improving maintainability

Testing

  • Verified cleanup of 105 orphaned networks on ci-1
  • Builds successfully, passes clippy
  • Prevents future accumulation with proactive cleanup

Fixes network interface exhaustion on CI and production systems.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadsrc/jail/linux/docker.rs
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch 2 times, most recently from 038382b to 285e85eCompareSeptember 13, 2025 16:46
Issues fixed:
1. Docker networks accumulating without cleanup (105+ orphaned networks on CI)
2. Race condition: concurrent jails deleting each other's networks during setup
3. Canary files in /tmp being cleared by system, breaking orphan detection
4. Canary files deleted even when cleanup fails, losing track of orphaned resources
Critical race condition fix:
- Create canary BEFORE jail.setup() to prevent concurrent deletion
- Previously: Jail A creates network → Jail B runs cleanup → sees A's network has no canary → deletes it
- Now: Canary created first, so network is protected during setup
- Delete canary if setup fails to avoid orphaned canaries
Other improvements:
- Move canary files from /tmp to user data dir (~/.local/share/httpjail/canaries)
- Prevents system tmp cleaners from removing canaries
- Ensures canaries persist across reboots
- Fix cleanup order in ManagedJail::drop()
- Explicitly call jail.cleanup() BEFORE deleting canary
- Only delete canary if cleanup succeeds
- Leave canary for orphan cleanup if cleanup fails
- Add cleanup_all_orphaned_docker_networks() to DockerLinux
- Scans for and removes Docker networks without canary files
- Called at setup to handle networks orphaned by crashes/kills
The improved cleanup strategy:
1. On setup: Create canary, clean up orphaned networks, then create new network
2. On normal exit: Clean up resources, then delete canary only if successful
3. On cleanup failure: Leave canary so orphan cleanup can retry later
4. On orphan detection: Clean up resources for stale canaries
This prevents network interface pool exhaustion and race conditions in CI/production.
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch from 696e0e7 to 145b617CompareSeptember 13, 2025 16:50
- Extract common network name generation with NETWORK_PREFIX constant
- Add helper methods for jail ID extraction and error detection
- Consolidate error checking patterns with is_not_found_error() and is_already_exists_error()
- Extract Docker flag constants and image index finding logic
- Reduce code duplication from ~540 lines to cleaner abstractions
- Improve maintainability with centralized string patterns
@ammarioammario changed the title fix: improve Docker network cleanup to prevent resource exhaustionfix: prevent Docker network resource exhaustion with improved cleanupSep 13, 2025
@ammario
ammario merged commit 542eece into mainSep 13, 2025
6 checks passed
@ammario
ammario deleted the fix-docker-network-cleanup branch September 13, 2025 16:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix: prevent Docker network resource exhaustion with improved cleanup by ammario · Pull Request #41 · coder/httpjail · GitHub
Skip to content

fix: prevent Docker network resource exhaustion with improved cleanup - #41

Merged
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup
Sep 13, 2025
Merged

fix: prevent Docker network resource exhaustion with improved cleanup#41
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup

Conversation

@ammario

@ammarioammario commented Sep 13, 2025

Copy link
Copy Markdown
Member

Problem

CI instance experiencing network interface pool exhaustion due to orphaned Docker networks accumulating over time. Investigation found 105+ stale networks.

Additionally identified a race condition where concurrent jail initialization could delete networks before their canary files were created.

Solution

  1. Comprehensive orphan cleanup: Added cleanup_all_orphaned_docker_networks() to remove networks without canary files
  2. Race condition fix: Create canary files BEFORE network setup to prevent concurrent deletion
  3. Cleanup ordering: Ensure canaries are deleted LAST, only after successful cleanup
  4. Persistent canaries: Moved from /tmp to user data directory to survive reboots
  5. DRY refactoring: Extracted common patterns to reduce code duplication

Key Changes

Cleanup Improvements

  • Scan and remove orphaned Docker networks at jail setup
  • Only delete canary files after successful resource cleanup
  • Move canary files to ~/.local/share/httpjail/canaries/ for persistence

Race Condition Fix

  • Create canary BEFORE jail.setup() to protect resources during creation
  • Prevents concurrent jails from deleting each other's networks

Code Quality (DRY)

  • Extract network/table name generation with constants
  • Add is_not_found_error() and is_already_exists_error() helpers
  • Consolidate Docker flag handling with FLAGS_WITH_VALUES constant
  • Reduce code duplication while improving maintainability

Testing

  • Verified cleanup of 105 orphaned networks on ci-1
  • Builds successfully, passes clippy
  • Prevents future accumulation with proactive cleanup

Fixes network interface exhaustion on CI and production systems.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadsrc/jail/linux/docker.rs
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch 2 times, most recently from 038382b to 285e85eCompareSeptember 13, 2025 16:46
Issues fixed:
1. Docker networks accumulating without cleanup (105+ orphaned networks on CI)
2. Race condition: concurrent jails deleting each other's networks during setup
3. Canary files in /tmp being cleared by system, breaking orphan detection
4. Canary files deleted even when cleanup fails, losing track of orphaned resources
Critical race condition fix:
- Create canary BEFORE jail.setup() to prevent concurrent deletion
- Previously: Jail A creates network → Jail B runs cleanup → sees A's network has no canary → deletes it
- Now: Canary created first, so network is protected during setup
- Delete canary if setup fails to avoid orphaned canaries
Other improvements:
- Move canary files from /tmp to user data dir (~/.local/share/httpjail/canaries)
- Prevents system tmp cleaners from removing canaries
- Ensures canaries persist across reboots
- Fix cleanup order in ManagedJail::drop()
- Explicitly call jail.cleanup() BEFORE deleting canary
- Only delete canary if cleanup succeeds
- Leave canary for orphan cleanup if cleanup fails
- Add cleanup_all_orphaned_docker_networks() to DockerLinux
- Scans for and removes Docker networks without canary files
- Called at setup to handle networks orphaned by crashes/kills
The improved cleanup strategy:
1. On setup: Create canary, clean up orphaned networks, then create new network
2. On normal exit: Clean up resources, then delete canary only if successful
3. On cleanup failure: Leave canary so orphan cleanup can retry later
4. On orphan detection: Clean up resources for stale canaries
This prevents network interface pool exhaustion and race conditions in CI/production.
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch from 696e0e7 to 145b617CompareSeptember 13, 2025 16:50
- Extract common network name generation with NETWORK_PREFIX constant
- Add helper methods for jail ID extraction and error detection
- Consolidate error checking patterns with is_not_found_error() and is_already_exists_error()
- Extract Docker flag constants and image index finding logic
- Reduce code duplication from ~540 lines to cleaner abstractions
- Improve maintainability with centralized string patterns
@ammarioammario changed the title fix: improve Docker network cleanup to prevent resource exhaustionfix: prevent Docker network resource exhaustion with improved cleanupSep 13, 2025
@ammario
ammario merged commit 542eece into mainSep 13, 2025
6 checks passed
@ammario
ammario deleted the fix-docker-network-cleanup branch September 13, 2025 16:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent Docker network resource exhaustion with improved cleanup by ammario · Pull Request #41 · coder/httpjail · GitHub
Skip to content

fix: prevent Docker network resource exhaustion with improved cleanup - #41

Merged
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup
Sep 13, 2025
Merged

fix: prevent Docker network resource exhaustion with improved cleanup#41
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup

Conversation

@ammario

@ammarioammario commented Sep 13, 2025

Copy link
Copy Markdown
Member

Problem

CI instance experiencing network interface pool exhaustion due to orphaned Docker networks accumulating over time. Investigation found 105+ stale networks.

Additionally identified a race condition where concurrent jail initialization could delete networks before their canary files were created.

Solution

  1. Comprehensive orphan cleanup: Added cleanup_all_orphaned_docker_networks() to remove networks without canary files
  2. Race condition fix: Create canary files BEFORE network setup to prevent concurrent deletion
  3. Cleanup ordering: Ensure canaries are deleted LAST, only after successful cleanup
  4. Persistent canaries: Moved from /tmp to user data directory to survive reboots
  5. DRY refactoring: Extracted common patterns to reduce code duplication

Key Changes

Cleanup Improvements

  • Scan and remove orphaned Docker networks at jail setup
  • Only delete canary files after successful resource cleanup
  • Move canary files to ~/.local/share/httpjail/canaries/ for persistence

Race Condition Fix

  • Create canary BEFORE jail.setup() to protect resources during creation
  • Prevents concurrent jails from deleting each other's networks

Code Quality (DRY)

  • Extract network/table name generation with constants
  • Add is_not_found_error() and is_already_exists_error() helpers
  • Consolidate Docker flag handling with FLAGS_WITH_VALUES constant
  • Reduce code duplication while improving maintainability

Testing

  • Verified cleanup of 105 orphaned networks on ci-1
  • Builds successfully, passes clippy
  • Prevents future accumulation with proactive cleanup

Fixes network interface exhaustion on CI and production systems.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadsrc/jail/linux/docker.rs
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch 2 times, most recently from 038382b to 285e85eCompareSeptember 13, 2025 16:46
Issues fixed:
1. Docker networks accumulating without cleanup (105+ orphaned networks on CI)
2. Race condition: concurrent jails deleting each other's networks during setup
3. Canary files in /tmp being cleared by system, breaking orphan detection
4. Canary files deleted even when cleanup fails, losing track of orphaned resources
Critical race condition fix:
- Create canary BEFORE jail.setup() to prevent concurrent deletion
- Previously: Jail A creates network → Jail B runs cleanup → sees A's network has no canary → deletes it
- Now: Canary created first, so network is protected during setup
- Delete canary if setup fails to avoid orphaned canaries
Other improvements:
- Move canary files from /tmp to user data dir (~/.local/share/httpjail/canaries)
- Prevents system tmp cleaners from removing canaries
- Ensures canaries persist across reboots
- Fix cleanup order in ManagedJail::drop()
- Explicitly call jail.cleanup() BEFORE deleting canary
- Only delete canary if cleanup succeeds
- Leave canary for orphan cleanup if cleanup fails
- Add cleanup_all_orphaned_docker_networks() to DockerLinux
- Scans for and removes Docker networks without canary files
- Called at setup to handle networks orphaned by crashes/kills
The improved cleanup strategy:
1. On setup: Create canary, clean up orphaned networks, then create new network
2. On normal exit: Clean up resources, then delete canary only if successful
3. On cleanup failure: Leave canary so orphan cleanup can retry later
4. On orphan detection: Clean up resources for stale canaries
This prevents network interface pool exhaustion and race conditions in CI/production.
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch from 696e0e7 to 145b617CompareSeptember 13, 2025 16:50
- Extract common network name generation with NETWORK_PREFIX constant
- Add helper methods for jail ID extraction and error detection
- Consolidate error checking patterns with is_not_found_error() and is_already_exists_error()
- Extract Docker flag constants and image index finding logic
- Reduce code duplication from ~540 lines to cleaner abstractions
- Improve maintainability with centralized string patterns
@ammarioammario changed the title fix: improve Docker network cleanup to prevent resource exhaustionfix: prevent Docker network resource exhaustion with improved cleanupSep 13, 2025
@ammario
ammario merged commit 542eece into mainSep 13, 2025
6 checks passed
@ammario
ammario deleted the fix-docker-network-cleanup branch September 13, 2025 16:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent Docker network resource exhaustion with improved cleanup by ammario · Pull Request #41 · coder/httpjail · GitHub
Skip to content

fix: prevent Docker network resource exhaustion with improved cleanup - #41

Merged
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup
Sep 13, 2025
Merged

fix: prevent Docker network resource exhaustion with improved cleanup#41
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup

Conversation

@ammario

@ammarioammario commented Sep 13, 2025

Copy link
Copy Markdown
Member

Problem

CI instance experiencing network interface pool exhaustion due to orphaned Docker networks accumulating over time. Investigation found 105+ stale networks.

Additionally identified a race condition where concurrent jail initialization could delete networks before their canary files were created.

Solution

  1. Comprehensive orphan cleanup: Added cleanup_all_orphaned_docker_networks() to remove networks without canary files
  2. Race condition fix: Create canary files BEFORE network setup to prevent concurrent deletion
  3. Cleanup ordering: Ensure canaries are deleted LAST, only after successful cleanup
  4. Persistent canaries: Moved from /tmp to user data directory to survive reboots
  5. DRY refactoring: Extracted common patterns to reduce code duplication

Key Changes

Cleanup Improvements

  • Scan and remove orphaned Docker networks at jail setup
  • Only delete canary files after successful resource cleanup
  • Move canary files to ~/.local/share/httpjail/canaries/ for persistence

Race Condition Fix

  • Create canary BEFORE jail.setup() to protect resources during creation
  • Prevents concurrent jails from deleting each other's networks

Code Quality (DRY)

  • Extract network/table name generation with constants
  • Add is_not_found_error() and is_already_exists_error() helpers
  • Consolidate Docker flag handling with FLAGS_WITH_VALUES constant
  • Reduce code duplication while improving maintainability

Testing

  • Verified cleanup of 105 orphaned networks on ci-1
  • Builds successfully, passes clippy
  • Prevents future accumulation with proactive cleanup

Fixes network interface exhaustion on CI and production systems.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadsrc/jail/linux/docker.rs
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch 2 times, most recently from 038382b to 285e85eCompareSeptember 13, 2025 16:46
Issues fixed:
1. Docker networks accumulating without cleanup (105+ orphaned networks on CI)
2. Race condition: concurrent jails deleting each other's networks during setup
3. Canary files in /tmp being cleared by system, breaking orphan detection
4. Canary files deleted even when cleanup fails, losing track of orphaned resources
Critical race condition fix:
- Create canary BEFORE jail.setup() to prevent concurrent deletion
- Previously: Jail A creates network → Jail B runs cleanup → sees A's network has no canary → deletes it
- Now: Canary created first, so network is protected during setup
- Delete canary if setup fails to avoid orphaned canaries
Other improvements:
- Move canary files from /tmp to user data dir (~/.local/share/httpjail/canaries)
- Prevents system tmp cleaners from removing canaries
- Ensures canaries persist across reboots
- Fix cleanup order in ManagedJail::drop()
- Explicitly call jail.cleanup() BEFORE deleting canary
- Only delete canary if cleanup succeeds
- Leave canary for orphan cleanup if cleanup fails
- Add cleanup_all_orphaned_docker_networks() to DockerLinux
- Scans for and removes Docker networks without canary files
- Called at setup to handle networks orphaned by crashes/kills
The improved cleanup strategy:
1. On setup: Create canary, clean up orphaned networks, then create new network
2. On normal exit: Clean up resources, then delete canary only if successful
3. On cleanup failure: Leave canary so orphan cleanup can retry later
4. On orphan detection: Clean up resources for stale canaries
This prevents network interface pool exhaustion and race conditions in CI/production.
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch from 696e0e7 to 145b617CompareSeptember 13, 2025 16:50
- Extract common network name generation with NETWORK_PREFIX constant
- Add helper methods for jail ID extraction and error detection
- Consolidate error checking patterns with is_not_found_error() and is_already_exists_error()
- Extract Docker flag constants and image index finding logic
- Reduce code duplication from ~540 lines to cleaner abstractions
- Improve maintainability with centralized string patterns
@ammarioammario changed the title fix: improve Docker network cleanup to prevent resource exhaustionfix: prevent Docker network resource exhaustion with improved cleanupSep 13, 2025
@ammario
ammario merged commit 542eece into mainSep 13, 2025
6 checks passed
@ammario
ammario deleted the fix-docker-network-cleanup branch September 13, 2025 16:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix: prevent Docker network resource exhaustion with improved cleanup by ammario · Pull Request #41 · coder/httpjail · GitHub
Skip to content

fix: prevent Docker network resource exhaustion with improved cleanup - #41

Merged
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup
Sep 13, 2025
Merged

fix: prevent Docker network resource exhaustion with improved cleanup#41
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup

Conversation

@ammario

@ammarioammario commented Sep 13, 2025

Copy link
Copy Markdown
Member

Problem

CI instance experiencing network interface pool exhaustion due to orphaned Docker networks accumulating over time. Investigation found 105+ stale networks.

Additionally identified a race condition where concurrent jail initialization could delete networks before their canary files were created.

Solution

  1. Comprehensive orphan cleanup: Added cleanup_all_orphaned_docker_networks() to remove networks without canary files
  2. Race condition fix: Create canary files BEFORE network setup to prevent concurrent deletion
  3. Cleanup ordering: Ensure canaries are deleted LAST, only after successful cleanup
  4. Persistent canaries: Moved from /tmp to user data directory to survive reboots
  5. DRY refactoring: Extracted common patterns to reduce code duplication

Key Changes

Cleanup Improvements

  • Scan and remove orphaned Docker networks at jail setup
  • Only delete canary files after successful resource cleanup
  • Move canary files to ~/.local/share/httpjail/canaries/ for persistence

Race Condition Fix

  • Create canary BEFORE jail.setup() to protect resources during creation
  • Prevents concurrent jails from deleting each other's networks

Code Quality (DRY)

  • Extract network/table name generation with constants
  • Add is_not_found_error() and is_already_exists_error() helpers
  • Consolidate Docker flag handling with FLAGS_WITH_VALUES constant
  • Reduce code duplication while improving maintainability

Testing

  • Verified cleanup of 105 orphaned networks on ci-1
  • Builds successfully, passes clippy
  • Prevents future accumulation with proactive cleanup

Fixes network interface exhaustion on CI and production systems.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadsrc/jail/linux/docker.rs
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch 2 times, most recently from 038382b to 285e85eCompareSeptember 13, 2025 16:46
Issues fixed:
1. Docker networks accumulating without cleanup (105+ orphaned networks on CI)
2. Race condition: concurrent jails deleting each other's networks during setup
3. Canary files in /tmp being cleared by system, breaking orphan detection
4. Canary files deleted even when cleanup fails, losing track of orphaned resources
Critical race condition fix:
- Create canary BEFORE jail.setup() to prevent concurrent deletion
- Previously: Jail A creates network → Jail B runs cleanup → sees A's network has no canary → deletes it
- Now: Canary created first, so network is protected during setup
- Delete canary if setup fails to avoid orphaned canaries
Other improvements:
- Move canary files from /tmp to user data dir (~/.local/share/httpjail/canaries)
- Prevents system tmp cleaners from removing canaries
- Ensures canaries persist across reboots
- Fix cleanup order in ManagedJail::drop()
- Explicitly call jail.cleanup() BEFORE deleting canary
- Only delete canary if cleanup succeeds
- Leave canary for orphan cleanup if cleanup fails
- Add cleanup_all_orphaned_docker_networks() to DockerLinux
- Scans for and removes Docker networks without canary files
- Called at setup to handle networks orphaned by crashes/kills
The improved cleanup strategy:
1. On setup: Create canary, clean up orphaned networks, then create new network
2. On normal exit: Clean up resources, then delete canary only if successful
3. On cleanup failure: Leave canary so orphan cleanup can retry later
4. On orphan detection: Clean up resources for stale canaries
This prevents network interface pool exhaustion and race conditions in CI/production.
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch from 696e0e7 to 145b617CompareSeptember 13, 2025 16:50
- Extract common network name generation with NETWORK_PREFIX constant
- Add helper methods for jail ID extraction and error detection
- Consolidate error checking patterns with is_not_found_error() and is_already_exists_error()
- Extract Docker flag constants and image index finding logic
- Reduce code duplication from ~540 lines to cleaner abstractions
- Improve maintainability with centralized string patterns
@ammarioammario changed the title fix: improve Docker network cleanup to prevent resource exhaustionfix: prevent Docker network resource exhaustion with improved cleanupSep 13, 2025
@ammario
ammario merged commit 542eece into mainSep 13, 2025
6 checks passed
@ammario
ammario deleted the fix-docker-network-cleanup branch September 13, 2025 16:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent Docker network resource exhaustion with improved cleanup by ammario · Pull Request #41 · coder/httpjail · GitHub
Skip to content

fix: prevent Docker network resource exhaustion with improved cleanup - #41

Merged
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup
Sep 13, 2025
Merged

fix: prevent Docker network resource exhaustion with improved cleanup#41
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup

Conversation

@ammario

@ammarioammario commented Sep 13, 2025

Copy link
Copy Markdown
Member

Problem

CI instance experiencing network interface pool exhaustion due to orphaned Docker networks accumulating over time. Investigation found 105+ stale networks.

Additionally identified a race condition where concurrent jail initialization could delete networks before their canary files were created.

Solution

  1. Comprehensive orphan cleanup: Added cleanup_all_orphaned_docker_networks() to remove networks without canary files
  2. Race condition fix: Create canary files BEFORE network setup to prevent concurrent deletion
  3. Cleanup ordering: Ensure canaries are deleted LAST, only after successful cleanup
  4. Persistent canaries: Moved from /tmp to user data directory to survive reboots
  5. DRY refactoring: Extracted common patterns to reduce code duplication

Key Changes

Cleanup Improvements

  • Scan and remove orphaned Docker networks at jail setup
  • Only delete canary files after successful resource cleanup
  • Move canary files to ~/.local/share/httpjail/canaries/ for persistence

Race Condition Fix

  • Create canary BEFORE jail.setup() to protect resources during creation
  • Prevents concurrent jails from deleting each other's networks

Code Quality (DRY)

  • Extract network/table name generation with constants
  • Add is_not_found_error() and is_already_exists_error() helpers
  • Consolidate Docker flag handling with FLAGS_WITH_VALUES constant
  • Reduce code duplication while improving maintainability

Testing

  • Verified cleanup of 105 orphaned networks on ci-1
  • Builds successfully, passes clippy
  • Prevents future accumulation with proactive cleanup

Fixes network interface exhaustion on CI and production systems.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadsrc/jail/linux/docker.rs
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch 2 times, most recently from 038382b to 285e85eCompareSeptember 13, 2025 16:46
Issues fixed:
1. Docker networks accumulating without cleanup (105+ orphaned networks on CI)
2. Race condition: concurrent jails deleting each other's networks during setup
3. Canary files in /tmp being cleared by system, breaking orphan detection
4. Canary files deleted even when cleanup fails, losing track of orphaned resources
Critical race condition fix:
- Create canary BEFORE jail.setup() to prevent concurrent deletion
- Previously: Jail A creates network → Jail B runs cleanup → sees A's network has no canary → deletes it
- Now: Canary created first, so network is protected during setup
- Delete canary if setup fails to avoid orphaned canaries
Other improvements:
- Move canary files from /tmp to user data dir (~/.local/share/httpjail/canaries)
- Prevents system tmp cleaners from removing canaries
- Ensures canaries persist across reboots
- Fix cleanup order in ManagedJail::drop()
- Explicitly call jail.cleanup() BEFORE deleting canary
- Only delete canary if cleanup succeeds
- Leave canary for orphan cleanup if cleanup fails
- Add cleanup_all_orphaned_docker_networks() to DockerLinux
- Scans for and removes Docker networks without canary files
- Called at setup to handle networks orphaned by crashes/kills
The improved cleanup strategy:
1. On setup: Create canary, clean up orphaned networks, then create new network
2. On normal exit: Clean up resources, then delete canary only if successful
3. On cleanup failure: Leave canary so orphan cleanup can retry later
4. On orphan detection: Clean up resources for stale canaries
This prevents network interface pool exhaustion and race conditions in CI/production.
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch from 696e0e7 to 145b617CompareSeptember 13, 2025 16:50
- Extract common network name generation with NETWORK_PREFIX constant
- Add helper methods for jail ID extraction and error detection
- Consolidate error checking patterns with is_not_found_error() and is_already_exists_error()
- Extract Docker flag constants and image index finding logic
- Reduce code duplication from ~540 lines to cleaner abstractions
- Improve maintainability with centralized string patterns
@ammarioammario changed the title fix: improve Docker network cleanup to prevent resource exhaustionfix: prevent Docker network resource exhaustion with improved cleanupSep 13, 2025
@ammario
ammario merged commit 542eece into mainSep 13, 2025
6 checks passed
@ammario
ammario deleted the fix-docker-network-cleanup branch September 13, 2025 16:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent Docker network resource exhaustion with improved cleanup by ammario · Pull Request #41 · coder/httpjail · GitHub
Skip to content

fix: prevent Docker network resource exhaustion with improved cleanup - #41

Merged
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup
Sep 13, 2025
Merged

fix: prevent Docker network resource exhaustion with improved cleanup#41
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup

Conversation

@ammario

@ammarioammario commented Sep 13, 2025

Copy link
Copy Markdown
Member

Problem

CI instance experiencing network interface pool exhaustion due to orphaned Docker networks accumulating over time. Investigation found 105+ stale networks.

Additionally identified a race condition where concurrent jail initialization could delete networks before their canary files were created.

Solution

  1. Comprehensive orphan cleanup: Added cleanup_all_orphaned_docker_networks() to remove networks without canary files
  2. Race condition fix: Create canary files BEFORE network setup to prevent concurrent deletion
  3. Cleanup ordering: Ensure canaries are deleted LAST, only after successful cleanup
  4. Persistent canaries: Moved from /tmp to user data directory to survive reboots
  5. DRY refactoring: Extracted common patterns to reduce code duplication

Key Changes

Cleanup Improvements

  • Scan and remove orphaned Docker networks at jail setup
  • Only delete canary files after successful resource cleanup
  • Move canary files to ~/.local/share/httpjail/canaries/ for persistence

Race Condition Fix

  • Create canary BEFORE jail.setup() to protect resources during creation
  • Prevents concurrent jails from deleting each other's networks

Code Quality (DRY)

  • Extract network/table name generation with constants
  • Add is_not_found_error() and is_already_exists_error() helpers
  • Consolidate Docker flag handling with FLAGS_WITH_VALUES constant
  • Reduce code duplication while improving maintainability

Testing

  • Verified cleanup of 105 orphaned networks on ci-1
  • Builds successfully, passes clippy
  • Prevents future accumulation with proactive cleanup

Fixes network interface exhaustion on CI and production systems.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadsrc/jail/linux/docker.rs
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch 2 times, most recently from 038382b to 285e85eCompareSeptember 13, 2025 16:46
Issues fixed:
1. Docker networks accumulating without cleanup (105+ orphaned networks on CI)
2. Race condition: concurrent jails deleting each other's networks during setup
3. Canary files in /tmp being cleared by system, breaking orphan detection
4. Canary files deleted even when cleanup fails, losing track of orphaned resources
Critical race condition fix:
- Create canary BEFORE jail.setup() to prevent concurrent deletion
- Previously: Jail A creates network → Jail B runs cleanup → sees A's network has no canary → deletes it
- Now: Canary created first, so network is protected during setup
- Delete canary if setup fails to avoid orphaned canaries
Other improvements:
- Move canary files from /tmp to user data dir (~/.local/share/httpjail/canaries)
- Prevents system tmp cleaners from removing canaries
- Ensures canaries persist across reboots
- Fix cleanup order in ManagedJail::drop()
- Explicitly call jail.cleanup() BEFORE deleting canary
- Only delete canary if cleanup succeeds
- Leave canary for orphan cleanup if cleanup fails
- Add cleanup_all_orphaned_docker_networks() to DockerLinux
- Scans for and removes Docker networks without canary files
- Called at setup to handle networks orphaned by crashes/kills
The improved cleanup strategy:
1. On setup: Create canary, clean up orphaned networks, then create new network
2. On normal exit: Clean up resources, then delete canary only if successful
3. On cleanup failure: Leave canary so orphan cleanup can retry later
4. On orphan detection: Clean up resources for stale canaries
This prevents network interface pool exhaustion and race conditions in CI/production.
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch from 696e0e7 to 145b617CompareSeptember 13, 2025 16:50
- Extract common network name generation with NETWORK_PREFIX constant
- Add helper methods for jail ID extraction and error detection
- Consolidate error checking patterns with is_not_found_error() and is_already_exists_error()
- Extract Docker flag constants and image index finding logic
- Reduce code duplication from ~540 lines to cleaner abstractions
- Improve maintainability with centralized string patterns
@ammarioammario changed the title fix: improve Docker network cleanup to prevent resource exhaustionfix: prevent Docker network resource exhaustion with improved cleanupSep 13, 2025
@ammario
ammario merged commit 542eece into mainSep 13, 2025
6 checks passed
@ammario
ammario deleted the fix-docker-network-cleanup branch September 13, 2025 16:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix: prevent Docker network resource exhaustion with improved cleanup by ammario · Pull Request #41 · coder/httpjail · GitHub
Skip to content

fix: prevent Docker network resource exhaustion with improved cleanup - #41

Merged
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup
Sep 13, 2025
Merged

fix: prevent Docker network resource exhaustion with improved cleanup#41
ammario merged 4 commits into
mainfrom
fix-docker-network-cleanup

Conversation

@ammario

@ammarioammario commented Sep 13, 2025

Copy link
Copy Markdown
Member

Problem

CI instance experiencing network interface pool exhaustion due to orphaned Docker networks accumulating over time. Investigation found 105+ stale networks.

Additionally identified a race condition where concurrent jail initialization could delete networks before their canary files were created.

Solution

  1. Comprehensive orphan cleanup: Added cleanup_all_orphaned_docker_networks() to remove networks without canary files
  2. Race condition fix: Create canary files BEFORE network setup to prevent concurrent deletion
  3. Cleanup ordering: Ensure canaries are deleted LAST, only after successful cleanup
  4. Persistent canaries: Moved from /tmp to user data directory to survive reboots
  5. DRY refactoring: Extracted common patterns to reduce code duplication

Key Changes

Cleanup Improvements

  • Scan and remove orphaned Docker networks at jail setup
  • Only delete canary files after successful resource cleanup
  • Move canary files to ~/.local/share/httpjail/canaries/ for persistence

Race Condition Fix

  • Create canary BEFORE jail.setup() to protect resources during creation
  • Prevents concurrent jails from deleting each other's networks

Code Quality (DRY)

  • Extract network/table name generation with constants
  • Add is_not_found_error() and is_already_exists_error() helpers
  • Consolidate Docker flag handling with FLAGS_WITH_VALUES constant
  • Reduce code duplication while improving maintainability

Testing

  • Verified cleanup of 105 orphaned networks on ci-1
  • Builds successfully, passes clippy
  • Prevents future accumulation with proactive cleanup

Fixes network interface exhaustion on CI and production systems.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadsrc/jail/linux/docker.rs
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch 2 times, most recently from 038382b to 285e85eCompareSeptember 13, 2025 16:46
Issues fixed:
1. Docker networks accumulating without cleanup (105+ orphaned networks on CI)
2. Race condition: concurrent jails deleting each other's networks during setup
3. Canary files in /tmp being cleared by system, breaking orphan detection
4. Canary files deleted even when cleanup fails, losing track of orphaned resources
Critical race condition fix:
- Create canary BEFORE jail.setup() to prevent concurrent deletion
- Previously: Jail A creates network → Jail B runs cleanup → sees A's network has no canary → deletes it
- Now: Canary created first, so network is protected during setup
- Delete canary if setup fails to avoid orphaned canaries
Other improvements:
- Move canary files from /tmp to user data dir (~/.local/share/httpjail/canaries)
- Prevents system tmp cleaners from removing canaries
- Ensures canaries persist across reboots
- Fix cleanup order in ManagedJail::drop()
- Explicitly call jail.cleanup() BEFORE deleting canary
- Only delete canary if cleanup succeeds
- Leave canary for orphan cleanup if cleanup fails
- Add cleanup_all_orphaned_docker_networks() to DockerLinux
- Scans for and removes Docker networks without canary files
- Called at setup to handle networks orphaned by crashes/kills
The improved cleanup strategy:
1. On setup: Create canary, clean up orphaned networks, then create new network
2. On normal exit: Clean up resources, then delete canary only if successful
3. On cleanup failure: Leave canary so orphan cleanup can retry later
4. On orphan detection: Clean up resources for stale canaries
This prevents network interface pool exhaustion and race conditions in CI/production.
@ammario
ammarioforce-pushed the fix-docker-network-cleanup branch from 696e0e7 to 145b617CompareSeptember 13, 2025 16:50
- Extract common network name generation with NETWORK_PREFIX constant
- Add helper methods for jail ID extraction and error detection
- Consolidate error checking patterns with is_not_found_error() and is_already_exists_error()
- Extract Docker flag constants and image index finding logic
- Reduce code duplication from ~540 lines to cleaner abstractions
- Improve maintainability with centralized string patterns
@ammarioammario changed the title fix: improve Docker network cleanup to prevent resource exhaustionfix: prevent Docker network resource exhaustion with improved cleanupSep 13, 2025
@ammario
ammario merged commit 542eece into mainSep 13, 2025
6 checks passed
@ammario
ammario deleted the fix-docker-network-cleanup branch September 13, 2025 16:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ammario