Skip to content

Cleanup cron: hung S3 still stalls the schedule at title-icon and bootstrap-package cleanup #54128

Description

@AndreyKizimenko

Fleet versions

  • Discovered: rc-minor-fleet-v4.93.0 (ca7b161)

Web browser and operating system: N/A (API)


💥 Actual behavior

When S3 stops responding, the cleanups_then_aggregation schedule still stalls. #49619 gave cleanup_unused_software_installers a 10-minute timeout, but the next two jobs, cleanup_unused_software_title_icons and cleanup_unused_bootstrap_packages, hit the same S3 bucket with no timeout. After the installer job times out, the schedule hangs in the title-icon cleanup until the connection drops or the server restarts, and no later job runs (cleanup_host_mdm_commands, cleanup_worker_jobs, revoke_old_conditional_access_certs, aggregation).

🛠️ Expected behavior

A hung S3 call in the title-icon or bootstrap-package cleanup gives up after a bounded time, like the installer cleanup does since #49619, and the rest of the schedule keeps running.

🧑‍💻 Steps to reproduce

These steps:

  • Have been confirmed to consistently lead to reproduction in multiple Fleet instances.
  • Describe the workflow that led to the error, but have not yet been reproduced in multiple Fleet instances.
  1. Put a proxy in front of the software installers S3 endpoint that answers every ListObjectsV2 with the real headers but never finishes the body. (In a dev setup, a proxy that sends no headers at all is cut off after 45s by the dev S3 client, so stall the body instead.)
  2. fleetctl trigger --name cleanups_then_aggregation
  3. After 10 minutes cleanup_unused_software_installers fails with context deadline exceeded. GET /debug/pprof/goroutine?debug=2 then shows the schedule in CleanupUnusedSoftwareTitleIcons → commonFileStore.Cleanup → ListObjectsV2, and it stays there. In QA it sat there 23 minutes until the connection was dropped.

🕯️ More info (optional)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

#g-auto-patchingProduct group focused on auto patching softwarebugSomething isn't working as documented~released bugThis bug was found in a stable release.

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions