Two related liveness/robustness issues:
Session::is_open() is connection.is_some(), not socket state. With enable_auto_reconnect = false, a session whose connection died (silent peer, FIN lost, etc.) is reused indefinitely under load: the pool's acquire-side eviction loop (entry.session.is_open()) keeps handing it out, every RPC on it blocks or fails, and nothing ever discards it. A transport-level failure should mark the connection broken so is_open() turns false and the pool discards/replaces the session.
- Frame-too-large rejection desynchronizes the connection.
TFramedReadTransport (thrift 0.23) rejects a frame above its default 16,384,000-byte cap before draining the body, leaving the connection desynchronized; fetch_results does not go through with_retry, so the desynchronized connection is then reused. Go and C# use the same cap, so the cap itself is not Rust-specific — the fix worth having is that a transport-level failure (including this one) marks the session broken, so the pool evicts it and auto-reconnect (when enabled) replaces it. (execute_query_raw deliberately excludes the result-set-pinned fetch_results from retry; see spec gotcha #13.)
Two related liveness/robustness issues:
Session::is_open()isconnection.is_some(), not socket state. Withenable_auto_reconnect = false, a session whose connection died (silent peer, FIN lost, etc.) is reused indefinitely under load: the pool's acquire-side eviction loop (entry.session.is_open()) keeps handing it out, every RPC on it blocks or fails, and nothing ever discards it. A transport-level failure should mark the connection broken sois_open()turns false and the pool discards/replaces the session.TFramedReadTransport(thrift 0.23) rejects a frame above its default 16,384,000-byte cap before draining the body, leaving the connection desynchronized;fetch_resultsdoes not go throughwith_retry, so the desynchronized connection is then reused. Go and C# use the same cap, so the cap itself is not Rust-specific — the fix worth having is that a transport-level failure (including this one) marks the session broken, so the pool evicts it and auto-reconnect (when enabled) replaces it. (execute_query_rawdeliberately excludes the result-set-pinnedfetch_resultsfrom retry; see spec gotcha #13.)