LuciferYang opened a new issue, #10252:
URL: https://github.com/apache/paimon/issues/10252

   ### Search before asking
   
   - [X] I searched in the [issues](https://github.com/apache/paimon/issues) 
and found nothing similar.
   
   ### Paimon version
   
   master
   
   ### Compute Engine
   
   N/A (core)
   
   ### Minimal reproduce step
   
   1. During snapshot expiration, `ChangelogManager.commitChangelog` writes 
`changelog-<id>` with `fileIO.writeFile(path, json, true)`, a direct overwrite 
of the target path. If the process or machine crashes mid-write, the changelog 
file is left at its final path either empty or partially written.
   2. A later `OrphanFilesClean` run calls 
`ChangelogManager.safelyGetAllChangelogs`. For the empty file, 
`Changelog.fromJson("")` throws `UncheckedIOException`, which is not caught by 
the consumer's `catch (IOException)`, so it propagates and `collectSnapshots` 
rethrows it as `IOException`. The whole enumeration fails and orphan cleaning 
cannot run, even though every other changelog file is valid.
   
   ### What doesn't meet your expectations?
   
   Changelog metadata should be written atomically, the way snapshots and hint 
files already are, so a crash never leaves a partial file at the canonical 
path. `safelyGetAllChangelogs` is meant to be resilient (it already tolerates 
`FileNotFoundException`), so one empty or torn changelog file should be skipped 
instead of aborting the whole listing.
   
   ### Anything else?
   
   _No response_
   
   ### Are you willing to submit a PR?
   
   - [X] I'm willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to