Skip to content

feat: make Unix domain socket path and mode configurable - #84

Open
pypingou wants to merge 2 commits into
eclipse-score:mainfrom
pypingou:feature/configurable-socket
Open

pypingou wants to merge 2 commits into
eclipse-score:mainfrom
pypingou:feature/configurable-socket

Conversation

@pypingou

@pypingou pypingou commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

Make the datarouter Unix domain socket configurable via environment variables while maintaining backward compatibility (defaults to abstract namespace with "datarouter_socket" path).

This enables containerized deployments where both the datarouter and applications run in separate containers and communicate via file-based sockets with shared volume mounts. Also supports running multiple datarouter instances with unique abstract namespace sockets.

Changes:

  • Add socket_config module for centralized socket configuration
  • Support DATAROUTER_SOCKET_PATH environment variable (default: "datarouter_socket")
  • Support DATAROUTER_SOCKET_MODE environment variable ("abstract" or "file", default: "abstract")
  • Update socketserver to use configurable socket address
  • Add comprehensive unit tests (9 tests, all passing)
  • Platform-specific defaults: Linux uses abstract, QNX uses file-based

Environment variables:

  • DATAROUTER_SOCKET_PATH: Socket path (e.g., "/var/run/datarouter.sock" or "custom_socket")
  • DATAROUTER_SOCKET_MODE: "abstract" for abstract namespace or "file" for filesystem-based

Example usage for containerized datarouter + application:

Both containers set:

export DATAROUTER_SOCKET_PATH=/var/run/datarouter.sock
export DATAROUTER_SOCKET_MODE=file

And mount the same volume at /var/run

Notes for Reviewer

Pre-Review Checklist for the PR Author

  • PR title is short, expressive and meaningful
  • Commits are properly organized
  • Relevant issues are linked in the References section
  • Tests are conducted
  • Unit tests are added

Checklist for the PR Reviewer

  • Commits are properly organized and messages are according to the guideline
  • Unit tests have been written for new behavior
  • Public API is documented
  • PR title describes the changes

Post-review Checklist for the PR Author

  • All open points are addressed and tracked via issues

References

Closes #

@pypingou
pypingou requested review from 4og and antonkri as code owners April 9, 2026 12:52
@pypingou
pypingou temporarily deployed to workflow-approval April 9, 2026 12:52 — with GitHub Actions Inactive
@pypingou
pypingou temporarily deployed to workflow-approval April 9, 2026 12:52 — with GitHub Actions Inactive
@github-actions

github-actions Bot commented Apr 9, 2026 •

Copy link
Copy Markdown

License Check Results

🚀 The license check job ran with the Bazel command:

bazel run --lockfile_mode=error //:license-check

Status: ⚠️ Needs Review

Click to expand output
[License Check Output]
Extracting Bazel installation...
Starting local Bazel server (8.6.0) and connecting to it...
INFO: Invocation ID: 143f1d36-b910-429f-a3df-13651f047232
Computing main repo mapping: 
Computing main repo mapping: 
Computing main repo mapping: 
Computing main repo mapping: 
Computing main repo mapping: 
Computing main repo mapping: 
Computing main repo mapping: 
Computing main repo mapping: 
Computing main repo mapping: 
Loading: 
Loading: 4 packages loaded
Loading: 4 packages loaded
    currently loading: 
Loading: 4 packages loaded
    currently loading: 
WARNING: Target pattern parsing failed.
ERROR: Skipping '//:license-check': no such target '//:license-check': target 'license-check' not declared in package '' defined by /home/runner/work/logging/logging/BUILD
ERROR: no such target '//:license-check': target 'license-check' not declared in package '' defined by /home/runner/work/logging/logging/BUILD
INFO: Elapsed time: 15.607s
INFO: 0 processes.
ERROR: Build did NOT complete successfully
ERROR: Build failed. Not running target

@github-actions

github-actions Bot commented Apr 9, 2026

Copy link
Copy Markdown

The created documentation from the pull request is available at: docu-html

@arsibo

arsibo commented Apr 21, 2026 •

Copy link
Copy Markdown
Contributor

please come to our FT meeting to discuss
We want to focus on QM Toolchain first. See https://github.com/orgs/eclipse-score/discussions/2757#:~:text=for%20logging%20is-,first,-QM%20Infrastructure%20shall

@pypingou
pypingou requested a review from rmaddikery as a code owner June 5, 2026 12:54
@pypingou
pypingou had a problem deploying to workflow-approval June 5, 2026 12:55 — with GitHub Actions Failure
@pypingou
pypingou had a problem deploying to workflow-approval June 5, 2026 12:55 — with GitHub Actions Failure
@pypingou
pypingou had a problem deploying to workflow-approval June 5, 2026 12:55 — with GitHub Actions Failure
@pypingou

pypingou commented Jun 9, 2026

Copy link
Copy Markdown
Contributor Author

@arsibo Sorry for the late reply. Joining meeting is not the most practical thing for me. Is there a possibility/place where we could have this discussion asynchronously?

@pypingou

Copy link
Copy Markdown
Contributor Author

@anmittag I'm a little confused about this MR being assigned to me. Isn't the assignee supposed to do something with this MR?
Could you help me understand what is expected of me?

@anmittag

Copy link
Copy Markdown
Member

Well @pypingou you have started a pr. I am expecting a pr author to follow up or accompany the pr till closure.

@pypingou

Copy link
Copy Markdown
Contributor Author

@anmittag ok, for me the assignee would be more the reviewer rather than the author, but ok that's fine.

I'm unclear what the next steps are though. I've asked if there is an asynchronous alternative to attending the logging meeting and so far without answer.

Let's just discuss in this PR first and resort to a meeting only if we really need a higher-bandwidth mode of communication? Is there anything in this PR that is not clear to you?

@anmittag

Copy link
Copy Markdown
Member

@pypingou no reviewers are mentioned separately
image

@pypingou
pypingou force-pushed the feature/configurable-socket branch from 56ac4e7 to dcd86ee Compare July 23, 2026 10:45
@pypingou
pypingou had a problem deploying to workflow-approval July 23, 2026 10:45 — with GitHub Actions Failure
@pypingou
pypingou had a problem deploying to workflow-approval July 23, 2026 10:45 — with GitHub Actions Failure
@pypingou
pypingou had a problem deploying to workflow-approval July 23, 2026 10:45 — with GitHub Actions Failure
@pypingou
pypingou had a problem deploying to workflow-approval July 23, 2026 10:45 — with GitHub Actions Failure

@rmaddikery rmaddikery left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A review will continue after the checklist has been introduced for code changes. Additionally such a change would break the regular copybara exports, I would suggesest to wait until we have completed the migration (planned in score v0.10). If this is urgent please join the CFT and we will try to find an alternative.

@pypingou

Copy link
Copy Markdown
Contributor Author

Ensure component/integration testing exercising the path and mode ensuring that the daemon has sufficient permissions to perform the actions. Take note that the daemon runs non-root in production environments.

Tried to address this in commit 1d65e83d. I added an integration test that requires a non-root test process, resolves the configured file-socket path and mode, and starts the real UnixDomainServer. It verifies socket creation with 0660 permissions, client connectivity, stale-socket cleanup on restart, and refusal to unlink a regular file. The test passes normally and under TSan and ASan/UBSan/LSan.

};

const UnixDomainSockAddr addr(score::logging::config::kSocketAddress, true);
const UnixDomainSockAddr addr = score::logging::config::CreateSocketAddress(score::os::Stdlib::instance());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please use an instantiated Stdlib and not the instance() - its safer since you offload the lifetime handling to the language

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adjusted

if (!unlink_ret.has_value())
const char* path = static_cast<const char*>(addr.addr.sun_path);
score::os::StatBuffer st{};
if (score::os::Stat::instance().stat(path, st).has_value())

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adjusted

if (!addr.IsAbstract())
{
using Mode = score::os::Stat::Mode;
constexpr auto kSocketPerms = Mode::kReadUser | Mode::kWriteUser | Mode::kReadGroup | Mode::kWriteGroup;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why should the group have write permissions?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

non-root clients sharing the socket GID would need write permission to connect. Do you want me to drop it?

@pypingou
pypingou force-pushed the feature/configurable-socket branch from fef8cf4 to b8d578a Compare October 1, 2026 15:09
@pypingou
pypingou force-pushed the feature/configurable-socket branch from b8d578a to fd17082 Compare October 2, 2026 10:51
pypingou and others added 2 commits October 3, 2026 18:07
Make the datarouter Unix domain socket configurable via environment
variables while maintaining backward compatibility (defaults to abstract
namespace with "datarouter_socket" path).

This enables containerized deployments where both the datarouter and
applications run in separate containers and communicate via file-based
sockets with shared volume mounts. Also supports running multiple
datarouter instances with unique abstract namespace sockets.

Changes:
- Add socket_config module for centralized socket configuration
- Support DATAROUTER_SOCKET_PATH and DATAROUTER_SOCKET_MODE env vars
- Use score::os::Stdlib for env access (mockable via StdlibMock in tests)
- Add S_ISSOCK check before unlinking to prevent removing non-socket files
- Set restrictive permissions (0660) on file-based sockets after bind
- Expose kMaxPathLength/kMaxAbstractPathLength from UnixDomainSockAddr
- Platform-specific defaults: Linux uses abstract, QNX uses file-based

Environment variables:
- DATAROUTER_SOCKET_PATH: Socket path (default: "datarouter_socket")
- DATAROUTER_SOCKET_MODE: "abstract" or "file" (default: "abstract")

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@pypingou
pypingou force-pushed the feature/configurable-socket branch from fd17082 to 9bd797e Compare October 3, 2026 16:07

This branch is waiting to be deployed

1 waiting deployment
workflow-approval — 9bd797e6 Waiting Oct 3, 2026 by pypingou via qnx-build (x86_64-qnx) / approval #1140
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

5 participants