Repository navigation
Thread cancellation through 10 PostgreSQL web reads (#4203) - #4390
Merged
Merged
Conversation
get_pg_xmin_horizon, get_pg_wraparound_risk, get_pg_replication_stats, get_pg_predicate_stats and get_pg_kernel_stats now take a CancellationToken and pass it to every store call, so an abandoned web request stops its query instead of running to completion. Removes the five from CancellationAllowlist.
get_pg_io_stats, get_pg_database_stats, get_pg_autovacuum_health and get_pg_index_usage now take a CancellationToken and pass it to every store call. Dispatch entries and allowlist removal follow in the next commit alongside get_pg_session_states.
get_pg_session_states now takes a CancellationToken and passes it to every store call. Wires the RequestAborted dispatch and removes all 10 slice tools from CancellationAllowlist: get_pg_xmin_horizon, get_pg_wraparound_risk, get_pg_session_states, get_pg_replication_stats, get_pg_predicate_stats, get_pg_kernel_stats, get_pg_io_stats, get_pg_index_usage, get_pg_database_stats, get_pg_autovacuum_health.
This was referenced Sep 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #4203.
Why
The web
/api/readsurface abandons its request when the caller disconnects, but these 10 PostgreSQL-target MCP tools ran every store call to completion regardless — a slow query for a client that already left kept holding a connection and burning CPU for no reader. #4357 and #4359 established the pattern (trailingCancellationToken cancellationToken = default, threaded to every store call,c.RequestAbortedat dispatch, removed fromCancellationAllowlist); this applies it to the 10 single-tool PostgreSQL files in scope.What changes
Each of these tool methods now takes a trailing
CancellationToken cancellationToken = default, threads it through every store call (resolver, rollup/coverage reads, primary reads, capture/probe counts,NotCollectedStatusAsync/RuntimePrecondition.StatusAsync), narrows its catch block towhen (ex is not OperationCanceledException), and is removed fromCancellationAllowlistwith its dispatch entry passingcancellationToken: c.RequestAborted:get_pg_xmin_horizon(DarlingMcpPgXminTools.cs)get_pg_wraparound_risk(DarlingMcpPgWraparoundTools.cs)get_pg_session_states(DarlingMcpPgSessionStatesTools.cs)get_pg_replication_stats(DarlingMcpPgReplicationStatsTools.cs)get_pg_predicate_stats(DarlingMcpPgPredicateTools.cs)get_pg_kernel_stats(DarlingMcpPgKernelStatsTools.cs)get_pg_io_stats(DarlingMcpPgIoTools.cs)get_pg_index_usage(DarlingMcpPgIndexUsageTools.cs)get_pg_database_stats(DarlingMcpPgDatabaseTools.cs)get_pg_autovacuum_health(DarlingMcpPgAutovacuumTools.cs)All storage-layer reader methods called by these tools already accepted a
CancellationToken cancellationToken = defaultparameter, so no storage-layer signature changes were needed — only the MCP tool layer andDarlingWebEndpoints.cs(dispatch table +CancellationAllowlist) changed. Two internal helper methods in the touched files (DarlingMcpPgDatabaseTools.EmptyAsync,DarlingMcpPgIndexUsageTools.EmptyAsync,DarlingMcpPgSessionStatesTools.EmptyAsync) gained a trailingCancellationToken cancellationToken = defaultparameter and now pass it to their own store calls.Did NOT touch
DarlingMcpPgIndexTools.cs,DarlingMcpPgLoggingAuditTools.cs,DarlingMcpPgLogEventTools.cs,DarlingMcpPgCpuUtilizationTools.csorDarlingMcpPgBlockingTools.cs— out of scope for this batch.Test plan
dotnet build Darling/PerformanceMonitor.Darling.Service/PerformanceMonitor.Darling.Service.csproj -p:EnableWindowsTargeting=true— 0 errors.dotnet build Darling/Darling.Tests/Darling.Tests.csproj -p:EnableWindowsTargeting=true— 0 Warning(s), 0 Error(s).WebReadCancellationPinTestsreflection ratchet (EveryStoreReadingToolMethod_TakesACancellationToken_UnlessAllowlisted,CancellationAllowlist_HasNoStaleEntry) walks every dispatch entry NOT on the allowlist and fails if it dropsc.RequestAbortedor if the target method lacks aCancellationTokenparameter. Removing these 10 tools from the allowlist makes the ratchet enforce them going forward — RED case: any of these 10 dispatch entries omittingcancellationToken: c.RequestAborted, or the target method lacking the trailingCancellationTokenparameter, now failsCancellationAllowlist_HasNoStaleEntry/EveryStoreReadingToolMethod_TakesACancellationToken_UnlessAllowlistedwhere it previously passed (silently) because the tool was allowlisted. No new pin needed — the ratchet already covers every tool leaving the allowlist.CHANGELOG entry
SECTION: Fixed
ENTRY:
get_pg_xmin_horizon,get_pg_wraparound_risk,get_pg_session_states,get_pg_replication_stats,get_pg_predicate_stats,get_pg_kernel_stats,get_pg_io_stats,get_pg_index_usage,get_pg_database_statsandget_pg_autovacuum_healthran every store call to completion even after the web caller disconnected. Each now takes aCancellationTokenand passes it to every store call, so an abandoned request stops its query instead of running to completion.REF:
[Thread cancellation through 10 PostgreSQL web reads (#4203) #4390]: Thread cancellation through 10 PostgreSQL web reads (#4203) #4390
Known limits
EmptyAsyncprivate helpers noted above (each file-local, non-breaking).DarlingWebEndpoints.cs; this branch was based ondev, not on either — expect a textual merge conflict in the dispatch table / allowlist region.