Commit Graph

15353 Commits

Author SHA1 Message Date
Francisco Guerrero 57dabaea8c Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Bound declared value length against readable bytes in CBUtil
2026-07-27 10:20:02 -05:00
Francisco Guerrero 247289d7b6 Merge branch 'cassandra-5.0' into cassandra-6.0
* cassandra-5.0:
  Bound declared value length against readable bytes in CBUtil
2026-07-27 10:13:42 -05:00
Francisco Guerrero ecc0a3e77b Merge branch 'cassandra-4.1' into cassandra-5.0
* cassandra-4.1:
  Bound declared value length against readable bytes in CBUtil
2026-07-27 10:05:03 -05:00
Francisco Guerrero 2507eceb29 Merge branch 'cassandra-4.0' into cassandra-4.1
* cassandra-4.0:
  Bound declared value length against readable bytes in CBUtil
2026-07-27 10:01:06 -05:00
Francisco Guerrero 251b0e9b91 Bound declared value length against readable bytes in CBUtil
A 32-bit length field read from the wire by CBUtil.readValue (and its
siblings) flowed directly into new byte[length] with no upper bound,
allowing an unauthenticated client to drive the JVM into
OutOfMemoryError: 'Requested array size exceeds VM limit' — and, with
the default -XX:OnOutOfMemoryError=kill -9 %p, terminate the process —
by declaring Integer.MAX_VALUE as the SASL-token length in AUTH_RESPONSE.

Guard the allocation in the single private readRawBytes(ByteBuf, int)
that all int32-length readers funnel through, rejecting lengths that
exceed the buffer's readable bytes with a ProtocolException.

patch by Francisco Guerrero; reviewed by Stefan Miklosovic for CASSANDRA-21521
2026-07-27 09:51:36 -05:00
Francisco Guerrero 4412926e4f Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  ninja fix: ensure defaultReadThresholds is cleared for CASSANDRA-21467
2026-07-27 09:37:15 -05:00
Maxim Muzafarov 5bf01cc7c0
Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Allow unreserved keywords as user and identity names in USER and IDENTITY statements
2026-07-27 16:10:11 +02:00
Maxim Muzafarov c4c3048b13
Allow unreserved keywords as user and identity names in USER and IDENTITY statements
patch by Maxim Muzafarov; reviewed by Dmitry Konstantinov for CASSANDRA-21510
2026-07-27 16:03:06 +02:00
Stefan Miklosovic af202bddc2
Merge branch 'cassandra-6.0' into trunk 2026-07-27 15:53:17 +02:00
Francisco Guerrero 8fc52f5d2f
Reduce allocations in DefaultQueryOptions when read thresholds are enabled
patch by Francisco Guerrero; reviewed by Dmitry Konstantinov, Stefan Miklosovic for CASSANDRA-21467
2026-07-27 15:50:28 +02:00
Francisco Guerrero f7f52421c7 Merge branch 'cassandra-5.0' into cassandra-6.0
* cassandra-5.0:
  Ensure a Message's Response streamId is always set
2026-07-26 21:06:39 -05:00
Francisco Guerrero 79c8669b84 Merge branch 'cassandra-4.1' into cassandra-5.0
* cassandra-4.1:
  Ensure a Message's Response streamId is always set
2026-07-26 20:59:15 -05:00
Francisco Guerrero 9ddfe0fb22 Ensure a Message's Response streamId is always set
patch by Francisco Guerrero; reviewed by Caleb Rackliffe, Benedict Elliot Smith, Tejal Chakeres, Alexander Mitin for CASSANDRA-21508
2026-07-26 20:51:21 -05:00
Dmitry Konstantinov b3acdfda08 Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Reduce number of scheduledTasks on metric id release in ThreadLocalMetrics
2026-07-26 17:48:09 +01:00
Dmitry Konstantinov ddfdf5d69f Reduce number of scheduledTasks on metric id release in ThreadLocalMetrics
Use a single one-time scheduled task with two tick-tock buffers to recycle metric IDs after a sufficiently long delay.
Use phantom references for ThreadLocalMetrics cleanup ony if it is needed to reduce the references processing overhead.

patch by Dmitry Konstantinov; reviewed by Benedict Elliott Smith for CASSANDRA-21475
2026-07-26 17:46:40 +01:00
Stefan Miklosovic 3bee9024c2
Merge branch 'cassandra-6.0' into trunk 2026-07-26 11:27:16 +02:00
koo.taejin 03304bce53
Cache various Enum.values() used in deserialization to avoid per-read array allocation
patch by Koo Taejin; reviewed by Dmitry Konstantinov, Stefan Miklosovic for CASSANDRA-21528
2026-07-26 11:15:22 +02:00
Edward db0871ce8b Don't increment client metrics on messaging service connection unpause
patch by Edward Chu; reviewed by Aleksey Yeschenko for CASSANDRA-21491
2026-07-25 13:04:33 +01:00
Stefan Miklosovic 7666b19ac6
Merge branch 'cassandra-6.0' into trunk 2026-07-24 23:23:36 +02:00
dhingarkan 564d30ad8e
Fix Accord transaction error message when altering a table
patch by Motoki Unno; reviewed by Dmitry Konstantinov, Stefan Miklosovic for CASSANDRA-20580
2026-07-24 23:22:26 +02:00
Stefan Miklosovic ca42cfe68d
Add nodetool getreplicas
nodetool getendpoints is deprecated. Also, all StorageServiceMBean.getNaturalEndpoints* methods are
deprecated and they call their replica counterparts. The deprecated methods are also not used directly anywhere
in the code (nor tests).

patch by Stefan Miklosovic; reviewed by Brandon Williams for CASSANDRA-17665
2026-07-23 21:51:51 +02:00
Stefan Miklosovic d75d603281
Merge branch 'cassandra-6.0' into trunk 2026-07-20 20:47:47 +02:00
Stefan Miklosovic 15a6bac06d
Merge branch 'cassandra-5.0' into cassandra-6.0 2026-07-20 20:45:18 +02:00
Stefan Miklosovic bd345213c1
Merge branch 'cassandra-4.1' into cassandra-5.0 2026-07-20 20:43:56 +02:00
Stefan Miklosovic 1c702382de
Merge branch 'cassandra-4.0' into cassandra-4.1 2026-07-20 20:42:36 +02:00
Jeremiah Jordan 26d7b166ba
Verify extension type before initializing reflectively-loaded classes
Cassandra resolves pluggable extensions by class name from configuration, schema, and tooling
inputs. These names were loaded with an initializing Class.forName(name) and type-checked only
afterward, so the named class ran its static initializer before its type was confirmed. After this
change such classes will be loaded without initialization, verified against the expected interface or
base class, and initialized only through normal use after validation.

A shared FBUtilities.classForNameWithoutInitialization helper and typed
instanceOrConstruct/construct overloads apply this to the configurable extension points loaded by
class name: the authentication, authorization, role-management, network and
internode-authenticator backends, the partitioner, audit logger, configuration loader, seed provider,
snitch, abstract types, secondary and custom indexes, compaction strategy, compressor, replication
strategy, SASI analyzers, key and cache providers, query handler, storage and stream hooks, tracing,
the JMX authorization proxy, MBeans, the monotonic clock, nodetool Sjk, triggers, the
sstableloader and stress class options, and diagnostic event classes (loaded without initialization
and checked against DiagnosticEvent, preserving the InvalidClassException contract and the existing
package restriction).

Regression tests confirm that an invalid-type load is rejected without initializing the target
class, and that valid implementations still resolve.

Hadoop client integration and hard-coded JDK and internal class probes are left unchanged.

patch by Jeremiah Jordan; reviewed by Stefan Miklosovic for CASSANDRA-21525
2026-07-20 20:03:45 +02:00
Caleb Rackliffe f989d96b4b Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  SAI Component Checksum Validation Should be Segment-Aware
2026-07-18 23:21:07 -05:00
Caleb Rackliffe 27cc24bc79 Merge branch 'cassandra-5.0' into cassandra-6.0
* cassandra-5.0:
  SAI Component Checksum Validation Should be Segment-Aware
2026-07-18 23:14:02 -05:00
Caleb Rackliffe 4bd98de6ee SAI Component Checksum Validation Should be Segment-Aware
patch by Caleb Rackliffe; reviewed by Francisco Guerrero for CASSANDRA-21516
2026-07-18 22:53:56 -05:00
Stefan Miklosovic e56b58732c
Merge branch 'cassandra-6.0' into trunk 2026-07-10 11:16:49 +02:00
Stefan Miklosovic 2397d52df7
Depend only on platform-specific Zstd JNI native libraries
patch by Stefan Miklosovic; reviewed by Yifan Cai for CASSANDRA-21483
2026-07-10 11:15:25 +02:00
Dmitry Konstantinov 788bbc0891 Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Expose immediately-executed tasks in the queries virtual table
2026-07-09 09:31:02 +01:00
Dmitry Konstantinov 480320f3cf Expose immediately-executed tasks in the queries virtual table
SEPExecutor.maybeExecuteImmediately() runs a task synchronously on the
calling worker thread, nested within the task the worker is already
running. Such immediate tasks were invisible in system_views.queries, which only exposed each worker's primary running task.
This is common on the coordinator path, where a local read or mutation is executed immediately within the enclosing QUERY task.

Each SEPWorker now also tracks an immediate current task, set around
maybeExecuteImmediately(), and exposes it as an additional
DebuggableTaskRunner, so the queries table reports both the enclosing
task and the immediate one as separate rows.

patch by Dmitry Konstantinov; reviewed by Caleb Rackliffe for CASSANDRA-21471
2026-07-09 09:22:10 +01:00
Sam Tunnicliffe 1332e217f9 Merge branch 'cassandra-6.0' into trunk 2026-07-08 15:36:49 +01:00
Sam Tunnicliffe 1df3a8cef0 Setup async transformation before making internode request
Patch by Sam Tunnicliffe and Dmitry Konstantinov; reviewed by Sam
Tunnicliffe and Dmitry Konstantinov for CASSANDRA-21384

Co-authored-by: Dmitry Konstantinov <netudima@gmail.com>
2026-07-08 15:35:09 +01:00
Sam Tunnicliffe 6bee931da9 Merge branch 'cassandra-6.0' into trunk 2026-07-06 11:53:17 +01:00
Sam Tunnicliffe e1e56e5d5d Add CMS membership directly to ClusterMetadata
Patch by Sam Tunnicliffe; reviewed by Marcus Eriksson for
CASSANDRA-20736
2026-07-06 11:52:18 +01:00
Stefan Miklosovic 50ddce8455
Merge branch 'cassandra-6.0' into trunk 2026-07-03 11:15:03 +02:00
Stefan Miklosovic 15f139b91e
Merge branch 'cassandra-5.0' into cassandra-6.0 2026-07-03 11:08:42 +02:00
arvindksi274-ksolves 464b2e54f4
Support Python 3.12 and 3.13 in cqlsh
patch by Arvind Kandpal; reviewed by Stefan Miklosovic, Michael Semb Wever for CASSANDRA-20997
2026-07-03 11:02:14 +02:00
Caleb Rackliffe 9783cfeb73 Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Make synchronization on VectorMemoryIndex inserts more granular
2026-07-02 16:09:18 -05:00
Caleb Rackliffe bf4437296b Merge branch 'cassandra-5.0' into cassandra-6.0
* cassandra-5.0:
  Make synchronization on VectorMemoryIndex inserts more granular
2026-07-02 15:50:45 -05:00
Mick Semb Wever a44720c779
Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Fix publishing to ASF Nexus of Accord artefacts when release staging
2026-07-01 19:29:25 +02:00
Mick Semb Wever 5282f81d0a
Fix publishing to ASF Nexus of Accord artefacts when release staging
Also fail the build if any artefacts fail to upload.

 patch by mick semb wever; reviewed by David Capwell for CASSANDRA-21261
2026-07-01 19:25:15 +02:00
Sam Tunnicliffe 807cb652fb Merge branch 'cassandra-6.0' into trunk 2026-07-01 14:39:03 +01:00
Jon Meredith b1f30e94f5 Move long running TCM operations to a longer timout
Replaces the fixed-retry commit loop with deadline-based exponential
backoff for long running CMS commit operations (cms_commit_timeout=1h, 5s-60s jitter)
to allow heavily contended CMS nodes time to commit transforms.

Patch by Jon Meredith and Sam Tunnicliffe; reviewed by Jon Meredith and
Sam Tunnicliffe for CASSANDRA-21453

Co-authored-by: Sam Tunnicliffe <samt@apache.org>
2026-07-01 14:36:28 +01:00
Stefan Miklosovic 2b3258fe86
Merge branch 'cassandra-6.0' into trunk 2026-06-30 10:33:03 +02:00
Arvind Kandpal 26d6b4f665
Offline nodetool commands should not print network options in help
- Introduced LocalCommand marker interface to identify commands that execute purely locally without a JMX connection.
- Updated History command to implement LocalCommand.
- Updated CassandraCliHelpLayout to check for LocalCommand instead of calling execution-flow methods, safely suppressing JMX options for offline commands.

patch by Arvind Kandpal; reviewed by Stefan Miklosovic, Maxim Muzafarov for CASSANDRA-20876
2026-06-30 10:23:39 +02:00
Sam Tunnicliffe 8f8c4ec09e Merge branch 'cassandra-6.0' into trunk 2026-06-29 18:17:54 +01:00
Sam Tunnicliffe 896d1d6415 Defer the creation of system_cluster_metadata keyspace until CMS initialization
* Insert the actual PreInitialize entry in the distribute metadata log
  table using a callback after the log is bootstrapped.
* Remove the implicit insert on subsequent commit, i.e. of the Initialize entry
* Enables the full specifics of PreInit to be encoded in the serialized form,
  removing the special casing for the first CMS member and other nodes
* Correctly invalidate cached KeyspaceMetadata when in a pre-initialized state
* Update Host ids in the system.peers_v2 table directly following CMS initialization
* Initialise gossip/local host id after CMS initialization completes
* Clean up CMS initialization errors which occur after the PreInitialize stage

Co-authored-by: Alex Petrov <oleksandr.petrov@gmail.com>
Co-authored-by: Marcus Eriksson <marcuse@apache.org>
2026-06-29 18:09:42 +01:00