ChallengeFind the bug
This piece of code caused a crashing bug on a QA server ( and we are lucky it didn’t go to production ).
Can you spot the bug?
I will give you a hint, it is the code that isn’t there.
More posts in "Challenge" series:
- (04 Jan 2023) what does this code print?
- (14 Dec 2022) What does this code print?
- (01 Jul 2022) Find the stack smash bug… – answer
- (30 Jun 2022) Find the stack smash bug…
- (03 Jun 2022) Spot the data corruption
- (06 May 2022) Spot the optimization–solution
- (05 May 2022) Spot the optimization
- (06 Apr 2022) Why is this code broken?
- (16 Dec 2021) Find the slow down–answer
- (15 Dec 2021) Find the slow down
- (03 Nov 2021) The code review bug that gives me nightmares–The fix
- (02 Nov 2021) The code review bug that gives me nightmares–the issue
- (01 Nov 2021) The code review bug that gives me nightmares
- (16 Jun 2021) Detecting livelihood in a distributed cluster
- (21 Apr 2020) Generate matching shard id–answer
- (20 Apr 2020) Generate matching shard id
- (02 Jan 2020) Spot the bug in the stream
- (28 Sep 2018) The loop that leaks–Answer
- (27 Sep 2018) The loop that leaks
- (03 Apr 2018) The invisible concurrency bug–Answer
- (02 Apr 2018) The invisible concurrency bug
- (31 Jan 2018) Find the bug in the fix–answer
- (30 Jan 2018) Find the bug in the fix
- (19 Jan 2017) What does this code do?
- (26 Jul 2016) The race condition in the TCP stack, answer
- (25 Jul 2016) The race condition in the TCP stack
- (28 Apr 2015) What is the meaning of this change?
- (26 Sep 2013) Spot the bug
- (27 May 2013) The problem of locking down tasks…
- (17 Oct 2011) Minimum number of round trips
- (23 Aug 2011) Recent Comments with Future Posts
- (02 Aug 2011) Modifying execution approaches
- (29 Apr 2011) Stop the leaks
- (23 Dec 2010) This code should never hit production
- (17 Dec 2010) Your own ThreadLocal
- (03 Dec 2010) Querying relative information with RavenDB
- (29 Jun 2010) Find the bug
- (23 Jun 2010) Dynamically dynamic
- (28 Apr 2010) What killed the application?
- (19 Mar 2010) What does this code do?
- (04 Mar 2010) Robust enumeration over external code
- (16 Feb 2010) Premature optimization, and all of that…
- (12 Feb 2010) Efficient querying
- (10 Feb 2010) Find the resource leak
- (21 Oct 2009) Can you spot the bug?
- (18 Oct 2009) Why is this wrong?
- (17 Oct 2009) Write the check in comment
- (15 Sep 2009) NH Prof Exporting Reports
- (02 Sep 2009) The lazy loaded inheritance many to one association OR/M conundrum
- (01 Sep 2009) Why isn’t select broken?
- (06 Aug 2009) Find the bug fixes
- (26 May 2009) Find the bug
- (14 May 2009) multi threaded test failure
- (11 May 2009) The regex that doesn’t match
- (24 Mar 2009) probability based selection
- (13 Mar 2009) C# Rewriting
- (18 Feb 2009) write a self extracting program
- (04 Sep 2008) Don't stop with the first DSL abstraction
- (02 Aug 2008) What is the problem?
- (28 Jul 2008) What does this code do?
- (26 Jul 2008) Find the bug fix
- (05 Jul 2008) Find the deadlock
- (03 Jul 2008) Find the bug
- (02 Jul 2008) What is wrong with this code
- (05 Jun 2008) why did the tests fail?
- (27 May 2008) Striving for better syntax
- (13 Apr 2008) calling generics without the generic type
- (12 Apr 2008) The directory tree
- (24 Mar 2008) Find the version
- (21 Jan 2008) Strongly typing weakly typed code
- (28 Jun 2007) Windsor Null Object Dependency Facility
Is a transaction or some other synchronization method missing here? That is, it seeks the values, then deletes them. The data could change during the deletions.
It's in the loop... ?
I think, you're missing a check before deleting it ...
Where does 'data' comes from? (The ApplyToKeyAndActiveVersions line).
Ayende, where's your sweet spot in the Esent database? Do you miss good ol' days of WINAPI programming, or is Esent exceptionally performant/stable/powerful/whatever? Maybe there was a reason Microsoft has hidden it?
No, that is handled elsewhere
Another table that we join against.
You are close...
No, that is not it.
I use it when I need a local DB. It is really easy to use when you get how it is working.
It helps that it is the only local DB with true threading support.
maybe issue is related with closure of the session and data variables here: v=>Api.JetDelete(session, data)
No, that is not it
Maybe "v => Api.JetDelete(session, data)" can't be run thru delegate for some reason?
No, that is not it. It works just fine.
I take it the crash is a stack overflow from an infinite loop and that you are either missing a breaking condition or not doing something that would should effect the 'position'..
Basically no idea, is this something that will probably only make sense when illustrated and explained?
What happens to the table cursor after Api.JetDelete()?
And does Api.JetDelete() immediately remove the table row or only mark it as deleted?
Otherwise scenario could be:
Api.JetDelete moves cursor forward
Api.TryMovePrevious moves cursor backwards (to same row)
=> infinite loop
Stephen, That would hang, not crash...
Ah, true ;)
(btw ayende, having problems submitting comments from ie7/8- not sure if its just me, hitting submit doesn't do anything it just sits there).
No stack overflow, no, and not an infinite loop, but you should concentrate on the loop
It is marking that for deletion in the end of the current transaction, TryMovePrevious is not the issue.
The loop will terminate at the expected time.
I guess that you are trying to clean expired values (stuff we don't care about anymore).. thus having a big result set would pose a problem... am I right?
do we need to know the contract of the jet api to find the problem?
If the Api.RetrieveColumnAsString gets the first one then the Api.TryMovePrevious would never go to the rest but stop when the first one is deleted.
Tada, you are very close.
No, you don't.
No, that is not the behavior we have
How often do values expire?
You're calling the function on a fixed timer and it's being executed again, before the previous execution has finished. Considering it results in a crash, it's probably stacking a good number of times.
That is a user defined value. In the system that we are talking abut, 24 hours
What timer? There isn't any external code involved that affect the bug in this function
The call to Api.JetDelete should probably be called with session and key, not session and keyS (deleting everything)?
keys is the variable holding the table name, not a collection. It is instruction to delete the current row.
Two Api.JetDelete calls?
Notice what I said, what is the code that IS NOT THERE?!
You get the version but do not check it has expired?
TBH I am guessing based on what I would expect to see rather than understanding the code / api that this is using but it seems like the most logical thing.
No, that is not that.
And you don't need to understand anything about the API to see the problem.
The problem is that until you see the problem, you don't know what it is.
I am actually encouraged that no one managed to find it.
It means that I am not that stupid
Commit size will become huge in this case... Since you say that it is about code that isn't there, all I am able to come with is fixing a maximum of expired values to be processed in the loop and process the remaining later. That's similar to ORA-01555 snapshot too old!
TADA! You got it!
When you hit it exactly right, you may get a LOT of expired values.
Those expired values can be big enough to hit the commit limit, and cause an error!
So I was stupid, I thought so! :-)
Wow... gloubidou I am impress.
Oren, how did you uncover the bug? If the application throw an exception somewhere then it's probably not that hard to trace down the culprit. Did you catch it through stress testing?
Silly question: why is there a commit limit?
As I said, we run into this error in QA.
Once I had the stack trace, and the error, it was really obvious what was wrong