From: Paul Brannan Date: 2004-09-28T23:10:06+09:00 Subject: Re: safety of timeout() On Tue, Sep 28, 2004 at 08:47:29PM +0900, Brian Candler wrote: > At least, that's what I understand to be the crux of the issue. In many > cases it's not going to be a major concern. You may be able to rewrite the > code to make it safer by pushing the timeouts down to the lowest possible > level. The above example could be rewritten safely as: > > File.open("mylog","a") do |f| > timeout(30) do > ... do stuff > end > end I like your description of the problem, Brian. I've tried to explain this before and not been able to articulate it quite so well. I would like to add one additional problem to your explanation, though: timeout exceptions can prevent you from knowing whether or not an operation actually succeeded. We have this problem with CORBA timeouts in particular; a remote call is made, and the process on the other side is running slowly. It does, however, complete the operation, just as the timeout exception is being fired. So do I treat the operation as success (since I know the request reached the other side, as I didn't get a communications failure exception), or do I treat the operation as failure (since I did get an exception and I did fail to get a return value from the call)? A solution I've used in the past has been to use an event loop and let it handle the timeouts. The timeout then occurs only when the event loop has control; when the timeout does occur, a proc is called that handles the timeout. This proc may raise an exception or it may take some other action. For long-running operations, I periodically yield control to the event loop when it is safe. Paul