NIFI-16290 - Node offload should give processors a bounded grace period to stop cleanly before forced termination - #11621
Open
pvillard31 wants to merge 1 commit into
Open
NIFI-16290 - Node offload should give processors a bounded grace period to stop cleanly before forced termination#11621pvillard31 wants to merge 1 commit into
pvillard31 wants to merge 1 commit into
Conversation
…od to stop cleanly before forced termination
pvillard31
force-pushed
the
NIFI-16290
branch
from
September 3, 2026 21:42
4020a82 to
1f3faab
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
NIFI-16290 - Node offload should give processors a bounded grace period to stop cleanly before forced termination
StandardFlowService.offload()currently callsrootGroup.stopProcessing()and discards the returned future, then immediately force-terminates any processor whose logical scheduled state is STOPPED. Since logical STOPPED also covers the physical STOPPING state, this can terminate a processor before its asynchronous stop lifecycle has actually finished (overtaking@OnUnscheduled, aborting the wait for active threads to drain, and skipping@OnStopped) so processors never get a real chance to release external resources cleanly during node offload. This PR adds a bounded grace period: offload now waits on the aggregatestopProcessing()future for up tonifi.flowcontroller.graceful.shutdown.periodbefore falling through to the existing unconditional termination sweep. A hung or wedged processor, including one holding an uncommitted ProcessSession, still cannot block offload indefinitely (the fallback always runs regardless of outcome: completed, timed out, interrupted, or exceptional). The graceful-wait outcome is logged for operational visibility.The change is covered by a new unit test suite in
TestStandardFlowServicethat deterministically exercises multiple paths: normal completion, timeout, interruption during the processor/RPG/queue waits with correct restore semantics, exceptional/cancelled futures, and that termination still runs even when the graceful wait completes normally, which is required to roll back FlowFiles held in an uncommitted session. The clusteredOffloadITsystem test retains its originaltestOffloadscenario, now also running against a shortgraceful.shutdown.periodoverride so it exercises the new code path on every iteration.Tracking
Please complete the following tracking steps prior to pull request creation.
Issue Tracking
Pull Request Tracking
NIFI-00000NIFI-00000VerifiedstatusPull Request Formatting
mainbranchVerification
Please indicate the verification steps performed prior to pull request creation.
Build
./mvnw clean install -P contrib-checkLicensing
LICENSEandNOTICEfilesDocumentation