ntf: stop a managed server's fatal from exiting the service - #87
Conversation
Managed server ports now come from a configurable range below the OS ephemeral range, and a create that loses a port to another program is retried with fresh ports. Signed-off-by: R.I.Pienaar <rip@devco.net>
|
Claude finished @ripienaar's task in 2m 55s —— View job Review of PR #87 complete
Summary: Traced the retry/rollback and port-reservation logic end to end ( Left two non-blocking observations as inline comments and a summary comment:
|
Review summaryTraced the retry/rollback and port-reservation paths (
Two non-blocking points left as inline comments:
No security or correctness blockers found. |
Managed server ports now come from a configurable range below the OS ephemeral range, and a create that loses a port to another program is retried with fresh ports.
Each managed server logs to its own file, and that logger's Fatalf calls os.Exit, so one managed server failing to bind a port killed the whole service with nothing on its console. Managed servers now log through a wrapper whose Fatalf writes to server.log and the service log, records the error and returns, so the create fails and the service stays up.