fix(session): confirm routed delivery and keep playback state with the owner

This commit is contained in:
2026-09-26 14:45:40 +10:00
parent 086fdb8257
commit 611bcf2c4a
17 changed files with 1068 additions and 216 deletions
@@ -15,28 +15,32 @@ namespace Emby.Server.Implementations.Session;
/// <summary>
/// A Redis-backed <see cref="ISessionDirectory"/>. A session is owned by the instance holding its
/// connection: ownership is claimed through a check-and-set, so an instance that only served a request
/// for the session cannot take it from the instance the device is actually connected to. Each entry is a
/// key with an expiry, so the sessions of an instance that stops refreshing them disappear on their own.
/// connection: ownership is claimed through a check-and-set against a connection epoch handed out by
/// Redis, so an instance that only served a request for the session cannot take it from the instance the
/// device is actually connected to, and no instance's clock is compared against another's. Each entry is
/// a key with an expiry, so the sessions of an instance that stops refreshing them disappear on their own.
/// </summary>
public sealed class RedisSessionDirectory : ISessionDirectory
{
private const string KeyPrefix = "jellyfin:session:";
private const string OwnerKeyPrefix = "jellyfin:sessionowner:";
private const string EpochKeyPrefix = "jellyfin:sessionepoch:";
/// <summary>
/// Lua script for an atomic ownership claim. The owner key holds <c>connectedTicks|pod</c>, where
/// the ticks are zero for an instance that holds no connection. A claim by another instance is
/// refused unless its connection is newer than the recorded one, so the instance holding the live
/// connection keeps ownership however many requests the others serve.
/// Lua script for an atomic ownership claim. The owner key holds <c>epoch|pod</c>, where the epoch is
/// zero for an instance that holds no connection. Another instance takes ownership only by presenting
/// a connection epoch newer than the recorded one, so neither the instances serving the session's
/// requests nor two instances without a connection can take it from the one that has it.
/// </summary>
private const string ClaimScript = @"
redis.call('PEXPIRE', KEYS[3], ARGV[5])
local current = redis.call('GET', KEYS[1])
if current then
local separator = string.find(current, '|', 1, true)
local connected = tonumber(string.sub(current, 1, separator - 1))
local owner = string.sub(current, separator + 1)
if owner ~= ARGV[1] and connected > 0 and tonumber(ARGV[2]) <= connected then
local claiming = tonumber(ARGV[2])
if owner ~= ARGV[1] and (claiming == 0 or claiming <= connected) then
return 0
end
end
@@ -56,6 +60,15 @@ if string.sub(current, separator + 1) ~= ARGV[1] then return 0 end
redis.call('DEL', KEYS[1], KEYS[2])
return 1";
/// <summary>
/// Lua script allocating the next connection epoch. The counter outlives the entries that reference
/// it, so it never restarts underneath a recorded epoch.
/// </summary>
private const string EpochScript = @"
local epoch = redis.call('INCR', KEYS[1])
redis.call('PEXPIRE', KEYS[1], ARGV[1])
return epoch";
private static readonly JsonSerializerOptions _jsonOptions = JsonDefaults.Options;
private readonly IConnectionMultiplexer _redis;
@@ -85,10 +98,26 @@ return 1";
private long EntryTtlMs => Math.Max(1, _options.EntryTtlSeconds) * 1000L;
// Outlives the entries that name an epoch, so a live entry never outlives the counter it came from.
private long EpochTtlMs => EntryTtlMs * 4;
private TimeSpan OperationTimeout => TimeSpan.FromSeconds(Math.Max(1, _options.OperationTimeoutSeconds));
/// <inheritdoc />
public async Task<bool> PublishAsync(SessionDirectoryEntry entry, long connectedUtcTicks, CancellationToken cancellationToken = default)
public async Task<long> AllocateConnectionEpochAsync(string sessionId, CancellationToken cancellationToken = default)
{
ArgumentException.ThrowIfNullOrEmpty(sessionId);
var epoch = (long?)await _db.ScriptEvaluateAsync(
EpochScript,
keys: new RedisKey[] { EpochKeyPrefix + sessionId },
values: new RedisValue[] { EpochTtlMs }).WaitAsync(OperationTimeout, cancellationToken).ConfigureAwait(false);
return epoch ?? 0;
}
/// <inheritdoc />
public async Task<bool> PublishAsync(SessionDirectoryEntry entry, long connectionEpoch, CancellationToken cancellationToken = default)
{
ArgumentNullException.ThrowIfNull(entry);
@@ -102,13 +131,14 @@ return 1";
{
var claimed = (long?)await _db.ScriptEvaluateAsync(
ClaimScript,
keys: new RedisKey[] { OwnerKeyPrefix + sessionId, KeyPrefix + sessionId },
keys: new RedisKey[] { OwnerKeyPrefix + sessionId, KeyPrefix + sessionId, EpochKeyPrefix + sessionId },
values: new RedisValue[]
{
entry.OwnerPod,
connectedUtcTicks.ToString(CultureInfo.InvariantCulture),
connectionEpoch.ToString(CultureInfo.InvariantCulture),
JsonSerializer.Serialize(entry, _jsonOptions),
EntryTtlMs
EntryTtlMs,
EpochTtlMs
}).WaitAsync(OperationTimeout, cancellationToken).ConfigureAwait(false);
return claimed == 1;
@@ -139,17 +169,11 @@ return 1";
/// <inheritdoc />
public async Task<SessionDirectoryEntry?> GetAsync(string sessionId, CancellationToken cancellationToken = default)
{
try
{
var raw = await _db.StringGetAsync(KeyPrefix + sessionId).WaitAsync(OperationTimeout, cancellationToken).ConfigureAwait(false);
// A store that cannot be read says nothing about where the session is, so the failure is raised
// rather than reported as "no such session", which would be acted on as a local-only session.
var raw = await _db.StringGetAsync(KeyPrefix + sessionId).WaitAsync(OperationTimeout, cancellationToken).ConfigureAwait(false);
return raw.HasValue ? Deserialize(raw) : null;
}
catch (Exception ex)
{
_logger.LogWarning(ex, "Failed to read session {SessionId} from the directory.", sessionId);
return null;
}
return raw.HasValue ? Deserialize(raw) : null;
}
/// <inheritdoc />
@@ -157,49 +181,61 @@ return 1";
{
var entries = new List<SessionDirectoryEntry>();
try
foreach (var server in _redis.GetServers())
{
foreach (var server in _redis.GetServers())
if (!server.IsConnected)
{
if (!server.IsConnected)
{
continue;
}
continue;
}
var keys = new List<RedisKey>();
var keys = new List<RedisKey>();
try
{
await foreach (var key in server.KeysAsync(database: _db.Database, pattern: KeyPrefix + "*", pageSize: 1000).WithCancellation(cancellationToken).ConfigureAwait(false))
{
keys.Add(key);
}
}
catch (Exception ex) when (ex is not OperationCanceledException)
{
// Degrade to the sessions that could be read rather than failing the request outright.
_logger.LogWarning(ex, "Failed to list the session directory on {Server}; its sessions are not reported.", server.EndPoint);
continue;
}
var values = await Task.WhenAll(keys.Select(key => _db.StringGetAsync(key)))
.WaitAsync(OperationTimeout, cancellationToken).ConfigureAwait(false);
foreach (var raw in values)
foreach (var raw in await Task.WhenAll(keys.Select(key => ReadAsync(key, cancellationToken))).ConfigureAwait(false))
{
if (!raw.HasValue)
{
if (!raw.HasValue)
{
continue;
}
continue;
}
var entry = Deserialize(raw);
if (entry?.Session is not null)
{
entries.Add(entry);
}
var entry = Deserialize(raw);
if (entry?.Session is not null)
{
entries.Add(entry);
}
}
}
catch (Exception ex)
{
// Degrade to the sessions this instance holds rather than failing the request outright.
_logger.LogWarning(ex, "Failed to read the session directory; only local sessions are reported.");
return Array.Empty<SessionDirectoryEntry>();
}
return entries;
}
// One unreadable key must not discard the entries that did load.
private async Task<RedisValue> ReadAsync(RedisKey key, CancellationToken cancellationToken)
{
try
{
return await _db.StringGetAsync(key).WaitAsync(OperationTimeout, cancellationToken).ConfigureAwait(false);
}
catch (Exception ex) when (ex is not OperationCanceledException)
{
_logger.LogWarning(ex, "Failed to read a session directory entry.");
return RedisValue.Null;
}
}
private SessionDirectoryEntry? Deserialize(RedisValue raw)
{
try