feat(sources): add disconnect_mode option to tcp sources - #25331
Closed
tronboto wants to merge 2 commits into
Closed
feat(sources): add disconnect_mode option to tcp sources#25331tronboto wants to merge 2 commits into
tronboto wants to merge 2 commits into
Conversation
Contributor
Author
|
@vectordotdev/vector would be grateful for some feedback on this when you get a chance, thanks. |
pront
reviewed
Jul 2, 2026
| @@ -0,0 +1,3 @@ | |||
| Added a `disconnect_mode` configuration option to the `socket` (TCP mode), `logstash`, `fluent`, `syslog` (TCP mode), and `statsd` (TCP mode) sources. This controls how Vector closes TCP connections on shutdown or when `max_connection_duration_secs` elapses. The `drain` mode maintains the existing graceful shutdown behaviour while the `abort` mode closes connections immediately without waiting for the client to acknowledge the shutdown. This is useful for clients that never read from the socket and therefore cannot detect a graceful shutdown. The `logstash` and `fluent` sources default to `abort` to match the behaviour of Logstash's own Beats input plugin and Fluentd's `in_forward` plugin respectively. | |||
Member
There was a problem hiding this comment.
The PR frames this as a breaking change so this changelog should also be breaking.md.
More importantly I think we cannot go ahead with this PR as is:
- We can extract the shutdown(SHUT_WR) fix into an independent PR.
- Maybe we can go ahead with the new
disconnect_modeif the default for all affected components isdrainto preserve existing behavior. - Optional but breaking change in a future PR: flip logstash/fluent defaults from drain to abort to match upstream Logstash/Fluentd
Contributor
Author
There was a problem hiding this comment.
Thanks @pront . That all makes sense. Will try and find some time to look at these this week.
Contributor
Author
|
Closing. Have split this up into 2 separate PRs as requested: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a
disconnect_modeconfiguration option to TCP sources (socket, logstash, fluent, syslog, statsd) that controls how connections are closed on shutdown or whenmax_connection_duration_secselapses.The two modes are:
drain(default for socket, syslog, statsd) - sends aFINand waits for the client to close. Existing behaviour.abort(default for logstash, fluent) - setsSO_LINGER=0to force close immediately withRST.The original motivation is "write-only" clients such as Serilog.Sinks.Network that never read from the socket and therefore cannot detect a graceful shutdown. Additionally, the "reference implementations" for the beats (logstash) and fluent protocols also use an abort style shutdown:
This change also fixes a pre-existing bug where
shutdown(SHUT_WR)would be called repeatedly on every loop iteration aftermax_connection_duration_secselapsed, rather than just once. The kernel ignores subsequent calls but it's still wasteful.Vector configuration
How did you test this PR?
tcpdump.sources::socket:tcp_disconnect_mode_abort_on_shutdown- verifies RST is received immediately on shutdown.Change Type
Is this a breaking change?
disconnect_modefor logstash and fluent changes from drain to abort)Does this PR include user facing changes?
References
Closes #23855
Notes
@vectordotdev/vectorto reach out to us regarding this PR.pre-pushhook, please see this template.make fmtmake check-clippy(if there are failures it's possible some of them can be fixed withmake clippy-fix)make testgit merge origin masterandgit push.Cargo.lock), pleaserun
make build-licensesto regenerate the license inventory and commit the changes (if any). More detail s on the dd-rust-license-tool.