KAFKA-10188: Prevent SinkTask::preCommit from being called after SinkTask::stop#8910
KAFKA-10188: Prevent SinkTask::preCommit from being called after SinkTask::stop#8910rhauch merged 1 commit intoapache:trunkfrom
Conversation
gharris1727
left a comment
There was a problem hiding this comment.
LGTM, thanks @C0urante for the fix!
| this.sinkTaskMetricsGroup.recordOffsetSequenceNumber(commitSeqno); | ||
| this.consumer = consumer; | ||
| this.isTopicTrackingEnabled = workerConfig.getBoolean(TOPIC_TRACKING_ENABLE_CONFIG); | ||
| this.taskStopped = false; |
There was a problem hiding this comment.
Shouldn't this be volatile?
Yes, it's true that WorkerSinkTask.close() is always and only called from within the WorkerTask.doRun() after the tasks determines it will stop. However, the onPartitionsRevoked(...) method is called from the consumer thread, and making the field volatile is the only way to ensure that the consumer thread reads a non-cached value.
There was a problem hiding this comment.
The Javadocs for the ConsumerRebalanceLister state that the callback "will only execute in the user thread as part of the poll(long) call"; I think we have a guarantee here that onPartitionsRevoked will be called on the same thread that sets taskStopped to false. A fun way to verify this is to view the exceptions that get thrown by this bug; the stack traces include these lines:
at org.apache.kafka.connect.runtime.WorkerSinkTask$HandleRebalance.onPartitionsRevoked(WorkerSinkTask.java:695)
at org.apache.kafka.clients.consumer.internals.ConsumerCoordinator.invokePartitionsRevoked(ConsumerCoordinator.java:312)
at org.apache.kafka.clients.consumer.internals.ConsumerCoordinator.onLeavePrepare(ConsumerCoordinator.java:744)
at org.apache.kafka.clients.consumer.internals.AbstractCoordinator.close(AbstractCoordinator.java:976)
at org.apache.kafka.clients.consumer.internals.ConsumerCoordinator.close(ConsumerCoordinator.java:888)
at org.apache.kafka.clients.consumer.KafkaConsumer.close(KafkaConsumer.java:2368)
at org.apache.kafka.clients.consumer.KafkaConsumer.close(KafkaConsumer.java:2335)
at org.apache.kafka.clients.consumer.KafkaConsumer.close(KafkaConsumer.java:2285)
at org.apache.kafka.common.utils.Utils.closeQuietly(Utils.java:933)
at org.apache.kafka.connect.runtime.WorkerSinkTask.close(WorkerSinkTask.java:174)
at org.apache.kafka.connect.runtime.WorkerTask.doClose(WorkerTask.java:164)
at org.apache.kafka.connect.runtime.WorkerTask.doRun(WorkerTask.java:191)
at org.apache.kafka.connect.runtime.WorkerTask.run(WorkerTask.java:235)
The only edge case I can think of might be with asynchronous offset commits, but fwict those don't trigger asynchronous rebalance listener callbacks (if they trigger rebalances or rebalance listener callbacks at all).
| workerTask.stop(); | ||
| workerTask.close(); | ||
|
|
||
| PowerMock.verifyAll(); |
There was a problem hiding this comment.
Verified locally that this test fails when the additions to the onPartitionsRevoked(...) method above are removed locally. Nice work, @C0urante.
* commit '2804257fe221f37e5098bd': (67 commits) KAFKA-10562: Properly invoke new StateStoreContext init (apache#9388) MINOR: trivial cleanups, javadoc errors, omitted StateStore tests, etc. (apache#8130) KAFKA-10564: only process non-empty task directories when internally cleaning obsolete state stores (apache#9373) KAFKA-9274: fix incorrect default value for `task.timeout.ms` config (apache#9385) KAFKA-10362: When resuming Streams active task with EOS, the checkpoint file is deleted (apache#9247) KAFKA-10028: Implement write path for feature versioning system (KIP-584) (apache#9001) KAFKA-10402: Upgrade system tests to python3 (apache#9196) KAFKA-10186; Abort transaction with pending data with TransactionAbortedException (apache#9280) MINOR: Remove `TargetVoters` from `DescribeQuorum` (apache#9376) Revert "KAFKA-10469: Resolve logger levels hierarchically (apache#9266)" MINOR: Don't publish javadocs for raft module (apache#9336) KAFKA-9929: fix: add missing default implementations (apache#9321) KAFKA-10188: Prevent SinkTask::preCommit from being called after SinkTask::stop (apache#8910) KAFKA-10338; Support PEM format for SSL key and trust stores (KIP-651) (apache#9345) KAFKA-10527; Voters should not reinitialize as leader in same epoch (apache#9348) MINOR: Refactor unit tests around RocksDBConfigSetter (apache#9358) KAFKA-6733: Printing additional ConsumerRecord fields in DefaultMessageFormatter (apache#9099) MINOR: Annotate test BlockingConnectorTest as integration test (apache#9379) MINOR: Fix failing test due to KAFKA-10556 PR (apache#9372) KAFKA-10439: Connect's Values to parse BigInteger as Decimal with zero scale. (apache#9320) ...
Jira
The general lifecycle for a sink task is:
SinkTaskobjectSinkTask::initializeSinkTask::startSinkTask::putSinkTask::preCommitand committing the resulting map ofTopicPartitionto offset to KafkaSinkTask::stopSinkTask::preCommit)This final offset commit happens indirectly: closing the consumer for a sink task causes the rebalance listener for that consumer to be triggered, and the rebalance listener the framework uses for its consumers performs an offset commit for the task when partitions are revoked.
This is a bit of a problem because the framework calls
SinkTask::stopbefore closing the consumer for the task. It's possible and even likely that tasks will have de-allocated resources necessary for theirpreCommitmethod and will fail unexpectedly at this point.Since the framework already ensures that offsets are committed after the last call to
SinkTask::put, it should be fine to remove this extra offset commit. There is still a chance that some data may be dropped in the case that a task performs completely asynchronous writes to Kafka and has written data between the pre-stop call toSinkTask::preCommitand the post-stop one, but there will be no loss of delivery guarantees provided by the framework, and this change will adhere to the publicly-stated API for sink tasks.A unit test is added that covers the internal
WorkerSinkTask::closemethod and ensures thatSinkTask::preCommitis not called during that method.Committer Checklist (excluded from commit message)