[#1068] Apply what a running backend takes of a configuration change, and ask for a restart for what it does not - #1069
Open
vharseko wants to merge 2 commits into
Conversation
This was referenced Sep 18, 2026
vharseko
force-pushed
the
issues/1068-backend-properties-applied-or-reported
branch
from
September 19, 2026 09:52
48a7d9e to
4bc401f
Compare
Member
Author
|
Rebased onto the restacked #1066 ( Re-run green on the rebased head: |
…han what the configuration says by then, and ask for a restart when the cache size changes PDBStorage and JEStorage reserved their cache size from the memory quota by reading config in buildConfiguration and released it by reading config again in close(). applyConfigurationChange swapped config in between without touching the quota or the cache, and neither db-cache-size nor db-cache-percent was marked as needing a restart, so a cache grown from 64 MB to 128 MB while the backend ran released 128 against 64 taken at the next disable - the one an online import makes included - and the quota believed 64 MB free that the server did not have, for the life of the JVM; a shrink left the difference reserved by nobody. The running cache was the old size throughout. Both storages now keep two numbers of their own: the cache size of the configuration they opened with, and of it what the quota granted - a tryAcquire it refused, which an open at startup is not checked against, reserved nothing and used to be released all the same. close() gives back the granted size. isConfigurationChangeAcceptable admits the difference to what is held rather than to config, which a change admitted but not yet applied has already moved to the new size. applyConfigurationChange on an open storage whose cache size the change moves sets adminActionRequired and says so (NOTE_CONFIG_DB_CACHE_REQUIRES_RESTART): PersistIt cannot resize a buffer pool once the database is open, and JEStorage has never resized its environment. The two properties are marked component-restart in both configuration XMLs, as db-directory is. PDBStorageTest and JEStorageTest, six cases each: the grow and the shrink give back what was taken, the change asks for a restart and names both sizes, a change which leaves the cache alone asks for nothing, admission is against what is held, and a reservation the quota refused is not given back.
…onfiguration change, and ask for a restart for what it does not Nine properties of the JE and PDB backends were neither applied to a running backend nor marked as requiring a restart. JEStorage.applyConfigurationChange handled the directory, its permissions and the disk thresholds and left the environment - configured once, at the open - as it was, while the XML kept db-cleaner-min-utilization, db-run-cleaner, db-evictor-core-threads, db-evictor-max-threads, db-evictor-keep-alive, db-num-cleaner-threads, db-txn-no-sync and db-txn-write-no-sync (JE) and db-checkpointer-wakeup-interval (PDB) as live properties, which they had been in the local-db backend OPENDJ-1719 replaced. A change of any of them was reported as applied while the backend ran on unchanged until it was next opened; so was a native property changed through je-property. JEStorage now builds the environment configuration the changed configuration describes and hands it to Environment.setMutableConfig, which takes of it what JE accepts while it runs: the properties above, the durability, and a mutable native property - all but the cache, which stays with the memory reserved for it until the restart OpenIdentityPlatform#1063 asks for. Every immutable JE parameter whose value differs from the running environment's is reported with the new NOTE 631, which names the property, the value the environment runs with and the one configured, and reaches the error log as a warning - where the change result of a property marked in the XML alone never did. An import's environment is left alone: it runs on a configuration of its own, and the backend opens again on the changed one once the import is over. The build of the environment configuration is split from the checks of the open (ConfigurableEnvironment.toEnvironmentConfig): no cache size probe against the memory quota, no level set on the JE loggers, so that a configuration change can be checked against it as well - and it is: isConfigurationChangeAcceptable and isConfigurationAcceptable refuse a durability which sets both flags (db-txn-write-no-sync is on by default, so setting db-txn-no-sync alone is one) and a native property JE does not know before the change is written. Nothing checked either before, and the backend failed to open on them at its next restart. A configuration which sets neither durability flag now sets COMMIT_SYNC explicitly: what JE falls back on, but set, since JE leaves the durability an environment has in place when a configuration hands it none. PDBStorage reports a change of db-checkpointer-wakeup-interval with the same note, holding the configured interval against the one the database opened with - PersistIt takes no configuration once one is set - and the property is marked component-restart in PDBBackendConfiguration.xml. The definition of je-property says which of its changes wait for a restart.
vharseko
force-pushed
the
issues/1068-backend-properties-applied-or-reported
branch
from
September 19, 2026 14:42
4bc401f to
4ea1d18
Compare
Member
Author
|
Restacked on the new head of #1066 ( |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1068. Stacked on #1066 (
64f3cffd00, on master since #994 merged): the same lines of bothapplyConfigurationChange, both XMLs and the ordinal after its 630;JEStorageTestexists only from #999 on. Merge after #1066.What was wrong
Nine properties of the JE and PDB backends were neither applied to a running backend nor marked as requiring a restart, so
dsconfigreported a change of them applied and the backend ran on unchanged until it was next opened.JEStorage.applyConfigurationChangehandleddb-directory, its permissions and the disk thresholds and left the environment - configured once, at the open - as it was; nothing in the server calledEnvironment.setMutableConfig. The same went for a native property changed throughje-property, mutable or not (not in the issue's table, same cause).Two things the issue had wrong, found on the way:
requires-admin-actionin the XML reaches the reference documentation and property help alone -dsconfigprints nothing about it at set time, and a change result withoutadminActionRequiredcarries nothing to the error log either. So "asdb-log-file-maxalready does" was not true of the change result: the marking is all those properties had. The oldRootContainerreported every changed immutable parameter in the change result, which the server logs as a warning (WARN 647); that shape is restored for all of them.db-txn-write-no-syncis on by default, sodsconfig set-backend-prop --set db-txn-no-sync:trueon a JE backend yields a durability which sets both flags. Nothing checked that at change time: the change was admitted and written, and the backend failed to open onERR_CONFIG_JEB_DURABILITY_CONFLICTat its next restart. (aChangeWhichLeavesTheCacheSizeAloneAsksForNothingof [#1063] Give back what the open reserved rather than what the configuration says by then, and ask for a restart when the cache size changes #1066 used exactly that as its "unrelated change"; it now sets the write flag off as well.)What this does
JE -
applyToEnvironmentbuilds the environment configuration the changed configuration describes (ConfigurableEnvironment.toEnvironmentConfig) and hands it toEnvironment.setMutableConfig, which takes of it what JE accepts while it runs:db-cleaner-min-utilization,db-run-cleaner,db-evictor-core-threads,db-evictor-max-threads,db-evictor-keep-alive,db-num-cleaner-threads, the durability (db-txn-no-sync/db-txn-write-no-sync, every way - a configuration which sets neither now setsCOMMIT_SYNCexplicitly, since JE leaves the durability an environment has in place when handed none) and a mutableje-property. All but the cache:je.maxMemory/je.maxMemoryPercentare mutable too, but the cache stays with the memory reserved for it until the restart #1063 asks for, so the change hands the environment its current values back. Every immutable JE parameter whose value differs from the running environment's is reported with the newNOTE_CONFIG_DB_PROPERTY_REQUIRES_RESTART(631), naming the property asdsconfigknows it (or the JE property name forje-property), the value the environment runs with and the one configured. An import's environment is left alone - it runs on a configuration of its own and the backend opens again on the changed one once the import is over; held to the import's configuration, every property the import sets differently would ask for a restart.toEnvironmentConfigis the build alone - no cache size probe against the memory quota (#1067), no level set on the JE loggers (that moves toparseConfigEntry, the open's road) - so that a change can be checked against it:isConfigurationChangeAcceptableandisConfigurationAcceptablenow refuse a conflicting durability and a native property JE does not know before the change is written.PDB -
db-checkpointer-wakeup-intervalis set on the PersistIt configuration at the open alone andPersistit.setConfigurationrefuses once one is set, so a change of it reports 631 against the interval the database opened with (db.getConfiguration().getCheckpointInterval(), no new field), and the property is markedcomponent-restartinPDBBackendConfiguration.xml.je-property's definition says which of its changes wait for a restart.Left as they are:
db-logging-levelanddb-logging-file-handler-onkeep theircomponent-restartmarking. The JUL level is set by the open alone, as before; the file handler's level (je.env.fileLoggingLevel) is mutable in JE and so follows a change from now on - the marking is conservative about it, not wrong.Tests
JEStorageTest: the six mapped properties reachenv.getMutableConfig(); the durability follows the change every way; a mutableje-propertyis applied and an immutable one asks for a restart with 631;db-log-file-maxasks for a restart with 631; a change while open leaves the cache where the open reserved it (the #1063 interplay); a change during an import leaves the import's environment alone; a change while closed touches nothing; a durability which sets both flags and an unknown native property are refused by both acceptability checks.PDBStorageTest: a changed interval asks for a restart with 631 and the database keeps its own; a change while closed asks for nothing.Verified locally: the issue reproduced on master, on the #999 head and on the #1066 head with a direct TestNG repro of every row (JE 7/7 red, PDB 1/1 red,
db-txn-no-syncon PDB green as a control); the new tests are red without the fix (5 JE + 1 PDB) and green with it; mutants (nosetMutableConfig, cache not pinned, immutables unreported, import's environment held to the configuration, PDB silent) each red on their own case; regression set of 18 classes / 240 tests (FailedBackendOpenTest, PDB/JE TestCase + Encrypted, ReplayedConfigChangeTest, OnDiskMergeImporterTest, the pluggable tree tests, ImportLDIF/RebuildIndex/VerifyIndex, BackendConfigManagerTestCase) green.