| 127 | } |
| 128 | |
| 129 | void local_endpoint::escalate_internal(std::unique_lock<std::mutex>& _lock) { |
| 130 | if (is_value(state_).any_of(state_e::FAILED, state_e::STOPPED)) { |
| 131 | return; |
| 132 | } |
| 133 | set_state_unlocked(state_e::FAILED); |
| 134 | |
| 135 | // Note: |
| 136 | // There are two competing problems: |
| 137 | // 1. We should avoid locking any mutex when invoking the error handler, |
| 138 | // as this has the potential of a lock inversion |
| 139 | // 2. The error handler needs to be called asap, to avoid cleaning up a "wrong" |
| 140 | // endpoint, because the current error handlers are not guaranteed to identify this |
| 141 | // endpoint uniquely, but only by the client identifier. |
| 142 | // |
| 143 | // While "1." can not be avoided, "2." is accidental complexity imposed on this class. |
| 144 | // In the future "2." should be rethought allowing to call "post" |
| 145 | // here. This would greatly ease reasoning about locking the class mutex, across |
| 146 | // functions. |
| 147 | cleanup_handler_t h = std::move(cleanup_handler_); // allowed to be invoked only once anyhow |
| 148 | if (h) { |
| 149 | _lock.unlock(); |
| 150 | h(true); |
| 151 | _lock.lock(); |
| 152 | } |
| 153 | } |
| 154 | |
| 155 | bool local_endpoint::send(byte_t const* _data, uint32_t _size) { |
| 156 | std::scoped_lock const lock{mutex_}; |