[ 
https://issues.apache.org/jira/browse/YUNIKORN-3384?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Dale Richardson reassigned YUNIKORN-3384:
-----------------------------------------

    Assignee: Dale Richardson

> Partition accounting property fuzzer
> ------------------------------------
>
>                 Key: YUNIKORN-3384
>                 URL: https://issues.apache.org/jira/browse/YUNIKORN-3384
>             Project: Apache YuniKorn
>          Issue Type: Test
>          Components: core - scheduler, shim - kubernetes
>            Reporter: Dale Richardson
>            Assignee: Dale Richardson
>            Priority: Major
>
> A property fuzzer for the core's partition-level accounting. The shim cache 
> fuzzer
> (YUNIKORN-3373) guards shim bookkeeping; nothing guarded the core's. This is 
> the
> structural guard for that class from the core side.
> h3. Design
> Seeded, weighted random operation sequences (several hundred ops per seed, 
> several
> seeds) against a real PartitionContext with a small queue hierarchy, driven
> through the same entry points the RM uses: add/remove node (removal with live
> allocations included), add/remove app, add ask, TryAllocate cycles, release 
> with
> each TerminationType, replace-ask, reservation create/cancel, required-node 
> asks.
> After every operation it checks:
> * Q1 each queue's allocated == sum of its children (recursive)
> * Q2 each leaf queue's allocated == sum of its apps' allocated
> * Q3 usage never negative, never over a set maximum
> * Q4 user/group tracked usage == sum of owned apps' allocated
> * Q5 each node's allocated == sum of allocations on it
> * Q6 queue pending == sum of app pending asks
> * R1 every reservation references a live app + ask + node
> plus a running allocated-minus-released model cross-check.
> h3. Verification
> Green on master across all seeds (this is a guard, not necessarily a finder). 
> Its
> teeth are proven by mutation testing: five deliberate accounting breaks each 
> fire
> the expected invariant (e.g. dropping queue.DecAllocatedResource fires 
> Q2/Q3/model;
> dropping the parent recursion fires Q1; breaking the user tracker fires Q4). 
> All
> mutations reverted -- the committed diff is test-only. Runtime ~4s.
> h3. Findings
> Two real core defects were found while building this and are filed separately:
> YUNIKORN-3379 (PLACEHOLDER_REPLACED crash) and YUNIKORN-3380 
> (RemoveAllAllocations
> quota leak). Their trigger operations are deliberately excluded from the 
> committed
> fuzzer so it stays green and mergeable; a follow-up can add them once the 
> bugs are
> fixed.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to