forked from temporalio/temporal
-
Notifications
You must be signed in to change notification settings - Fork 0
Fence scheduler rollback destination ownership #47
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,44 @@ | ||
| # CHASM-to-workflow rollback ownership | ||
|
|
||
| ## Fix | ||
|
|
||
| Rollback now stores the initiating request ID in `WorkflowMigrationState` in the same CHASM | ||
| transition that pauses the source. Every destination `StartWorkflowExecution` attempt reuses that | ||
| ID. A `WorkflowExecutionAlreadyStarted` response is accepted only when its recorded start request | ||
| ID matches; otherwise the task reports a conflict and leaves CHASM paused and migration-pending. | ||
|
|
||
| The admin handler generates an ID when an older caller omits one before beginning the CHASM | ||
| transition. A task created by an older binary without durable identity fails closed and retains | ||
| the source instead of guessing ownership. | ||
|
|
||
| This prevents two reproduced failures: | ||
|
|
||
| - An unrelated V1 workflow at the destination no longer causes CHASM to close. | ||
| - If the destination start commits but the CHASM close fails, retry uses the same start identity. | ||
| A destination that subsequently closes cannot be recreated with a rotated request ID and | ||
| `ALLOW_DUPLICATE`. | ||
|
|
||
| The strict check may retain CHASM if the owned V1 workflow has already continued as new and the | ||
| current run no longer reports the original start request ID. That is a safe availability failure: | ||
| the task does not close the source without ownership proof. A future chain-owner field can permit | ||
| that case without weakening the invariant. | ||
|
|
||
| ## Sentinel release | ||
|
|
||
| The rollback preflight now blocks a dummy workflow only while its status is running. Completed and | ||
| terminated sentinels have released their reservation and no longer delay rollback until history | ||
| retention deletes them. Existing running-sentinel behavior is unchanged. | ||
|
|
||
| ## Failure and load assessment | ||
|
|
||
| - Crash before destination start: the durable request ID is retried. | ||
| - Destination commit with lost response: the matching `AlreadyStarted` response reconciles it. | ||
| - Source-close failure: retry cannot create another workflow chain with a different ID. | ||
| - Foreign collision or missing identity: CHASM remains paused and visible for operator recovery. | ||
| - Namespace failover: the request ID is replicated as CHASM state; no process-local cache is used. | ||
| - At 10x rollback load, the fix adds no RPC and no ordinary scheduler hot-path work. It stores one | ||
| string per pending rollback and replaces random identity generation with a state read already | ||
| required to export the snapshot. | ||
|
|
||
| The forward workflow-to-CHASM defects require the separate History ingress-fence protocol and are | ||
| not claimed fixed by this rollback layer. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When an older caller omits
request_id, each Admin API invocation generates a different value. If the first invocation commitsMigrateToWorkflowbut its response is lost, the caller's retry reaches the pending migration with a new ID andScheduler.MigrateToWorkflowreturnsAlreadyExistsinstead of idempotent success. The fallback ID must remain stable across external retries, or omission should be handled without treating retries as competing migrations.Useful? React with 👍 / 👎.