Skip to content

fixes for --no-buckd - #280

Closed
martinpitt wants to merge 4 commits into
amutable-systems:mainfrom
martinpitt:tine-exec
Closed

martinpitt wants to merge 4 commits into
amutable-systems:mainfrom
martinpitt:tine-exec

Conversation

@martinpitt

@martinpitt martinpitt commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

I am currently experimenting with --no-buckd mode. This is currently broken, and buck itself needs some fixes for that which we need to pull into our fork if we want to go ahead with this: facebook/buck2#1551

This series fixes a conceptual problem with long-running processes through buck run, see the individual commits for details. We don't really need that if we decide to keep daemon mode, but OTOH this is relatively small and conceptually nice anyway.

With this series, I can patch ci.sh to always use daemon-less mode, I had a watch pgrep -af [b]uck2d running in parallel:

--- tools/ci.sh
+++ tools/ci.sh
@@ -6,7 +6,7 @@
 # The full CI pipeline. Arguments select groups, e.g. `tools/ci.sh check build`
 set -Eeuo pipefail
 cd "$(dirname "$0")/.."
-buck=(bin/tine buck)
+buck=(bin/tine buck --no-buckd)
 only_groups=("$@")
 
 # GitHub folds each group into a log group; an interactive terminal gets a bold banner; anything else
@@ -134,7 +134,7 @@ secureboot_pkcs11() {
     "${buck[@]}" build tine//tools:swtpm-signing.box
 
     pkcs11_dir=$(mktemp -d)
-    bin/tine exec tine//tools:signing-server -- "$pkcs11_dir" > "$pkcs11_dir/log" 2>&1 &
+    bin/tine exec tine//tools:signing-server --no-buckd -- "$pkcs11_dir" > "$pkcs11_dir/log" 2>&1 &
     server_pid=$!
     trap pkcs11_cleanup EXIT
     until [ -S "$pkcs11_dir/sock/pkcs11" ]; do
@@ -204,4 +204,4 @@ group build             -- whole_cell build
 group image-tests       -- whole_cell test --include image "${vm_filter[@]}"
 group secureboot-pkcs11 -- secureboot_pkcs11
 # The shared cache with a real Buck on both ends; in its own isolation dir.
-group remote-cache      -- "${buck[@]}" run tine//tests:cache-roundtrip
+#group remote-cache      -- "${buck[@]}" run tine//tests:cache-roundtrip

This needs the patched buck from the above PR. I built that locally and told tine to use it:

❱❱❱ cat tine.local.toml 
[buck2.platforms.Linux-x86_64]
sha256 = "b532412119f41dff0d35bd618cbf6d6036f5d2345003ef48b0bc3bbc66289e5f"

(note that this breaks the remote-cache test group, as that wants to write its own tine.local.toml).

I had claude research how much it would cost to use daemon-less mode by default, and how much we can lose in both tine and our buck2 fork. My main motivation is to drop the inotify shenanigans, which are a gift that keeps on giving. The detailed plan: plan-tine-daemonless.md

TL/DR:

  • -700 lines in our buck fork (all the inotify patches), but + ~ 50 to add a "null" file watcher which --no-buckd would use by default.
  • biggest caveat: parallel bin/tine build invocations break. What the daemon does is to serialize these requests, with daemonless they'd step on each other, so tine needs to do the locking itself (flock on buck-out).
  • tine.py would not be a net shrinkage: we can lose a few dozen lines of daemon management, but the flock stuff brings back about an equal amount.
  • the main advantage is robustness with dropping inotify, the tine complexity does not really change.

Verdict/personal recommendation: this PR is cheap enough that we should land it to make --no-buckd functional for people who use it explicitly. Going the full way is not the big win that we hoped for, but might still be worth it to avoid the trouble we ran into yesterday with Rodrigo. Let's discuss it, but not do it in a whim.

A verb that needs a ready Buck without handing the process over to it
has no entry point: everything from the cache shim to the config refresh
lived inline in `buck_command()`. Move the preparation into
`setup_buck()`.

Signed-off-by: Martin Pitt <martin@amutable.com>
A service started as `buck run <target> &` keeps a Buck client alive for
its whole runtime. With `--no-buckd` the client is also the daemon. No
later Buck command may coexist with that, as it will kill the previous
one. The actual command that runs does not actually *need* the buck client
nor daemon: every piece is a plain buck-out artifact. Also, a signal to
the job will hit the buck client instead of the target command.

Introduce `tine exec` for such long-lived background services, which
avoids both issues: it asks Buck for the run command line with
`--emit-shell` and execs it, so the process owns its pid and Buck is
gone once the build is.

Signed-off-by: Martin Pitt <martin@amutable.com>
`tine box` is one case of a long-lived/indefinite target process which
held a Buck client open for the whole box session. Reimplement it using
the new `exec` mechanism. Same command, same arguments, but the box owns
its pid and Buck exits after the build.

Signed-off-by: Martin Pitt <martin@amutable.com>
The backgrounded `buck run` kept a Buck client as the server's pid for
the whole group, which broke running with `--no-buckd`. Move it to our
new `exec` mechanism.

Signed-off-by: Martin Pitt <martin@amutable.com>
@martinpitt
martinpitt marked this pull request as draft October 9, 2026 08:10
@martinpitt

Copy link
Copy Markdown
Member Author

facebook/buck2#1551 updated. With that, we don't need this any more.

@martinpitt martinpitt closed this Oct 9, 2026
@martinpitt
martinpitt deleted the tine-exec branch October 9, 2026 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant