ChannelDbConnectionPool transaction support - #4487
Conversation
There was a problem hiding this comment.
Pull request overview
Adds full transaction enlistment/routing support to the V2 ChannelDbConnectionPool, aligning behavior with the legacy WaitHandleDbConnectionPool so pooled connections correctly participate in ambient System.Transactions flows (including async acquisition).
Changes:
- Implemented transaction lifecycle plumbing in
ChannelDbConnectionPool(PutObjectFromTransactedPool,TransactionEnded, transacted acquisition path, and updated return/deactivation logic). - Enabled async acquisition to restore the captured ambient transaction on the worker thread (
ADP.SetCurrentTransaction(...)). - Added a comprehensive unit test suite for channel-pool transaction behavior and removed the now-stale
NotImplementedExceptionassertions.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs | New transaction-focused unit tests for the channel-based pool, mirroring WaitHandle pool coverage and adding channel-specific scenarios. |
| src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTest.cs | Removes tests that asserted transaction methods were unimplemented (now implemented). |
| src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs | Implements transaction support: transacted pool vending/parking, correct return paths for enlisted connections, and async ambient transaction propagation. |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Comments suppressed due to low confidence (2)
src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs:649
task2Doneis declared but never used, which adds noise and makes the synchronization intent harder to follow. Remove it (or use it if it was meant to assert task2 completion).
using var task2Done = new ManualResetEventSlim(false);
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:1206
GetInternalConnectioncreates aCancellationTokenSourceeven when a connection was successfully retrieved from the transacted pool, which adds avoidable allocations on that hot path. Consider returning early afterGetFromTransactedPoolsucceeds so the CTS/loop is skipped entirely.
// Derive a CancellationTokenSource from the TimeoutTimer so pool-internal wait operations
// (channel reads, semaphore waits) are cancelled when the overall budget expires.
using CancellationTokenSource cancellationTokenSource = timeout.CreateCancellationTokenSource();
CancellationToken cancellationToken = cancellationTokenSource.Token;
mdaigle
left a comment
There was a problem hiding this comment.
Overall, the tests need a lot of cleanup. Verify pool count, idle, general stats and metrics at each step. Remove tests that are a strict subset of other tests. Add comments, think deeply about which tests are really required and provide good coverage. Use code coverage metrics to guide your decisions.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Comments suppressed due to low confidence (1)
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:260
- The new XML doc for
HasTransactionAffinitysays connections may be "vended from (and parked in)" theTransactedConnectionPoolwhen enabled. The code still parks connections based onconnection.EnlistedTransactioninDecideReturnDispositioneven when transaction affinity is disabled (e.g., manually enlisted connections), so the doc is misleading about the parking behavior. Consider rewording to clarify that this flag controls automatic transaction affinity (consulting the transacted pool / auto-enlisting on activation), not whether parking can occur at all.
/// <summary>
/// Indicates whether connections may be vended from (and parked in) the
/// <see cref="TransactedConnectionPool"/>. This mirrors automatic transaction enlistment:
/// when enlistment is disabled a connection is never bound to an ambient transaction, so
/// the transacted store must not be consulted.
/// </summary>
private bool HasTransactionAffinity => PoolGroupOptions.HasTransactionAffinity;
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (1)
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:260
- The
HasTransactionAffinitydoc comment currently states the transacted store “must not be consulted” when enlistment is disabled, but the return path still parks any manually-enlisted connection (connection.EnlistedTransaction != null) in the transacted store (matching WaitHandle behavior). The summary should be narrowed to describe ambient-transaction consultation/activation only, to avoid misleading future maintainers.
/// Indicates whether connections may be vended from (and parked in) the
/// <see cref="TransactedConnectionPool"/>. This mirrors automatic transaction enlistment:
/// when enlistment is disabled a connection is never bound to an ambient transaction, so
/// the transacted store must not be consulted.
/// </summary>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (2)
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:258
- The HasTransactionAffinity summary is misleading: the pool can still park explicitly-enlisted connections in the TransactedConnectionPool even when transaction affinity (ambient auto-enlist) is disabled. The property is only used to decide whether to consult the transacted store for the ambient transaction and pass it to activation.
/// <summary>
/// Indicates whether connections may be vended from (and parked in) the
/// <see cref="TransactedConnectionPool"/>. This mirrors automatic transaction enlistment:
/// when enlistment is disabled a connection is never bound to an ambient transaction, so
/// the transacted store must not be consulted.
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:1366
- SqlClientDiagnostics.Metrics free-connection accounting looks inconsistent in ChannelDbConnectionPool: this path decrements free connections when vending from the transacted pool, and TransactedConnectionPool.TransactionEnded also decrements before calling PutObjectFromTransactedPool, but the channel pool never increments/decrements free-connection metrics when writing to/reading from the idle channel (unlike WaitHandleDbConnectionPool.PutNewObject/GetFromGeneralPool). This can leave free-connection telemetry incorrect after transaction completion (and generally makes metrics hard to interpret for the V2 pool).
connection.ObjectID);
SqlClientDiagnostics.Metrics.ExitFreeConnection();
// Transacting connections are exempt from idle-timeout and clear-generation eviction
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (1)
src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs:662
- The XML doc comment for
GetConnectionAsync_DoesNotSetAmbientTransactionOnPoolWorkerThreadis malformed: it ends with</summary>but is missing the opening/// <summary>tag. If XML doc generation is enabled for this project or analyzer warnings are treated as errors, this can fail the build. Add the missing<summary>opening line so the comment is well-formed.
/// ExecutionContext does not unwind, so doing it on a thread pool thread would leave a stale
/// transaction behind for unrelated work later scheduled onto that same thread -- including
/// the login-time auto-enlistment that non-pooled connections perform against the ambient
/// transaction. The pool must pass the transaction explicitly instead of assigning it.
///
…read With TransactionScopeAsyncFlowOption.Enabled the ambient transaction rides an AsyncLocal and is live on the pool's worker thread, so reading Transaction.Current inside the Task.Run would appear to work. Enabled is not the default, though: a plain TransactionScope keeps the transaction in thread-static storage, which does not flow, and the worker would silently fail to enlist. The WaitHandle pool enlists correctly there, so capturing on the caller's thread is a compatibility requirement as well as a safety net for apps that forget the option. It keeps the connection in the intended transaction rather than letting it run outside one; it does not make the suppressed-flow pattern otherwise work. Verified by mutation: switching the worker to Transaction.Current fails exactly three tests, which the test comment now names. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The thread assertion was not load-bearing. Mutation testing confirms the leak is caught by the ambient transaction assertion alone: reinstating ADP.SetCurrentTransaction on the pool's worker fails this test at that assert, and nothing else in the class notices. Observing the transaction the factory sees is an observation of the code under test, not of whichever thread happened to run it, so it does not depend on thread identity or scheduling the way an id comparison or an IsThreadPoolThread check does. Also restore the summary opening on this test's doc comment, which had been truncated. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The test opens no TransactionScope, so its own thread already has no ambient transaction. Wrapping the open in Task.Run added a thread hop without changing what the test discriminates. Verified: mutating the pool to read Transaction.Current on the worker still fails this test. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
| public void PutObjectFromTransactedPool(DbConnectionInternal connection) | ||
| { | ||
| throw new NotImplementedException(); | ||
| Debug.Assert(connection.EnlistedTransaction is null, |
There was a problem hiding this comment.
I wonder if we need StandaloneConnection and TransactionConnection types to model this, and make it impossible to mix up. For future consideration.
| // presume that the caller is the only one using the connection, that all pre-push logic | ||
| // has been done, and that all transactions have ended. | ||
| SqlClientEventSource.Log.TryPoolerTraceEvent( | ||
| "<prov.DbConnectionPool.PutObjectFromTransactedPool|RES|CPOOL> {0}, Connection {1}, Transaction has ended.", |
There was a problem hiding this comment.
Shouldn't a log about the transaction ending live where it ends, and log its unique ID? I think this log would be more effective down in the if/else blocks: "Returning connection to pool", "Destroying unpoolable connection"
| } | ||
|
|
||
| SqlClientEventSource.Log.TryPoolerTraceEvent( | ||
| "<prov.DbConnectionPool.GetFromTransactedPool|RES|CPOOL> {0}, Connection {1}, Popped from transacted pool.", |
There was a problem hiding this comment.
It might be helpful to include the transaction identifier in all logs related to transactions.
- Move the PutObjectFromTransactedPool trace into the return/destroy branches so each logs what actually happened. - Include the transaction identifier in the GetFromTransactedPool trace. - Explain why TransactionEnded does not call PutObjectFromTransactedPool itself: the callback is conditional on the connection having been parked. - Narrow the HasTransactionAffinity doc to ambient enlistment. Explicitly enlisted connections are parked on return regardless of the flag. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #4487 +/- ##
==========================================
- Coverage 64.71% 62.80% -1.91%
==========================================
Files 288 283 -5
Lines 44088 67136 +23048
==========================================
+ Hits 28532 42167 +13635
- Misses 15556 24969 +9413
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
| public void PutObjectFromTransactedPool(DbConnectionInternal connection) | ||
| { | ||
| throw new NotImplementedException(); | ||
| Debug.Assert(connection.EnlistedTransaction is null, |
There was a problem hiding this comment.
Out of curiosity, are these Debug Asserts useful, i.e. do we run tests on Debug builds?
There was a problem hiding this comment.
It might be good to even have a SqlClientEventSource Log to emit this error (just in case we do get into a bad situation like this and a customer trace and point at this bug)
There was a problem hiding this comment.
Yes, our PR pipelines compile and run everything in Debug mode.
This is a programming error within the driver itself - there is no remedy for a customer other than waiting for us to fix it. Throwing here would likely cause the connection to become ophaned and never be cleaned up. We're between a rock and a hard place. Leaving the Debug.Assert() may cause us to put the connection in the idle pool and have an unrelated command re-use it, unknowingly within the still-open transaction - seems pretty bad (data corruption?). Throwing may leak the connection - not good, but better than data corruption.
In reality, I think we just need a test that proves we never actually call this with an enlisted connection, and add a TODO to re-design the interactions between normal pools and transaction pools to completely avoid such a situation.
There was a problem hiding this comment.
It's a holdover from the existing implementation. Like Paul mentioned, I had some refactors in mind, but chose to delay them to focus on feature completeness. I'll come back to this point in the future.
| // Deactivate before inspecting the connection's transaction state. Deactivation is what | ||
| // detaches a completed transaction, so reading EnlistedTransaction beforehand could park | ||
| // a connection in the transacted pool under a transaction that has already ended. |
There was a problem hiding this comment.
I think this comment is describing the wrong mechanism, and I want to check we are on the same page before suggesting a change.
DeactivateConnection does not detach a transaction. It calls Deactivate() (SqlConnectionInternal.cs:2015), which never touches EnlistedTransaction. The detach happens earlier and in a different method: DbConnectionInternal.CloseConnection calls DetachCurrentTransactionIfEnded() at line 464, before it calls ReturnInternalConnection at line 472 -- and the comment there even says "ReturnInternalConnection calls Deactivate for us." So by the time we reach this point, a completed transaction is already detached regardless of the ordering here.
That said, I am fairly confident the deactivate-first ordering is still correct, just for a different reason. DeactivateConnection mutates both of the things we branch on immediately after it:
Deactivate()dooms the connection when_asyncCommandCount != 0(SqlConnectionInternal.cs:2030-2033) and in its catch at 2059 -- so theIsConnectionDoomedcheck below must run after it.DeactivateConnectionitself callsDoNotPoolThisConnection()on load-balance-timeout expiry (DbConnectionInternal.cs:527-536) -- so theCanBePooledcheck must run after it too.
Which is exactly why DeactivateObject orders it this way in the WaitHandle pool.
My concern with the wording as-is: it frames the constraint as transaction-specific. Someone optimizing the non-transacted return path later could read this and reasonably conclude it is safe to hoist the doomed/poolable checks above the DeactivateConnection call -- and quietly start pooling doomed connections.
Would you be open to rewording this to the doom/poolability reason instead? Or have I misread the detach path?
Suggested fix
Reword to the doom/poolability reason:
// Deactivate before evaluating the disposition below. Deactivation can change the answer:
// SqlConnectionInternal.Deactivate dooms a connection that still has outstanding async
// commands, and DeactivateConnection retires one whose load-balance lifetime has expired.
// Reading CanBePooled or EnlistedTransaction first would pool or park a connection that
// deactivation was about to reject.The same wording appears on ReturnConnection_AfterTransactionCompleted_ReturnsToIdleChannel in the new test file, so that doc comment would want the same correction -- I have left a separate note there with a test that pins the ordering for the reason above.
There was a problem hiding this comment.
You were right, the comment described the wrong mechanism. Deactivate() never touches EnlistedTransaction. The detach happens earlier, in DbConnectionInternal.CloseConnection, which calls DetachCurrentTransactionIfEnded() before it calls ReturnInternalConnection.
The actual reason for the ordering is that DeactivateConnection mutates both gates the return path branches on: Deactivate() dooms the connection when async commands are still outstanding, and DoNotPoolThisConnection() fires when the load balance timeout has elapsed. Rewrote the comment around that.
| { | ||
| // TODO: Full transaction enlistment support (Story 2). | ||
| // Carry the old connection's enlistment over to the replacement so that a connection | ||
| // replaced mid-transaction stays bound to the same transaction. |
There was a problem hiding this comment.
Not blocking, and I have already talked myself out of most of this -- posting it for the comment it suggests rather than a code change.
The two ReplaceConnection branches retire oldConnection differently: this one goes through RemoveConnection(oldConnection), while the create-new branch below calls oldConnection.Dispose() directly.
Having read further, the divergence is required, not accidental:
- This branch takes
newConnectionfromGetIdleConnection(), so it already occupies its own slot. Two slots are held and one must be released, henceRemoveConnection. - The create-new branch calls
_connectionSlots.TryReplace(oldConnection, newConnection)(line 417), which swaps the replacement into the old connection's slot. By the timeDispose()runs,oldConnectionis already untracked -- callingRemoveConnectionthere would be wrong, not merely redundant.
So the paths cannot be unified, and I withdraw the suggestion to do so.
Suggested fix
Just make the reason local, so the next reader does not repeat this trip:
// newConnection came from the idle channel, so it already holds a slot of its own; releasing
// oldConnection's slot here keeps the pool's count accurate. This is deliberately different
// from the create-new branch below, which hands oldConnection's slot to the replacement via
// _connectionSlots.TryReplace and therefore only disposes it.
oldConnection.DeactivateConnection();
RemoveConnection(oldConnection);Does that match your reasoning, or was there another consideration behind the split?
There was a problem hiding this comment.
Added the comment. The slot accounting checks out: in the idle branch newConnection came from GetIdleConnection() and already holds a slot of its own, so RemoveConnection(oldConnection) releases the old one and keeps the count accurate. The create-new branch hands the old connection's slot to the replacement via _connectionSlots.TryReplace, so calling RemoveConnection there would signal a free slot that doesn't exist.
| // A transaction root that cannot be pooled must be put in stasis rather than | ||
| // closed. Closing it would orphan the root transaction with no means to promote | ||
| // itself to a full delegated transaction, or to commit or roll back. | ||
| // System.Transactions keeps the connection owned (not lost) and is certain to | ||
| // call the appropriate callback when the transaction ends. | ||
| if (connection.IsTransactionRoot) | ||
| { | ||
| connection.SetInStasis(); | ||
| disposition = ReturnDisposition.HeldByTransaction; | ||
| } |
There was a problem hiding this comment.
Checking whether this omission was deliberate rather than asserting it is wrong.
WaitHandleDbConnectionPool.DeactivateObject has one more stasis case that I do not see reproduced here: while Running and CanBePooled, it checks obj.IsTransactionRoot && obj.Pool == null and puts the connection in stasis (lines 630-634). Under this implementation, such a connection would instead land in the transacted store (if enlisted) or the idle channel.
I lean toward this being genuinely dead code in V1 -- it is marked with its own // TODO: how did we get here if the pool is null?, and a connection being returned to this pool should have Pool == this by construction. So I suspect dropping it is correct.
But I would rather hear it from you than infer it: was this consciously dropped as unreachable, or did it just not come across during the port? If it was deliberate, a one-line comment noting that V1 case and why it does not apply here would save the next person the same archaeology.
Suggested fix
If it was deliberate, something like this on the branch below:
// WaitHandleDbConnectionPool.DeactivateObject has a further case here --
// IsTransactionRoot && Pool == null -> SetInStasis (lines 630-634) -- that is not reproduced.
// It is unreachable: a connection being returned to this pool has Pool == this by
// construction, which is why V1 marks it with its own "how did we get here?" TODO.If instead you would rather keep V1 parity literally, the equivalent would be an extra clause in the same branch, but I would not push for that -- a dead branch carried forward is worse than a comment explaining why it was dropped.
There was a problem hiding this comment.
Deliberate, and I've added a comment saying so. ReturnInternalConnection is reached through the connection's own Pool reference, so it can't be called without a pool in the first place.
The branch is redundant even in V1: its later branch takes the same action for a transaction root that can't be pooled, which is what the first case in the V2 switch does.
| // continuation running on an arbitrary thread, so Transaction.Current at this point | ||
| // says nothing reliable about the caller's transaction. | ||
| // | ||
| // We must not read Transaction.Current inside the Task.Run below instead. A |
There was a problem hiding this comment.
Fixed. Also added a missing paragraph break that had run the cancellation token note into the transaction discussion.
| Assert.NotNull(outerTransaction); | ||
|
|
||
| var owner1 = new SqlConnection(); | ||
| var connection1 = GetConnection(owner1); |
There was a problem hiding this comment.
Is there a way to confirm that connection1.EnlistedTransaction is outerTransaction ? (Here and everywhere else). And also confirm that EnlistedTransaction is null when we don't expect a transaction to be in play?
There was a problem hiding this comment.
Added an AssertEnlistedIn helper and applied it across the return routing, vending, completion, and replacement tests, including null assertions where no transaction should be in play. It compares by equality rather than reference, because the EnlistedTransaction setter stores a clone.
Two of these earned their keep. The affinity disabled test now shows an ambient transaction present but the connection unenlisted, and ReplaceConnection_CarriesEnlistedTransactionToNewConnection previously only inferred the carry over from pool counts rather than asserting it.
| // Completing the inner transaction releases only its connection; the outer transaction's | ||
| // connection stays parked. | ||
| AssertPoolState(count: 2, idleCount: 1, transactedCount: 1); | ||
| Assert.Equal(1, TransactedConnectionsFor(outerTransaction!)); |
There was a problem hiding this comment.
Could/should we confirm that innerTransaction has a 0 count here?
There was a problem hiding this comment.
Added, along with the same assertion at the vend point before connection2 is returned. That one shows connection2 was newly created rather than taken from the store, which is what the test is named for.
Confirmed the post completion 0 is meaningful rather than an artifact of looking up a completed transaction: TransactedConnectionPool.TransactionEnded removes the key once the list empties, and its own lookup succeeds using the original transaction against a cloned dictionary key.
| AssertPoolState(count: 1, idleCount: 0, transactedCount: 1); | ||
|
|
||
| // Act | ||
| scope.Complete(); |
There was a problem hiding this comment.
Could another thread check-out the connection while Complete() is running?
There was a problem hiding this comment.
Can you give an example? I don't think I know what you mean exactly.
| Assert.NotNull(transaction); | ||
|
|
||
| // Act | ||
| _pool.TransactionEnded(transaction!, connection); |
There was a problem hiding this comment.
What about the case where the connection was enlisted with the transaction, and we call TransactionEnded() without any of the other normal transaction lifecycle events?
There was a problem hiding this comment.
Yes, this is a supported case: a transaction can complete while the application still holds its connection.
The pool treats it as a no-op. Parking is what hands a connection to the pool, so a connection that was never parked has no entry in TransactedConnections, IndexOf returns -1, and the PutObjectFromTransactedPool callback is skipped. The connection stays checked out and reaches the pool only through the normal ReturnInternalConnection path when it's closed.
The enlistment isn't dropped at completion time, though. SqlConnectionInternal.UnbindOnTransactionCompletion is false, so DetachTransaction(txn, isExplicitlyReleasing: false) skips the unbind while the connection still has an owner. It's unbound lazily: on next use via CheckEnlistedTransactionBinding, or at close via DetachCurrentTransactionIfEnded.
Added TransactionCompletes_WhileConnectionStillCheckedOut_LeavesItCheckedOut for the real completion path, and strengthened the existing bare-TransactionEnded test to use an actually-enlisted connection.
Correct the ReturnInternalConnection comment: deactivation does not detach a completed transaction, that happens in CloseConnection before the pool is called. The real constraint is that DeactivateConnection mutates both gates the return path branches on. Explain why ReplaceConnection releases the old connection's slot in the idle branch but not in the create-new branch, and note that the V1 stasis case for a null pool is unreachable and redundant. Assert EnlistedTransaction alongside the pool-state assertions so the tests confirm what a connection is bound to, not just where it was filed. Add transacted store counts for the inner transaction at vend and after completion. Cover a transaction completing while its connection is still checked out, and strengthen the bare TransactionEnded test to use an enlisted connection. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.
Suppressed comments (1)
src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs:897
EnlistTransaction(null)is commonly used to unenlist/detach. The mock currently ignoresnull, which can leaveEnlistedTransactionset and make the tests diverge from real provider behavior (and potentially mask bugs around detachment). Consider settingEnlistedTransaction = transaction;unconditionally so null clears enlistment.
public override void EnlistTransaction(Transaction? transaction)
{
if (transaction != null)
{
EnlistedTransaction = transaction;
}
}
| Debug.Assert(connection.EnlistedTransaction is null, | ||
| "PutObjectFromTransactedPool was called with a connection that is still enlisted. " + | ||
| "The transaction must have ended and been detached before the connection returns to " + | ||
| "general circulation, otherwise it could be vended to a caller in a different transaction."); | ||
|
|
||
| // Called by the transacted connection pool once it has removed the connection from its | ||
| // list. We put the connection back into general circulation. | ||
| // | ||
| // NOTE: no locking is required here because if we're in this method we can safely | ||
| // presume that the caller is the only one using the connection, that all pre-push logic | ||
| // has been done, and that all transactions have ended. | ||
| if (State is Running && connection.CanBePooled) | ||
| { | ||
| SqlClientEventSource.Log.TryPoolerTraceEvent( | ||
| "<prov.DbConnectionPool.PutObjectFromTransactedPool|RES|CPOOL> {0}, Connection {1}, Transaction has ended; returning connection to pool.", | ||
| Id, | ||
| connection.ObjectID); | ||
|
|
||
| connection.ResetConnection(); | ||
| PutConnectionInIdleChannel(connection); | ||
| } |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (1)
src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs:902
- The new transaction-affinity tests don’t exercise the transaction-root pathways added/relied on by the implementation (stasis via IsTransactionRoot / IsTxRootWaitingForTxEnd, and the dead-root rethrow behavior in GetFromTransactedPool). In this file, MockDbConnectionInternal never overrides IsTransactionRoot (so it stays false) and never simulates liveness failures, so those branches in ChannelDbConnectionPool aren’t covered by unit tests.
internal class MockDbConnectionInternal : DbConnectionInternal
{
private static int s_nextId = 1;
public int MockId { get; } = Interlocked.Increment(ref s_nextId);
public override string ServerVersion => "Mock";
public override ConnectionCapabilities Capabilities => new();
public override DbTransaction BeginTransaction(System.Data.IsolationLevel il)
{
throw new NotImplementedException();
}
public override void EnlistTransaction(Transaction? transaction)
{
if (transaction != null)
{
EnlistedTransaction = transaction;
}
}
protected override void Activate(Transaction? transaction)
{
EnlistedTransaction = transaction;
}
Rebased onto
mainnow that #4429 has merged. Unit tests: 834 passed / 0 failed.Summary
Implements transaction support in
ChannelDbConnectionPool, usingWaitHandleDbConnectionPoolas the reference for correct behavior. Before this change the channel pool constructed aTransactedConnectionPoolbut never used it, and threeIDbConnectionPoolmembers threwNotImplementedException.Changes
PutObjectFromTransactedPool(wasNotImplementedException) — returns a connection to general circulation once its transaction has ended, or destroys it if the pool is no longer running or the connection can't be pooled.TransactionEnded(wasNotImplementedException) — delegates toTransactedConnectionPool.TransactionEnded, which calls back intoPutObjectFromTransactedPool.ReturnInternalConnection— rewritten to mirrorWaitHandleDbConnectionPool.DeactivateObject. It now deactivates first (deactivation is what detaches a completed transaction, so readingEnlistedTransactionbeforehand could park a connection under an already-ended transaction), then decides under the connection lock between the transacted pool, stasis, the idle channel, and destruction. The idle-channel path moved into a newPutConnectionInIdleChannelhelper.GetFromTransactedPool(new) — vends a connection already enlisted in the ambient transaction. Transacted connections are exempt from idle-timeout and clear-generation eviction, since closing them would abort a possibly-distributed transaction, so only liveness is checked. A dead transaction root rethrows rather than silently retrying, because its delegated transaction cannot be recovered on another connection.GetInternalConnection/PrepareConnection— consult the transacted pool when the pool group has transaction affinity, and pass the ambient transaction through toActivateConnection.taskCompletionSource.Task.AsyncStateand threads it explicitly through the open, rather than assigningTransaction.Currenton the thread pool thread. See the section below.RemoveConnection— no longer disposes a transaction root that is still waiting for its delegated transaction to end (parity withDestroyObject). It comes back throughPutObjectFromTransactedPoolwhen the transaction completes.ReplaceConnection— no functional change; the twoTODO: Full transaction enlistment support (Story 2)markers from ChannelDbConnectionPool replace connection #4429 are removed now that enlistment is wired through.How connections move between the idle channel and the transacted store
The transacted store (
TransactedConnectionPool, keyed byTransaction) reserves a connection for one specific transaction, so reusing it avoids promoting that transaction to a distributed one. The only edge into it is a return while still enlisted; the only edges out are a pop by a caller in the same transaction, or the transaction ending.Return path (
ReturnInternalConnection)flowchart TD R["ReturnInternalConnection"] --> V["ValidateOwnershipAndSetPoolingState"] V --> D["DeactivateConnection"] D --> Doomed{"IsConnectionDoomed?"} Doomed -- yes --> Destroy["RemoveConnection (Destroy)"] Doomed -- no --> Poolable{"State is Running and CanBePooled?"} Poolable -- no --> Root{"IsTransactionRoot?"} Root -- yes --> Stasis["SetInStasis (HeldByTransaction)"] Root -- no --> Destroy Poolable -- yes --> Enl{"EnlistedTransaction is not null?"} Enl -- yes --> Park["PutTransactedObject (HeldByTransaction)"] Enl -- no --> Reuse["PutConnectionInIdleChannel (Reuse)"]DeactivateConnectionruns beforeEnlistedTransactionis read, because deactivation is what detaches an already-completed transaction. Reading first would park the connection under a transaction that has already ended, and it would never be released.Transaction end: back to general circulation
flowchart TD Sig["System.Transactions signals completion"] --> Where{"where is the connection?"} Where -- "parked in the transacted store" --> TE["pool.TransactionEnded"] TE --> TCP["TransactedConnectionPool.TransactionEnded removes it from the list"] TCP --> Put["PutObjectFromTransactedPool"] Where -- "in stasis" --> DTE["DelegatedTransactionEnded then TerminateStasis(true)"] DTE --> Put Where -- "never parked, still checked out" --> NoOp["no-op: stays with its owner"] Put --> Ok{"State is Running and CanBePooled?"} Ok -- yes --> Reset["ResetConnection then PutConnectionInIdleChannel"] Ok -- no --> Rm["RemoveConnection"]A connection in stasis reaches
PutObjectFromTransactedPooltoo, but by definition it got there because the pool was stopping or it was unpoolable, so it always takes theRemoveConnectionbranch.A parked connection keeps its
_connectionSlotsreservation, so it still counts towardCountandMaxPoolSize, but notIdleCount. OnlyRemoveConnectionreleases the slot.Tests
ChannelDbConnectionPoolTransactionTest(18 tests): return routing (enlisted, not enlisted, completed transaction,Enlist=false, shut-down pool), vending from the transacted store under the same and different transactions, commit/rollback, completion after shutdown,TransactionEndedfor a connection that was never parked, enlistment carry-over throughReplaceConnection, and the ambient-transaction flow cases below. Every test asserts full pool state (Count,IdleCount, transacted count) after each step, and the pool is built with a frozenTimeProvider.NotImplementedExceptionfrom the three now-implemented members.Validation
Unit tests: 834 passed / 0 failed on
net9.0.Manual/integration tests were run against a local SQL Server with
Switch.Microsoft.Data.SqlClient.UseConnectionPoolV2enabled, acrossTransactionEnlistmentTest,TransactionPoolTest,SQL.TransactionTest,ParallelTransactionsTest,ConnectionPoolTest,PoolBlockPeriodTestandDistributedTransactionTest(48 tests):This change fixes three previously failing tests:
TestAutoEnlistment_TxScopeNonComplete,TestManualEnlistment_EnlistandTestManualEnlistment_Enlist_TxScopeComplete.The 6 failures shared with the V1 baseline are all
PlatformNotSupportedException: This platform does not support distributed transactions— MSDTC isn't available on the test machine. The 2 remaining failures (ConnectionPoolTest.ReclaimEmancipatedOnOpenTest) are a pre-existing V2 gap:ReclaimEmancipatedObjectshas never been implemented inChannelDbConnectionPool. Both were confirmed by reverting this change and reproducing.A broader V2 sweep (
SqlCommand,AsyncTest,MARSTest,DataReaderTest,ConnectivityTests,WeakRefTest,AdapterTest,ExceptionTest,RetryLogic) gave 213 passed / 9 failed, where all 9 are named-pipe tests that fail identically on V1.Ambient transaction flow on the async path
Transaction.Currentdoes not flow into aTask.Rununless theTransactionScopewas created withTransactionScopeAsyncFlowOption.Enabled(the default isSuppress, which keeps the ambient transaction in thread-static storage). The async open path therefore cannot simply readTransaction.Current— it has to take the transaction from theTaskCompletionSource'sAsyncState, which is whereSqlConnection.InternalOpenAsynccaptures it. That is the only site in the repo that constructs aTaskCompletionSource<DbConnectionInternal>, and it always passes the ambient transaction, so the mechanism is reliable (including acrossOpenAsyncRetry.Retry, which reuses the same TCS).The original approach was to restore it by assigning
ADP.SetCurrentTransaction(...)inside theTask.Run. That is unsafe here: assigningTransaction.Currentwrites to thread-static storage thatExecutionContextdoes not unwind, so the transaction outlives the open and is observable by unrelated work later scheduled onto the same thread pool thread — most notably the login-time auto-enlistment that non-pooled connections perform againstTransaction.Current. Atry/finallyrestore doesn't fix it either, because the async continuation may resume on a different thread than the one that was polluted. (WaitHandleDbConnectionPooldoes the same assignment safely becauseWaitForPendingOpenasserts it is not on a thread pool thread.)The fix is to never mutate
Transaction.Currentin the pool: the transaction is captured on the caller's thread and threaded explicitly throughGetInternalConnectionintoGetFromTransactedPoolandPrepareConnection. The sync path passesADP.GetCurrentTransaction()directly, since it runs on the caller's thread.Four regression tests cover this:
GetConnection_Sync_UsesAmbientTransactionFromCallersThreadTransaction.Current, which is correct because it runs on the caller's threadGetConnectionAsync_UsesAmbientTransactionCapturedOnCallersThreadAsyncFlowOption.Enabledstill enlistsGetConnectionAsync_WithAsyncFlowDisabled_StillEnlistsInAmbientTransactionSuppress) scope still enlists, even though the transaction provably does not flow off the caller's threadGetConnectionAsync_EnteredFromThreadWithoutAmbientTransaction_EnlistsFromAsyncStateAsyncState, not from whatever is ambient on the entering thread — this is theOpenAsyncRetry.RetrycaseThe last one is load-bearing and not redundant:
TryGetConnectionreadsAsyncStatewhile still on the caller's thread, so in the scope-based testsTransaction.Currenthappens to agree withAsyncState. Only entering the pool from a thread with no ambient transaction distinguishes them. Verified by mutation — replacing theAsyncStateread withnullfails 5 tests, and replacing it withADP.GetCurrentTransaction()fails only the retry-path and no-leak tests.Checklist
UseConnectionPoolV2switch, which defaults to offNotes
ReclaimEmancipatedObjectsremains unimplemented in the channel pool; it is orthogonal to transactions and left for a follow-up.