Conversation
…pache#286) confirm() unconditionally called onConfirm(confirmingMsg.seq) with the PASSED-IN message, even when the drain loop removed nothing because the head of unconfirmedPacketIds was still un-acked. A client acknowledging packetId 2 while packetId 1 is in flight (the spec places no ordering requirement on PUBACK) would then clear stagingBuffer up to the second message's seq and commit sendBufferUpToSeq past it - deleting the never-acknowledged first message from the inbox. On session resume it is not redelivered: permanent loss. Advance the watermark only when the drain loop actually removed a contiguous prefix; when zero entries were removed, do not call onConfirm at all. Regression test: outOfOrderPubAckMustNotAdvanceInboxWatermark. Control experiment: fails on unfixed code, passes with the fix. Full PersistentSessionHandlerTest (24) passes. Fixes apache#286
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Baseline:
main @ eef5e3af(the PR's base commit).Summary
confirm()unconditionally calledonConfirm(confirmingMsg.seq)with the passed-in message, even when the drain loop removed nothing because the head ofunconfirmedPacketIdswas still un-acked. A client acknowledgingpacketId 2whilepacketId 1is in flight (the spec places no ordering requirement on PUBACK) would then:confirmingMsgstill refers to the parameter),onConfirm(secondMsg.seq)anyway,MQTTPersistentSessionHandler, clearstagingBuffer.headMap(secondSeq, true)— including the never-acknowledged first message — advanceinboxConfirmedUpToSeq, and commitsendBufferUpToSeqto the inbox store, which deletes the corresponding chunk range.On session resume the first message is not redelivered: permanent loss of a never-acknowledged message.
Root cause
The same over-confirmation is reachable without any client misbehaviour: the five delayed-failure paths (
:1115,:1122,:1152,:1161,:1166) runctx.executor().execute(() -> confirm(packetId, false))after the fact, by which time an older entry may be sitting un-acked at the head.Change
Advance the watermark only when the drain loop actually removed a contiguous prefix: track whether any entry was removed and skip the
onConfirmcall entirely when nothing was.Testing
Regression test
MQTT3PersistentSessionHandlerTest.outOfOrderPubAckMustNotAdvanceInboxWatermark: fetch two QoS1 messages, PUBACK the second only, verifyinboxClientnever receives acommitwithsendBufferUpToSeq.Control experiment on unfixed code: the test fails (a commit IS issued past the un-acked message). With the fix: passes. Full
MQTT3PersistentSessionHandlerTest(24 tests) passes.Happy to adjust the semantics if the maintainers prefer a different watermark policy.
Full report: #286.
Fixes #286