Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-15335

Node can corrupt gossip state and become unreplaceable

    XMLWordPrintableJSON

    Details

      Description

      In StorageService#prepareToJoin, a starting node first sends out an endpoint state without any tokens. Later, in StorageService#finishJoiningRing it sends out an endpoint state with it’s tokens. If that node dies between these 2 events and cannot be restarted due to some unrecoverable error, the ring’s gossip state will be missing tokens for that node. This won’t cause any immediate data loss since TMD is populated from system.peers, but it will prevent a replacement node from associating that address with it’s tokens and replacing it. It could also cause data loss if other nodes are added to the ring and don’t see an owned token where there should be one.

        Attachments

          Activity

            People

            • Assignee:
              bdeggleston Blake Eggleston
              Reporter:
              bdeggleston Blake Eggleston
              Authors:
              Blake Eggleston
              Reviewers:
              Marcus Eriksson, Sam Tunnicliffe
            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: