Skip to content

Comments

Fix resource leak in KafkaIO GCS truststore file download#37681

Merged
Abacn merged 1 commit intoapache:masterfrom
PDGGK:fix-kafka-gcs-resource-leak
Feb 23, 2026
Merged

Fix resource leak in KafkaIO GCS truststore file download#37681
Abacn merged 1 commit intoapache:masterfrom
PDGGK:fix-kafka-gcs-resource-leak

Conversation

@PDGGK
Copy link
Contributor

@PDGGK PDGGK commented Feb 22, 2026

Summary

  • Convert manual resource close to try-with-resources in identityOrGcsToLocalFile to prevent leaking ReadableByteChannel, FileOutputStream, and WritableByteChannel when an IOException occurs during the copy loop
  • Preserve the original IOException as the cause of the IllegalArgumentException for easier debugging

Fixes #37680

Test plan

  • Existing KafkaIO tests pass (compileJava and spotlessApply verified)
  • CI precommit checks

Convert manual resource close to try-with-resources in
identityOrGcsToLocalFile to prevent leaking ReadableByteChannel,
FileOutputStream, and WritableByteChannel when an IOException
occurs during the copy loop. Also preserve the original IOException
as the cause of the IllegalArgumentException.
@gemini-code-assist
Copy link
Contributor

Summary of Changes

Hello @PDGGK, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a potential resource leak in the KafkaIO connector when downloading GCS truststore files. The changes refactor the file download logic to use try-with-resources, ensuring that I/O resources are properly closed even if exceptions occur. Additionally, error reporting is enhanced by including the root cause of I/O exceptions in the thrown IllegalArgumentException for better debugging.

Highlights

  • Resource Management: Converted manual resource closing for ReadableByteChannel, FileOutputStream, and WritableByteChannel to try-with-resources to prevent leaks during IOException in the identityOrGcsToLocalFile method.
  • Error Handling: Modified the IllegalArgumentException thrown during file fetching to preserve the original IOException as its cause, improving debugging capabilities.

🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Changelog
  • sdks/java/io/kafka/src/main/java/org/apache/beam/sdk/io/kafka/KafkaReadSchemaTransformProvider.java
    • Refactored resource management in identityOrGcsToLocalFile to use try-with-resources for ReadableByteChannel, FileOutputStream, and WritableByteChannel.
    • Updated the IllegalArgumentException thrown in case of IOException to include the original IOException as its cause.
Activity
  • The author verified that existing KafkaIO tests pass.
  • The author verified compileJava and spotlessApply.
  • CI precommit checks are pending.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@github-actions
Copy link
Contributor

Checks are failing. Will not request review until checks are succeeding. If you'd like to override that behavior, comment assign set of reviewers

@PDGGK
Copy link
Contributor Author

PDGGK commented Feb 23, 2026

The failing Java Unit Tests (self-hosted, ubuntu-20.04, main) check is unrelated to this PR — it's a flaky BeamFnLoggingClientTest.testServerCloseNotifiesTermination in sdks/java/harness, while this PR only modifies KafkaReadSchemaTransformProvider.java. All 16 other checks pass.

assign set of reviewers

@github-actions
Copy link
Contributor

Assigning reviewers:

R: @ahmedabu98 for label java.
R: @sjvanrossum for label kafka.

Note: If you would like to opt out of this review, comment assign to next reviewer.

Available commands:

  • stop reviewer notifications - opt out of the automated review tooling
  • remind me after tests pass - tag the comment author after tests pass
  • waiting on author - shift the attention set back to the author (any comment or push by the author will return the attention set to the reviewers)

The PR bot will only process comments in the main thread (not review comments).

@Abacn
Copy link
Contributor

Abacn commented Feb 23, 2026

Just note that this may fix potential network connection (for readable channel) and file handle leak (for writable channel), while there is another potential temp file leak that is still present, though I think it's benign.

@Abacn
Copy link
Contributor

Abacn commented Feb 23, 2026

Thanks!

@Abacn Abacn merged commit 9bfb7ab into apache:master Feb 23, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Resource leak in KafkaIO GCS truststore file download

2 participants