Repository navigation
Thread cancellation through 10 PostgreSQL-target web reads (#4203) - #4373
Merged
Merged
Conversation
get_pg_buffer_usage, get_pg_extensions, get_pg_lock_stats, get_pg_server_config, get_pg_server_config_changes, get_pg_write_stats, get_pg_database_trend, get_pg_io_trend, get_pg_query_duration_trend and get_pg_wait_trend now take a CancellationToken and pass it to every store call, so an abandoned web request stops its query instead of running to completion. Removes the ten from CancellationAllowlist.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #4203.
Why
Ten PostgreSQL-target
/api/readreads (get_pg_buffer_usage,get_pg_extensions,get_pg_lock_stats,get_pg_server_config,get_pg_server_config_changes,get_pg_write_stats,get_pg_database_trend,get_pg_io_trend,get_pg_query_duration_trend,get_pg_wait_trend) ran their store queries to completion even after the browser abandoned the request, because their tool methods took noCancellationTokenand their dispatch entries were onCancellationAllowlist.What changes
Each of the ten
[McpServerTool]methods inDarlingMcpPgServerStateTools.csandDarlingMcpPgTrendTools.csgains a trailingCancellationToken cancellationToken = default, threaded into every store call in its body (resolver, rollup/availability probes, reads, not-collected status checks). Eachcatchblock is narrowed towhen (ex is not OperationCanceledException). All ten storage-layer and shared-helper methods already accepted aCancellationTokenwith a default, so no signature changes were needed downstream; only the tool methods andDarlingWebEndpoints.cs's dispatch table needed updating. The ten names are removed fromCancellationAllowlistand their dispatch entries now passcancellationToken: c.RequestAborted.Test plan
dotnet build Darling/PerformanceMonitor.Darling.Service/PerformanceMonitor.Darling.Service.csprojanddotnet build Darling/Darling.Tests/Darling.Tests.csproj -p:EnableWindowsTargeting=true: both 0 warnings / 0 errors.WebReadCancellationPinTests(existing, generic, no changes needed) enforces this class of change directly off the code:AConvertedReadEndpoint_ObservesCancellation_InsteadOfDialingTheStoreis a[Theory]over every dispatch entry not on the allowlist (built fromDarlingWebEndpoints.BuildReadDispatch().Keys.Except(CancellationAllowlist)) — before this change the ten tools were on the allowlist and excluded from the theory entirely; after this change they are in scope and each is asserted to throwOperationCanceledExceptionagainst a dead store with an already-cancelledHttpContext.RequestAborted, notNpgsqlException. RED case: if one of the ten dispatch entries above had itscancellationToken: c.RequestAbortedargument dropped while staying off the allowlist, its case would throwNpgsqlException(from actually dialing the dead port) instead ofOperationCanceledException, and the theory case for that tool name fails.EveryStoreReadingToolMethod_TakesACancellationToken_UnlessAllowlisted(reflection over[McpServerTool]methods with anNpgsqlDataSourceparameter, on the read surface, not allowlisted) would fail listing any of the ten as an offender if its method had noCancellationTokenparameter.CancellationAllowlist_HasNoStaleEntrywould fail if any of the ten were still on the allowlist now that their methods carry a token.net10.0-windows, builds on macOS but cannot run) — listed unchecked; CI decides them. The pin's own design (see the theory's data source) is what would go RED on a regression, per above.Darling.Tests,net10.0-windows): builds 0/0 here, cannot run on macOS. CI decides.For the coordinator
CancellationAllowlistcount: down by 10 (the ten PostgreSQL-target reads named above).DarlingServerResolver.ResolveOrErrorAsync,DarlingEngineCapability.NotCollectedStatusAsync/PostgresTargetFactsAsync,DarlingRuntimePrecondition.StatusAsync, and every storage-layer reader touched already had aCancellationToken cancellationToken = defaultparameter; only the tool methods and the twousingblocks (addedSystem.Threading) andDarlingWebEndpoints.csdispatch/allowlist changed.DarlingWebEndpoints.cs'sCancellationAllowlistand dispatch table); PR Thread cancellation through 7 Blocking web reads (#4203) #4360 also touches that allowlist. Textual conflict on merge is expected and is the PR tender's to resolve, per the brief.CHANGELOG entry
SECTION: Fixed
ENTRY:
REF:
[Thread cancellation through 10 PostgreSQL-target web reads (#4203) #4373]: Thread cancellation through 10 PostgreSQL-target web reads (#4203) #4373