Siyao Meng created HDDS-16435:
---------------------------------

             Summary: OM LINEARIZABLE_ALLOW_FOLLOWER read can return stale data 
from a superseded leader
                 Key: HDDS-16435
                 URL: https://issues.apache.org/jira/browse/HDDS-16435
             Project: Apache Ozone
          Issue Type: Bug
            Reporter: Siyao Meng


h3. Finding
Under the opt-in leader-skip config (LINEARIZABLE_ALLOW_FOLLOWER), a superseded 
leader still self-reporting LEADER_AND_READY serves a raw local read with no 
ReadIndex or leadership recheck, so a client that explicitly asked for no-stale 
reads can silently receive committed data older than an acknowledged write 
during a partition-induced split-brain window. Three related model-checking 
findings share this root cause: MC-1 (the RPC read path), MC-2 
(LINEARIZABLE_ALLOW_FOLLOWER routed to a stale-capable raw local read while 
LINEARIZABLE_LEADER_ONLY keeps ReadIndex), and CR-2 (on leader fall-back the 
gRPC/S3 gateway transport re-hints to DEFAULT while the RPC transport keeps 
LINEARIZABLE_ALLOW_FOLLOWER). Bounded, externally observable linearizability 
(safety) violation via a missing leadership/quorum check. ENV_LIMITED: 
MiniOzoneHACluster cannot inject the asymmetric partition, so the routing/hint 
divergence was reproduced but the live stale value was not.

h3. Classification
* Verdict: ENV_LIMITED
* Severity: High
* Source: Specula TLA+ model checking and confirmation debate, finding 
MC-1/MC-2/CR-2

h3. Reproduce
{noformat}
Ozone commit: 9fbf9ee0cb1bd2f5f5d437b6719ebbe5309351fb
Specula:      v1.1.0 (commit c6aa3dfa)
Target:       om-follower-read
Guidance:     
campaigns/ozone-9fbf9ee/targets/001-om-follower-read/.prompt-extra.md
{noformat}
{code:none}
specula run --agent=claude-code --effort=high --keep-original --max-parallel=2 \
  --enable-reviews --confirm-debate --tlc-memory-limit=28G --tlc-worker-limit=8 
\
  "om-follower-read|apache/ozone|Java|Use the target-specific .prompt-extra.md"
{code}
Discovered under HDDS-16428 (Specula TLA+ verification effort). The TLA+ 
specification, counterexample, and confirmation debate live in the Specula run 
artifacts.

Generated with Specula (Claude Opus 4.8).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to