Conversation
… terminating `MergeTreeTransaction::afterCommit` and `rollback` are `noexcept`. They write part version metadata (`creation_csn`, `removal_csn`, `removal_tid`) and the CSN of a mutation to disk. A storage error in one of these writes escaped and terminated the server, although the transaction was already committed (or rolled back) in the transaction log and a restart repairs the files from it. The six writes now go through `retryMetadataStore`: the error is retried with backoff for up to 60 seconds per object; `LOGICAL_ERROR` and `NOT_IMPLEMENTED` are rethrown at once; an exhausted budget, or a server shutdown, rethrows as before, so a lost write is never hidden. `MergeTreeMutationEntry::writeCSN` used to append one line to the mutation file; a write that fails half-way, or is repeated, could leave a partial or duplicated `csn` line, which the loader rejects. The whole record is now written through a temporary file and replaces the old one, so a retry is idempotent. `loadMutations` tolerates a temporary file that a repair earlier in the same pass has already consumed. `KILL MUTATION` between the log write and `afterCommit` erases the mutation entry and cannot roll the committing transaction back; `setMutationCSN` then threw `LOGICAL_ERROR` under `noexcept`. It now logs a warning: the parts are already mutated and there is nothing left to write. Two `ONCE` failpoints and the stateless test `05053_transaction_metadata_store_retry` cover the commit of parts, the commit of a mutation and a rollback. Closes: #2344 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GhVd7eMAWdFubNk4g1B2Tx Signed-off-by: Mikhail Filimonov <mfilimonov@altinity.com>
…a-store-retry-squashed
k-morozov
self-requested a review
September 22, 2026 17:30
k-morozov
requested changes
Sep 24, 2026
filimonov
added a commit
to filimonov/ClickHouse
that referenced
this pull request
Sep 27, 2026
- moved `[cas-txn-commit-inside-noexcept-aftercommit]` -> ref-protocol.md (KEEP; added a status note that the class fix is tracked as open PR Altinity#2396) - moved `[cas-transient-lease-fence-surfaces-to-clients]` -> ref-protocol.md (KEEP) Part of unit u1-inbox of the CAS docs grooming campaign (verdict: tmp/groom/u1-inbox/verdict.md, 36/36 APPLY). Original text carried over verbatim per the unit's applier-brief override. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
filimonov
added a commit
to filimonov/ClickHouse
that referenced
this pull request
Sep 27, 2026
…rs_config copy with async inserts disabled Profile settings are read by AccessControl from the users file, so command-line profile flags never reached them, and this tree defaults async_insert to 1 while async inserts are refused inside transactions. The recipe now copies users.xml, links the CI override disable_async_inserts.xml and points the server at the copy via users_config; the transaction check is BEGIN TRANSACTION; ROLLBACK and a fourth check asserts async_insert = 0. PR Altinity#2396 (in progress, CAS-177). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V8mZSGiD8iJumpJMiQnrmC
…tation - `retryMetadataStore` takes a stopwatch started at the beginning of `afterCommit` / `rollback`, so the 60 s budget covers the whole callback instead of each object: a commit of N parts no longer waits up to N times the budget, and a retry on the unknown-state path blocks the log updating thread for at most one budget. - `killMutation` erases the map entry before deleting the file, so a retry after a failure could not delete the file anyway. It runs once; a non-invariant error is logged and the leftover file is removed at the next load. - `loadMutations` takes the directory listing before touching any file: repairing a record rewrites `mutation_N.txt` through a temporary file, and a directory iterator gives no guarantee about entries that change under it. - `writeCSN` sets the in-memory CSN after the file is replaced. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GhVd7eMAWdFubNk4g1B2Tx Signed-off-by: Mikhail Filimonov <mfilimonov@altinity.com>
…-26.6/transaction-metadata-store-retry-squashed
k-morozov
approved these changes
Sep 30, 2026
Member
PR #2396 Distributed-Systems Audit
SummaryNo confirmed distributed-systems defects in the reviewed scope. |
Member
PR #2396 CI Verification ReportVerification (2026-10-01)
VerdictNo current failure is caused by this PR, and no failure remains The final run has seven logically distinct failed jobs and one cancelled job. GitHub also shows duplicate commit-status contexts and the aggregate
Current red checks
Direct coverage of the changeThe added
The test is intentionally skipped on S3-storage lanes by its tags. Earlier failures on the first two PR revisions are superseded on the final head:
Recommendations
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
MergeTreeTransaction::afterCommitandrollbackarenoexceptand write part version metadata and mutation CSNs to disk. A storage error in one of these writes escaped and terminated the server, although the transaction was already committed (or rolled back) in the transaction log and a restart repairs the files from it. This is what killed the server in the CAS test runs of the linked issue.The six writes now go through one helper,
retryMetadataStore: the error is retried with backoff for up to 60 seconds per object;LOGICAL_ERRORandNOT_IMPLEMENTEDare rethrown at once; an exhausted budget, or a server shutdown, rethrows as before, so a lost write is never hidden.MergeTreeMutationEntry::writeCSNrewrites the whole mutation record through a temporary file, so a retry is idempotent.setMutationCSNlogs a warning instead of throwingLOGICAL_ERRORwhenKILL MUTATIONerased the entry during the commit window. TwoONCEfailpoints and the stateless test05053_transaction_metadata_store_retrycover the commit of parts, the commit of a mutation and a rollback.The change is generic MergeTree code and is meant to be cherry-picked to upstream unchanged.
Closes: #2344
Changelog category (leave one):
Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):
Fixed a server termination when a disk write of transaction metadata (part CSN or mutation CSN) failed inside the commit or rollback of a MergeTree transaction; such writes are now retried for a bounded time. Also fixed a termination when
KILL MUTATIONraced with the commit of a transactional mutation.Documentation entry for user-facing changes
CI/CD Options
Exclude tests:
Regression jobs to run:
🤖 Generated with Claude Code
https://claude.ai/code/session_01GhVd7eMAWdFubNk4g1B2Tx