Skip to content

[fix][broker] Propagate bundle split failures to the completion future - #26735

Merged
lhotari merged 1 commit into
apache:masterfrom
zhanghaou:fix-bundle-split-failure
Sep 28, 2026
Merged

lhotari merged 1 commit into
apache:masterfrom
zhanghaou:fix-bundle-split-failure

Conversation

@zhanghaou

Copy link
Copy Markdown
Contributor

Motivation

When using a non-extensible load manager, a failed bundle cache load can leave the future returned by NamespaceService.splitAndOwnBundle() pending indefinitely.

In splitAndOwnBundleOnceAndRetry(), the stage returned by splitBundles(...).thenAccept(...) is discarded. If splitBundles() completes exceptionally, the success callback is skipped and updateFuture is never completed. The outer completion future consequently remains pending.

The surrounding try/catch does not handle exceptional future completion, including when the returned future has already failed. The ownership-release timeout does not cover this failure because it is only installed after the namespace bundle update succeeds.

Modifications

  • Handle exceptions on the stage returned by splitBundles(...).thenAccept(...) and propagate them to updateFuture, allowing the existing failure-handling path to complete the outer future.
  • Add NamespaceServiceSplitFailureTest in the broker test group, covering both an already-failed policies read and a policies read that fails after splitAndOwnBundle() returns.
  • Exercise the real namespace service and bundle factory with an isolated, non-started broker test context, injecting failures at the local policies read boundary.

Verifying this change

The new parameterized regression test asserts that the outer future completes exceptionally with ServiceUnitNotReadyException in both failure timings.

Local validation:

  • Without the fix, both cases fail because the outer future remains pending.
  • With the fix, both cases pass with the default test-group filters.
  • quickCheck passes.
./gradlew :pulsar-broker:test \
  --tests 'org.apache.pulsar.broker.namespace.NamespaceServiceSplitFailureTest' \
  -PtestRetryCount=0 \
  -PtestFailFast=false

./gradlew quickCheck

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

Handle failures from the splitBundles dependent stage so namespace splitting does not remain pending. Add broker-group regression coverage for immediate and delayed bundle cache load failures.

Assisted-by: OpenAI Codex

@lhotari lhotari left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@lhotari
lhotari merged commit 4e098ac into apache:master Sep 28, 2026
44 checks passed
@zhanghaou
zhanghaou deleted the fix-bundle-split-failure branch September 29, 2026 03:01
ascentstream-bot pushed a commit to ascentstream/pulsar that referenced this pull request Oct 1, 2026
ascentstream-bot pushed a commit to ascentstream/pulsar that referenced this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants