Commit Graph

9442 Commits

Author SHA1 Message Date
Benedict Elliott Smith 25f6d75be8 fixup 2026-07-31 15:01:32 +01:00
Benedict Elliott Smith ba683a02fd Improve Rebootstrap:
- Distinguish corrupt/incomplete cases; latter case only refuses uncertain data
     - Ensures quorum durability before marking own log faulty
     - Refuse unsafe operations more selectively once log marked faulty
     - Simplify and merge logic with standard bootstrap
2026-07-30 16:20:22 +01:00
Benedict Elliott Smith 988235c736 fix ThreadLocalTaskRunner reentrancy
claude tests

fix negative histogram values under simulation, and catch and refuse bad values in other cases
2026-07-30 15:58:20 +01:00
Benedict Elliott Smith c4b0257b38 Refactor AccordExecutor/Task responsibilities, in particular:
- fix race conditions when updating Task.info (between running and Exclusive methods)
 - do not run consequences of actions that fail and do not become durable (e.g. applying to data store/post-applying a transaction that we failed to complete the PreApplied/Applying step for)
2026-07-30 12:42:07 +01:00
Benedict Elliott Smith 15bede148a split AccordExecutor et al into own package 2026-07-28 12:16:31 +01:00
Benedict Elliott Smith 37b4fbf08f Accord Executor QoS
Fairness: tasks are grouped by kind of work, and for each group we track work arrival and service via decaying counters. If work for some group(s) begin to be served at a much lower rate than some other group (e.g. because that group has a large backlog, that by simple priority comes first), then we begin processing some fraction of the work by service-ratio rather than priority. This means that we cannot starve request processing because, e.g., a sync point has produced thousands of state save tasks.

Incremental processing: tasks that process many keys may be declared INCR or ASYNC. ASYNC indicates the keys are needed (so should be loaded), but may be used in follow-up work so the task may be executed if the data is not yet loaded. An ASYNC task may be followed by an INCR task that processes keys as they are loaded, with limits to the batch sizes. This limits the latency impact of processing larger transactions such as sync points. INCR tasks may be declared to be processed in either an arbitrary order with no isolation, or “atomically” with its parent task. In the latter case, the complete unit of work appears to execute as a single execution to external observers (blocking progress on unprocessed keys).

Key-level ordering: AccordCacheEntry can inflate a special Queue object that can be used to impose ordering constraints: FIFO for atomic work (once it has been part processed, or submitted as part of a parent task); prioritised for tasks that have a key-level priority to impose (i.e. PreAccept/Accept/Commit/Stable/Apply want to be ordered by TxnId); and unsequenced tasks for those that have no sequencing restrictions.

Additional improvements:
 - AccordCacheEntry are now explicitly LOCKED for the duration of their usage, which may span multiple executions for long running INCR tasks.
 - ExclusiveExecutor releases its ownership lock immediately, since AccordCacheEntry locks guarantee safety (as they will not be released until the task is cleaned up)
 - CassandraThread tracks active and locked AccordExecutor, so that we may safely and more aggressively use executeMaybeImmediately, safe in the knowledge it will never permit cross-executor executions or multiple executor locks to be held.

Also:
 - Rename PreLoadContext -> ExecutionContext
 - Break out AccordExecutor/AccordTask into separate package
2026-07-28 11:39:53 +01:00
Benedict Elliott Smith 1cffe9a8a0 Executor Fairness 2026-07-27 17:48:54 +01:00
Benedict Elliott Smith 13956ddf21 rename PreLoadContext to ExecutionContext, and SequentialAsyncExecutor -> ExclusiveAsyncExecutor 2026-07-27 17:48:54 +01:00
Benedict Elliott Smith bfcdf927f8 Fix SignalLock.incrementAsyncWork (wrong guard, can lead to ISE) 2026-07-27 17:48:54 +01:00
Francisco Guerrero 57dabaea8c Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Bound declared value length against readable bytes in CBUtil
2026-07-27 10:20:02 -05:00
Francisco Guerrero 247289d7b6 Merge branch 'cassandra-5.0' into cassandra-6.0
* cassandra-5.0:
  Bound declared value length against readable bytes in CBUtil
2026-07-27 10:13:42 -05:00
Francisco Guerrero ecc0a3e77b Merge branch 'cassandra-4.1' into cassandra-5.0
* cassandra-4.1:
  Bound declared value length against readable bytes in CBUtil
2026-07-27 10:05:03 -05:00
Francisco Guerrero 2507eceb29 Merge branch 'cassandra-4.0' into cassandra-4.1
* cassandra-4.0:
  Bound declared value length against readable bytes in CBUtil
2026-07-27 10:01:06 -05:00
Francisco Guerrero 251b0e9b91 Bound declared value length against readable bytes in CBUtil
A 32-bit length field read from the wire by CBUtil.readValue (and its
siblings) flowed directly into new byte[length] with no upper bound,
allowing an unauthenticated client to drive the JVM into
OutOfMemoryError: 'Requested array size exceeds VM limit' — and, with
the default -XX:OnOutOfMemoryError=kill -9 %p, terminate the process —
by declaring Integer.MAX_VALUE as the SASL-token length in AUTH_RESPONSE.

Guard the allocation in the single private readRawBytes(ByteBuf, int)
that all int32-length readers funnel through, rejecting lengths that
exceed the buffer's readable bytes with a ProtocolException.

patch by Francisco Guerrero; reviewed by Stefan Miklosovic for CASSANDRA-21521
2026-07-27 09:51:36 -05:00
Maxim Muzafarov 5bf01cc7c0
Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Allow unreserved keywords as user and identity names in USER and IDENTITY statements
2026-07-27 16:10:11 +02:00
Maxim Muzafarov c4c3048b13
Allow unreserved keywords as user and identity names in USER and IDENTITY statements
patch by Maxim Muzafarov; reviewed by Dmitry Konstantinov for CASSANDRA-21510
2026-07-27 16:03:06 +02:00
Stefan Miklosovic af202bddc2
Merge branch 'cassandra-6.0' into trunk 2026-07-27 15:53:17 +02:00
Francisco Guerrero 8fc52f5d2f
Reduce allocations in DefaultQueryOptions when read thresholds are enabled
patch by Francisco Guerrero; reviewed by Dmitry Konstantinov, Stefan Miklosovic for CASSANDRA-21467
2026-07-27 15:50:28 +02:00
Francisco Guerrero a3ec88632d Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Ensure a Message's Response streamId is always set
2026-07-26 21:13:21 -05:00
Francisco Guerrero f7f52421c7 Merge branch 'cassandra-5.0' into cassandra-6.0
* cassandra-5.0:
  Ensure a Message's Response streamId is always set
2026-07-26 21:06:39 -05:00
Francisco Guerrero 79c8669b84 Merge branch 'cassandra-4.1' into cassandra-5.0
* cassandra-4.1:
  Ensure a Message's Response streamId is always set
2026-07-26 20:59:15 -05:00
Francisco Guerrero 9ddfe0fb22 Ensure a Message's Response streamId is always set
patch by Francisco Guerrero; reviewed by Caleb Rackliffe, Benedict Elliot Smith, Tejal Chakeres, Alexander Mitin for CASSANDRA-21508
2026-07-26 20:51:21 -05:00
Dmitry Konstantinov b3acdfda08 Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Reduce number of scheduledTasks on metric id release in ThreadLocalMetrics
2026-07-26 17:48:09 +01:00
Dmitry Konstantinov ddfdf5d69f Reduce number of scheduledTasks on metric id release in ThreadLocalMetrics
Use a single one-time scheduled task with two tick-tock buffers to recycle metric IDs after a sufficiently long delay.
Use phantom references for ThreadLocalMetrics cleanup ony if it is needed to reduce the references processing overhead.

patch by Dmitry Konstantinov; reviewed by Benedict Elliott Smith for CASSANDRA-21475
2026-07-26 17:46:40 +01:00
Stefan Miklosovic 3fad760416
Merge branch 'cassandra-6.0' into trunk 2026-07-25 09:56:30 +02:00
Arvind Kandpal f51c29c196
Add compound primary key example to nodetool getendpoints help
patch by Arvind Kandpal; reviewed by Dmitry Konstantinov, Stefan Miklosovic for CASSANDRA-15904
2026-07-25 09:53:44 +02:00
Stefan Miklosovic 0840eb35af
Merge branch 'cassandra-6.0' into trunk 2026-07-24 13:17:09 +02:00
Dmitry Konstantinov 0040482e26
Reduce disk space usage by CommitLogSegmentManagerCDCTest
patch by Dmitry Konstantinov; reviewed by Michael Semb Wever for CASSANDRA-21534
2026-07-24 13:13:17 +02:00
Stefan Miklosovic ca42cfe68d
Add nodetool getreplicas
nodetool getendpoints is deprecated. Also, all StorageServiceMBean.getNaturalEndpoints* methods are
deprecated and they call their replica counterparts. The deprecated methods are also not used directly anywhere
in the code (nor tests).

patch by Stefan Miklosovic; reviewed by Brandon Williams for CASSANDRA-17665
2026-07-23 21:51:51 +02:00
Stefan Miklosovic d75d603281
Merge branch 'cassandra-6.0' into trunk 2026-07-20 20:47:47 +02:00
Stefan Miklosovic 15a6bac06d
Merge branch 'cassandra-5.0' into cassandra-6.0 2026-07-20 20:45:18 +02:00
Stefan Miklosovic bd345213c1
Merge branch 'cassandra-4.1' into cassandra-5.0 2026-07-20 20:43:56 +02:00
Stefan Miklosovic 1c702382de
Merge branch 'cassandra-4.0' into cassandra-4.1 2026-07-20 20:42:36 +02:00
Jeremiah Jordan 26d7b166ba
Verify extension type before initializing reflectively-loaded classes
Cassandra resolves pluggable extensions by class name from configuration, schema, and tooling
inputs. These names were loaded with an initializing Class.forName(name) and type-checked only
afterward, so the named class ran its static initializer before its type was confirmed. After this
change such classes will be loaded without initialization, verified against the expected interface or
base class, and initialized only through normal use after validation.

A shared FBUtilities.classForNameWithoutInitialization helper and typed
instanceOrConstruct/construct overloads apply this to the configurable extension points loaded by
class name: the authentication, authorization, role-management, network and
internode-authenticator backends, the partitioner, audit logger, configuration loader, seed provider,
snitch, abstract types, secondary and custom indexes, compaction strategy, compressor, replication
strategy, SASI analyzers, key and cache providers, query handler, storage and stream hooks, tracing,
the JMX authorization proxy, MBeans, the monotonic clock, nodetool Sjk, triggers, the
sstableloader and stress class options, and diagnostic event classes (loaded without initialization
and checked against DiagnosticEvent, preserving the InvalidClassException contract and the existing
package restriction).

Regression tests confirm that an invalid-type load is rejected without initializing the target
class, and that valid implementations still resolve.

Hadoop client integration and hard-coded JDK and internal class probes are left unchanged.

patch by Jeremiah Jordan; reviewed by Stefan Miklosovic for CASSANDRA-21525
2026-07-20 20:03:45 +02:00
Caleb Rackliffe f989d96b4b Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  SAI Component Checksum Validation Should be Segment-Aware
2026-07-18 23:21:07 -05:00
Caleb Rackliffe 27cc24bc79 Merge branch 'cassandra-5.0' into cassandra-6.0
* cassandra-5.0:
  SAI Component Checksum Validation Should be Segment-Aware
2026-07-18 23:14:02 -05:00
Caleb Rackliffe 4bd98de6ee SAI Component Checksum Validation Should be Segment-Aware
patch by Caleb Rackliffe; reviewed by Francisco Guerrero for CASSANDRA-21516
2026-07-18 22:53:56 -05:00
Dmitry Konstantinov a14a954788 Fix flakiness in CommitLogSegmentManagerCDCTest
Restore deleteCDCRawFiles logic which is present in 6.0 and trunk but probably lost in 5.0 due to merges
Files may be concurrently removed by the CDC management thread, so we tolerate a file that has already been deleted rather than failing the test.
Fix IndexOutOfBoundsException at commitlog.AbstractCommitLogSegmentManager.forceRecycleAll - it is already fixed in 6.0/trunk.
Cleanup test data after run to reduce disk usage.

Patch by Dmitry Konstantinov; reviewed by Michael Semb Wever for CASSANDRA-20091
2026-07-12 21:55:58 +01:00
Maxim Muzafarov d60927cb14
Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Forbid ambiguous option/parameter keys in nodetool command hierarchy
2026-07-11 21:39:38 +02:00
Maxim Muzafarov 7874fdae57
Forbid ambiguous option/parameter keys in nodetool command hierarchy
patch by Maxim Muzafarov; reviewed by Dmitry Konstantinov for CASSANDRA-21509
2026-07-11 21:31:41 +02:00
Dmitry Konstantinov 788bbc0891 Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Expose immediately-executed tasks in the queries virtual table
2026-07-09 09:31:02 +01:00
Dmitry Konstantinov 480320f3cf Expose immediately-executed tasks in the queries virtual table
SEPExecutor.maybeExecuteImmediately() runs a task synchronously on the
calling worker thread, nested within the task the worker is already
running. Such immediate tasks were invisible in system_views.queries, which only exposed each worker's primary running task.
This is common on the coordinator path, where a local read or mutation is executed immediately within the enclosing QUERY task.

Each SEPWorker now also tracks an immediate current task, set around
maybeExecuteImmediately(), and exposes it as an additional
DebuggableTaskRunner, so the queries table reports both the enclosing
task and the immediate one as separate rows.

patch by Dmitry Konstantinov; reviewed by Caleb Rackliffe for CASSANDRA-21471
2026-07-09 09:22:10 +01:00
Sam Tunnicliffe 1332e217f9 Merge branch 'cassandra-6.0' into trunk 2026-07-08 15:36:49 +01:00
Sam Tunnicliffe 1df3a8cef0 Setup async transformation before making internode request
Patch by Sam Tunnicliffe and Dmitry Konstantinov; reviewed by Sam
Tunnicliffe and Dmitry Konstantinov for CASSANDRA-21384

Co-authored-by: Dmitry Konstantinov <netudima@gmail.com>
2026-07-08 15:35:09 +01:00
Sam Tunnicliffe 6bee931da9 Merge branch 'cassandra-6.0' into trunk 2026-07-06 11:53:17 +01:00
Sam Tunnicliffe e1e56e5d5d Add CMS membership directly to ClusterMetadata
Patch by Sam Tunnicliffe; reviewed by Marcus Eriksson for
CASSANDRA-20736
2026-07-06 11:52:18 +01:00
Caleb Rackliffe 9783cfeb73 Merge branch 'cassandra-6.0' into trunk
* cassandra-6.0:
  Make synchronization on VectorMemoryIndex inserts more granular
2026-07-02 16:09:18 -05:00
Caleb Rackliffe bf4437296b Merge branch 'cassandra-5.0' into cassandra-6.0
* cassandra-5.0:
  Make synchronization on VectorMemoryIndex inserts more granular
2026-07-02 15:50:45 -05:00
Caleb Rackliffe 448d98ce31 Make synchronization on VectorMemoryIndex inserts more granular
patch by Caleb Rackliffe; reviewed by David Capwell for CASSANDRA-21160

Co-authored-by: Caleb Rackliffe <calebrackliffe@gmail.com>
Co-authored-by: David Capwell <dcapwell@apache.org>
2026-07-02 15:22:41 -05:00
Sam Tunnicliffe 807cb652fb Merge branch 'cassandra-6.0' into trunk 2026-07-01 14:39:03 +01:00