Expand description
POSIX shared-memory helpers — V1 substrate for cross-process rings.
Wraps shm_open / ftruncate / mmap / munmap / shm_unlink
into a small, RAII-friendly API. Unix-only; Windows support is
a separate concern (Win32 named file mapping) that can land later.
§Naming
Segments are named /orbit-{fleet}-{kind}-{uid} — fleet name from
the embedder, KIND from OrbitTyped::KIND, UID from geteuid().
UID-scoping avoids the /dev/shm sticky-bit cross-user collision
problem (a stale segment owned by one user blocks another from
shm_unlink-ing it on next boot).
Rings that require a process-recoverable writer lock also open a
companion orbit-{fleet}-{kind}-{uid}.lock file. It carries no
ring data or state; it only supplies a regular-file inode for flock,
because advisory locking on a POSIX SHM descriptor is not uniformly
supported across the Unix targets Orbit serves. An unlocked stale
companion file is safe to reuse.
Those files live in a per-uid directory — $XDG_RUNTIME_DIR/orbit-{uid}
where the session provides one, /tmp/orbit-{uid} otherwise — created
0700 and checked on every lock. They were once in /tmp directly, which
made them squattable: see [lock_dir].
§Lifetime
ShmRegion owns the mapped pointer and unmaps on drop. It does
NOT shm_unlink on drop — the segment lives until an explicit
ShmRegion::unlink call. This matches POSIX convention: a
segment with mapped users is not removed; shm_unlink only
prevents new opens, the current mapping stays valid until the
last process unmaps.
Structs§
- Fleet
Membership - A process’s membership in a fleet: a shared
flockon the fleet’s lock file, held for as long as this lives and released by the kernel when the process dies, however it dies. It is whattry_lock_fleet_exclusivecontends with, so a tool that removes the fleet’s segments cannot do so while any member is alive. - ShmRegion
- A mapped POSIX SHM region. Drop unmaps;
unlinkremoves the underlying name and any companion lock file (only the creator should call it on shutdown). - ShmRegion
Lock - RAII guard for a
ShmRegion’s process-recoverable exclusive lock.
Enums§
- ShmValidation
- Result of physically validating an existing POSIX SHM object.
Constants§
- SHM_
NAMESPACE - Namespace used by Orbit POSIX shared-memory objects.
Functions§
- fleet_
lock_ path - Where a fleet’s members hold their presence:
<lock dir>/orbit-<fleet>.fleet. - fleet_
lock_ path_ for_ uid - The same for another user’s fleet, for lifecycle tools that address a uid other than their own.
- join_
fleet_ membership - Join the fleet’s membership. Waits for a lifecycle tool that holds the exclusive lock at that moment; a clear in progress finishes first.
- ring_
segment_ name - Build the conventional name for an Orbit ring segment.
- ring_
segment_ name_ for_ uid - Build the conventional name for an Orbit ring segment owned by
uid. - try_
lock_ fleet_ exclusive - Exclusive hold on a fleet, for the tool that removes its segments.