Skip to content

[Bug] Broker CI JVM crashes in Conscrypt getApplicationProtocol during SSL engine finalization #26659

Description

@lhotari

Issue description

The CI - Unit - Brokers - Broker Group 3 job crashed a test JVM in Conscrypt native code during SSL engine finalization. The crash fails :pulsar-broker:test without an individual test assertion failure in the job log.

Observed in Pulsar CI run 35465136609, job 105956628728, on PR #26654 (head commit 2ddde5ff5c02638ca31e9380294e8302d5425de7, branch lh-improve-auto-split-select, targeting master). This records where the crash was observed; a causal connection to that PR has not been established.

Expected: the broker-admin test group completes without crashing a test JVM.

Actual: at 2026-09-19 19:51:00 UTC, Gradle Test Executor 4 (PID 2709) received SIGSEGV in Conscrypt on the Secondary finalizer thread, about 188 seconds after that JVM started. Gradle reported the process exit as 134 at 20:13:17 UTC and failed the task.

User environment

  • Pulsar development build: 5.0.0-SNAPSHOT
  • Java: Amazon Corretto 25.0.4.8.1, OpenJDK 25.0.4.1+8-LTS
  • Conscrypt: org.conscrypt:conscrypt-openjdk-uber:2.6.2 (from the crash report classpath)
  • Gradle: 9.7.1
  • OS: Ubuntu 24.04.5 LTS, Linux amd64
  • Runner: AMD EPYC 7763, 4 available cores, 15 GB memory
  • Test JVM maximum heap: -Xmx1300m

Error messages

From hs_err_pid2709.log:

SIGSEGV (0xb) at pc=0x00007f5b7a2eefd4, pid=2709, tid=15519
Problematic frame:
C  [libconscrypt_openjdk_jni-linux-x86_6417898474096350000.so+0xeefd4]

Current thread: JavaThread "Secondary finalizer" [_thread_in_native, id=15519]

Java frames:
org.conscrypt.NativeCrypto.getApplicationProtocol(JLorg/conscrypt/NativeSsl;)[B
org.conscrypt.NativeSsl.getApplicationProtocol()[B
org.conscrypt.ActiveSession.getApplicationProtocol()Ljava/lang/String;
org.conscrypt.SessionSnapshot.<init>(Lorg/conscrypt/ConscryptSession;)V
org.conscrypt.ConscryptEngine.transitionTo(I)V
org.conscrypt.ConscryptEngine.closeAndFreeResources()V
org.conscrypt.ConscryptEngine.finalize()V
java.lang.ref.Finalizer.runFinalizer(Ljdk/internal/access/JavaLangAccess;)V
java.lang.ref.Finalizer$1.run()V
java.lang.Thread.run()V

siginfo: si_signo: 11 (SIGSEGV), si_code: 1 (SEGV_MAPERR), si_addr: 0x0000000000000118

Gradle subsequently reported:

org.gradle.process.ProcessExecutionException: Process 'Gradle Test Executor 4' finished with non-zero exit value 134 (this value may indicate that the process was terminated with the SIGABRT signal)

Reproducing the issue

Observed once in the linked CI job; no reliable standalone reproducer or triggering test method has been identified. The CI entry point was:

./pulsar-build/run_unit_group_gradle.sh BROKER_GROUP_3

The log shows that it invoked:

./gradlew --no-configuration-cache :pulsar-broker:test -PtestGroups=broker-admin -PtestFailFast=true

Additional information

The confirmed failure location is Conscrypt's native application-protocol lookup while ConscryptEngine.finalize() closes resources and creates a session snapshot. The fault address is consistent with a null-pointer dereference, but the underlying lifecycle defect has not been established. This should not yet be classified as a known test flake or attributed to a particular test.

The essential crash signature is included above so it remains available after the artifacts expire. Existing Pulsar issues were searched for Conscrypt; no matching finalizer crash was found.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type/bugThe PR fixed a bug or issue reported a bug

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions