Skip to main content

sqlite_graphrag/
llm_slots.rs

1//! GAP-004 (v1.0.82): cross-process semaphore for spawning LLM subprocesses.
2//!
3//! When N Claude Code sessions run in parallel on the same host, each `remember`/`edit`/
4//! `recall`/`hybrid-search`/`enrich`/`deep-research`/`ingest` wants to spawn its own
5//! `codex exec` or `claude -p` subprocess. Without coordination, N subprocesses saturate
6//! the shared OAuth rate limit (observed: 19+ concurrent codex in the transcript
7//! of 2026-06-15).
8//!
9//! ## Solution
10//! - Slot files at `${XDG_RUNTIME_DIR:-~/.local/share}/sqlite-graphrag/llm-slots/slot-{0..N}.lock`
11//! - `fs4::FileExt::try_lock_exclusive` for atomic cross-process acquire (fcntl on Unix,
12//!   LockFileEx on Windows — `fs4` 0.9 with trustScore 9.6 confirmed via context7)
13//! - RAII guard `LlmSlotGuard` with `Drop` releases automatically on panic
14//! - Integration with `reaper.rs::scan_and_kill_orphans` to detect orphaned slots
15//!
16//! ## Usage
17//! ```rust,ignore
18//! use crate::llm_slots::acquire_llm_slot;
19//!
20//! let _guard = acquire_llm_slot(4, 30)?;
21//! // ... spawn LLM subprocess ...
22//! // the guard releases the slot automatically when it leaves scope
23//! ```
24
25use fs4::fs_std::FileExt;
26use std::fs::{self, File, OpenOptions};
27use std::path::PathBuf;
28use std::time::{Duration, Instant};
29
30use crate::errors::AppError;
31
32/// RAII guard that releases the slot automatically on panic, abrupt cancellation,
33/// or normal scope exit.
34pub struct LlmSlotGuard {
35    #[allow(dead_code)]
36    slot_file: File,
37    slot_id: u32,
38    acquired_at: Instant,
39}
40
41impl LlmSlotGuard {
42    /// Returns the slot id (0..max-1) this guard holds. Used by
43    /// `slots release --slot-id N` to map back to the file path.
44    pub fn slot_id(&self) -> u32 {
45        self.slot_id
46    }
47}
48
49impl Drop for LlmSlotGuard {
50    fn drop(&mut self) {
51        // Libera o lock do filesystem E remove o slot file.
52        // The flock is released automatically when `slot_file` is dropped (RAII).
53        let path = slot_path(self.slot_id);
54        if let Err(e) = fs::remove_file(&path) {
55            tracing::debug!(slot_id = self.slot_id, error = %e, "slot file removal failed (already gone?)");
56        }
57        tracing::debug!(
58            slot_id = self.slot_id,
59            held_ms = self.acquired_at.elapsed().as_millis() as u64,
60            "llm slot released"
61        );
62    }
63}
64
65/// Acquires a free LLM slot, waiting up to `wait_secs` seconds.
66///
67/// Iterates over `slot_id` in `[0, max_concurrent)` and tries `create_new` + `try_lock_exclusive`.
68/// If all slots are busy, polls with `sleep(100ms)` until `wait_secs` expires.
69///
70/// ## Errors
71/// - `AppError::LockBusy` (exit 75) if `wait_secs` expires without a free slot
72/// - `AppError::Io` if the filesystem fails
73pub fn acquire_llm_slot(max_concurrent: u32, wait_secs: u64) -> Result<LlmSlotGuard, AppError> {
74    if max_concurrent == 0 {
75        return Err(AppError::Validation(
76            "max_concurrent deve ser >= 1 para acquire_llm_slot".to_string(),
77        ));
78    }
79    let dir = slots_dir();
80    fs::create_dir_all(&dir).map_err(|e| {
81        AppError::Io(std::io::Error::new(
82            e.kind(),
83            format!("failed to create slots dir {}: {e}", dir.display()),
84        ))
85    })?;
86
87    let stale = find_stale_slots(max_concurrent);
88    for slot_id in &stale {
89        let _ = force_release(*slot_id);
90        tracing::info!(slot_id, "released stale LLM slot (PID dead)");
91    }
92
93    let start = Instant::now();
94    let timeout = Duration::from_secs(wait_secs);
95
96    loop {
97        for slot_id in 0..max_concurrent {
98            let path = slot_path(slot_id);
99            match OpenOptions::new().write(true).create_new(true).open(&path) {
100                Ok(mut file) => {
101                    if file.try_lock_exclusive().is_ok() {
102                        let pid = std::process::id();
103                        // Write pid into the file so diagnostics can report the holder
104                        use std::io::Write;
105                        let _ = writeln!(file, "pid={pid}");
106                        tracing::debug!(slot_id, pid, "llm slot acquired");
107                        return Ok(LlmSlotGuard {
108                            slot_file: file,
109                            slot_id,
110                            acquired_at: Instant::now(),
111                        });
112                    }
113                    // Slot file existe mas está locked por outro processo
114                }
115                Err(_) => {
116                    // Slot file já existe (race condition rara) — tenta próximo
117                }
118            }
119        }
120        // All slots busy — polling
121        if start.elapsed() >= timeout {
122            return Err(AppError::LockBusy(format!(
123                "failed to acquire LLM slot within {wait_secs}s (max={max_concurrent} concurrent)"
124            )));
125        }
126        std::thread::sleep(Duration::from_millis(100));
127    }
128}
129
130/// Returns the current status of the LLM slots (for the `slots status --json` subcommand).
131#[derive(Debug, Clone, serde::Serialize)]
132pub struct SlotStatus {
133    /// Max.
134    pub max: u32,
135    /// Active.
136    pub active: u32,
137    /// Pids.
138    pub pids: Vec<u32>,
139}
140
141/// Read status.
142pub fn read_status(max_concurrent: u32) -> SlotStatus {
143    let mut active = 0u32;
144    let mut pids = Vec::new();
145    for slot_id in 0..max_concurrent {
146        let path = slot_path(slot_id);
147        if path.exists() {
148            active += 1;
149            if let Ok(content) = fs::read_to_string(&path) {
150                if let Some(pid_line) = content.lines().find(|l| l.starts_with("pid=")) {
151                    if let Ok(pid) = pid_line[4..].parse::<u32>() {
152                        pids.push(pid);
153                    }
154                }
155            }
156        }
157    }
158    SlotStatus {
159        max: max_concurrent,
160        active,
161        pids,
162    }
163}
164
165/// Releases a specific slot (for the `slots release --slot-id N --yes` subcommand).
166pub fn force_release(slot_id: u32) -> Result<(), AppError> {
167    let path = slot_path(slot_id);
168    if path.exists() {
169        fs::remove_file(&path).map_err(|e| {
170            AppError::Io(std::io::Error::new(
171                e.kind(),
172                format!("failed to release slot {slot_id}: {e}"),
173            ))
174        })?;
175    }
176    Ok(())
177}
178
179/// Lists stale slot IDs (orphaned PIDs) — for automatic cleanup.
180pub fn find_stale_slots(max_concurrent: u32) -> Vec<u32> {
181    let mut stale = Vec::new();
182    for slot_id in 0..max_concurrent {
183        let path = slot_path(slot_id);
184        if path.exists() {
185            if let Ok(content) = fs::read_to_string(&path) {
186                if let Some(pid_line) = content.lines().find(|l| l.starts_with("pid=")) {
187                    if let Ok(pid) = pid_line[4..].parse::<u32>() {
188                        if !pid_alive(pid) {
189                            stale.push(slot_id);
190                        }
191                    }
192                }
193            }
194        }
195    }
196    stale
197}
198
199/// Checks whether a PID is alive on the system (best-effort cross-platform).
200#[cfg(unix)]
201fn pid_alive(pid: u32) -> bool {
202    // Try signal 0 (no-op) to check process existence
203    unsafe { libc::kill(pid as i32, 0) == 0 }
204}
205
206#[cfg(not(unix))]
207fn pid_alive(pid: u32) -> bool {
208    // No Windows, sem equivalente direto; assume vivo se arquivo existe.
209    // Cleanup manual via `slots cleanup --yes` é a via.
210    let _ = pid;
211    true
212}
213
214/// Slots dir.
215pub fn slots_dir() -> PathBuf {
216    // GAP-SG-94: never hardcode "/tmp". Prefer XDG runtime, then the shared
217    // cache resolver (same root as lock files), then the OS temp directory.
218    if let Ok(runtime) = std::env::var("XDG_RUNTIME_DIR") {
219        if !runtime.is_empty() {
220            return PathBuf::from(runtime).join("sqlite-graphrag/llm-slots");
221        }
222    }
223    if let Ok(Some(cache)) = crate::config::get_setting("cache.dir") {
224        if !cache.is_empty() {
225            return PathBuf::from(cache).join("llm-slots");
226        }
227    }
228    // `paths::cache_dir` returns Result; fall back to OS temp on failure.
229    match crate::paths::cache_dir() {
230        Ok(cache) => cache.join("llm-slots"),
231        Err(_) => std::env::temp_dir().join("sqlite-graphrag/llm-slots"),
232    }
233}
234
235/// Slot path.
236pub fn slot_path(id: u32) -> PathBuf {
237    slots_dir().join(format!("slot-{id}.lock"))
238}
239
240/// Resolves the default LLM max-host-concurrency value.
241///
242/// Calibrated for the LLM-only build: each worker holds one subprocess
243/// `codex` or `claude` invocation. The formula mirrors the CLI semaphore
244/// in `lock::calculate_safe_concurrency`:
245///   `min(ncpus, available_memory_mb / LLM_WORKER_RSS_MB)`
246///
247/// Falls back to `MAX_CONCURRENT_CLI_INSTANCES` (16) when `sysinfo`
248/// cannot read `/proc/meminfo` (rare).
249pub fn default_max_concurrency() -> u32 {
250    let cpus = std::thread::available_parallelism()
251        .map(|n| n.get() as u32)
252        .unwrap_or(4);
253    // Without `sysinfo` at hand here, we use a conservative memory
254    // estimate: 4 GiB available on most hosts. The CLI semaphore in
255    // `lock::calculate_safe_concurrency` is the source of truth when
256    // exact memory data is available; this fallback just keeps the
257    // LLM slot default in the same order of magnitude.
258    let assumed_available_mb: u32 = 4096;
259    let per_worker = crate::constants::LLM_WORKER_RSS_MB as u32;
260    let safe = assumed_available_mb / per_worker.max(1);
261    let capped = safe.min(crate::constants::MAX_CONCURRENT_CLI_INSTANCES as u32);
262    cpus.min(capped).max(1)
263}
264
265#[cfg(test)]
266mod tests {
267    use super::*;
268    use std::sync::Arc;
269    use std::sync::Barrier;
270    use std::thread;
271
272    // Serialises every test that mutates the process-global slot env
273    // (XDG_RUNTIME_DIR / --cache-dir / cache.dir). Without this, parallel
274    // tests clobber each other's env and collide in the same slots dir.
275    static SLOT_TEST_LOCK: std::sync::Mutex<()> = std::sync::Mutex::new(());
276
277    fn unique_test_dir() -> PathBuf {
278        let mut dir = std::env::temp_dir();
279        dir.push(format!(
280            "llm-slots-test-{}-{}",
281            std::process::id(),
282            std::time::SystemTime::now()
283                .duration_since(std::time::UNIX_EPOCH)
284                .unwrap()
285                .as_nanos()
286        ));
287        dir
288    }
289
290    fn isolate_slots_env() -> (Option<String>, Option<String>) {
291        let orig_xdg = std::env::var("XDG_RUNTIME_DIR").ok();
292        // Use unique XDG_RUNTIME_DIR so slots do not collide (no product env).
293        std::env::set_var("XDG_RUNTIME_DIR", unique_test_dir());
294        (orig_xdg, None)
295    }
296
297    fn restore_slots_env(orig_xdg: Option<String>, _orig_cache: Option<String>) {
298        match orig_xdg {
299            Some(v) => std::env::set_var("XDG_RUNTIME_DIR", v),
300            None => std::env::remove_var("XDG_RUNTIME_DIR"),
301        }
302    }
303
304    #[test]
305    fn slot_enforces_max_concurrency() {
306        let _serial = SLOT_TEST_LOCK.lock().unwrap_or_else(|e| e.into_inner());
307        let (orig_xdg, orig_cache) = isolate_slots_env();
308
309        let _g1 = acquire_llm_slot(2, 5).expect("first slot");
310        let _g2 = acquire_llm_slot(2, 5).expect("second slot");
311        let start = std::time::Instant::now();
312        let result = acquire_llm_slot(2, 1);
313        assert!(result.is_err(), "third slot should fail with max=2");
314        assert!(
315            start.elapsed() >= std::time::Duration::from_secs(1),
316            "should wait full timeout before failing"
317        );
318
319        restore_slots_env(orig_xdg, orig_cache);
320    }
321
322    #[test]
323    fn slot_releases_on_drop() {
324        let _serial = SLOT_TEST_LOCK.lock().unwrap_or_else(|e| e.into_inner());
325        let (orig_xdg, orig_cache) = isolate_slots_env();
326
327        let g1 = acquire_llm_slot(1, 5).expect("first slot");
328        drop(g1);
329        let _g2 = acquire_llm_slot(1, 5).expect("second slot after drop");
330
331        restore_slots_env(orig_xdg, orig_cache);
332    }
333
334    #[test]
335    fn slot_max_concurrent_zero_is_validation_error() {
336        let result = acquire_llm_slot(0, 1);
337        assert!(matches!(result, Err(AppError::Validation(_))));
338    }
339
340    #[test]
341    fn read_status_reflects_active_slots() {
342        let _serial = SLOT_TEST_LOCK.lock().unwrap_or_else(|e| e.into_inner());
343        let (orig_xdg, orig_cache) = isolate_slots_env();
344
345        let _g1 = acquire_llm_slot(4, 5).expect("first slot");
346        let status = read_status(4);
347        assert_eq!(status.max, 4);
348        assert!(status.active >= 1);
349        assert!(!status.pids.is_empty());
350
351        restore_slots_env(orig_xdg, orig_cache);
352    }
353
354    #[test]
355    fn concurrent_acquires_with_2_threads_serialize() {
356        let _serial = SLOT_TEST_LOCK.lock().unwrap_or_else(|e| e.into_inner());
357        let (orig_xdg, orig_cache) = isolate_slots_env();
358
359        let barrier = Arc::new(Barrier::new(3));
360        let mut handles = vec![];
361        for _ in 0..3 {
362            let b = barrier.clone();
363            handles.push(thread::spawn(move || {
364                b.wait();
365                acquire_llm_slot(2, 5)
366            }));
367        }
368        let results: Vec<_> = handles.into_iter().map(|h| h.join().unwrap()).collect();
369        let successes = results.iter().filter(|r| r.is_ok()).count();
370        // max=2 → no máximo 2 succeeds simultâneos (mas teste serializa)
371        assert!(successes >= 1);
372
373        restore_slots_env(orig_xdg, orig_cache);
374    }
375}