modernuo/Projects/Server/Console/ConsoleInputPump.cs
Kamron Batman 7434ed7ee1
fix(console): stop headless servers from pegging a CPU core (#2535)
## Problem

On headless Linux deployments (systemd service, Docker without a TTY, `nohup`), the ModernUO process pegs a full CPU core even when idle. It does not reproduce on Windows because that runs with an interactive console.

## Root cause

`ConsoleInputHandler` runs a background thread (named "Console Input Handler") that loops on `Console.ReadLine()`. When stdin is **not** an interactive terminal, `Console.ReadLine()` returns `null` at end-of-stream **immediately** on every call, so the loop `continue`s in a tight spin — one core at 100%.

Reproduced in a container running the actual distribution: the "Console Input Handler" thread sat at ~90% CPU on a headless boot; with a blocking stdin it dropped to idle.

## Fix

1. **Detect headless once at startup:** `Core.Headless = Console.IsInputRedirected`.
2. **Extract a testable `ConsoleInputPump`** that owns the input stream: per line read, it *atomically* (under one lock) either delivers the line to a waiting prompt or dispatches a console command, and it **ends on EOF instead of spinning**. Cleanup runs unconditionally in a `finally`, so a pending prompt is always released (never hangs). Replaces the old `async void` loop and the fragile `_expectUserInput` / two-`AutoResetEvent` / `_input` handshake.
3. **`ConsoleInputHandler` becomes a thin headless-aware facade** over the pump. Headless: the reader thread never starts (`Console input disabled (headless: stdin is not a TTY).`), and `ReadLine()` throws a fatal `HeadlessConsoleInputException`.
4. **Data-gating and first-boot prompts** (deserialization "delete bad types? y/n", save-conflict, config/expansion setup) now route through `ConsoleInputHandler.ReadLine()`, so a headless server crashes fatal with a clear message instead of reading `null` (previously an NRE or a silent wrong branch).

Design decision (model b): headless servers are expected to be supplied with configuration/save data (including the owner account); interactive prompts when headless are fatal by design.

## Testing

- New `ConsoleInputPumpTests` (5 tests): EOF ends the loop without spinning; command dispatch; a pending prompt receives the next line; EOF while a prompt is pending completes it with `null` (no hang); a throwing command lookup does not hang a pending prompt. The tests synchronize on real pump state (no `Thread.Sleep`), so they are deterministic on slow CI.
- Full `Server.Tests`: no new failures introduced.

## End-to-end verification (Docker, real distribution)

| | Console Input Handler thread | Container CPU |
|---|---|---|
| Before fix (headless boot) | ~90% | ~199% (2 cores) |
| After fix (headless boot) | **not started** | **~11%** |

After the fix, a headless boot logs `Console input disabled (headless: stdin is not a TTY).`, loads the world normally, and idles instead of spinning.
2026-07-16 18:52:43 -07:00

162 lines
4.8 KiB
C#

using System;
using System.IO;
using System.Threading;
using Server.Logging;
namespace Server;
/// <summary>
/// Owns a console input stream. Each line read is atomically either delivered to a
/// waiting <see cref="ReadLine"/> caller (a prompt) or dispatched as a command via the
/// supplied lookup. EOF ends the loop instead of spinning. Correct-by-construction:
/// the prompt-vs-command decision is made under a single lock at the moment a line is read.
/// Command handlers dispatched by <see cref="Run"/> execute on the reader thread and
/// must never call <see cref="ReadLine"/> — doing so would deadlock the pump (the reader
/// thread would be blocked waiting on itself to read the next line).
/// </summary>
internal sealed class ConsoleInputPump
{
private readonly TextReader _input;
private readonly Func<string, Action<string>> _lookup;
private readonly Server.Logging.ILogger _logger;
private readonly Lock _gate = new();
private readonly AutoResetEvent _promptDelivered = new(false);
private bool _promptPending;
private string _promptResult;
private volatile bool _running = true;
public ConsoleInputPump(TextReader input, Func<string, Action<string>> lookup, Server.Logging.ILogger logger = null)
{
_input = input ?? throw new ArgumentNullException(nameof(input));
_lookup = lookup ?? throw new ArgumentNullException(nameof(lookup));
_logger = logger;
}
public bool Running => _running;
// Test-observable: true while a ReadLine() caller is registered and waiting for the
// next line. Lets tests synchronize on the rendezvous state instead of sleeping.
internal bool HasPendingPrompt
{
get
{
lock (_gate)
{
return _promptPending;
}
}
}
public void Run()
{
try
{
while (_running && !Core.Closing)
{
string line;
try
{
line = _input.ReadLine();
}
catch
{
_logger?.Warning("Console commands have been disabled due to an error.");
break;
}
if (line == null)
{
break; // EOF — never spin
}
bool isCommand;
lock (_gate)
{
if (_promptPending)
{
_promptResult = line;
_promptPending = false;
_promptDelivered.Set();
isCommand = false;
}
else
{
isCommand = true;
}
}
if (!isCommand)
{
continue;
}
var trimmed = line.Trim();
if (trimmed.Length == 0)
{
continue;
}
var split = trimmed.Split(' ', 2);
try
{
var action = _lookup(split[0].ToLower());
action?.Invoke(split.Length > 1 ? split[1] : string.Empty);
}
catch (Exception e)
{
_logger?.Error(e, "Failed to execute console command: {Command}", line);
}
}
}
finally
{
_running = false;
ReleasePendingPrompt(null);
}
}
/// <summary>
/// Blocks the calling thread until the next console line is available, or until the
/// pump stops (returning <c>null</c>). Intended for a single, sequential caller at a
/// time — ModernUO's console prompts run one after another during startup/steps.
/// Concurrent callers are not supported: a second caller overlapping with a pending
/// prompt will race with it for the next line. Must not be called from the reader
/// thread (i.e. from within a command handler dispatched by <see cref="Run"/>), as
/// that would deadlock the pump.
/// </summary>
public string ReadLine()
{
lock (_gate)
{
if (!_running)
{
return null;
}
_promptResult = null;
_promptPending = true;
}
_promptDelivered.WaitOne();
lock (_gate)
{
return _promptResult;
}
}
private void ReleasePendingPrompt(string result)
{
lock (_gate)
{
if (_promptPending)
{
_promptResult = result;
_promptPending = false;
_promptDelivered.Set();
}
}
}
}