Skip to content

Disable system.kafka_consumers by default (due to possible live memory leak)#57822

Merged
alexey-milovidov merged 1 commit intoClickHouse:masterfrom
azat:kafka-disable-stat
Dec 14, 2023
Merged

Disable system.kafka_consumers by default (due to possible live memory leak)#57822
alexey-milovidov merged 1 commit intoClickHouse:masterfrom
azat:kafka-disable-stat

Conversation

@azat
Copy link
Member

@azat azat commented Dec 13, 2023

Changelog category (leave one):

  • Bug Fix (user-visible misbehavior in an official stable release)

Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):

Disable system.kafka_consumers by default (due to possible live memory leak)

It is not safe to use statistics because of how KafkaEngine works - it pre-creates consumers, and this leads to the situation when this statistics entries generated (RD_KAFKA_OP_STATS), but never consumed.

Which creates a live memory leak for a server with Kafka tables, but without materialized view attached to it (and no SELECT).

Another problem is that this makes shutdown very slow, because of how pending queue entries are handled in librdkafka, it uses TAILQ_INSERT_SORTED, which is sorted insert into linked list, which works incredibly slow (likely you will never wait till it ends and kill the server)

For instance in my production setup the server was running for ~67 days with such table, and it got 1'942'233 TAILQ_INSERT_SORTED entries (which perfectly matches by the way - 67*86400/3 = 1'929'600), and it moved only 289'806 entries for a few hours, though I'm not sure how much time the process was in the running state, since most of the time it was with debugger attached.

So for now let's disable it, to make this patch easy for backporting, and I will think about long term fix - do not pre-create consumers in Kafka engine.

Fixes: #50999 (cc @ilejn)

…y leak)

It is not safe to use statistics because of how KafkaEngine works - it
pre-creates consumers, and this leads to the situation when this
statistics entries generated (RD_KAFKA_OP_STATS), but never consumed.

Which creates a live memory leak for a server with Kafka tables, but
without materialized view attached to it (and no SELECT).

Another problem is that this makes shutdown very slow, because of how
pending queue entries are handled in librdkafka, it uses
TAILQ_INSERT_SORTED, which is sorted insert into linked list, which
works incredibly slow (likely you will never wait till it ends and kill
the server)

For instance in my production setup the server was running for ~67 days
with such table, and it got 1'942'233 `TAILQ_INSERT_SORTED` entries
(which perfectly matches by the way - `67*86400/3` = 1'929'600), and it
moved only 289'806 entries for a few hours, though I'm not sure how much
time the process was in the running state, since most of the time it was
with debugger attached.

So for now let's disable it, to make this patch easy for backporting,
and I will think about long term fix - do not pre-create consumers in
Kafka engine.

Signed-off-by: Azat Khuzhin <[email protected]>
@robot-clickhouse robot-clickhouse added the pr-bugfix Pull request with bugfix, not backported by default label Dec 13, 2023
@robot-clickhouse
Copy link
Member

robot-clickhouse commented Dec 13, 2023

This is an automated comment for commit 055c231 with description of existing statuses. It's updated for the latest CI running

❌ Click here to open a full report in a separate page

Successful checks
Check nameDescriptionStatus
AST fuzzerRuns randomly generated queries to catch program errors. The build type is optionally given in parenthesis. If it fails, ask a maintainer for help✅ success
ClickHouse build checkBuilds ClickHouse in various configurations for use in further steps. You have to fix the builds that fail. Build logs often has enough information to fix the error, but you might have to reproduce the failure locally. The cmake options can be found in the build log, grepping for cmake. Use these options and follow the general build process✅ success
Compatibility checkChecks that clickhouse binary runs on distributions with old libc versions. If it fails, ask a maintainer for help✅ success
Docker image for serversThe check to build and optionally push the mentioned image to docker hub✅ success
Fast testNormally this is the first check that is ran for a PR. It builds ClickHouse and runs most of stateless functional tests, omitting some. If it fails, further checks are not started until it is fixed. Look at the report to see which tests fail, then reproduce the failure locally as described here✅ success
Flaky testsChecks if new added or modified tests are flaky by running them repeatedly, in parallel, with more randomization. Functional tests are run 100 times with address sanitizer, and additional randomization of thread scheduling. Integrational tests are run up to 10 times. If at least once a new test has failed, or was too long, this check will be red. We don't allow flaky tests, read the doc✅ success
Install packagesChecks that the built packages are installable in a clear environment✅ success
Mergeable CheckChecks if all other necessary checks are successful✅ success
Performance ComparisonMeasure changes in query performance. The performance test report is described in detail here. In square brackets are the optional part/total tests✅ success
Push to DockerhubThe check for building and pushing the CI related docker images to docker hub✅ success
SQLTestThere's no description for the check yet, please add it to tests/ci/ci_config.py:CHECK_DESCRIPTIONS✅ success
SQLancerFuzzing tests that detect logical bugs with SQLancer tool✅ success
SqllogicRun clickhouse on the sqllogic test set against sqlite and checks that all statements are passed✅ success
Stateful testsRuns stateful functional tests for ClickHouse binaries built in various configurations -- release, debug, with sanitizers, etc✅ success
Stress testRuns stateless functional tests concurrently from several clients to detect concurrency-related errors✅ success
Style CheckRuns a set of checks to keep the code style clean. If some of tests failed, see the related log from the report✅ success
Unit testsRuns the unit tests for different release types✅ success
Upgrade checkRuns stress tests on server version from last release and then tries to upgrade it to the version from the PR. It checks if the new server can successfully startup without any errors, crashes or sanitizer asserts✅ success
Check nameDescriptionStatus
Bugfix validate checkChecks that either a new test (functional or integration) or there some changed tests that fail with the binary built on master branch❌ error
CI runningA meta-check that indicates the running CI. Normally, it's in success or pending state. The failed status indicates some problems with the PR⏳ pending
Integration testsThe integration tests report. In parenthesis the package type is given, and in square brackets are the optional part/total tests❌ failure
Stateless testsRuns stateless functional tests for ClickHouse binaries built in various configurations -- release, debug, with sanitizers, etc❌ failure

@ilejn
Copy link
Contributor

ilejn commented Dec 13, 2023

Hm ... sorry to hear that it caused so many troubles.
Thanks for the insights,
we'll definitely try to fix these issues.

@azat
Copy link
Member Author

azat commented Dec 13, 2023

we'll definitely try to fix these issues.

Here is a fix - #57829

@alexey-milovidov alexey-milovidov self-assigned this Dec 14, 2023
@alexey-milovidov alexey-milovidov merged commit 7a2edb4 into ClickHouse:master Dec 14, 2023
@alexey-milovidov
Copy link
Member

@azat, it is much better to remove the feature entirely than disabling it.

@azat azat deleted the kafka-disable-stat branch December 14, 2023 08:09
@azat
Copy link
Member Author

azat commented Dec 14, 2023

it is much better to remove the feature entirely than disabling it.

@alexey-milovidov I think that this information can be useful, and I've already submitted a proper fix.
And I've submitted a workaround and a proper fix separately since "proper fix" is not that trivial, and backporting it is a bad idea.

And also let's backport this patch.

@chiragb1994
Copy link

Will this fix be backported to v23.8?

Enmk pushed a commit to Altinity/ClickHouse that referenced this pull request Dec 22, 2023
Disable system.kafka_consumers by default (due to possible live memory leak)
Enmk added a commit to Altinity/ClickHouse that referenced this pull request Dec 22, 2023
…tem_kafka_consumers_table

23.8 Backport of ClickHouse#57822 - Disable `system.kafka_consumers` by default
@azat
Copy link
Member Author

azat commented Dec 27, 2023

@alexey-milovidov objections on backporting this patch?

robot-clickhouse added a commit that referenced this pull request Dec 27, 2023
robot-clickhouse added a commit that referenced this pull request Dec 27, 2023
robot-clickhouse added a commit that referenced this pull request Dec 27, 2023
alexey-milovidov added a commit that referenced this pull request Dec 27, 2023
Backport #57822 to 23.8: Disable system.kafka_consumers by default (due to possible live memory leak)
alexey-milovidov added a commit that referenced this pull request Dec 27, 2023
Backport #57822 to 23.9: Disable system.kafka_consumers by default (due to possible live memory leak)
alexey-milovidov added a commit that referenced this pull request Dec 27, 2023
Backport #57822 to 23.10: Disable system.kafka_consumers by default (due to possible live memory leak)
alexey-milovidov added a commit that referenced this pull request Dec 27, 2023
Backport #57822 to 23.11: Disable system.kafka_consumers by default (due to possible live memory leak)
@robot-ch-test-poll2 robot-ch-test-poll2 added the pr-backports-created Backport PRs are successfully created, it won't be processed by CI script anymore label Dec 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr-backports-created Backport PRs are successfully created, it won't be processed by CI script anymore pr-bugfix Pull request with bugfix, not backported by default pr-must-backport Pull request should be backported intentionally. Use this label with great care!

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants