Skip to content

Dead sessions are reused with auto-reconnect off; frame-too-large rejection desynchronizes the connection #8

Description

@CritasWang

Two related liveness/robustness issues:

  1. Session::is_open() is connection.is_some(), not socket state. With enable_auto_reconnect = false, a session whose connection died (silent peer, FIN lost, etc.) is reused indefinitely under load: the pool's acquire-side eviction loop (entry.session.is_open()) keeps handing it out, every RPC on it blocks or fails, and nothing ever discards it. A transport-level failure should mark the connection broken so is_open() turns false and the pool discards/replaces the session.
  2. Frame-too-large rejection desynchronizes the connection. TFramedReadTransport (thrift 0.23) rejects a frame above its default 16,384,000-byte cap before draining the body, leaving the connection desynchronized; fetch_results does not go through with_retry, so the desynchronized connection is then reused. Go and C# use the same cap, so the cap itself is not Rust-specific — the fix worth having is that a transport-level failure (including this one) marks the session broken, so the pool evicts it and auto-reconnect (when enabled) replaces it. (execute_query_raw deliberately excludes the result-set-pinned fetch_results from retry; see spec gotcha #13.)

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions