Skip to content

XML connector: saves are not atomic, and a failed save is reported as success #160

Description

@maximthomas

Found while profiling the XML connector (#157). Line references are to 1abfe74. Reproduced through ConnectorFacade with the test schemas from OpenICF-xml-connector/src/test/resources/test/xml_store.

The connector writes the file in dispose(), which the framework calls after every operation.

  • Not atomic. dispose() writes through new FileOutputStream(path) (XMLHandlerImpl.java#L454), which truncates the file before Saxon rewrites it. On a large file this can take seconds (XML connector: every operation reparses and rewrites the whole file, and DOM walks take O(N²) #157). A crash, a kill or a full disk in that window leaves a truncated file. Every later operation then fails with ConnectorException: org.xml.sax.SAXParseException … XML document structures must start and end within the same entity until someone repairs the file.
  • Failure reported as success. If the write fails, dispose() throws a ConnectorException (L468-L473), but the framework only logs exceptions from dispose() (ConnectorAPIOperationRunnerProxy.java#L149-L154). The create, update or delete returns success, and its change is lost when the next operation reloads the file. With a read-only file, create returns a uid, and a later search does not find the object.

Writing to a temporary file in the same directory and moving it over the original would avoid the truncation. To report a failed save, the connector has to save before the operation returns, because the framework does not propagate exceptions from dispose().

Activity

  1. self-assigned this
    on Oct 6, 2026
  2. added
    bugSomething isn't working
    data-lossFixes or risks loss or corruption of stored data
    on Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingconnector:xmlXML connectordata-lossFixes or risks loss or corruption of stored data

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions