Skip to content

fix: use a monotonic clock for the cache polling timeout - #3529

Draft
csviri wants to merge 1 commit into
operator-framework:mainfrom
csviri:fix/poll-local-cache-midnight-wraparound
Draft

fix: use a monotonic clock for the cache polling timeout#3529
csviri wants to merge 1 commit into
operator-framework:mainfrom
csviri:fix/poll-local-cache-midnight-wraparound

Conversation

@csviri

@csviri csviri commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator

pollLocalCache computed its deadline with LocalTime:

var startTime = LocalTime.now();
final var timeoutTime = startTime.plus(timeoutMillis, ChronoUnit.MILLIS);
while (timeoutTime.isAfter(LocalTime.now())) {

LocalTime is a time of day and wraps at midnight, so for any call made
within timeoutMillis of 00:00 the computed deadline is earlier than
the current time. The loop body never runs and the method throws
OperatorException("Timeout of resource polling from cache for resource")
immediately, failing the update it was retrying even though the resource
would have appeared in cache. With the default 10s timeout that is a
10-second window each day.

LocalTime.now() is also wall-clock based, so an NTP step or a DST change
can shorten or extend the timeout.

Switches to System.nanoTime(), which is monotonic and has no wrap-around
concern, using overflow-safe subtraction for the comparison.

No test is added: reproducing this requires controlling the clock, and the
class is already deprecated for removal.

Part of #3517

`pollLocalCache` computed its deadline with `LocalTime`:

    var startTime = LocalTime.now();
    final var timeoutTime = startTime.plus(timeoutMillis, ChronoUnit.MILLIS);
    while (timeoutTime.isAfter(LocalTime.now())) {

`LocalTime` is a time of day and wraps at midnight, so for any call made
within `timeoutMillis` of 00:00 the computed deadline is *earlier* than
the current time. The loop body never runs and the method throws
`OperatorException("Timeout of resource polling from cache for resource")`
immediately, failing the update it was retrying even though the resource
would have appeared in cache. With the default 10s timeout that is a
10-second window each day.

`LocalTime.now()` is also wall-clock based, so an NTP step or a DST change
can shorten or extend the timeout.

Switches to `System.nanoTime()`, which is monotonic and has no wrap-around
concern, using overflow-safe subtraction for the comparison.

No test is added: reproducing this requires controlling the clock, and the
class is already deprecated for removal.
Copilot AI review requested due to automatic review settings July 30, 2026 09:05
@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a correctness issue in PrimaryUpdateAndCacheUtils.pollLocalCache where the cache-polling timeout was computed using LocalTime (time-of-day), which can wrap at midnight and is susceptible to wall-clock adjustments. It switches the timeout tracking to a monotonic clock so the polling loop behaves consistently.

Changes:

  • Replace LocalTime/ChronoUnit deadline computation with a System.nanoTime()-based timeout.
  • Use TimeUnit.MILLISECONDS.toNanos(...) to convert the configured timeout into nanoseconds.
  • Remove now-unneeded java.time imports.

Comment on lines 233 to +235
var resourceId = ResourceID.fromResource(staleResource);
var startTime = LocalTime.now();
final var timeoutTime = startTime.plus(timeoutMillis, ChronoUnit.MILLIS);
while (timeoutTime.isAfter(LocalTime.now())) {
final var deadlineNanos = System.nanoTime() + TimeUnit.MILLISECONDS.toNanos(timeoutMillis);
while (System.nanoTime() - deadlineNanos < 0) {
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants