Repository navigation
Fix spurious failures when upgrading private inner nodes - #43
Open
Konstantin V Shvachko (shvachko) wants to merge 1 commit into
Open
Konstantin V Shvachko (shvachko) wants to merge 1 commit into
Konstantin V Shvachko (shvachko) wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Use strong
compare_exchangeinReadGuard::upgradeso a permitted spurious weak-CAS failure is not reported asTreeError::Lockedon an unchanged private inner node. The production change preserves the expected version, the new version, both memory orderings, and genuine contention/stale-version rejection.Root cause
Inner-root splitting (
tree.rs, new-root publication) and snapshot recovery (snapshot.rs, inner-node reconstruction) upgrade newly allocated, unpublished inner nodes and unwrap the result. The old helper made a singlecompare_exchange_weakattempt. That operation is allowed to returnErr(expected)even when no other thread changed the lock.On Windows ARM64 this was observed during native loading. An isolated probe of the unchanged production helper recorded 989 unchanged-version failures in 100 million uncontended attempts; a strong-CAS control recorded none. This is a portable API-contract bug, not an ARM64-specific requirement. Returning a retry from the root-publication site is not a safe substitute: the old root has already been split/demoted there.
This is separate from the allocation-publication race in #42 and does not incorporate that PR or #41.
Regression coverage
#[path]against a minimal test-only node/atomic shim. The shim injects one permitted unchanged-value weak-CAS failure; there is no fault-injection hook or additional abstraction in the library.Locked, version zero), then passes with strong CAS.Shuttle 0.7.1 does not model spurious integer weak-CAS failures, so its ordinary concurrency test cannot replace the deterministic fixture. CI Shuttle commands now explicitly select
--lib: the existing Shuttle platform shims requirecfg(test), while the new integration fixture is a separate crate. The native integration fixture still runs under ordinarycargo testand the sanitizer job.Validation
Windows ARM64, Rust 1.93.0:
cargo test --release --test inner_lock_spurious: 5 passed.cargo test --lib inner_root_split: 1 passed.cargo test --release --lib --features shuttle shuttle_bf_tree_concurrent_operations: passed, four PCT runners with 4,000 executions each.cargo fmt --all -- --check: passed.cargo clippy --release --tests: passed, existing upstream warnings; none reported in the added tests.A broader native run is not claimed green: the existing
snapshot::tests::cpr_snapshot_cache_onlyaborts atstorage.rs:183(allocation write-lock unwrap), followed by cleanup failure. Reproduced independently on untouched upstreamca61307and on this branch. That allocation-publication defect is addressed separately by #42; it is not bundled here. Linux/x64 and hosted CI results remain pending.