When BTreeRow.merge reconciles an update into a row whose existing deletion
shadows the update's cells, it filtered the update (incoming) side of the merge
with Reconciler.retain, which records the removal via
PostReconciliationFunction.delete. On the memtable write path that subtracts the
shadowed cells' on-heap size from the allocator's ownership even though that
incoming data was never allocated to the memtable. Under overwrite/delete churn
that re-applies cells already covered by a newer row/partition deletion (e.g.
repair re-streaming), the allocator's "owns" counter drifts negative and the next
flush trips "AssertionError: Negative released" in MemtablePool$SubPool.released
via MemtableAllocator$SubAllocator.releaseAll during discard.
Filter the update (incoming) side with a non-recording variant,
Reconciler.removeShadowed, and keep retain() for the existing side,
whose data the memtable already owns. The filtered result is identical; only the
erroneous accounting notification is dropped. This mirrors the already-correct
complex-column path in ColumnData.merge.
patch by Stefan Miklosovic; reviewed by Dmitry Konstantinov for CASSANDRA-21469
Assisted-By: Claude Opus 4.8 <noreply@anthropic.com>
CommandChanges.shouldCleanup short-circuits to NO if there is no data, but this is incorrect as Cleanup.EXPUNGE may have dropped the data and the record must receive cleanup EXPUNGE and be reported as ERASED.
Also Fix:
- Populate CFK system table row markers so we can stop reading sstables as soon as we have data
- system_accord_debug.executors has wrong clustering type
- RemoteToLocalVirtualTable should lazily allocate the partition collector to avoid LIMIT clause filtering removing it before it's populated
- ActiveEpochs.withNewEpochs should handle transition from 0 -> more than 1
- RedundantBefore.minGcBefore should be NONE if empty
- Update RangesForEpoch directly, so that we cannot have race conditions where the ownership is unknown
- Avoid reentrancy on local callbacks
- Ensure ReadCoordinator callbacks are invoked on owning thread
- Avoid deadlock when notifying ComplexListener(s)
- Release IntrusivePriorityHeap memory from large capacity heaps when empty
- Prevent SynchronousRecoverAwait reentrancy when invoking onDone (by exposing and invoking invokeOnDone that first sets isDone)
- maybeExecute must invoke either notWaiting or notifyWaiting to ensure tryExecuteListening terminates
Also Improve:
- Configurable execute_waiting_on_start
patch by Benedict; reviewed by Alan Wang and Alex Petrov for CASSANDRA-21440
This commit fixes several issues found using the Cassandra
edge case explorer skill for the BTI feature.
patch by Francisco Guerrero; reviewed by Aleksey Yeschenko for CASSANDRA-21353
Wires the conventional AGENTS.md -> SECURITY.md -> security model chain so automated tooling
can mechanically discover the project's security model. No model content is changed.
patch by Jarek Potiuk; reviewed by Stefan Miklosovic, Michael Semb Wever for CASSANDRA-21464
Assisted-by: Claude Opus 4.8 (1M context)
Resolve broken cross-module xrefs and image/anchor targets across the
cassandra docs tree. Companion to apache/cassandra-website#319 (merged
2026-05-13) under the same JIRA umbrella.
Forward-merge of trunk commit 32826fe563 to cassandra-6.0, which was
omitted from the 2026-05-14 forward-merge of this fix to the release
branches. Two hunks in create-custom-index.adoc were already present
via the CASSANDRA-21342 long-tail forward-merge; one additional
unqualified collection-create xref in the same file (not present on
trunk at the time of the original patch) is fixed here. All retargeted
anchors verified present on cassandra-6.0, including
list-superusers-statement (absent on 5.0, present here).
patch by Patrick McFadin; reviewed by Brandon Williams for CASSANDRA-21342
CASSANDRA-21342: Long-tail xref follow-up (cassandra-6.0)
Forward-merge of the trunk long-tail xref fix (commit cc97ee5332) to
cassandra-6.0. Twenty-six files updated; mechanical xref retargets and
three added [[anchor]] targets following the existing convention.
One conflict resolved: create-custom-index.adoc - took the trunk side
for both conflict blocks; the "For related information" line and the
collection-create/list/set bullet list now use
xref:cassandra:developing/cql/collections/...
Note: a separate broken xref at create-custom-index.adoc:58 remains on
cassandra-6.0 (out of scope here). It was fixed on trunk and
cassandra-5.0 by PR #4807 but appears to have been missed in the
forward-merge to cassandra-6.0. To be handled as a separate audit
follow-up.
patch by Patrick McFadin; reviewed by Mick Semb Wever for CASSANDRA-21342
CASSANDRA-21342: Long-tail xref follow-up (cassandra-5.0)
Forward-merge of the trunk long-tail xref fix (commit cc97ee5332) to
cassandra-5.0. Twenty-six files updated; mechanical xref retargets and
three added [[anchor]] targets following the existing convention.
One conflict resolved: architecture/index.adoc - kept 5.0's no-Accord
state with the snitch xref qualified to cassandra:managing/operating/.
patch by Patrick McFadin; reviewed by Mick Semb Wever for CASSANDRA-21342
CASSANDRA-21342: Long-tail xref follow-up (cassandra-4.1 subset)
Forward-merge of the cassandra-4.0 long-tail subset onto cassandra-4.1.
Same three files, same six edits as the 4.0 commit.
patch by Patrick McFadin; reviewed by Mick Semb Wever for CASSANDRA-21342
Subset of the trunk long-tail xref follow-up (commit cc97ee5332)
applicable to cassandra-4.0. Three files have broken patterns that
still apply on this branch after PR #4807's forward-merge: the
architecture index, finding_nodes, and use_tools self-page xrefs.
Six edits total. Mechanical retargets only; no prose was rewritten.
Edits omitted (trunk-only):
* Twenty files introduced in 5.0 or later (developing/cql/, reference/
cql-commands/, managing/operating/, etc).
* use_tools.adoc edits 4 and 5 (different line state on 4.x;
packet-capture anchor section structure differs).
patch by Patrick McFadin; reviewed by Mick Semb Wever for CASSANDRA-21342