Skip to content

fix: plugin install context canceled by detaching from HTTP request c…#604

Open
IthacaDream wants to merge 1 commit intolanggenius:mainfrom
IthacaDream:fix/context-canceled-problem
Open

fix: plugin install context canceled by detaching from HTTP request c…#604
IthacaDream wants to merge 1 commit intolanggenius:mainfrom
IthacaDream:fix/context-canceled-problem

Conversation

@IthacaDream
Copy link

Fixes #603

Description

Summary

Plugin installation/upgrade runs asynchronously after returning a task ID, but previously reused the HTTP request context (c.Request.Context()). When the handler returned, the context was canceled, causing uv sync (started via exec.CommandContext) to fail with context canceled.

Changes

  • Detach background install/upgrade goroutines from request cancellation using context.WithoutCancel(ctx).
  • Preserve tracing context via log.EnsureTrace(...) for downstream spans/logs.

Type of Change

  • Bug fix
  • New feature
  • Refactor
  • Performance improvement
  • Other

Essential Checklist

Testing

  • I have tested the changes locally and confirmed they work as expected
  • I have added unit tests where necessary and they pass successfully

Bug Fix (if applicable)

  • I have used GitHub syntax to close the related issue (e.g., Fixes #123 or Closes #123)

Additional Information

Local plugin dependency installation (uv sync / uv pip install) no longer fails immediately due to premature context cancellation.

@dosubot dosubot bot added the size:XS This PR changes 0-9 lines, ignoring generated files. label Feb 7, 2026
@gemini-code-assist
Copy link
Contributor

Summary of Changes

Hello @IthacaDream, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request resolves a critical bug where asynchronous plugin installation and upgrade operations were prematurely terminated. Previously, these background tasks inherited the HTTP request's context, leading to cancellation once the request handler returned. The fix introduces a mechanism to create a new context that is not canceled with the HTTP request, ensuring that these long-running operations can complete successfully without interruption, thereby improving the reliability of plugin management.

Highlights

  • Context Cancellation Fix: Plugin installation and upgrade processes no longer fail prematurely due to the HTTP request context being canceled. Background goroutines are now detached from the request's cancellation signal.
  • Tracing Context Preservation: The tracing context is explicitly preserved for downstream spans and logs using log.EnsureTrace(...) when detaching the context.

🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Changelog
  • internal/service/install_plugin.go
    • Modified InstallMultiplePluginsToTenant to use context.WithoutCancel(log.EnsureTrace(ctx)) for the background plugin installation goroutines.
    • Modified UpgradePlugin to use context.WithoutCancel(log.EnsureTrace(ctx)) for the background plugin upgrade goroutine.
Activity
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@dosubot dosubot bot added bug Something isn't working plugin-daemon labels Feb 7, 2026
Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request addresses a critical bug where background plugin installation and upgrade tasks were prematurely canceled. While the fix correctly uses context.WithoutCancel to detach the background task's context, this approach introduces a risk of resource exhaustion. Detaching the context without applying a new timeout could lead to background tasks hanging indefinitely, potentially filling the routine pool and causing a Denial of Service for subsequent plugin operations. It is recommended to add a reasonable timeout to these detached contexts. Additionally, the use of log.EnsureTrace is a good addition for observability, and the changes are applied consistently in InstallMultiplePluginsToTenant and UpgradePlugin.

}
taskIDs := taskRegistry.IDs()

ctx = context.WithoutCancel(log.EnsureTrace(ctx))
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-medium medium

The use of context.WithoutCancel detaches the background task from the request context, which is intended to prevent premature cancellation. However, it also removes any timeouts associated with the original context. Without a new timeout, background tasks (which may involve long-running external commands like uv sync) could hang indefinitely, potentially exhausting the routine pool and leading to a Denial of Service (DoS). Consider applying a reasonable timeout to the detached context.

}

taskIDs := taskRegistry.IDs()
ctx = context.WithoutCancel(log.EnsureTrace(ctx))
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-medium medium

Similar to the issue in InstallMultiplePluginsToTenant, detaching the context here without adding a new timeout could lead to hanging background tasks and resource exhaustion in the routine pool.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working plugin-daemon size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Plugin install fails with context canceled because HTTP request context is used in background goroutine

1 participant