Apache Software Foundation / SeaTunnel
Merged upstreamReliabilitySelected contributionMerged Sep 30, 2026

Prevent a Kudu client deadlock in Flink JobManager

Removed a lock-order inversion trigger from Kudu client construction while preserving the existing Kerberos and ticket-cache authentication paths.

apache/seatunnel · #12480

Distributed-runtime reliability fix

SeaTunnel Kudu jobs on Flink and JDK 11 no longer risk freezing the JobManager during client initialization under a non-Kerberos JAAS Subject.

Problem

Kudu 1.15 eagerly formatted a non-Kerberos caller Subject while initializing its security context. On JDK 11, Subject and resource-bundle internals could acquire the principal-set and domain-combiner locks in the opposite order from concurrent thread creation, deadlocking the Flink JobManager and leaving Kudu jobs hung until the 90-minute CI limit.

Approach

Builds the Kudu client outside an ambient Subject only when that Subject has no Kerberos principal. Kudu already ignores that Subject and falls back to the ticket cache, while Kerberos-bearing Subjects and calls without a Subject retain the original construction path.

Impact and scope

  • Fixes a real connector runtime hazard affecting source, sink, reader, enumerator, and catalog paths that share KuduUtil.
  • Preserves authentication behavior while removing the connector's trigger for the JDK lock-order deadlock.
  • Addresses a recurring CI failure pattern with 114 Kudu legs cancelled after more than 60 minutes across the analyzed development runs.
  • Keeps the production change to one client-construction choke point and adds explicit protection for the unchanged Kerberos path.

Validation

  • The focused Kudu connector suite passed 11 tests on JDK 8 and JDK 11, including regressions for non-Kerberos and Kerberos caller Subjects.
  • A forced-race reproduction hung 3 of 3 times on the development baseline and passed 15 of 15 times with the fix; an unchanged Kudu E2E matrix passed 29 of 29 invocations across Zeta, Flink, and Spark legs that were run.
  • Three upstream reviewers, including an Apache SeaTunnel member, approved the authored change; all five current hosted checks pass and GH-12132 is closed.