Repository navigation
[feat][broker] PIP-469: Legacy-aware topic policies backend routing and metadata-store topic policies - #25707
Conversation
…nd metadata-store topic policies
current: BUILD SUCCESSFUL in 2m 18s
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Implements PIP-469 topic-policies backend routing to preserve legacy __change_events behavior while enabling a new metadata-store-backed topic policies implementation, and refactors existing topic policies tests to run significantly faster.
Changes:
- Add
LegacyAwareTopicPoliciesServiceto route per-namespace operations to either legacy system-topic or configured backend. - Introduce
MetadataStoreTopicPoliciesServiceimplementation backed by metadata stores, with listener support. - Refactor
TopicPoliciesTestlifecycle to reduce repeated broker setup/teardown and add a derived test suite for the metadata-store backend.
Reviewed changes
Copilot reviewed 9 out of 9 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| pulsar-broker/src/test/java/org/apache/pulsar/broker/service/TopicPolicyTestUtils.java | Extends bypass-cache helper to work with legacy-aware routing and the metadata-store backend. |
| pulsar-broker/src/test/java/org/apache/pulsar/broker/service/LegacyAwareTopicPoliciesServiceTest.java | Adds upgrade/downgrade and listener behavior coverage for legacy-aware routing and metadata-store storage. |
| pulsar-broker/src/test/java/org/apache/pulsar/broker/admin/TopicPoliciesTest.java | Refactors test lifecycle to reduce runtime and adapts tests to multiple policies backends. |
| pulsar-broker/src/test/java/org/apache/pulsar/broker/admin/MetadataStoreTopicPoliciesTest.java | Reuses TopicPoliciesTest against the metadata-store backend, disabling inapplicable system-topic tests. |
| pulsar-broker/src/main/java/org/apache/pulsar/broker/service/SystemTopicBasedTopicPoliciesService.java | Loosens visibility on bundle-ownership cleanup to enable reuse/integration. |
| pulsar-broker/src/main/java/org/apache/pulsar/broker/service/MetadataStoreTopicPoliciesService.java | Adds new metadata-store-backed implementation for topic policies with store notifications and listeners. |
| pulsar-broker/src/main/java/org/apache/pulsar/broker/service/LegacyAwareTopicPoliciesService.java | Adds per-namespace routing layer between legacy system-topic backend and configured backend. |
| pulsar-broker/src/main/java/org/apache/pulsar/broker/PulsarService.java | Wraps configured topic policies service with legacy-aware routing when system topics are enabled. |
| pulsar-broker-common/src/main/java/org/apache/pulsar/broker/ServiceConfiguration.java | Updates configuration documentation to describe built-in topic policies service implementations and legacy behavior. |
|
We might need to consider whether to change the |
dao-jun
left a comment
There was a problem hiding this comment.
LGTM, just 2 minor comments
- Metadata-store listeners are never unregistered on close() (resource leak)
MetadataStoreTopicPoliciesService.start() line 354-355:
localStore.registerListener(notification -> handleNotification(notification, false));
configurationStore.registerListener(notification -> handleNotification(notification, true));
The return value of registerListener (a registration handle) is discarded. close() only clears the local listeners map and invalidates caches, but never unregisters these metadata-store listeners. After close(), the service can still receive and process notifications (the closed flag guards most paths, but the listener
lambdas themselves are still held by the metadata store). Consider capturing and closing the registration handles in close().
- Path structure deviates from PIP-469 design document
The PIP design doc specifies:
- Global: /admin/topic-policies/{tenant}/{namespace}/{domain}/{encodedTopic}
- Local: /admin/local-policies/topic-policies/{tenant}/{namespace}/{domain}/{encodedTopic}
The implementation uses:
- Global: /admin/topic-policies/global/{tenant}/{namespace}/{domain}/{encodedTopic}
- Local: /admin/topic-policies/local/{tenant}/{namespace}/{domain}/{encodedTopic}
The code's approach is arguably cleaner (both scopes under one root), but the discrepancy from the approved design should be explicitly called out and either the PIP or the code should be updated for consistency.
|
Let me address these two comments before merging |
|
@dao-jun I've updated the document for why the implementation adopts a different path.
Regarding the previous comment, it seems to be wrong. Firstly, Secondly, it follows the similar pattern of Though this PR has registered two listeners with a parameter that indicates if the policy is global so that we don't need to check if the notification path starts with Could you double check the review comments if they are generated from LLM? |
|
@nodece Let me merge it first because this topic is out of the scope of the topic policies service itself. I agree that your comments [1] and [2] make sense, but it's more like an issue that should be resolved by structured concurrency, which needs careful design. It would be better add a common abstraction for listeners and skip all of them after closing the topic policies service. [1] #25707 (comment) |
|
I tried to write a test to reproduce and then found that even if a listener is registered due to the race, there still might be a real issue. private static final CountDownLatch realCloseLatch = new CountDownLatch(1);
private static final CountDownLatch closeLatch = new CountDownLatch(1);
public static class MockTopicPoliciesService extends MetadataStoreTopicPoliciesService {
public void close() {
super.close();
realCloseLatch.countDown();
try {
if (!closeLatch.await(10, TimeUnit.SECONDS)) {
log.info().log("Failed to close TopicPoliciesService within the timeout");
}
} catch (InterruptedException e) {
log.info().log("Interrupted when closing TopicPoliciesService");
}
}
}The test can be easily written based on the mocked implementation above.
Therefore, basically these zombie listeners won't be notified. In another case, if the CAS of the |
…nd metadata-store topic policies (apache#25707) (cherry picked from commit 8652efa) (cherry picked from commit 712372f) (cherry picked from commit c333504)
…nd metadata-store topic policies (apache#25707) (cherry picked from commit 8652efa) (cherry picked from commit 712372f) (cherry picked from commit c333504)
…nd metadata-store topic policies (apache#25707) (cherry picked from commit 8652efa) (cherry picked from commit 712372f)
pip: #25547
This PR reuses
TopicPoliciesTestto test most functionality of the new metadata store based implementation, so it also introduces improvements onTopicPoliciesTest, which requires too much time to run before (100+ tests, where each test callsinternalSetupandinternalCleanup).