--- /dev/null
+Return-Path: <m.walters@qmul.ac.uk>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+ by olra.theworths.org (Postfix) with ESMTP id C9AED431FB6\r
+ for <notmuch@notmuchmail.org>; Tue, 17 Apr 2012 01:42:38 -0700 (PDT)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -1.098\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-1.098 tagged_above=-999 required=5\r
+ tests=[DKIM_ADSP_CUSTOM_MED=0.001, FREEMAIL_FROM=0.001,\r
+ NML_ADSP_CUSTOM_MED=1.2, RCVD_IN_DNSWL_MED=-2.3] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+ by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+ with ESMTP id mvQIniGsOOzB for <notmuch@notmuchmail.org>;\r
+ Tue, 17 Apr 2012 01:42:38 -0700 (PDT)\r
+Received: from mail2.qmul.ac.uk (mail2.qmul.ac.uk [138.37.6.6])\r
+ (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))\r
+ (No client certificate requested)\r
+ by olra.theworths.org (Postfix) with ESMTPS id 0F77C431FAE\r
+ for <notmuch@notmuchmail.org>; Tue, 17 Apr 2012 01:42:38 -0700 (PDT)\r
+Received: from smtp.qmul.ac.uk ([138.37.6.40])\r
+ by mail2.qmul.ac.uk with esmtp (Exim 4.71)\r
+ (envelope-from <m.walters@qmul.ac.uk>)\r
+ id 1SK3zf-00043w-Aq; Tue, 17 Apr 2012 09:42:35 +0100\r
+Received: from 94-192-233-223.zone6.bethere.co.uk ([94.192.233.223]\r
+ helo=localhost)\r
+ by smtp.qmul.ac.uk with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.69)\r
+ (envelope-from <m.walters@qmul.ac.uk>)\r
+ id 1SK3ze-0001IF-PN; Tue, 17 Apr 2012 09:42:34 +0100\r
+From: Mark Walters <markwalters1009@gmail.com>\r
+To: Austin Clements <amdragon@MIT.EDU>,\r
+ Justus Winter <4winter@informatik.uni-hamburg.de>\r
+Subject: Re: [RFC] Split notmuch_database_close into two functions\r
+In-Reply-To: <20120412165744.GF13549@mit.edu>\r
+References:\r
+ <1332291311-28954-1-git-send-email-4winter@informatik.uni-hamburg.de>\r
+ <20120401032323.GH5949@mit.edu>\r
+ <20120412090533.2074.78211@thinkbox.jade-hamburg.de>\r
+ <20120412165744.GF13549@mit.edu>\r
+User-Agent: Notmuch/0.12+110~gbc97b4a (http://notmuchmail.org) Emacs/23.3.1\r
+ (x86_64-pc-linux-gnu)\r
+Date: Tue, 17 Apr 2012 09:42:55 +0100\r
+Message-ID: <87mx6a4uls.fsf@qmul.ac.uk>\r
+MIME-Version: 1.0\r
+Content-Type: text/plain; charset=us-ascii\r
+X-Sender-Host-Address: 94.192.233.223\r
+X-QM-SPAM-Info: Sender has good ham record. :)\r
+X-QM-Body-MD5: 193c4160caa46f9f63d218ae448bbf9e (of first 20000 bytes)\r
+X-SpamAssassin-Score: -1.8\r
+X-SpamAssassin-SpamBar: -\r
+X-SpamAssassin-Report: The QM spam filters have analysed this message to\r
+ determine if it is\r
+ spam. We require at least 5.0 points to mark a message as spam.\r
+ This message scored -1.8 points.\r
+ Summary of the scoring: \r
+ * -2.3 RCVD_IN_DNSWL_MED RBL: Sender listed at http://www.dnswl.org/,\r
+ * medium trust\r
+ * [138.37.6.40 listed in list.dnswl.org]\r
+ * 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail\r
+ provider * (markwalters1009[at]gmail.com)\r
+ * -0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay\r
+ * domain\r
+ * 0.5 AWL AWL: From: address is in the auto white-list\r
+X-QM-Scan-Virus: ClamAV says the message is clean\r
+Cc: notmuch@notmuchmail.org\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+ <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Tue, 17 Apr 2012 08:42:38 -0000\r
+\r
+On Thu, 12 Apr 2012, Austin Clements <amdragon@MIT.EDU> wrote:\r
+> Quoth Justus Winter on Apr 12 at 11:05 am:\r
+>> Quoting Austin Clements (2012-04-01 05:23:23)\r
+>> >Quoth Justus Winter on Mar 21 at 1:55 am:\r
+>> >> I propose to split the function notmuch_database_close into\r
+>> >> notmuch_database_close and notmuch_database_destroy so that long\r
+>> >> running processes like alot can close the database while still using\r
+>> >> data obtained from queries to that database.\r
+>> >\r
+>> >Is this actually safe? My understanding of Xapian::Database::close is\r
+>> >that, once you've closed the database, basically anything can throw a\r
+>> >Xapian exception. A lot of data is retrieved lazily, both by notmuch\r
+>> >and by Xapian, so simply having, say, a notmuch_message_t object isn't\r
+>> >enough to guarantee that you'll be able to get data out of it after\r
+>> >closing the database. Hence, I don't see how this interface could be\r
+>> >used correctly.\r
+>> \r
+>> I do not know how, but both alot and afew (and occasionally the\r
+>> notmuch binary) are somehow safely using this interface on my box for\r
+>> the last three weeks.\r
+>\r
+> I see. TL;DR: This isn't safe, but that's okay if we document it.\r
+>\r
+> The bug report [0] you pointed to was quite informative. At its core,\r
+> this is really a memory management issue. To sum up for the record\r
+> (and to check my own thinking): It sounds like alot is careful not to\r
+> use any notmuch objects after closing the database. The problem is\r
+> that, currently, closing the database also talloc_free's it, which\r
+> recursively free's everything derived from it. Python later GCs the\r
+> wrapper objects, which *also* try to free their underlying objects,\r
+> resulting in a double free.\r
+>\r
+> Before the change to expose notmuch_database_close, the Python\r
+> bindings would only talloc_free from destructors. Furthermore, they\r
+> prevented the library from recursively freeing things at other times\r
+> by internally maintaining a reverse reference for every library talloc\r
+> reference (e.g., message is a sub-allocation of query, so the bindings\r
+> keep a reference from each message to its query to ensure the query\r
+> doesn't get freed). The ability to explicitly talloc_free the\r
+> database subverts this mechanism.\r
+>\r
+>\r
+> So, I've come around to thinking that splitting notmuch_database_close\r
+> and _destroy is okay. It certainly parallels the rest of the API\r
+> better. However, notmuch_database_close needs a big warning similar\r
+> to Xapian::Database::close's warning that retrieving information from\r
+> objects derived from this database may not work after calling close.\r
+> notmuch_database_close is really a specialty interface, and about the\r
+> only thing you can guarantee after closing the database is that you\r
+> can destroy other objects. This is also going to require a SONAME\r
+> major version bump, as mentioned by others. Which, to be fair, would\r
+> be a good opportunity to fix some other issues, too, like how\r
+> notmuch_database_open can't return errors and how\r
+> notmuch_database_get_directory is broken on read-only databases. The\r
+> actual bump should be done at release time, but maybe we should drop a\r
+> note somewhere (NEWS?) so we don't forget.\r
+\r
+Can I just check that there is no way to reopen the Xapian database\r
+readonly? (I may be using the wrong term: I mean is there a way of\r
+switching an open read-write database to read-only without losing the\r
+attached structures/messages/threads etc) If I understand it this would\r
+be sufficient as it would free the lock, but could be more generally\r
+useful for long lived notmuch processes.\r
+\r
+Best wishes\r
+\r
+Mark\r