ChannelDbConnectionPool transaction support - #4487
Conversation
There was a problem hiding this comment.
Pull request overview
Adds full transaction enlistment/routing support to the V2 ChannelDbConnectionPool, aligning behavior with the legacy WaitHandleDbConnectionPool so pooled connections correctly participate in ambient System.Transactions flows (including async acquisition).
Changes:
- Implemented transaction lifecycle plumbing in
ChannelDbConnectionPool(PutObjectFromTransactedPool,TransactionEnded, transacted acquisition path, and updated return/deactivation logic). - Enabled async acquisition to restore the captured ambient transaction on the worker thread (
ADP.SetCurrentTransaction(...)). - Added a comprehensive unit test suite for channel-pool transaction behavior and removed the now-stale
NotImplementedExceptionassertions.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs | New transaction-focused unit tests for the channel-based pool, mirroring WaitHandle pool coverage and adding channel-specific scenarios. |
| src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTest.cs | Removes tests that asserted transaction methods were unimplemented (now implemented). |
| src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs | Implements transaction support: transacted pool vending/parking, correct return paths for enlisted connections, and async ambient transaction propagation. |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Comments suppressed due to low confidence (2)
src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs:649
task2Doneis declared but never used, which adds noise and makes the synchronization intent harder to follow. Remove it (or use it if it was meant to assert task2 completion).
using var task2Done = new ManualResetEventSlim(false);
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:1206
GetInternalConnectioncreates aCancellationTokenSourceeven when a connection was successfully retrieved from the transacted pool, which adds avoidable allocations on that hot path. Consider returning early afterGetFromTransactedPoolsucceeds so the CTS/loop is skipped entirely.
// Derive a CancellationTokenSource from the TimeoutTimer so pool-internal wait operations
// (channel reads, semaphore waits) are cancelled when the overall budget expires.
using CancellationTokenSource cancellationTokenSource = timeout.CreateCancellationTokenSource();
CancellationToken cancellationToken = cancellationTokenSource.Token;
mdaigle
left a comment
There was a problem hiding this comment.
Overall, the tests need a lot of cleanup. Verify pool count, idle, general stats and metrics at each step. Remove tests that are a strict subset of other tests. Add comments, think deeply about which tests are really required and provide good coverage. Use code coverage metrics to guide your decisions.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Comments suppressed due to low confidence (1)
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:260
- The new XML doc for
HasTransactionAffinitysays connections may be "vended from (and parked in)" theTransactedConnectionPoolwhen enabled. The code still parks connections based onconnection.EnlistedTransactioninDecideReturnDispositioneven when transaction affinity is disabled (e.g., manually enlisted connections), so the doc is misleading about the parking behavior. Consider rewording to clarify that this flag controls automatic transaction affinity (consulting the transacted pool / auto-enlisting on activation), not whether parking can occur at all.
/// <summary>
/// Indicates whether connections may be vended from (and parked in) the
/// <see cref="TransactedConnectionPool"/>. This mirrors automatic transaction enlistment:
/// when enlistment is disabled a connection is never bound to an ambient transaction, so
/// the transacted store must not be consulted.
/// </summary>
private bool HasTransactionAffinity => PoolGroupOptions.HasTransactionAffinity;
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (1)
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:260
- The
HasTransactionAffinitydoc comment currently states the transacted store “must not be consulted” when enlistment is disabled, but the return path still parks any manually-enlisted connection (connection.EnlistedTransaction != null) in the transacted store (matching WaitHandle behavior). The summary should be narrowed to describe ambient-transaction consultation/activation only, to avoid misleading future maintainers.
/// Indicates whether connections may be vended from (and parked in) the
/// <see cref="TransactedConnectionPool"/>. This mirrors automatic transaction enlistment:
/// when enlistment is disabled a connection is never bound to an ambient transaction, so
/// the transacted store must not be consulted.
/// </summary>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (2)
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:258
- The HasTransactionAffinity summary is misleading: the pool can still park explicitly-enlisted connections in the TransactedConnectionPool even when transaction affinity (ambient auto-enlist) is disabled. The property is only used to decide whether to consult the transacted store for the ambient transaction and pass it to activation.
/// <summary>
/// Indicates whether connections may be vended from (and parked in) the
/// <see cref="TransactedConnectionPool"/>. This mirrors automatic transaction enlistment:
/// when enlistment is disabled a connection is never bound to an ambient transaction, so
/// the transacted store must not be consulted.
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/ChannelDbConnectionPool.cs:1366
- SqlClientDiagnostics.Metrics free-connection accounting looks inconsistent in ChannelDbConnectionPool: this path decrements free connections when vending from the transacted pool, and TransactedConnectionPool.TransactionEnded also decrements before calling PutObjectFromTransactedPool, but the channel pool never increments/decrements free-connection metrics when writing to/reading from the idle channel (unlike WaitHandleDbConnectionPool.PutNewObject/GetFromGeneralPool). This can leave free-connection telemetry incorrect after transaction completion (and generally makes metrics hard to interpret for the V2 pool).
connection.ObjectID);
SqlClientDiagnostics.Metrics.ExitFreeConnection();
// Transacting connections are exempt from idle-timeout and clear-generation eviction
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (2)
src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs:665
- XML doc comment for this test method is missing the opening
<summary>tag, leaving an unterminated XML element (</summary>without a matching start tag). This can trigger CS1570/CS1574 when XML doc processing is enabled and also breaks the repo’s test-doc conventions.
/// ExecutionContext does not unwind, so doing it on a thread pool thread would leave a stale
/// transaction behind for unrelated work later scheduled onto that same thread -- including
/// the login-time auto-enlistment that non-pooled connections perform against the ambient
/// transaction. The pool must pass the transaction explicitly instead of assigning it.
///
src/Microsoft.Data.SqlClient/tests/UnitTests/ConnectionPool/ChannelDbConnectionPoolTransactionTest.cs:813
MockDbConnectionInternaluses the base defaultUnbindOnTransactionCompletion == true, but SqlClient’s realSqlConnectionInternaloverrides it tofalse(explicit unbinding). With the current mock,ReturnConnection_AfterTransactionCompleted_ReturnsToIdleChannelcan pass even if the pool readsEnlistedTransactionbefore deactivation, because the TransactionCompleted handler will have already cleared the enlistment. OverrideUnbindOnTransactionCompletiontofalseand detach ended transactions duringDeactivate()so the tests actually cover the “deactivate first to detach completed transaction” behavior.
protected override void Activate(Transaction? transaction)
{
EnlistedTransaction = transaction;
}
protected override void Deactivate()
{
}
|
|
||
| // Note: this logic mirrors WaitHandleDbConnectionPool.ReturnObject | ||
| ReturnDisposition disposition; | ||
| lock (connection) |
There was a problem hiding this comment.
We do some basic locking on the connection to make sure its state doesn't change out from under us.
I have doubts about how this interacts with "TransactionEnded". For now, I want to simply replicate the behavior of the WaitHandleDbConnectionPool. Any improvements to thread safety of transactions can come based on bug reports, in a separate PR, and target both pools.
Ports the transacted-pool state machine from WaitHandleDbConnectionPool so the channel pool honors ambient System.Transactions enlistment: - Implement PutObjectFromTransactedPool and TransactionEnded (previously NotImplementedException). - Rewrite ReturnInternalConnection to mirror DeactivateObject: deactivate first, then route the connection to the transacted pool, stasis, the idle channel, or destruction under the connection lock. - Vend connections already enlisted in the ambient transaction via a new GetFromTransactedPool helper, and pass the transaction through to PrepareConnection/ActivateConnection. - Set the ambient transaction on the async acquisition path from the TaskCompletionSource's AsyncState. - Guard RemoveConnection against disposing a transaction root that is still waiting for its delegated transaction to end. Adds ChannelDbConnectionPoolTransactionTest mirroring the WaitHandle pool's transaction test suite, and drops the stale NotImplementedException tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The async open path ran GetInternalConnection inside a Task.Run and restored the ambient transaction by assigning Transaction.Current on that thread pool thread. That assignment writes to thread-static storage which ExecutionContext does not unwind, so the transaction outlived the open and was observable by unrelated work later scheduled onto the same thread -- including the login-time auto-enlistment that non-pooled connections perform against Transaction.Current. A try/finally restore is not sufficient either, because the continuation may resume on a different thread than the one that was polluted. Instead, capture the ambient transaction on the caller's thread (from the TaskCompletionSource's AsyncState, which is where SqlConnection.OpenAsync puts it) and thread it explicitly through GetInternalConnection into GetFromTransactedPool and PrepareConnection. The sync path passes ADP.GetCurrentTransaction() directly since it runs on the caller's thread. Also gate the transaction on HasTransactionAffinity in one place so a pool without automatic enlistment neither reads from nor writes to the transacted store. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Source: - Flesh out the PutObjectFromTransactedPool asserts to say what invariant is being violated and why it matters. - Replace the five-way nested branch and three bool flags in ReturnInternalConnection with a ReturnDisposition enum and a single DecideReturnDisposition helper. The "shutting down", "transaction root with no pool" and "no longer poolable" cases all collapse into one reusability test followed by "stasis if it's a transaction root, otherwise destroy", which removes the need for the postcondition assert entirely. - Move the transacted-store lookup inside the acquisition loop so a connection returned to the store while we were looping is preferred over opening a fresh one. It breaks out of the loop to keep skipping the idle/generation gate, which must not apply to a transacted connection. - Document why a parked transacted connection is exempt from idle timeout and when its idle clock actually starts. Tests: - Rewrite the suite around specific behaviors: 16 focused tests replacing 33. Dropped the loop-driven stress tests (alternating commit/rollback, mixed workloads, deeply nested scopes, pool saturation, the flaky two-thread test) and the granular cases that were covered by a round trip. - Name the tests after the operation whose behavior they pin down, and document what invariant each one protects. - Assert full pool accounting (Count / IdleCount / transacted connections) at every step via AssertPoolState rather than spot-checking one collection. - Inject a frozen FakeTimeProvider so background maintenance cannot race the assertions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ess probe Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The async path only read the transaction out of the TaskCompletionSource's AsyncState, so a caller whose ambient transaction did flow (a TransactionScope created with TransactionScopeAsyncFlowOption.Enabled) but who supplied no AsyncState got no enlistment at all, while the same caller on the sync path did. Fall back to ADP.GetCurrentTransaction(), still read on the caller's thread before the open is scheduled, so both paths agree on the caller's transaction. AsyncState keeps priority because SqlConnection.OpenAsync captures it at the point of the call, which stays correct when a retry re-enters from a continuation on another thread. Test the ambient-transaction leak directly instead of inferring it from thread pool reuse: the mock connection factory runs on exactly the thread the pool does its open work on, so it now records that thread's id and ambient transaction. The test asserts the open really happened off the calling thread and that the pool left that thread's Transaction.Current null while still enlisting the connection. Both this and the new async ambient test were verified to fail when the corresponding defect is reintroduced. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reverts the ADP.GetCurrentTransaction() fallback added in 41a689d. It was both unreachable and unsafe: - SqlConnection.InternalOpenAsync is the only site repo-wide that constructs a TaskCompletionSource<DbConnectionInternal>, and it always captures the ambient transaction into AsyncState. OpenAsyncRetry.Retry re-enters TryOpen with that same TCS, so AsyncState survives retries. The fallback could never fire in production. - Reading Transaction.Current here is thread-sensitive in exactly the way the rest of this change set set out to eliminate: on a retry we are re-entered from a continuation on an arbitrary thread, so we could enlist in an unrelated ambient transaction. The async equivalent of the sync ambient-transaction test now exercises the real mechanism instead: the GetConnectionAsync helper mirrors InternalOpenAsync by capturing the caller's ambient transaction into AsyncState, and the test asserts enlistment from inside a TransactionScope. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Adds GetConnectionAsync_WithAsyncFlowDisabled_StillEnlistsInAmbientTransaction: a TransactionScope created with the default TransactionScopeAsyncFlowOption .Suppress keeps its transaction in thread-static storage, so it is ambient on the caller's thread but does not flow to the thread pool thread the pool opens on. The connection must still enlist. The open is started inside the scope and awaited outside it, because a suppressed scope must be disposed on the thread that created it; an explicit CommittableTransaction keeps the transaction alive past the scope so the pool is still enlisting in a live transaction. Also restores the retry-path coverage as GetConnectionAsync_EnteredFromThreadWithoutAmbientTransaction_EnlistsFromAsyncState. This is not redundant: TryGetConnection reads AsyncState while still on the caller's thread, so in the scope-based tests Transaction.Current happens to agree with AsyncState. Only entering the pool from a thread with no ambient transaction -- as OpenAsyncRetry.Retry does -- distinguishes the two. Verified by mutation: replacing the AsyncState read with null fails 5 tests, and replacing it with ADP.GetCurrentTransaction() fails only the retry-path and no-leak tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
b25ac8e to
d7ea9d3
Compare
Rebased onto
mainnow that #4429 has merged. Unit tests: 834 passed / 0 failed.Summary
Implements transaction support in
ChannelDbConnectionPool, usingWaitHandleDbConnectionPoolas the reference for correct behavior. Before this change the channel pool constructed aTransactedConnectionPoolbut never used it, and threeIDbConnectionPoolmembers threwNotImplementedException.Changes
PutObjectFromTransactedPool(wasNotImplementedException) — returns a connection to general circulation once its transaction has ended, or destroys it if the pool is no longer running or the connection can't be pooled.TransactionEnded(wasNotImplementedException) — delegates toTransactedConnectionPool.TransactionEnded, which calls back intoPutObjectFromTransactedPool.ReturnInternalConnection— rewritten to mirrorWaitHandleDbConnectionPool.DeactivateObject. It now deactivates first (deactivation is what detaches a completed transaction, so readingEnlistedTransactionbeforehand could park a connection under an already-ended transaction), then decides under the connection lock between the transacted pool, stasis, the idle channel, and destruction. The idle-channel path moved into a newPutConnectionInIdleChannelhelper.GetFromTransactedPool(new) — vends a connection already enlisted in the ambient transaction. Transacted connections are exempt from idle-timeout and clear-generation eviction, since closing them would abort a possibly-distributed transaction, so only liveness is checked. A dead transaction root rethrows rather than silently retrying, because its delegated transaction cannot be recovered on another connection.GetInternalConnection/PrepareConnection— consult the transacted pool when the pool group has transaction affinity, and pass the ambient transaction through toActivateConnection.taskCompletionSource.Task.AsyncStateand threads it explicitly through the open, rather than assigningTransaction.Currenton the thread pool thread. See the section below.RemoveConnection— no longer disposes a transaction root that is still waiting for its delegated transaction to end (parity withDestroyObject). It comes back throughPutObjectFromTransactedPoolwhen the transaction completes.ReplaceConnection— no functional change; the twoTODO: Full transaction enlistment support (Story 2)markers from ChannelDbConnectionPool replace connection #4429 are removed now that enlistment is wired through.How connections move between the idle channel and the transacted store
The transacted store (
TransactedConnectionPool, keyed byTransaction) reserves a connection for one specific transaction, so reusing it avoids promoting that transaction to a distributed one. The only edge into it is a return while still enlisted; the only edges out are a pop by a caller in the same transaction, or the transaction ending.Return path (
ReturnInternalConnection)flowchart TD R["ReturnInternalConnection"] --> V["ValidateOwnershipAndSetPoolingState"] V --> D["DeactivateConnection"] D --> Doomed{"IsConnectionDoomed?"} Doomed -- yes --> Destroy["RemoveConnection (Destroy)"] Doomed -- no --> Poolable{"State is Running and CanBePooled?"} Poolable -- no --> Root{"IsTransactionRoot?"} Root -- yes --> Stasis["SetInStasis (HeldByTransaction)"] Root -- no --> Destroy Poolable -- yes --> Enl{"EnlistedTransaction is not null?"} Enl -- yes --> Park["PutTransactedObject (HeldByTransaction)"] Enl -- no --> Reuse["PutConnectionInIdleChannel (Reuse)"]DeactivateConnectionruns beforeEnlistedTransactionis read, because deactivation is what detaches an already-completed transaction. Reading first would park the connection under a transaction that has already ended, and it would never be released.Transaction end: back to general circulation
flowchart TD Sig["System.Transactions signals completion"] --> Where{"where is the connection?"} Where -- "parked in the transacted store" --> TE["pool.TransactionEnded"] TE --> TCP["TransactedConnectionPool.TransactionEnded removes it from the list"] TCP --> Put["PutObjectFromTransactedPool"] Where -- "in stasis" --> DTE["DelegatedTransactionEnded then TerminateStasis(true)"] DTE --> Put Where -- "never parked, still checked out" --> NoOp["no-op: stays with its owner"] Put --> Ok{"State is Running and CanBePooled?"} Ok -- yes --> Reset["ResetConnection then PutConnectionInIdleChannel"] Ok -- no --> Rm["RemoveConnection"]A connection in stasis reaches
PutObjectFromTransactedPooltoo, but by definition it got there because the pool was stopping or it was unpoolable, so it always takes theRemoveConnectionbranch.A parked connection keeps its
_connectionSlotsreservation, so it still counts towardCountandMaxPoolSize, but notIdleCount. OnlyRemoveConnectionreleases the slot.Tests
ChannelDbConnectionPoolTransactionTest(18 tests): return routing (enlisted, not enlisted, completed transaction,Enlist=false, shut-down pool), vending from the transacted store under the same and different transactions, commit/rollback, completion after shutdown,TransactionEndedfor a connection that was never parked, enlistment carry-over throughReplaceConnection, and the ambient-transaction flow cases below. Every test asserts full pool state (Count,IdleCount, transacted count) after each step, and the pool is built with a frozenTimeProvider.NotImplementedExceptionfrom the three now-implemented members.Validation
Unit tests: 834 passed / 0 failed on
net9.0.Manual/integration tests were run against a local SQL Server with
Switch.Microsoft.Data.SqlClient.UseConnectionPoolV2enabled, acrossTransactionEnlistmentTest,TransactionPoolTest,SQL.TransactionTest,ParallelTransactionsTest,ConnectionPoolTest,PoolBlockPeriodTestandDistributedTransactionTest(48 tests):This change fixes three previously failing tests:
TestAutoEnlistment_TxScopeNonComplete,TestManualEnlistment_EnlistandTestManualEnlistment_Enlist_TxScopeComplete.The 6 failures shared with the V1 baseline are all
PlatformNotSupportedException: This platform does not support distributed transactions— MSDTC isn't available on the test machine. The 2 remaining failures (ConnectionPoolTest.ReclaimEmancipatedOnOpenTest) are a pre-existing V2 gap:ReclaimEmancipatedObjectshas never been implemented inChannelDbConnectionPool. Both were confirmed by reverting this change and reproducing.A broader V2 sweep (
SqlCommand,AsyncTest,MARSTest,DataReaderTest,ConnectivityTests,WeakRefTest,AdapterTest,ExceptionTest,RetryLogic) gave 213 passed / 9 failed, where all 9 are named-pipe tests that fail identically on V1.Ambient transaction flow on the async path
Transaction.Currentdoes not flow into aTask.Rununless theTransactionScopewas created withTransactionScopeAsyncFlowOption.Enabled(the default isSuppress, which keeps the ambient transaction in thread-static storage). The async open path therefore cannot simply readTransaction.Current— it has to take the transaction from theTaskCompletionSource'sAsyncState, which is whereSqlConnection.InternalOpenAsynccaptures it. That is the only site in the repo that constructs aTaskCompletionSource<DbConnectionInternal>, and it always passes the ambient transaction, so the mechanism is reliable (including acrossOpenAsyncRetry.Retry, which reuses the same TCS).The original approach was to restore it by assigning
ADP.SetCurrentTransaction(...)inside theTask.Run. That is unsafe here: assigningTransaction.Currentwrites to thread-static storage thatExecutionContextdoes not unwind, so the transaction outlives the open and is observable by unrelated work later scheduled onto the same thread pool thread — most notably the login-time auto-enlistment that non-pooled connections perform againstTransaction.Current. Atry/finallyrestore doesn't fix it either, because the async continuation may resume on a different thread than the one that was polluted. (WaitHandleDbConnectionPooldoes the same assignment safely becauseWaitForPendingOpenasserts it is not on a thread pool thread.)The fix is to never mutate
Transaction.Currentin the pool: the transaction is captured on the caller's thread and threaded explicitly throughGetInternalConnectionintoGetFromTransactedPoolandPrepareConnection. The sync path passesADP.GetCurrentTransaction()directly, since it runs on the caller's thread.Four regression tests cover this:
GetConnection_Sync_UsesAmbientTransactionFromCallersThreadTransaction.Current, which is correct because it runs on the caller's threadGetConnectionAsync_UsesAmbientTransactionCapturedOnCallersThreadAsyncFlowOption.Enabledstill enlistsGetConnectionAsync_WithAsyncFlowDisabled_StillEnlistsInAmbientTransactionSuppress) scope still enlists, even though the transaction provably does not flow off the caller's threadGetConnectionAsync_EnteredFromThreadWithoutAmbientTransaction_EnlistsFromAsyncStateAsyncState, not from whatever is ambient on the entering thread — this is theOpenAsyncRetry.RetrycaseThe last one is load-bearing and not redundant:
TryGetConnectionreadsAsyncStatewhile still on the caller's thread, so in the scope-based testsTransaction.Currenthappens to agree withAsyncState. Only entering the pool from a thread with no ambient transaction distinguishes them. Verified by mutation — replacing theAsyncStateread withnullfails 5 tests, and replacing it withADP.GetCurrentTransaction()fails only the retry-path and no-leak tests.Checklist
UseConnectionPoolV2switch, which defaults to offNotes
ReclaimEmancipatedObjectsremains unimplemented in the channel pool; it is orthogonal to transactions and left for a follow-up.