Skip to content

fix(#5356): fail fast on PARTITION_OWNED_PULL without shared MetaStore + arch-guard - #5367

Merged
qqeasonchen merged 1 commit into
developfrom
arch-guard/5356-ban-poll-all
Sep 8, 2026
Merged

qqeasonchen merged 1 commit into
developfrom
arch-guard/5356-ban-poll-all

Conversation

@qqeasonchen

@qqeasonchen qqeasonchen commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does

Closes #5356 — Phase 0 enforcement of the production-HA plan (#5354): PARTITION_OWNED_PULL must never silently degrade to an isolated in-process MetaStore. Also repairs the compile/test/checkstyle breaks that landed on develop via the 2026-09-07/08 Actions-outage blind merges — all found by running the complete CI pipeline locally (same gradle tasks as .github/workflows).

1. Boot fail-fast (the #5356 core)

Site Before After
UniRuntime.startPartitionOwnership() clusterMeta == null → new InMemoryMetaStore() — a misconfigured cluster looks healthy while every instance polls every partition IllegalStateException: PARTITION_OWNED_PULL requires a shared MetaStore: set eventmesh.meta.type/addr (e.g. nacos + address) or use LOCAL_STICKY_PULL for single-instance
EventMeshApplication cluster mode unknown eventmesh.meta.type → silently new InMemoryMetaStore() in cluster mode IllegalStateException: unsupported eventmesh.meta.type='<type>': cluster mode requires a shared MetaStore (supported: nacos)

Single-instance mode (LOCAL_STICKY_PULL default) keeps the documented in-memory store.

2. ArchUnit guardrails (12 → 14 rules)

  • ruleInMemoryMetaStoreOnlyFromBoot — only runtime.boot.. may depend on InMemoryMetaStore.
  • rulePartitionOwnershipOnlyFromBootAndCluster — PartitionOwnership visible only to boot / cluster / ingress / admin (read-only view).

3. Outage blind-merge repairs

Break Origin Fix
compileJava failed on develop — missing DeliveryTopology import #5344 add import
guard module missing rocketmq5 dep + org.lz4/at.yawk.lz4 capability conflict #5348 add dep + capabilitiesResolution
canary in storage.fakeplugin.. never matched rule's that-clause → _catches always failed #5348 move canary to storage.kafka test pkg
ClusterSubscriptionStore empty-bucket leak → topics() returned ghost topics #5345 cache.remove(topic, subs) when empty
checkstyle maxWarnings=0: unused imports, import order, aView/bView naming, declaration-usage distance (reaper ×2, SessionRegistry b) #5345/#5346 all fixed

4. Full local CI parity (Temurin 21.0.11)

Mirrors .github/workflows/ci.yml + architecture-guard.yml exactly:

./gradlew clean generateGrammarSource                              BUILD SUCCESSFUL
./gradlew :eventmesh-architecture-guard:architectureCheck          BUILD SUCCESSFUL
./gradlew clean build dist jacocoTestReport --parallel --daemon     -x spotlessJava -x generateGrammarSource -x generateDistLicense     -x checkDeniedLicense -x :eventmesh-architecture-guard:test   BUILD SUCCESSFUL (511 tasks, 10m47s)
./gradlew installPlugin                                            BUILD SUCCESSFUL

New tests: partitionOwnedPullWithoutMetaStoreFailsFast, ruleInMemoryMetaStoreOnlyFromBoot_check, rulePartitionOwnershipOnlyFromBootAndCluster_check.

Relations

Co-authored-by: qqeasonchen qqeasonchen@gmail.com

@qqeasonchen
qqeasonchen force-pushed the arch-guard/5356-ban-poll-all branch from 06360d3 to 4d05581 Compare September 8, 2026 10:08
Phase 0 enforcement of the production-HA plan (#5354): removes both
silent InMemoryMetaStore fallbacks, adds two ArchUnit guardrails, and
repairs the compile/test/checkstyle breaks that landed on develop via
the 2026-09-07/08 Actions-outage blind merges (all found by running
the full CI build locally).

Boot changes (the #5356 core):
- UniRuntime.startPartitionOwnership: clusterMeta == null now throws
  IllegalStateException instead of new InMemoryMetaStore().
- EventMeshApplication: unsupported meta type in cluster mode fails
  fast; single-instance mode keeps the documented in-memory store.

ArchUnit guardrails (12 -> 14 rules):
- ruleInMemoryMetaStoreOnlyFromBoot
- rulePartitionOwnershipOnlyFromBootAndCluster (boot/cluster/ingress/admin)

Outage blind-merge repairs:
- missing DeliveryTopology import (#5344): compileJava failed on develop
- guard module missing rocketmq5 dep + lz4-java capability conflict
  (org.lz4 vs at.yawk.lz4) for FakeStorageCanary (#5348)
- FakeStorageCanary in storage.fakeplugin.. never matched the
  ruleStoragePluginsIsolated that-clause (#5348): moved to
  storage.kafka test package
- ClusterSubscriptionStore left empty topic buckets after last
  subscriber removal (#5345): topics() returned ghosts; buckets now
  dropped when empty
- checkstyle (maxWarnings=0) violations in #5345/#5346 test files:
  unused imports (MetaListener, StandardCharsets, TaskStore, MetaStore,
  OffsetStore), import order (A2AMessageTransport, org.junit before
  io.cloudevents), local var names (aView/bView -> viewA/viewB),
  declaration-usage distance (reaper x2, SessionRegistry b)

Full local CI parity (Temurin 21.0.11, same tasks as .github/workflows):
- ./gradlew clean generateGrammarSource            -> BUILD SUCCESSFUL
- ./gradlew :eventmesh-architecture-guard:architectureCheck --no-daemon
                                                  -> BUILD SUCCESSFUL
- ./gradlew clean build dist jacocoTestReport --parallel --daemon
    -x spotlessJava -x generateGrammarSource -x generateDistLicense
    -x checkDeniedLicense -x :eventmesh-architecture-guard:test
                                                  -> BUILD SUCCESSFUL (511 tasks, 10m47s)
- ./gradlew installPlugin                         -> BUILD SUCCESSFUL

Refs #5356 (sub-issue of #5354).

Co-authored-by: qqeasonchen <qqeasonchen@gmail.com>
@qqeasonchen
qqeasonchen force-pushed the arch-guard/5356-ban-poll-all branch from 4d05581 to f374931 Compare September 8, 2026 10:40
@qqeasonchen
qqeasonchen merged commit 3dffe95 into develop Sep 8, 2026
1 check passed
qqeasonchen added a commit that referenced this pull request Sep 9, 2026
Phase 4 of the production-HA plan (#5354), sub-issue #5365: the final
acceptance evidence and the closure of the three parent issues.

evidence.md gains the "Production-HA acceptance (#5354)" section:
- one row per executed sub-issue (#5356-#5362, #5364) with PR,
  squash-commit, test files, reproducible test command, backend and
  topology, all marked PASS under the full local-CI pipeline (the
  verification of record during the Actions outage)
- #5363 marked NOT PLANNED with the deferral rationale and the
  compensating in-process coverage
- a section documenting the blind-merge repairs #5367 carried (develop
  was compile-red before it) so reviewers of the outage window have
  the full picture
- the 21-criterion mapping (A1-A5 / B1-B6 / C1-C10) from the three
  parent issues to the landed sub-issues

production-ha-plan.md is marked COMPLETE with pointers to the evidence
section.

With this, the plan's closure condition is met: the evidence table
records every executed sub-issue, and the parents (#5352 data-path,
#5353 control-plane, #5354 production HA) close on it.

Closes #5365
Closes #5352
Closes #5353
Closes #5354
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P0] arch-guard: ban InMemoryMetaStore and poll-all fallback in cluster mode

1 participant