Skip to content

Timeout local materialize inputs - #1488

Open
njskalski wants to merge 2 commits into
facebook:mainfrom
njskalski:timeout-local-materialize-inputs
Open

njskalski wants to merge 2 commits into
facebook:mainfrom
njskalski:timeout-local-materialize-inputs

Conversation

@njskalski

Copy link
Copy Markdown

OSS CAS/AC RPCs and the Ensure oneshot have no deadline. A hung BatchReadBlobs freezes ensure_materialized (dynamic analysis [local_materialize_inputs]) forever; keepalives leave TCP ESTABLISHED. Endpoint::timeout would also kill Execute on a shared frontend (#1221).

Bound unary CAS/AC (60s), ByteStream open (600s), and the Ensure oneshot (60s). Execute unbounded. DeadlineExceeded is retryable. 0 on grpc_timeout_secs / grpc_stream_timeout_secs / materializer_ensure_timeout_secs disables.

Seen on Buildbarn with --materializations=none: timeout fires (client RPC timeout (60s) expired), buck2-dm idle in ep_poll, build proceeds past the hang.

@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Sep 3, 2026
@njskalski
njskalski force-pushed the timeout-local-materialize-inputs branch 2 times, most recently from 2fb59fe to a836f99 Compare September 4, 2026 15:25
@meta-codesync

meta-codesync Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

This pull request has been imported. If you are a Meta employee, you can view this in D118630354. (Because this pull request was imported automatically, there will not be any future comments.)

`what-up` `dynamic analysis [local_materialize_inputs]` is
DeferredPreparationStage / MaterializedArtifacts. On a cold buck-out with
`--materializations=none`, that span waits on `ensure_materialized` of
`go_list` JSON (`dynattrs.artifact_value`). The fetch is BatchReadBlobs or
ByteStream Read with HTTP/2 keepalives but no per-RPC deadline, so a hung
frontend can leave TCP ESTABLISHED while `ensure_materialized` never
returns. Warm sqlite marks the path Materialized and skips the network,
which is why this is cold-only.

that share the same frontend address. This patch bounds only CAS/AC:

- `tokio::time::timeout` around unary CAS/AC RPCs (default 60s) and
  ByteStream Read/Write start (default 600s)
- `grpc-timeout` header on those requests for servers that honor it
- `Execute` left unbounded
- an expired deadline is retryable (existing 5-attempt retry), whether it
  arrives as `DeadlineExceeded` or as a `TimeoutExpired`-sourced
  `Cancelled` from the `grpc-timeout` header

Knobs: `[buck2_re_client] grpc_timeout_secs` and
`grpc_stream_timeout_secs` (`0` disables). This does not cover a stuck
`buck2-dm` that never dequeues `Ensure` (no RPC is sent).
`ensure_materialized` waits forever on a oneshot until the single
`buck2-dm` thread dequeues `MaterializerCommand::Ensure`. If that thread
is stuck in sync sqlite/WAL or clean-stale, no CAS RPC is sent and the
client RPC timeout cannot fire.

Bound only that oneshot (default 60s). The download future returned after
`Ensure` is accepted is already bounded by the CAS RPC timeout. The error
is distinct (`Materializer did not accept Ensure`) so a stuck command
thread is distinguishable from a hung `BatchReadBlobs`.

`[buck2] materializer_ensure_timeout_secs = 0` disables.
@njskalski
njskalski force-pushed the timeout-local-materialize-inputs branch from a836f99 to bc09fc3 Compare October 4, 2026 17:18

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant