Skip to content

Yjd dev - #1485

Merged
yuhaijun999 merged 2 commits into
dingodb:mainfrom
visualYJD:yjd-dev
Sep 7, 2026
Merged

Yjd dev#1485
yuhaijun999 merged 2 commits into
dingodb:mainfrom
visualYJD:yjd-dev

Conversation

@visualYJD

Copy link
Copy Markdown
Contributor

No description provided.

A failure domain is the unit whose members fail together. Several store
instances on one machine share its kernel, power and NIC, so the domain
is keyed by the store's server host; Helper::FailureDomainKey is the one
place to change when rack or zone awareness is added later.
FailureDomainProfile turns a peer set into its per-domain replica counts
sorted descending, and IsFailureDomainNoWorse compares two profiles
lexicographically ([1,1,1] < [2,1] < [3]) so callers can tell whether a
change packs more replicas into one domain than before.
…osts)

Every placement path worked per store_id with no notion of a host, so on
a four-host cluster with five store instances each, 1955 of 2009 regions
ended up with two replicas on one machine. This makes the coordinator
failure-domain aware, keyed by the store's server host:

- SelectStore spreads a new region's replicas over distinct hosts
  best-effort (PickStoresAcrossFailureDomains). With fewer hosts than
  replicas it stacks as little as possible and never fails creation.
- ChangePeerRegion and ChangePairPeerRegion get a commit-side guard
  (ValidateFailureDomainNoWorse): a same-size change may not make the
  per-host profile worse, an added replica may not exceed
  ceil(replicas / online hosts), removals always pass. The rule is
  "no worse", not "must be legal", so legacy packed regions stay
  repairable. Refusals return ECHANGE_PEER_FAILURE_DOMAIN_WORSE. In
  verify_peer_on_store mode the effective peer set is rebuilt with set
  semantics (BuildEffectiveStoreIds), so activating a shadow peer is not
  mistaken for adding a replica.
- Balance region pre-checks each move with the same rule, resolving peer
  hosts from the store map exactly like the guard, and reports domain
  rejections as one line per store pair.
- Balance leader refuses to move a leader into a host that already holds
  more than its even share times (1 + tolerance); a move between two
  stores on the same host is exempt.
- ChangePairPeerRegion rejects duplicate store ids, which set_difference
  would otherwise let through.

Runtime knobs via ControlConfig: enable_failure_domain_guard,
enable_failure_domain_placement, balance_leader_failure_domain_tolerance.
Bumps dingo-store-proto to 494bf56 for the new errno.

@yuhaijun999 yuhaijun999 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@yuhaijun999
yuhaijun999 added this pull request to the merge queue Sep 7, 2026
Merged via the queue into dingodb:main with commit 246ef45 Sep 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants