Rangsh opened a new issue, #12492:
URL: https://github.com/apache/seatunnel/issues/12492

   ### Related
   
   Follow-up from review of https://github.com/apache/seatunnel/pull/12081 
(residual gap agreed out of scope for that PR).
   
   cc @DanielLeens @SEZ9
   
   ### Describe the bug / gap
   
   In `WALWorkHandler` (`imap-storage-file`), the sole Disruptor consumer 
currently catches `Exception` around `writer.write(...)` and around 
`executeResponse(...)`:
   
   - `catch (Exception e)` does **not** catch `Error` (e.g. `OutOfMemoryError`).
   - If an `Error` escapes `writer.write()` (or otherwise kills the worker), 
the Disruptor consumer thread dies.
   - Nothing currently detects that the worker is dead, so it is not restarted.
   - After that point, in-flight / subsequent APPEND waiters still resolve via 
their **timed** `RequestFuture.get(timeout, unit)` path (they ride out 
`writDataTimeoutMilliseconds` / the shared batch deadline), but the worker 
itself stays dead and further APPENDs cannot succeed until process restart.
   
   `WALWorkHandlerSurvivabilityTest` already covers the `Exception` / 
fail-close path (non-`IOException` from `write()`, and `hsync()` failure). It 
does **not** cover this `Error` / dead-worker detection + recovery gap.
   
   ### Expected behavior
   
   When the WAL worker dies because of an `Error` (or equivalent uncaught 
throwable that kills the sole consumer):
   
   1. The failure is detected (not silent forever).
   2. Callers are not left depending only on wait timeouts with no indication 
that the writer pipeline is permanently down.
   3. Ideally the worker can be restarted safely, or the storage / node fails 
loudly in a controlled way rather than silently fail-closing forever.
   
   ### Proposed direction (for discussion)
   
   Separate from #12081. Possible approaches to evaluate in a follow-up PR:
   
   - Widen the handler boundary carefully for `Error` / `Throwable` where safe 
(without swallowing fatal JVM errors incorrectly), **and/or**
   - Add Disruptor exception handler / supervisor that detects consumer death 
and surfaces a clear failure / triggers recovery.
   - Add a regression test that proves an injected `Error` does not leave the 
pipeline silently dead forever.
   
   ### Scope note
   
   Do **not** block merge of #12081 on this. That PR already addresses the 
`Exception` survivability + fail-close + timed wait contract; this issue tracks 
only the residual `Error` / dead-worker gap called out by @SEZ9 and 
@DanielLeens.
   
   ### Environment
   
   - Module: `seatunnel-engine-storage/imap-storage-plugins/imap-storage-file`
   - Class: 
`org.apache.seatunnel.engine.imap.storage.file.disruptor.WALWorkHandler`
   - Head discussed in review: `7f69d7f69` on PR #12081


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to