Giving each controller a Reload method worked for the notification pipes, which only hold values, but not for the two bot channels: the NapCat client is stopped through a sync.Once and the Telegram polling context is created with the controller, so neither can be re-pointed once running. It also meant five bespoke implementations of the same idea. Replace the whole set instead. Manager.ReplaceAll swaps in a freshly built set under the registry lock, stops the outgoing controllers outside it, and starts the incoming ones off the calling goroutine so a slow handshake does not hold the settings request open. ReplaceAll is now the only way controllers are installed: Register is gone, because a lone registration would slip a controller in without recording the settings it was built from, which is what NeedsRebuild compares against. The rebuild runs from the reload hook and only fires when the controllerMethod section actually changed, so saving a message template or a webhook endpoint leaves the channels alone. NeedsRebuild compares the whole section by value, and a test pins that reloading a file reproduces it exactly — a default applied inconsistently would make every save look like a controller change and tear down every channel. With controllers immutable after construction and replaced wholesale, the atomic pointers and Reload methods have no writers left, so they are gone and the pipes return to plain fields. notifyReload now serializes hook execution for the same reason: a hook mutates process-wide state, and two overlapping settings updates would otherwise each decide to rebuild from their own view of what was applied. Kept from that work: applyEmailProxy restores gomail's default dialer when networkUseProxy is turned off. The old constructor only ever installed the proxy dialer, so switching the flag back left SMTP tunnelled through a proxy with no way to undo it short of a restart. Documents the resulting behaviour in the README under "What applies without a restart".
82 lines
2.9 KiB
Go
82 lines
2.9 KiB
Go
package config
|
|
|
|
import (
|
|
"fmt"
|
|
"sync"
|
|
|
|
"nukumizu-backend/postLog"
|
|
)
|
|
|
|
// reloadHooks are the callbacks run after the global configuration has been
|
|
// reloaded, i.e. after every settings update that touches config.json.
|
|
//
|
|
// They exist so that packages which already depend on config — the controller
|
|
// manager, the logger — can react to an update without config importing them,
|
|
// which would be an import cycle. Everything a hook needs is passed in.
|
|
var (
|
|
reloadHooksMu sync.Mutex
|
|
reloadHooks []func(*Config)
|
|
|
|
// reloadRunMu serializes hook execution. A hook mutates process-wide state
|
|
// — the logger's debug flag, the controller registry — so two overlapping
|
|
// settings updates must not run them at the same time, or both would decide
|
|
// to rebuild the controllers from their own view of what was applied.
|
|
reloadRunMu sync.Mutex
|
|
)
|
|
|
|
// OnReload registers a hook to run after every reload of the global
|
|
// configuration, receiving the configuration now in effect. Hooks run in
|
|
// registration order.
|
|
//
|
|
// Register once, at startup, before the first settings update can arrive: a
|
|
// hook registered later has already missed the updates that came before it, and
|
|
// the configuration it would have seen is not replayed.
|
|
//
|
|
// A hook runs on the goroutine serving /api/settings/set, so it must not block
|
|
// for long. It may be called concurrently by two overlapping updates.
|
|
func OnReload(hook func(*Config)) {
|
|
reloadHooksMu.Lock()
|
|
defer reloadHooksMu.Unlock()
|
|
reloadHooks = append(reloadHooks, hook)
|
|
}
|
|
|
|
// notifyReload runs every registered hook with cfg. A nil cfg is the signal
|
|
// that the update touched one of the other settings files, which have no
|
|
// hook-visible reload, and it is ignored.
|
|
//
|
|
// A panicking hook is logged and skipped rather than allowed to unwind through
|
|
// UpdateSettings: by the time hooks run the new configuration is already on
|
|
// disk and published in memory, so reporting the write as failed would be a
|
|
// lie, and the hooks registered after the broken one must still run.
|
|
func notifyReload(cfg *Config) {
|
|
if cfg == nil {
|
|
return
|
|
}
|
|
|
|
// Copy under the registry lock, then release it before running anything: a
|
|
// hook is free to register another hook without deadlocking.
|
|
reloadHooksMu.Lock()
|
|
hooks := make([]func(*Config), len(reloadHooks))
|
|
copy(hooks, reloadHooks)
|
|
reloadHooksMu.Unlock()
|
|
|
|
reloadRunMu.Lock()
|
|
defer reloadRunMu.Unlock()
|
|
for _, hook := range hooks {
|
|
runReloadHook(hook, cfg)
|
|
}
|
|
}
|
|
|
|
// runReloadHook runs one hook, isolating a panic to that hook. Recovering in a
|
|
// separate function rather than inline is deliberate: a deferred recover placed
|
|
// in the loop body would not run until notifyReload itself returned, which
|
|
// would abandon the remaining hooks.
|
|
func runReloadHook(hook func(*Config), cfg *Config) {
|
|
defer func() {
|
|
if r := recover(); r != nil {
|
|
postLog.Error(fmt.Sprintf("Configuration reload hook panicked: %v", r))
|
|
}
|
|
}()
|
|
hook(cfg)
|
|
}
|