Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Return error instead of panicking if rewriting fails #343

Merged
merged 25 commits into from
Dec 7, 2023
Merged
Show file tree
Hide file tree
Changes from 22 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/rust.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ jobs:
uses: actions-rs/toolchain@v1
with:
profile: minimal
toolchain: 1.66.0
toolchain: 1.67.1
override: true
components: rustfmt, clippy, rust-src
- uses: Swatinem/rust-cache@v1
Expand Down
4 changes: 1 addition & 3 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name = "raft-engine"
version = "0.4.1"
authors = ["The TiKV Project Developers"]
edition = "2018"
rust-version = "1.66.0"
rust-version = "1.67.1"
description = "A persistent storage engine for Multi-Raft logs"
readme = "README.md"
repository = "https://github.com/tikv/raft-engine"
Expand Down Expand Up @@ -95,8 +95,6 @@ nightly_group = ["nightly", "swap"]
raft-proto = { git = "https://github.com/tikv/raft-rs", branch = "master" }
protobuf = { git = "https://github.com/pingcap/rust-protobuf", branch = "v2.8" }
protobuf-codegen = { git = "https://github.com/pingcap/rust-protobuf", branch = "v2.8" }
# TODO: Use official grpc-rs once https://github.com/tikv/grpc-rs/pull/622 is merged.
grpcio = { git = "https://github.com/tabokie/grpc-rs", branch = "v0.10.x-win" }

[workspace]
members = ["stress", "ctl"]
2 changes: 1 addition & 1 deletion src/engine.rs
Original file line number Diff line number Diff line change
Expand Up @@ -172,7 +172,7 @@ where
}
perf_context!(log_write_duration).observe_since(now);
if sync {
// As per trait protocol, this error should be retriable. But we panic anyway to
// As per trait protocol, sync error should be retriable. But we panic anyway to
// save the trouble of propagating it to other group members.
self.pipe_log.sync(LogQueue::Append).expect("pipe::sync()");
}
Expand Down
7 changes: 5 additions & 2 deletions src/file_pipe_log/log_file.rs
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,8 @@ pub struct LogFileWriter<F: FileSystem> {
capacity: usize,
}

// All APIs provided by `LogFileWriter` are fail-safe, i.e. caller can continue
// using the same "writer" even if the previous operation failed.
impl<F: FileSystem> LogFileWriter<F> {
fn open(
handle: Arc<F::Handle>,
Expand All @@ -67,7 +69,7 @@ impl<F: FileSystem> LogFileWriter<F> {
}
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add a comment to this struct stating it should be fail-safe, i.e. user can still use the writer without breaking data consistency if any operation has failed.


fn write_header(&mut self, format: LogFileFormat) -> IoResult<()> {
self.writer.seek(SeekFrom::Start(0))?;
self.writer.rewind()?;
self.written = 0;
let mut buf = Vec::with_capacity(LogFileFormat::encoded_len(format.version));
format.encode(&mut buf).unwrap();
Expand Down Expand Up @@ -119,7 +121,8 @@ impl<F: FileSystem> LogFileWriter<F> {

pub fn sync(&mut self) -> IoResult<()> {
let _t = StopWatch::new(&*LOG_SYNC_DURATION_HISTOGRAM);
self.handle.sync()?;
// Panic if sync fails, in case of data loss.
self.handle.sync().unwrap();
Ok(())
}

Expand Down
35 changes: 11 additions & 24 deletions src/file_pipe_log/pipe.rs
Original file line number Diff line number Diff line change
Expand Up @@ -177,8 +177,13 @@ impl<F: FileSystem> SinglePipe<F> {

// Skip syncing directory in Windows. Refer to badger's discussion for more
// detail: https://github.com/dgraph-io/badger/issues/699
//
// Panic if sync calls fail, keep consistent with the behavior of
// `LogFileWriter::sync()`.
#[cfg(not(windows))]
std::fs::File::open(PathBuf::from(&self.paths[path_id])).and_then(|d| d.sync_all())?;
std::fs::File::open(PathBuf::from(&self.paths[path_id]))
.and_then(|d| d.sync_all())
.unwrap();
Ok(())
}

Expand Down Expand Up @@ -321,12 +326,7 @@ impl<F: FileSystem> SinglePipe<F> {
fail_point!("file_pipe_log::append");
let mut writable_file = self.writable_file.lock();
if writable_file.writer.offset() >= self.target_file_size {
if let Err(e) = self.rotate_imp(&mut writable_file) {
panic!(
"error when rotate [{:?}:{}]: {e}",
self.queue, writable_file.seq,
);
}
self.rotate_imp(&mut writable_file)?;
v01dstar marked this conversation as resolved.
Show resolved Hide resolved
}

let seq = writable_file.seq;
Expand Down Expand Up @@ -359,9 +359,7 @@ impl<F: FileSystem> SinglePipe<F> {
}
let start_offset = writer.offset();
if let Err(e) = writer.write(bytes.as_bytes(&ctx), self.target_file_size) {
if let Err(te) = writer.truncate() {
panic!("error when truncate {seq} after error: {e}, get: {}", te);
}
writer.truncate()?;
if is_no_space_err(&e) {
// TODO: There exists several corner cases should be tackled if
// `bytes.len()` > `target_file_size`. For example,
Expand All @@ -372,12 +370,7 @@ impl<F: FileSystem> SinglePipe<F> {
// - [3] Both main-dir and spill-dir have several recycled logs.
// But as `bytes.len()` is always smaller than `target_file_size` in common
// cases, this issue will be ignored temprorarily.
if let Err(e) = self.rotate_imp(&mut writable_file) {
panic!(
"error when rotate [{:?}:{}]: {e}",
self.queue, writable_file.seq
);
}
self.rotate_imp(&mut writable_file)?;
v01dstar marked this conversation as resolved.
Show resolved Hide resolved
// If there still exists free space for this record, rotate the file
// and return a special TryAgain Err (for retry) to the caller.
return Err(Error::TryAgain(format!(
Expand All @@ -403,15 +396,9 @@ impl<F: FileSystem> SinglePipe<F> {

fn sync(&self) -> Result<()> {
let mut writable_file = self.writable_file.lock();
let seq = writable_file.seq;
let writer = &mut writable_file.writer;
{
let _t = StopWatch::new(perf_context!(log_sync_duration));
if let Err(e) = writer.sync() {
panic!("error when sync [{:?}:{seq}]: {e}", self.queue);
}
}

let _t = StopWatch::new(perf_context!(log_sync_duration));
writer.sync().map_err(Error::Io)?;
Ok(())
}

Expand Down
2 changes: 1 addition & 1 deletion src/purge.rs
Original file line number Diff line number Diff line change
Expand Up @@ -439,7 +439,7 @@ where
)?;
let file_handle = self.pipe_log.append(LogQueue::Rewrite, log_batch)?;
if sync {
self.pipe_log.sync(LogQueue::Rewrite)?
self.pipe_log.sync(LogQueue::Rewrite)?;
}
log_batch.finish_write(file_handle);
self.memtables.apply_rewrite_writes(
Expand Down
130 changes: 83 additions & 47 deletions tests/failpoints/test_io_error.rs
Original file line number Diff line number Diff line change
Expand Up @@ -124,8 +124,7 @@ fn test_file_write_error() {
assert_eq!(engine.last_index(2).unwrap(), 1);
}

#[test]
fn test_file_rotate_error() {
fn test_file_rotate_error(restart_after_failure: bool) {
let dir = tempfile::Builder::new()
.prefix("test_file_rotate_error")
.tempdir()
Expand All @@ -138,68 +137,113 @@ fn test_file_rotate_error() {
let fs = Arc::new(ObfuscatedFileSystem::default());
let entry = vec![b'x'; 1024];

let engine = Engine::open_with_file_system(cfg.clone(), fs.clone()).unwrap();
engine
let mut engine = Some(Engine::open_with_file_system(cfg.clone(), fs.clone()).unwrap());
let mut engine_ref = engine.as_ref().unwrap();
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No need, you can re-assign a variable after it's moved, e.g. drop(engine); engine = Engine::new();

engine_ref
.write(&mut generate_batch(1, 1, 2, Some(&entry)), false)
.unwrap();
engine
engine_ref
.write(&mut generate_batch(1, 2, 3, Some(&entry)), false)
.unwrap();
engine
engine_ref
.write(&mut generate_batch(1, 3, 4, Some(&entry)), false)
.unwrap();
engine
engine_ref
.write(&mut generate_batch(1, 4, 5, Some(&entry)), false)
.unwrap();
assert_eq!(engine.file_span(LogQueue::Append).1, 1);
assert_eq!(engine_ref.file_span(LogQueue::Append).1, 1);
// The next write will be followed by a rotate.
{
// Fail to sync old log file.
let _f = FailGuard::new("log_fd::sync::err", "return");
assert!(catch_unwind_silent(|| {
let _ = engine.write(&mut generate_batch(1, 4, 5, Some(&entry)), false);
let _ = engine_ref.write(&mut generate_batch(1, 4, 5, Some(&entry)), false);
})
.is_err());
assert_eq!(engine.file_span(LogQueue::Append).1, 1);
}
if restart_after_failure {
engine = None;
engine = Some(Engine::open_with_file_system(cfg.clone(), fs.clone()).unwrap());
engine_ref = engine.as_ref().unwrap();
}
assert_eq!(engine_ref.file_span(LogQueue::Append).1, 1);
{
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Make two versions of this test: fn test_file_rotate_error(restart: bool)

// case 1
if restart {
  let engine = Engine::open_with_file_system(cfg.clone(), fs.clone()).unwrap();
}
// case 2
// ...

// Fail to create new log file.
let _f = FailGuard::new("default_fs::create::err", "return");
assert!(catch_unwind_silent(|| {
let _ = engine.write(&mut generate_batch(1, 4, 5, Some(&entry)), false);
})
.is_err());
assert_eq!(engine.file_span(LogQueue::Append).1, 1);
assert!(engine_ref
.write(&mut generate_batch(1, 4, 5, Some(&entry)), false)
.is_err());
}
if restart_after_failure {
engine = None;
engine = Some(Engine::open_with_file_system(cfg.clone(), fs.clone()).unwrap());
engine_ref = engine.as_ref().unwrap();
}
let num_files_before = std::fs::read_dir(&dir).unwrap().count();
{
// Fail to write header of new log file.
let _f = FailGuard::new("log_file::write::err", "1*off->return");
assert!(catch_unwind_silent(|| {
let _ = engine.write(&mut generate_batch(1, 4, 5, Some(&entry)), false);
})
.is_err());
assert_eq!(engine.file_span(LogQueue::Append).1, 1);
assert!(engine_ref
.write(&mut generate_batch(1, 4, 5, Some(&entry)), false)
.is_err());
}
{
if restart_after_failure {
engine = None;
engine = Some(Engine::open_with_file_system(cfg.clone(), fs.clone()).unwrap());
engine_ref = engine.as_ref().unwrap();
// The new log file is added during recovery phase of restart.
assert_eq!(engine_ref.file_span(LogQueue::Append).1, 2);
} else {
assert_eq!(engine_ref.file_span(LogQueue::Append).1, 1);
}
// Although the header is not written, the file is still created.
assert_eq!(
std::fs::read_dir(&dir).unwrap().count() - num_files_before,
1
);
if !restart_after_failure {
// If the engine restarted, the write does not require sync will succeed.
// Fail to sync new log file. The old log file is already sync-ed at this point.
let _f = FailGuard::new("log_fd::sync::err", "return");
assert!(catch_unwind_silent(|| {
let _ = engine.write(&mut generate_batch(1, 4, 5, Some(&entry)), false);
let _ = engine_ref.write(&mut generate_batch(1, 4, 5, Some(&entry)), false);
})
.is_err());
assert_eq!(engine.file_span(LogQueue::Append).1, 1);
assert_eq!(engine_ref.file_span(LogQueue::Append).1, 1);
}

// Only one log file should be created after all the incidents.
assert_eq!(
std::fs::read_dir(&dir).unwrap().count() - num_files_before,
1
);
// We can continue writing after the incidents.
engine
engine_ref
.write(&mut generate_batch(2, 1, 2, Some(&entry)), true)
.unwrap();
drop(engine);
let engine = Engine::open_with_file_system(cfg, fs).unwrap();
assert_eq!(engine.first_index(1).unwrap(), 1);
assert_eq!(engine.last_index(1).unwrap(), 4);
assert_eq!(engine.first_index(2).unwrap(), 1);
assert_eq!(engine.last_index(2).unwrap(), 1);
if restart_after_failure {
engine = None;
engine = Some(Engine::open_with_file_system(cfg.clone(), fs.clone()).unwrap());
engine_ref = engine.as_ref().unwrap();
}
assert_eq!(
std::fs::read_dir(&dir).unwrap().count() - num_files_before,
1
);
assert_eq!(engine_ref.first_index(1).unwrap(), 1);
assert_eq!(engine_ref.last_index(1).unwrap(), 4);
assert_eq!(engine_ref.first_index(2).unwrap(), 1);
assert_eq!(engine_ref.last_index(2).unwrap(), 1);
}

#[test]
fn test_file_rotate_error_without_restart() {
test_file_rotate_error(false);
}

#[test]
fn test_file_rotate_error_with_restart() {
test_file_rotate_error(true);
}

#[test]
Expand Down Expand Up @@ -262,10 +306,8 @@ fn test_concurrent_write_error() {
let _f2 = FailGuard::new("log_file::truncate::err", "return");
let entry_clone = entry.clone();
ctx.write_ext(move |e| {
catch_unwind_silent(|| {
e.write(&mut generate_batch(1, 11, 21, Some(&entry_clone)), false)
})
.unwrap_err();
e.write(&mut generate_batch(1, 11, 21, Some(&entry_clone)), false)
.unwrap_err();
});
// We don't test followers, their panics are hard to catch.
ctx.join();
Expand Down Expand Up @@ -527,20 +569,17 @@ fn test_no_space_write_error() {
cfg.dir = dir.path().to_str().unwrap().to_owned();
cfg.spill_dir = Some(spill_dir.path().to_str().unwrap().to_owned());
{
// Case 1: `Write` is abnormal for no space left, Engine should panic at
// Case 1: `Write` is abnormal for no space left, Engine should fail at
// `rotate`.
let cfg_err = Config {
target_file_size: ReadableSize(1),
..cfg.clone()
};
let engine = Engine::open(cfg_err).unwrap();
let _f = FailGuard::new("log_fd::write::no_space_err", "return");
assert!(catch_unwind_silent(|| {
engine
.write(&mut generate_batch(2, 11, 21, Some(&entry)), true)
.unwrap_err();
})
.is_err());
assert!(engine
.write(&mut generate_batch(2, 11, 21, Some(&entry)), true)
.is_err());
assert_eq!(
0,
engine
Expand All @@ -554,12 +593,9 @@ fn test_no_space_write_error() {
let _f1 = FailGuard::new("log_fd::write::no_space_err", "2*return->off");
let _f2 = FailGuard::new("file_pipe_log::force_choose_dir", "return");
// The first write should fail, because all dirs run out of space for writing.
assert!(catch_unwind_silent(|| {
engine
.write(&mut generate_batch(2, 11, 21, Some(&entry)), true)
.unwrap_err();
})
.is_err());
assert!(engine
.write(&mut generate_batch(2, 11, 21, Some(&entry)), true)
.is_err());
assert_eq!(
0,
engine
Expand Down
Loading