[BUG][PPL] Handle cancellation during Calcite-to-V2 fallback for sync and async queries
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
Línea de trabajo
Start by tracing the shared QueryService execution path used by synchronous PPL and async PPLQueryRunner, then inspect QueryJob and native PPL task cancellation. Add deterministic concurrency tests for both cancellation-versus-fallback orderings and the listed cancellation scenarios, with fallback enabled. Done means cancellation prevents fallback when it wins admission, admitted fallback stops and cleans up when cancellation follows, and sync/async integration tests verify observable attempts, worker drain, and PIT cleanup.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Problem
Synchronous PPL and async PPL execution share QueryService and its Calcite-to-V2 fallback decision. When cancellation races with an execution failure, the fallback path can treat that failure as an ordinary error and start V2 execution after cancellation was requested.
Recognizing CancellationException, TaskCancelledException, or wrapped/suppressed InterruptedException is only an exception-based safeguard. Cancellation state can be true while the exception contains no cancellation marker. There is also a race between checking a flag and starting fallback.
This issue tracks cancellation/fallback handling separately from the async DELETE work in #5846. It covers both synchronous and asynchronous PPL, rather than relying on async-only QueryJob state. Related: #5765 and production hardening in #5801.
Relevant behavior and evidence
- Normal synchronous PPL requests and async
PPLQueryRunnerrequests both reach the sameQueryServiceexecution path. QueryJobowns async lifecycle status. Synchronous queries have noQueryJob; native PPL task cancellation must also participate.- Async DELETE removes the job from the store before cancelling it, so executing queries cannot depend on a later job-store lookup.
- Unit-level regression scenarios reproduced V2 invocation after interrupted PIT waiting and after cancellation was suppressed during resource cleanup when
plugins.calcite.fallback.allowed=true. These are unit-level reproductions, not a claimed end-to-end production incident. - Existing async cancellation ITs verify cancellation acknowledgment, worker drain, bounded search activity, and PIT cleanup. They do not directly observe V2 fallback attempts or force the cancellation/fallback race; fallback is disabled by default.
Proposed direction
Use an explicit control allocated per PPL execution/task, shared with the async job when one exists. Keep OpenSearch task types out of the core-facing contract. Publish cancellation before callbacks and before exposing the relevant cancellation state, and atomically coordinate that publication with fallback admission. Propagate the same control across worker handoffs.
The implementation should define two orderings:
- Cancellation wins before fallback admission: V2 fallback must not start.
- Fallback was admitted first: cancellation must reach that execution, with bounded stop and cleanup behavior. Admission alone does not guarantee that already-running work stops.
Exception recognition may remain a secondary safeguard; it must not be the sole cancellation authority. Preserve timeout failure semantics and ordinary uncancelled fallback behavior. The final design need not use the proposed API shape if another explicit-state solution meets these guarantees.
Acceptance criteria
- Cover synchronous PPL task cancellation and async PPL DELETE, including owner forwarding.
- A cancelled execution followed by an ordinary error with no cancellation cause cannot be admitted to V2 fallback.
- Define and test cancellation-versus-fallback admission ordering with deterministic concurrency tests.
- Define and verify stopping and cleanup when fallback was admitted before cancellation.
- Cancellation remains observable after async job removal and across worker/thread handoffs; signals do not leak between queries on reused workers.
- Preserve terminal-state races, timeout failure semantics, and successful unsupported-query fallback when no cancellation is requested.
- Add UTs with fallback enabled for plain errors, interrupted PIT waiting, suppressed cleanup cancellation, and both race orderings.
- Add sync and async ITs with fallback explicitly enabled and restored, and observable fallback attempts. Verify worker drain and PIT/search-context cleanup.
Scope decision for #5846
At the author's request, cancellation/fallback policy changes and their dedicated regression tests are deferred to this issue. Regular async cancellation, deletion, routing, authorization, retention cleanup, and their lifecycle ITs remain in #5846.
- Lenguaje dominante
- Java
- Estrellas
- 175
- Forks
- 231
- Merge medio
- 2 d 5 h
- PR fusionados (30 d)
- 37
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de opensearch-project/sql
-
enhancement untriaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
opensearch-project/sql#5842 ·
Los mantenedores suelen responder en 1 día
-
[BUG] expand on a field that is not a column of the input fails as a ClassCastExceptionPosiblemente ocupada @RyanL1997 la tomó hace 3 días. Abiertountriaged
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
opensearch-project/sql#5840 ·
Los mantenedores suelen responder en 1 día
-
[BUG] PromQL queries fail with InvalidTypeIdException when metric has a label named "type"Posiblemente ocupada @nagendramohan la tomó hace 59 días. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
opensearch-project/sql#5684 · 4 comentarios ·
Los mantenedores suelen responder en 1 día
-
Mend: dependency security vulnerability
Dificultad 1/5 1-3 horas Aptitud para principiantes 84/100
opensearch-project/sql#5445 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
[DOC] Calcite settings documentation missing examplesPosiblemente ocupada @AzazelSensei la tomó hace 17 días. Abiertodocumentation PPL
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
opensearch-project/sql#4806 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de opensearch-project/sql
Issues similares
-
[BUG] S3 CORS responses omit Access-Control-Allow-Credentials for matched originsPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
floci-io/floci#5369 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
sqlcipher/sqlcipher-android#97 · 1 comentario ·
-
area-integrations
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
bug IIIF interoperability
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100