| | | 1 | | using System.Runtime.InteropServices; |
| | | 2 | | |
| | | 3 | | namespace Elsa.Common; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// Helpers for classifying exceptions during best-effort error handling. |
| | | 7 | | /// </summary> |
| | | 8 | | public static class ExceptionExtensions |
| | | 9 | | { |
| | | 10 | | /// <summary> |
| | | 11 | | /// Returns <c>true</c> when <paramref name="exception"/> represents a process-fatal condition that should |
| | | 12 | | /// NOT be swallowed even by best-effort code paths. Catches that filter on <c>!ex.IsFatal()</c> let normal |
| | | 13 | | /// failures through for logging-and-continue while letting fatal exceptions propagate to crash the process |
| | | 14 | | /// cleanly (the host's failure-fast policy can then decide what to do). |
| | | 15 | | /// </summary> |
| | | 16 | | /// <remarks> |
| | | 17 | | /// <para> |
| | | 18 | | /// Conditions classified as fatal: |
| | | 19 | | /// </para> |
| | | 20 | | /// <list type="bullet"> |
| | | 21 | | /// <item><see cref="OutOfMemoryException"/> (when not <see cref="InsufficientMemoryException"/>, which is recover |
| | | 22 | | /// <item><see cref="StackOverflowException"/></item> |
| | | 23 | | /// <item><see cref="AccessViolationException"/></item> |
| | | 24 | | /// <item><see cref="SEHException"/></item> |
| | | 25 | | /// <item><see cref="ThreadAbortException"/></item> |
| | | 26 | | /// </list> |
| | | 27 | | /// <para> |
| | | 28 | | /// Wrapper exceptions (<see cref="AggregateException"/>, <see cref="TypeInitializationException"/>, |
| | | 29 | | /// <see cref="System.Reflection.TargetInvocationException"/>) are unwrapped before classification so that, |
| | | 30 | | /// for example, an aggregate or <see cref="TypeInitializationException"/> wrapping a |
| | | 31 | | /// <see cref="StackOverflowException"/> is classified as fatal. |
| | | 32 | | /// </para> |
| | | 33 | | /// <para> |
| | | 34 | | /// Pattern: use as a filter on a generic <c>catch</c> where the surrounding logic must remain best-effort |
| | | 35 | | /// for non-fatal errors: |
| | | 36 | | /// <code> |
| | | 37 | | /// try { /* best-effort work */ } |
| | | 38 | | /// catch (Exception ex) when (!ex.IsFatal()) |
| | | 39 | | /// { |
| | | 40 | | /// logger.LogError(ex, "..."); |
| | | 41 | | /// } |
| | | 42 | | /// </code> |
| | | 43 | | /// </para> |
| | | 44 | | /// </remarks> |
| | | 45 | | public static bool IsFatal(this Exception? exception) |
| | | 46 | | { |
| | 34 | 47 | | while (exception is not null) |
| | | 48 | | { |
| | 22 | 49 | | if (exception is AggregateException aggregateException) |
| | 6 | 50 | | return aggregateException.Flatten().InnerExceptions.Any(inner => inner.IsFatal()); |
| | | 51 | | |
| | 20 | 52 | | switch (exception) |
| | | 53 | | { |
| | | 54 | | case StackOverflowException: |
| | | 55 | | case AccessViolationException: |
| | | 56 | | case SEHException: |
| | | 57 | | case ThreadAbortException: |
| | 5 | 58 | | return true; |
| | 3 | 59 | | case OutOfMemoryException when exception is not InsufficientMemoryException: |
| | | 60 | | // OOM is fatal, but InsufficientMemoryException (its derived form) is recoverable by design. |
| | 2 | 61 | | return true; |
| | | 62 | | } |
| | | 63 | | |
| | | 64 | | // Unwrap reflection-style wrappers so a fatal cause buried inside a TypeInitializationException is still |
| | | 65 | | // classified as fatal. |
| | 13 | 66 | | exception = exception switch |
| | 13 | 67 | | { |
| | 1 | 68 | | TypeInitializationException tie => tie.InnerException, |
| | 1 | 69 | | System.Reflection.TargetInvocationException tie => tie.InnerException, |
| | 11 | 70 | | _ => null, |
| | 13 | 71 | | }; |
| | | 72 | | } |
| | 12 | 73 | | return false; |
| | | 74 | | } |
| | | 75 | | } |