Files
scylladb/utils/exceptions.cc
Avi Kivity 094a2a4263 Merge "Catch unclosed partition sstable write #4794" from Tomasz
"
Not emitting partition_end for a partition is incorrect. SStable
writer assumes that it is emitted. If it's not, the sstable will not
be written correctly. The partition index entry for the last partition
will be left partially written, which will result in errors during
reads. Also, statistics and sstable key ranges will not include the
last partition.

It's better to catch this problem at the time of writing, and not
generate bad sstables.

Another way of handling this would be to implicitly generate a
partition_end, but I don't think that we should do this. We cannot
trust the mutation stream when invariants are violated, we don't know
if this was really the last partition which was supposed to be
written. So it's safer to fail the write.

Enabled for both mc and la/ka.

Passing --abort-on-internal-error on the command line will switch to
aborting instead of throwing an exception.

The reason we don't abort by default is that it may bring the whole
cluster down and cause unavailability, while it may not be necessary
to do so. It's safer to fail just the affected operation,
e.g. repair. However, failing the operation with an exception leaves
little information for debugging the root cause. So the idea is that the
user would enable aborts on only one of the nodes in the cluster to
get a core dump and not bring the whole cluster down.
"

* 'catch-unclosed-partition-sstable-write' of https://github.com/tgrabiec/scylla:
  sstables: writer: Validate that partition is closed when the input mutation stream ends
  config, exceptions: Add helper for handling internal errors
  utils: config_file: Introduce named_value::observe()

(cherry picked from commit 95c0804731)
(cherry picked from commit cf4c238b28)
2019-08-08 16:47:26 +03:00

86 lines
2.2 KiB
C++

/*
* Copyright 2015 ScyllaDB
*/
/* This file is part of Scylla.
*
* Scylla is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* Scylla is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with Scylla. If not, see <http://www.gnu.org/licenses/>.
*/
#include <seastar/core/print.hh>
#include <seastar/util/log.hh>
#include <seastar/util/backtrace.hh>
#include <exception>
#include <system_error>
#include <atomic>
#include "exceptions.hh"
#include <iostream>
bool check_exception(system_error_lambda_t f)
{
auto e = std::current_exception();
if (!e) {
return false;
}
try {
std::rethrow_exception(e);
} catch (std::system_error &e) {
return f(e);
} catch (...) {
return false;
}
return false;
}
bool is_system_error_errno(int err_no)
{
return check_exception([err_no] (const std::system_error &e) {
auto code = e.code();
return code.value() == err_no &&
code.category() == std::system_category();
});
}
bool should_stop_on_system_error(const std::system_error& e) {
if (e.code().category() == std::system_category()) {
// Whitelist of errors that don't require us to stop the server:
switch (e.code().value()) {
case EEXIST:
case ENOENT:
return false;
default:
break;
}
}
return true;
}
std::atomic<bool> abort_on_internal_error{false};
void set_abort_on_internal_error(bool do_abort) {
abort_on_internal_error.store(do_abort);
}
void on_internal_error(seastar::logger& logger, const seastar::sstring& msg) {
if (abort_on_internal_error.load()) {
logger.error("{}, at: {}", msg.c_str(), seastar::current_backtrace());
abort();
} else {
seastar::throw_with_backtrace<std::runtime_error>(msg.c_str());
}
}