fix(runtime): refresh stale empty directory views - #10625
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Fixes a silo-startup race in the experimental distributed grain directory where an empty Joining directory view could remain cached after cluster membership advanced to Active, causing activation registration to resolve no owner/address and leading to forwarded calls being rejected during Active-stage startup tasks.
Changes:
- Refreshes the distributed grain directory when an empty directory view is behind the latest observed cluster membership version (while preserving immediate empty results when the view is current).
- Generalizes
DirectoryMembershipServiceto depend onIClusterMembershipServiceto enable test-time membership service wrapping. - Adds deterministic coverage which holds the directory on a stale Joining membership view until it requests the newer Active view, validating the fix without relying on retries.
Show a summary per file
| File | Description |
|---|---|
| test/Orleans.Runtime.Tests/StartupTaskTests.cs | Adds deterministic regression coverage by wrapping cluster membership updates to reproduce the stale empty view scenario and asserting a refresh to the Active membership version occurs. |
| src/Orleans.Runtime/GrainDirectory/DistributedGrainDirectory.cs | Avoids treating an empty directory view as authoritative when cluster membership has already advanced beyond that view. |
| src/Orleans.Runtime/GrainDirectory/DirectoryMembershipService.cs | Switches from ClusterMembershipService to IClusterMembershipService to allow substituting membership behavior (primarily for testing). |
Review details
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 3/3 changed files
- Comments generated: 2
- Review effort level: Lite
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Review details
Suppressed comments (1)
Previously missed (1) — in code that hasn't changed since the last review.
test/Orleans.Runtime.Tests/StartupTaskTests.cs:109
Refreshcan release the delayed Active membership update beforestaleDirectoryVersionis initialized (there is a small window afteractiveUpdateDelayedis set but beforestaleDirectoryVersionis written inGetMembershipUpdates). If a concurrentRefreshhappens in that window, the gate can open early and make the test nondeterministic. Guard against the uninitialized (0) stale version before triggeringreleaseActiveUpdate.
if (Volatile.Read(ref this.activeUpdateDelayed) != 0 && minimumVersion.Value > staleVersion)
- Files reviewed: 3/3 changed files
- Comments generated: 0 new
- Review effort level: Lite
|
The refreshed CI run and two targeted retries show a recurring Azure reminder failure on this head rather than a one-off job issue. Azure Storage |
Fixes #10600
During silo startup, the distributed grain directory could still hold an empty Joining view after cluster membership had advanced to Active. That stale view was treated as authoritative, so activation registration returned no address and Active-stage startup task grain calls were rejected after forwarding.
Refresh the directory when cluster membership is newer than an empty directory view, while preserving the immediate empty result when the view is current. Add deterministic coverage which holds the directory on a positive-version Joining view until it requests the newer Active view, preserving the supported Active-stage startup task contract without retry-based masking.
Microsoft Reviewers: Open in CodeFlow