grpc: apply the config selector only after the LB policy is updated (#9442)

Per [gRFC
A31](https://github.com/grpc/proposal/blob/master/A31-xds-timeout-support-and-config-selector.md#implementation-for-xds-routeaction-support:~:text=When%20new%20clusters,INTERNAL%20status%20code.),
the channel must update its LB policy before applying a new config
selector, and the LB policy must synchronously provide a new picker
before its update method returns. This ordering guarantees that a config
selector never routes an RPC to a cluster unknown to the current picker.

This PR updates the channel to apply the config selector only after
`updateClientConnState` returns. Because `updateClientConnState` blocks
until the LB policy finishes processing the state update—and
`xds_cluster_manager` produces its new picker before returning—the new
picker is guaranteed to be in place first.

The config selector is then applied while holding `cc.mu`, and the
update is skipped if the channel closed or entered idle mode while the
lock was released. This preserves two invariants:
- The selector reset in `Close()` remains the final write.
- A stale update cannot overwrite the selector installed by a new
resolver after the channel exits idle mode.

Consistent with existing LB policy updates, this relies on the
(undocumented) guarantee that resolvers do not invoke `UpdateState`
concurrently, as overlapping calls could still apply config selectors
out of order.

RELEASE NOTES: 
* xds: Fix a race where RPCs could fail with `UNAVAILABLE: unknown
cluster selected for RPC` right after an xDS route configuration update
started sending traffic to a new cluster.
2 files changed
tree: 95677da8ece27f701b295d6579514e0d0183f559
  1. .gemini/
  2. .github/
  3. admin/
  4. attributes/
  5. authz/
  6. backoff/
  7. balancer/
  8. benchmark/
  9. binarylog/
  10. channelz/
  11. cmd/
  12. codes/
  13. connectivity/
  14. credentials/
  15. Documentation/
  16. encoding/
  17. examples/
  18. experimental/
  19. gcp/
  20. grpclog/
  21. health/
  22. internal/
  23. interop/
  24. keepalive/
  25. mem/
  26. metadata/
  27. orca/
  28. peer/
  29. profiling/
  30. reflection/
  31. resolver/
  32. scripts/
  33. security/
  34. serviceconfig/
  35. stats/
  36. status/
  37. tap/
  38. test/
  39. testdata/
  40. xds/
  41. AUTHORS
  42. backoff.go
  43. balancer_wrapper.go
  44. balancer_wrapper_test.go
  45. call.go
  46. clientconn.go
  47. clientconn_authority_test.go
  48. clientconn_disconnect_reason_noplan9.go
  49. clientconn_disconnect_reason_plan9.go
  50. clientconn_parsed_target_test.go
  51. clientconn_test.go
  52. CODE-OF-CONDUCT.md
  53. codec.go
  54. codec_test.go
  55. CONTRIBUTING.md
  56. default_dial_option_server_option_test.go
  57. dial_test.go
  58. dialoptions.go
  59. doc.go
  60. go.mod
  61. go.sum
  62. GOVERNANCE.md
  63. grpc_test.go
  64. interceptor.go
  65. LICENSE
  66. MAINTAINERS.md
  67. Makefile
  68. NOTICE.txt
  69. picker_wrapper.go
  70. picker_wrapper_test.go
  71. preloader.go
  72. producer_ext_test.go
  73. README.md
  74. resolver_balancer_ext_test.go
  75. resolver_test.go
  76. resolver_wrapper.go
  77. rpc_util.go
  78. rpc_util_test.go
  79. SECURITY.md
  80. server.go
  81. server_ext_test.go
  82. server_test.go
  83. service_config.go
  84. service_config_test.go
  85. stream.go
  86. stream_interfaces.go
  87. stream_test.go
  88. trace.go
  89. trace_notrace.go
  90. trace_test.go
  91. trace_withtrace.go
  92. version.go
README.md

gRPC-Go

GoDoc GoReportCard codecov

The Go implementation of gRPC: A high performance, open source, general RPC framework that puts mobile and HTTP/2 first. For more information see the Go gRPC docs, or jump directly into the quick start.

Prerequisites

Installation

Simply add the following import to your code, and then go [build|run|test] will automatically fetch the necessary dependencies:

import "google.golang.org/grpc"

Note: If you are trying to access grpc-go from China, see the FAQ below.

Learn more

FAQ

I/O Timeout Errors

The golang.org domain may be blocked from some countries. go get usually produces an error like the following when this happens:

$ go get -u google.golang.org/grpc
package google.golang.org/grpc: unrecognized import path "google.golang.org/grpc" (https fetch: Get https://google.golang.org/grpc?go-get=1: dial tcp 216.239.37.1:443: i/o timeout)

To build Go code, there are several options:

  • Set up a VPN and access google.golang.org through that.

  • With Go module support: it is possible to use the replace feature of go mod to create aliases for golang.org packages. In your project's directory:

    go mod edit -replace=google.golang.org/grpc=github.com/grpc/grpc-go@latest
    go mod tidy
    go mod vendor
    go build -mod=vendor
    

    Again, this will need to be done for all transitive dependencies hosted on golang.org as well. For details, refer to golang/go issue #28652.

Compiling error, undefined: grpc.SupportPackageIsVersion

Please update to the latest version of gRPC-Go using go get google.golang.org/grpc.

How to turn on logging

The default logger is controlled by environment variables. Turn everything on like this:

$ export GRPC_GO_LOG_VERBOSITY_LEVEL=99
$ export GRPC_GO_LOG_SEVERITY_LEVEL=info

The RPC failed with error "code = Unavailable desc = transport is closing"

This error means the connection the RPC is using was closed, and there are many possible reasons, including:

  1. mis-configured transport credentials, connection failed on handshaking
  2. bytes disrupted, possibly by a proxy in between
  3. server shutdown
  4. Keepalive parameters caused connection shutdown, for example if you have configured your server to terminate connections regularly to trigger DNS lookups. If this is the case, you may want to increase your MaxConnectionAgeGrace, to allow longer RPC calls to finish.

It can be tricky to debug this because the error happens on the client side but the root cause of the connection being closed is on the server side. Turn on logging on both client and server, and see if there are any transport errors.