Skip to content
Permalink
Browse files

[JENKINS-50599] Make Nodes#addNode fail atomically (#3383)

* Reproduce JENKINS-50599

* Make Nodes#addNode fail atomically

* Simplify rollback logic and add some tests

* Fix typo

* Rename lambda parameters to clarify that they are intentionally ignored

* Catch RuntimeException as well
  • Loading branch information...
dwnusbaum authored and oleg-nenashev committed Apr 14, 2018
1 parent c6561fa commit 9557da32a3550bd98acc9d04728547fcd98b8a15
Showing with 116 additions and 2 deletions.
  1. +17 −2 core/src/main/java/jenkins/model/Nodes.java
  2. +99 −0 test/src/test/java/jenkins/model/NodesTest.java
@@ -127,7 +127,8 @@ public void run() {
* @throws IOException if the list of nodes could not be persisted.
*/
public void addNode(final @Nonnull Node node) throws IOException {
if (node != nodes.get(node.getNodeName())) {
Node oldNode = nodes.get(node.getNodeName());
if (node != oldNode) {
// TODO we should not need to lock the queue for adding nodes but until we have a way to update the
// computer list for just the new node
Queue.withLock(new Runnable() {
@@ -139,7 +140,21 @@ public void run() {
}
});
// TODO there is a theoretical race whereby the node instance is updated/removed after lock release
persistNode(node);
try {
persistNode(node);
} catch (IOException | RuntimeException e) {
// JENKINS-50599: If persisting the node throws an exception, we need to remove the node from
// memory before propagating the exception.
Queue.withLock(new Runnable() {
@Override
public void run() {
nodes.compute(node.getNodeName(), (ignoredNodeName, ignoredNode) -> oldNode);
jenkins.updateComputerList();
jenkins.trimLabels();
}
});
throw e;
}
NodeListener.fireOnCreated(node);
}
}
@@ -0,0 +1,99 @@
/*
* The MIT License
*
* Copyright 2018 CloudBees, Inc.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy
* of this software and associated documentation files (the "Software"), to deal
* in the Software without restriction, including without limitation the rights
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
* copies of the Software, and to permit persons to whom the Software is
* furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in
* all copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
* THE SOFTWARE.
*/

package jenkins.model;

import hudson.model.Descriptor;
import hudson.model.Node;
import hudson.model.Slave;
import hudson.slaves.ComputerLauncher;
import java.io.IOException;
import org.junit.Rule;
import org.junit.Test;
import org.jvnet.hudson.test.Issue;
import org.jvnet.hudson.test.JenkinsRule;

import static org.hamcrest.Matchers.containsString;
import static org.hamcrest.Matchers.nullValue;
import static org.hamcrest.Matchers.sameInstance;
import static org.junit.Assert.assertThat;
import static org.junit.Assert.fail;

public class NodesTest {

@Rule
public JenkinsRule r = new JenkinsRule();

@Test
@Issue("JENKINS-50599")
public void addNodeShouldFailAtomically() throws Exception {
InvalidNode node = new InvalidNode("foo", "temp", r.createComputerLauncher(null));
try {
r.jenkins.addNode(node);
fail("Adding the node should have thrown an exception during serialization");
} catch (IOException e) {
String className = InvalidNode.class.getName();
assertThat("The exception should be from failing to serialize the node",
e.getMessage(), containsString("Failed to serialize " + className + "#cl for class " + className));
}
assertThat("The node should not exist since #addNode threw an exception",
r.jenkins.getNode("foo"), nullValue());
}

@Test
@Issue("JENKINS-50599")
public void addNodeShouldFailAtomicallyWhenReplacingNode() throws Exception {
Node oldNode = r.createSlave("foo", "", null);
r.jenkins.addNode(oldNode);
InvalidNode newNode = new InvalidNode("foo", "temp", r.createComputerLauncher(null));
try {
r.jenkins.addNode(newNode);
fail("Adding the node should have thrown an exception during serialization");
} catch (IOException e) {
String className = InvalidNode.class.getName();
assertThat("The exception should be from failing to serialize the node",
e.getMessage(), containsString("Failed to serialize " + className + "#cl for class " + className));
}
assertThat("The old node should still exist since #addNode threw an exception",
r.jenkins.getNode("foo"), sameInstance(oldNode));
}

@Test
public void addNodeShouldReplaceExistingNode() throws Exception {
Node oldNode = r.createSlave("foo", "", null);
r.jenkins.addNode(oldNode);
Node newNode = r.createSlave("foo", "", null);
r.jenkins.addNode(newNode);
assertThat(r.jenkins.getNode("foo"), sameInstance(newNode));
}

private static class InvalidNode extends Slave {
// JEP-200 whitelist changes prevent this field (and thus instances of this class) from being serialized.
private ClassLoader cl = InvalidNode.class.getClassLoader();

public InvalidNode(String name, String remoteFS, ComputerLauncher launcher) throws Descriptor.FormException, IOException {
super(name, remoteFS, launcher);
}
}
}

0 comments on commit 9557da3

Please sign in to comment.
You can’t perform that action at this time.