Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Protect the .Conn property of tabletHealthCheck from being read/modified concurrently. #16362

Closed
wants to merge 2 commits into from

Conversation

arthurschreiber
Copy link
Contributor

@arthurschreiber arthurschreiber commented Jul 10, 2024

Description

During multiple external primary failovers + TabletExternallyReparented calls across different keyspaces we've run into situations where different vtgate processes would end up being "stuck" and unable to serve queries that are supposed to be routed to the newly elected primary.

Those queries all fail with a vttablet: Connection Closed error, which can only happen if gRPCQueryClient.cc is set to nil. The only place in the code base where gRPCQueryClient.cc is modified is in gRPCQueryClient.Close, which in turn is only ever called from tabletHealthCheck.closeConnection or tabletHealthCheck.finalizeConn.

This leads me to believe that there are situations where we can end up with a tabletHealthCheck on which Conn is non-nil but gRPCQueryClient.cc is nil. This would explain the vttablet: Connection Closed errors we're seeing, while at the same time not seeing the grpc connection being re-established.

I noticed that the modification of tabletHealthCheck.Conn in both tabletHealthCheck.closeConnection and tabletHealthCheck.finalizeConn is not protected by a mutex like it is in tabletHealthCheck.Connection. I'm not sure this really explains the issue we're seeing, but it seems like a good idea to protect the .Conn property of tabletHealthCheck from being read/modified concurrently.

I added a test case that simulates how I believe this code is used in vtgate - by having tabletHealthCheck.checkConn run in one goroutine while calling tabletHealthCheck.Connection from another goroutine while the connection sporadically receives errors (so as to trigger tabletHealthCheck.closeConnection to be called).

Related Issue(s)

Checklist

  • "Backport to:" labels have been added if this change should be back-ported to release branches
  • If this change is to be back-ported to previous releases, a justification is included in the PR description
  • Tests were added or are not required
  • Did the new or modified tests pass consistently locally and on CI?
  • Documentation was added or is not required

Deployment Notes

Copy link
Contributor

vitess-bot bot commented Jul 10, 2024

Review Checklist

Hello reviewers! 👋 Please follow this checklist when reviewing this Pull Request.

General

  • Ensure that the Pull Request has a descriptive title.
  • Ensure there is a link to an issue (except for internal cleanup and flaky test fixes), new features should have an RFC that documents use cases and test cases.

Tests

  • Bug fixes should have at least one unit or end-to-end test, enhancement and new features should have a sufficient number of tests.

Documentation

  • Apply the release notes (needs details) label if users need to know about this change.
  • New features should be documented.
  • There should be some code comments as to why things are implemented the way they are.
  • There should be a comment at the top of each new or modified test to explain what the test does.

New flags

  • Is this flag really necessary?
  • Flag names must be clear and intuitive, use dashes (-), and have a clear help text.

If a workflow is added or modified:

  • Each item in Jobs should be named in order to mark it as required.
  • If the workflow needs to be marked as required, the maintainer team must be notified.

Backward compatibility

  • Protobuf changes should be wire-compatible.
  • Changes to _vt tables and RPCs need to be backward compatible.
  • RPC changes should be compatible with vitess-operator
  • If a flag is removed, then it should also be removed from vitess-operator and arewefastyet, if used there.
  • vtctl command output order should be stable and awk-able.

@vitess-bot vitess-bot bot added NeedsBackportReason If backport labels have been applied to a PR, a justification is required NeedsDescriptionUpdate The description is not clear or comprehensive enough, and needs work NeedsIssue A linked issue is missing for this Pull Request NeedsWebsiteDocsUpdate What it says labels Jul 10, 2024
@github-actions github-actions bot added this to the v21.0.0 milestone Jul 10, 2024
Copy link

codecov bot commented Jul 10, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 68.74%. Comparing base (eb29999) to head (3c6fa6f).
Report is 208 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #16362      +/-   ##
==========================================
+ Coverage   68.69%   68.74%   +0.04%     
==========================================
  Files        1547     1548       +1     
  Lines      198297   200153    +1856     
==========================================
+ Hits       136228   137598    +1370     
- Misses      62069    62555     +486     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@arthurschreiber arthurschreiber changed the title Protect the .Conn property of tabletHealthCheck from being modified concurrently. Protect the .Conn property of tabletHealthCheck from being read/modified concurrently. Jul 10, 2024
@@ -840,7 +840,7 @@ func (hc *HealthCheckImpl) TabletConnection(ctx context.Context, alias *topodata
hc.mu.Lock()
thc := hc.healthByAlias[tabletAliasString(topoproto.TabletAliasString(alias))]
hc.mu.Unlock()
if thc == nil || thc.Conn == nil {
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I removed this because I don't think this particular check makes sense (and it causes the race detector to be unhappy).

thc.Conn can become nil at any time, including right after this check.

Calling thc.Connection a few lines below will return a new connection object that will either be usable (if the vttablet on the other side of the connection can be accessed), or it will return an error when the connection is attempted to be used.

Removing this line seems to have impact on some integration tests and I'll try if I can figure out how to update them accordingly, but as-is this check simply leads to flaky behaviour and can't be trusted.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems correct to remove this check for the reasons you stated. We should wait and see what your test failures tell you.
One thing to note is that there seem to be exactly two paths to thc.Connection which, as you noted, is responsible for initializing the connection object. One is from here, and the other is from stream.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I went back and looked at the blame for this. Perhaps it is actually protecting us from some other race condition.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We may end up recreating a connection to a tablet that we are trying to drop.

…odified concurrently.

Signed-off-by: Arthur Schreiber <arthurschreiber@github.com>
@arthurschreiber arthurschreiber force-pushed the arthur/prevent-healtchec-conn-data-race branch from 3436cc4 to c22b815 Compare July 10, 2024 10:51
@arthurschreiber arthurschreiber marked this pull request as ready for review July 10, 2024 10:52
Signed-off-by: Arthur Schreiber <arthurschreiber@github.com>
utils.AssertContainsError(t, readConn, fetchAllCustomers, "is either down or nonexistent")
utils.AssertContainsError(t, readConn, fetchAllCustomers, "connect: connection refused")
Copy link
Member

@deepthi deepthi Jul 10, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We'll need a replacement test that produces the original error.

Comment on lines +110 to +111
// Wait for the tablet to become healthy
time.Sleep(30 * time.Millisecond)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To avoid flakiness, we should probably check in hc for the healthy tablet instead of sleeping for such a short amount of time.

Copy link
Contributor

This PR is being marked as stale because it has been open for 30 days with no activity. To rectify, you may do any of the following:

  • Push additional commits to the associated branch.
  • Remove the stale label.
  • Add a comment indicating why it is not stale.

If no action is taken within 7 days, this PR will be closed.

@github-actions github-actions bot added Stale Marks PRs as stale after a period of inactivity, which are then closed after a grace period. and removed Stale Marks PRs as stale after a period of inactivity, which are then closed after a grace period. labels Aug 19, 2024
Copy link
Contributor

This PR is being marked as stale because it has been open for 30 days with no activity. To rectify, you may do any of the following:

  • Push additional commits to the associated branch.
  • Remove the stale label.
  • Add a comment indicating why it is not stale.

If no action is taken within 7 days, this PR will be closed.

@github-actions github-actions bot added the Stale Marks PRs as stale after a period of inactivity, which are then closed after a grace period. label Sep 19, 2024
Copy link
Contributor

This PR was closed because it has been stale for 7 days with no activity.

@github-actions github-actions bot closed this Sep 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Component: VTGate NeedsBackportReason If backport labels have been applied to a PR, a justification is required NeedsDescriptionUpdate The description is not clear or comprehensive enough, and needs work NeedsIssue A linked issue is missing for this Pull Request NeedsWebsiteDocsUpdate What it says Stale Marks PRs as stale after a period of inactivity, which are then closed after a grace period. Type: Bug
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants