mirror of
https://github.com/milvus-io/milvus.git
synced 2026-07-21 10:15:43 +00:00
issue: #51253 > Rebased on master after #51254 merged. The `db_name`/`db_id` part of the original PR is now covered by #51254; this PR is reduced to the two remaining gaps on the same query-by-id path. ## Problem When `DescribeCollection` is called with **only a `collectionID`** — no collection name, no db name (e.g. the HTTP management API on `:9091`) — two gaps remain after #51254: 1. **Top-level `collection_name` is empty** on both the cached provider path and the `describeCollectionTask` path. The response is initialized from the (empty) `request.CollectionName` before the name is resolved, and never backfilled. 2. **The cached provider discards the caller-provided collection id.** After deriving the name from the id, it re-resolves the id from that name via `GetCollectionID(db, name)`. Id-only lookups are cached under the request db name — empty here — so with same-name collections in different databases, a concurrent cache refresh can rebind the entry under the `""` key and the request would silently describe the wrong collection (the derived name matches, the id does not). ## Fix - `service_provider.go`: - Backfill `resp.CollectionName` from the resolved cached schema when the request carried no name. Requests that pass a name (including aliases) still echo it unchanged. - Skip the name→id re-resolution when the caller already supplied the id. `GetCollectionInfo` already validates the cache entry against the id (`collInfo.collID != collectionID` → refresh by id), so the caller-provided id is authoritative end to end. Name+id requests keep the existing name-precedence behavior. - Resolve identifiers on local copies instead of rewriting `request.CollectionName`/`CollectionID` in place — the access log interceptor and the success metric labels serialize the request after the handler returns, and previously recorded the resolved values instead of what the client sent. - `task.go`: backfill `t.result.CollectionName` from the coordinator result on the non-cached path. - `meta_cache.go`: fix a stale comment on `ResolveCollectionAlias` — `update()` now always keys `collInfo` by the real collection name (aliases live in the separate alias map), the old comment described pre-refactor behavior. - Tests: - `TestCachedProxyServiceProvider_DescribeCollection_ByIDFillsNameAndUsesRequestID`: drives the id-only path; `GetCollectionID` is deliberately not mocked, so any regression back to re-resolving the id panics the test. - `TestDescribeCollectionTask_FillsNameFromResultWhenQueriedByID`: same assertion for the non-cached path. - Removed the now-unused `GetCollectionID` expectation from the test added in #51254 (that call no longer happens on the id-only path). ## Follow-up commit: entity-keyed meta cache with a cluster-wide id index Reviewing this path surfaced a deeper issue in the proxy meta cache, fixed in the second commit: - By-id lookups (`GetCollectionName`, `GetCollectionInfo` with an empty name) linearly scanned a whole db bucket under the read lock, on every request even on cache hits. - The bucket scanned/filled was keyed by the *request* db name — empty for id-only calls — so entries landed in a bogus `""` bucket: a collection also cached under its real db was duplicated, and same-name collections of different databases evicted each other from the single `""`-keyed slot. The cache is now entity-keyed instead of request-keyed: - Fills land under the collection's **actual database** (carried in the describe response); the `""` bucket no longer exists. - A cluster-wide `collectionID → entry` index serves by-id lookups in **O(1)** regardless of the request db — matching rootcoord, which resolves by-id describes straight from `collID2Meta` without consulting the db name. - Name lookups normalize an empty db name to `default`, mirroring rootcoord's backward-compat normalization (`meta_table.getCollectionByNameInternal`). This also closes a latent cross-database mis-hit: a name lookup with an empty db could previously return whichever same-name collection was last id-cached under the `""` bucket. - All removal paths maintain the index (pointer-identity-guarded unindexing); invalidation sweeps stay exhaustive. ## Verification - Ran locally against a current master core build: the full `TestMetaCache*`, `TestCachedProxyServiceProvider*`, `TestDescribeCollectionTask*`, alias and partition test sets all pass, plus the **full `internal/proxy` suite** (only the pre-existing etcd-dependent `TestProxyRpcLimit` fails locally — it needs a live etcd, unrelated to this change). - New tests: `TestCachedProxyServiceProvider_DescribeCollection_ByIDFillsNameAndUsesRequestID` (id-only path; also asserts the request is not rewritten), `TestDescribeCollectionTask_FillsNameFromResultWhenQueriedByID`, `TestMetaCache_ByIDIndexRealDBBucket` (same-name collections in two databases filled by id: no eviction, entries under real dbs, by-name reuses by-id fill, every removal path cleans the index), `TestMetaCache_EmptyDBNameSharesDefaultEntry`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --- ## Update: proxy meta cache rebuilt around an id-primary store (2 new commits) Following review discussions on invalidation cost and the alias-DDL races, this PR now also rebuilds the cache (issue: #51533, design doc: `docs/design-docs/design_docs/20260716-proxy-metacache-id-inverted-index.md` in this PR): 1. **`fix: forward the pre-alter alias target id in the AlterAlias expiration`** — rootcoord resolves the pre-alter target under its database lock and carries it in the new additive `AlterAliasMessageHeader.old_collection_id`; the ack callback emits a second expiration entry so proxies evict BOTH AlterAlias targets by id. Closes the race where a concurrent Describe re-points the proxy's alias resolution before the expiration arrives, leaving the old target permanently stale. Older rootcoords (field 0) fall back to the proxy's hint resolution. 2. **`enhance: rebuild the proxy meta cache around an id-primary store`** — the primary store is keyed by the cluster-unique collection id (single source of truth, with a per-database generation); name/alias resolution become hints validated against the primary on read; partition caches are keyed by id; fills are ordered against invalidations by a fill RWMutex (drain in-flight describes before evicting), replacing the per-collection timestamp floor. Every invalidation becomes O(1) — no more full-cache scans under the write lock on Load/Release/Drop/Rename/Alter broadcasts, and DropDatabase/AlterDatabase becomes a generation bump. Also removes a latent stale read (alias-keyed partition entries surviving DropCollection). Verification: targeted cache suites green (rename, alias re-point under concurrent describe, drop+recreate with a reused name, db-generation invalidation, cross-db isolation, gated-mock fill/invalidation ordering); three negative controls (hint validation / dbGen check / fill drain disabled) each fail exactly the test guarding them; full-package `-race` delegated to CI. --- ## Update: simplification series (final form) Following design review, the cache was iteratively simplified to an **id-primary store with declared hints** — every mechanism that could be replaced by an invariant was deleted (net-negative diffs throughout): - Primary store keyed by the cluster-unique collection id; liveness IS presence. Name/alias resolution are hints written ONLY together with their entry (declared aliases) and validated against the primary on every read — a stale hint can only cost one extra describe, never a stale read. - Fill/invalidation ordering via a fill RWMutex (drain in-flight describes before evicting); the per-collection timestamp floor, database generations, background GC, alias negative cache, per-partition cache, and the resolve-and-forget DescribeAlias path are all **deleted**. Evictions clean everything the entry owns synchronously; **no invalidation path performs any RPC**. - Old-rootcoord fallbacks: id-describes without DbName are served uncached; alias-DDL broadcasts without ids trigger hint resolution plus a holder scan **gated on that exact fingerprint** (dead code once rootcoords are upgraded), closing the ghost-alias case with no healing event. - **Accepted gaps (WONT-FIX)** are recorded in the design doc §6 — notably the upgrade-window new-target `Aliases` display lag (the association exists only at rootcoord; self-heals on first use; display-only). See `docs/design-docs/design_docs/20260716-proxy-metacache-id-inverted-index.md` for the full design, invariants and trade-offs. Signed-off-by: xiaofanluan <xf@hjjaq.com> Co-authored-by: xiaofanluan <xf@hjjaq.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
207 lines
6.7 KiB
Go
207 lines
6.7 KiB
Go
package proxy
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"google.golang.org/grpc"
|
|
"google.golang.org/grpc/metadata"
|
|
"google.golang.org/protobuf/encoding/prototext"
|
|
"google.golang.org/protobuf/proto"
|
|
|
|
"github.com/milvus-io/milvus-proto/go-api/v3/milvuspb"
|
|
"github.com/milvus-io/milvus/pkg/v3/util"
|
|
)
|
|
|
|
func TestDatabaseInterceptor(t *testing.T) {
|
|
ctx := context.Background()
|
|
interceptor := DatabaseInterceptor()
|
|
|
|
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
|
|
return "", nil
|
|
}
|
|
|
|
t.Run("empty md", func(t *testing.T) {
|
|
req := &milvuspb.CreateCollectionRequest{}
|
|
_, err := interceptor(ctx, req, &grpc.UnaryServerInfo{}, handler)
|
|
assert.NoError(t, err)
|
|
assert.Equal(t, util.DefaultDBName, req.GetDbName())
|
|
})
|
|
|
|
t.Run("with invalid metadata", func(t *testing.T) {
|
|
md := metadata.Pairs("xxx", "yyy")
|
|
ctx = metadata.NewIncomingContext(ctx, md)
|
|
req := &milvuspb.CreateCollectionRequest{}
|
|
_, err := interceptor(ctx, req, &grpc.UnaryServerInfo{}, handler)
|
|
assert.NoError(t, err)
|
|
assert.Equal(t, util.DefaultDBName, req.GetDbName())
|
|
})
|
|
|
|
t.Run("empty req", func(t *testing.T) {
|
|
md := metadata.Pairs("xxx", "yyy")
|
|
ctx = metadata.NewIncomingContext(ctx, md)
|
|
_, err := interceptor(ctx, "", &grpc.UnaryServerInfo{}, handler)
|
|
assert.NoError(t, err)
|
|
})
|
|
|
|
t.Run("id-only describe keeps omitted database empty", func(t *testing.T) {
|
|
md := metadata.Pairs(util.HeaderDBName, "db-from-header")
|
|
ctx := metadata.NewIncomingContext(context.Background(), md)
|
|
req := &milvuspb.DescribeCollectionRequest{CollectionID: 100}
|
|
_, err := interceptor(ctx, req, &grpc.UnaryServerInfo{}, handler)
|
|
assert.NoError(t, err)
|
|
assert.Empty(t, req.GetDbName())
|
|
})
|
|
|
|
t.Run("name-based describe still gets database from metadata", func(t *testing.T) {
|
|
md := metadata.Pairs(util.HeaderDBName, "db-from-header")
|
|
ctx := metadata.NewIncomingContext(context.Background(), md)
|
|
req := &milvuspb.DescribeCollectionRequest{CollectionName: "collection"}
|
|
_, err := interceptor(ctx, req, &grpc.UnaryServerInfo{}, handler)
|
|
assert.NoError(t, err)
|
|
assert.Equal(t, "db-from-header", req.GetDbName())
|
|
})
|
|
|
|
t.Run("external snapshot requests get db from metadata", func(t *testing.T) {
|
|
md := metadata.Pairs(util.HeaderDBName, "db")
|
|
ctx := metadata.NewIncomingContext(context.Background(), md)
|
|
testCases := []struct {
|
|
name string
|
|
req proto.Message
|
|
dbFun func(proto.Message) string
|
|
}{
|
|
{
|
|
name: "restore external snapshot",
|
|
req: &milvuspb.RestoreExternalSnapshotRequest{},
|
|
dbFun: func(req proto.Message) string {
|
|
return req.(*milvuspb.RestoreExternalSnapshotRequest).GetDbName()
|
|
},
|
|
},
|
|
{
|
|
name: "export snapshot",
|
|
req: &milvuspb.ExportSnapshotRequest{},
|
|
dbFun: func(req proto.Message) string {
|
|
return req.(*milvuspb.ExportSnapshotRequest).GetDbName()
|
|
},
|
|
},
|
|
}
|
|
|
|
for _, testCase := range testCases {
|
|
t.Run(testCase.name, func(t *testing.T) {
|
|
_, err := interceptor(ctx, testCase.req, &grpc.UnaryServerInfo{}, handler)
|
|
assert.NoError(t, err)
|
|
assert.Equal(t, "db", testCase.dbFun(testCase.req))
|
|
})
|
|
}
|
|
})
|
|
|
|
t.Run("test ok for all request", func(t *testing.T) {
|
|
availableReqs := []proto.Message{
|
|
&milvuspb.CreateCollectionRequest{},
|
|
&milvuspb.DropCollectionRequest{},
|
|
&milvuspb.TruncateCollectionRequest{},
|
|
&milvuspb.HasCollectionRequest{},
|
|
&milvuspb.LoadCollectionRequest{},
|
|
&milvuspb.ReleaseCollectionRequest{},
|
|
&milvuspb.DescribeCollectionRequest{},
|
|
&milvuspb.BatchDescribeCollectionRequest{},
|
|
&milvuspb.GetStatisticsRequest{},
|
|
&milvuspb.GetCollectionStatisticsRequest{},
|
|
&milvuspb.ShowCollectionsRequest{},
|
|
&milvuspb.AlterCollectionRequest{},
|
|
&milvuspb.AlterCollectionFieldRequest{},
|
|
&milvuspb.AddCollectionFunctionRequest{},
|
|
&milvuspb.DropCollectionFunctionRequest{},
|
|
&milvuspb.AlterCollectionFunctionRequest{},
|
|
&milvuspb.CreatePartitionRequest{},
|
|
&milvuspb.DropPartitionRequest{},
|
|
&milvuspb.HasPartitionRequest{},
|
|
&milvuspb.LoadPartitionsRequest{},
|
|
&milvuspb.ReleasePartitionsRequest{},
|
|
&milvuspb.GetPartitionStatisticsRequest{},
|
|
&milvuspb.ShowPartitionsRequest{},
|
|
&milvuspb.GetLoadingProgressRequest{},
|
|
&milvuspb.GetLoadStateRequest{},
|
|
&milvuspb.CreateIndexRequest{},
|
|
&milvuspb.DescribeIndexRequest{},
|
|
&milvuspb.DropIndexRequest{},
|
|
&milvuspb.AlterIndexRequest{},
|
|
&milvuspb.GetIndexBuildProgressRequest{},
|
|
&milvuspb.GetIndexStateRequest{},
|
|
&milvuspb.InsertRequest{},
|
|
&milvuspb.DeleteRequest{},
|
|
&milvuspb.SearchRequest{},
|
|
&milvuspb.HybridSearchRequest{},
|
|
&milvuspb.FlushRequest{},
|
|
&milvuspb.GetFlushStateRequest{},
|
|
&milvuspb.QueryRequest{},
|
|
&milvuspb.CreateAliasRequest{},
|
|
&milvuspb.DropAliasRequest{},
|
|
&milvuspb.AlterAliasRequest{},
|
|
&milvuspb.ListAliasesRequest{},
|
|
&milvuspb.DescribeAliasRequest{},
|
|
&milvuspb.GetPersistentSegmentInfoRequest{},
|
|
&milvuspb.GetQuerySegmentInfoRequest{},
|
|
&milvuspb.LoadBalanceRequest{},
|
|
&milvuspb.GetReplicasRequest{},
|
|
&milvuspb.ImportRequest{},
|
|
&milvuspb.RenameCollectionRequest{},
|
|
&milvuspb.TransferReplicaRequest{},
|
|
&milvuspb.ListImportTasksRequest{},
|
|
&milvuspb.OperatePrivilegeRequest{Entity: &milvuspb.GrantEntity{}},
|
|
&milvuspb.SelectGrantRequest{Entity: &milvuspb.GrantEntity{}},
|
|
&milvuspb.ManualCompactionRequest{},
|
|
&milvuspb.AddCollectionFieldRequest{},
|
|
&milvuspb.AddCollectionStructFieldRequest{},
|
|
&milvuspb.AlterCollectionSchemaRequest{},
|
|
&milvuspb.RunAnalyzerRequest{},
|
|
&milvuspb.RestoreExternalSnapshotRequest{},
|
|
&milvuspb.ExportSnapshotRequest{},
|
|
&milvuspb.RefreshExternalCollectionRequest{},
|
|
&milvuspb.ListRefreshExternalCollectionJobsRequest{},
|
|
}
|
|
|
|
md := metadata.Pairs(util.HeaderDBName, "db")
|
|
ctx = metadata.NewIncomingContext(ctx, md)
|
|
for _, req := range availableReqs {
|
|
before, err := proto.Marshal(req)
|
|
assert.NoError(t, err)
|
|
|
|
_, err = interceptor(ctx, req, &grpc.UnaryServerInfo{}, handler)
|
|
assert.NoError(t, err)
|
|
|
|
after, err := proto.Marshal(req)
|
|
assert.NoError(t, err)
|
|
|
|
assert.True(t, len(after) > len(before))
|
|
}
|
|
|
|
unavailableReqs := []proto.Message{
|
|
&milvuspb.GetMetricsRequest{},
|
|
&milvuspb.DummyRequest{},
|
|
&milvuspb.CalcDistanceRequest{},
|
|
&milvuspb.FlushAllRequest{},
|
|
&milvuspb.GetCompactionStateRequest{},
|
|
&milvuspb.GetCompactionPlansRequest{},
|
|
&milvuspb.GetFlushAllStateRequest{},
|
|
&milvuspb.GetImportStateRequest{},
|
|
}
|
|
|
|
for _, req := range unavailableReqs {
|
|
before, err := proto.Marshal(req)
|
|
assert.NoError(t, err)
|
|
|
|
_, err = interceptor(ctx, req, &grpc.UnaryServerInfo{}, handler)
|
|
assert.NoError(t, err)
|
|
|
|
after, err := proto.Marshal(req)
|
|
assert.NoError(t, err)
|
|
|
|
if len(after) != len(before) {
|
|
t.Errorf("req has been modified:%s", prototext.Format(req))
|
|
}
|
|
}
|
|
})
|
|
}
|