CloudFetch and M2M token exchange are unbounded and uninterruptible (v1.13.0)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Domain
- authentication, backend, backend-api-design, performance
Research direction
Start by tracing the download path in internal/rows/rows.go, internal/rows/arrowbased/arrowRows.go, and batchloader.go, then inspect auth/oauth/m2m/m2m.go and the related connector and config entries. Use the existing CloudFetch and authentication entry points to understand context, client, expiry, and token behavior. Done means the four reported paths have bounded, interruptible behavior or an explicit documented terminal condition, and the WithCloudFetch comment matches the default.
Written by the indexing model from the issue text.
Description
Version
v1.13.0
Summary
CloudFetch result downloads are unbounded and uninterruptible, and an expired
presigned link ends the read with no recovery path. Four issues, the first three
in the download path and the fourth on the auth path.
1. The caller's context is discarded
internal/rows/rows.go:622 and :624 pass r.ctx into NewArrowRowScanner,
but internal/rows/arrowbased/arrowRows.go:124 substitutes context.Background()
when constructing the iterator:
bi, err2 = NewCloudBatchIterator(context.Background(), rowSet.ResultLinks, ...)
So the context given to QueryContext never reaches the download. Cancelling the
query, or its deadline expiring, cannot stop an in-progress file fetch.
2. The download client has no timeout and no public setter
internal/rows/arrowbased/batchloader.go:62 falls back to http.DefaultClient,
which has no Timeout:
httpClient := http.DefaultClient
if cfg.HTTPClient != nil {
httpClient = cfg.HTTPClient
}
CloudFetchConfig.HTTPClient has no ConnOption. The only way to populate it is
WithTransport, which also replaces the Thrift transport as a side effect, and
the http.Client it builds (connector.go:421) sets no Timeout either.
Related: #307 asked for a configurable CloudFetch transport and was closed as
completed. WithTransport addresses the transport case, but a RoundTripper
cannot set http.Client.Timeout, so the timeout case above is still open.
Together with (1), a stalled download has neither a timeout nor working
cancellation. Because downloads are lazy (cloudIPCStreamIterator.Next(),
batchloader.go:200), the caller is blocked inside row iteration, so a deferred
rows.Close() cannot fire to break the stall.
3. Expired links are terminal
batchloader.go:453 returns errors.New(dbsqlerr.ErrLinkExpired). That constant
appears nowhere else in the module apart from its own definition: nothing handles
it and nothing re-issues links. A result set large enough that its presigned URLs
expire part-way through reading cannot be completed, only restarted.
CloudFetchConfig.MinTimeToExpiry defaults to 0 (internal/config/config.go:557
clamps only negative values) and likewise has no ConnOption, so a caller cannot
widen the safety margin.
4. The token exchange is unbounded and serialized
auth/oauth/m2m/m2m.go:41 holds authClient.mx across the token fetch, and the
token source is built with context.Background() (m2m.go:73), so
clientcredentials falls back to http.DefaultClient with no timeout. A hung
token endpoint therefore stalls every in-flight request on that connector
indefinitely, with no way for the caller to bound it. Endpoint discovery is
capped at 10s (auth/oauth/oauth.go:21), but the exchange itself is not.
Also, a doc mismatch
WithCloudFetch's comment (connector.go:429) says "Default is false", but
CloudFetchConfig.WithDefaults() sets UseCloudFetch = true unconditionally
(internal/config/config.go:546). CloudFetch is on by default.
Suggested fixes
- Pass the scanner's context through to
NewCloudBatchIteratorinstead of
context.Background(). - Expose
HTTPClientandMinTimeToExpiryasConnOptions, so a caller can bound
downloads without displacing the Thrift transport. Note thatWithTransportis
not a substitute: aRoundTrippercannot sethttp.Client.Timeout, so it can
only bound each hop of a redirect chain rather than the request as a whole. - Bound the token exchange, and consider not holding the mutex across it.
- Re-fetch result links on expiry, or if that is out of scope, document the
condition as terminal so callers can plan for it.
- Dominant language
- Go
- Stars
- 53
- Forks
- 67
- Avg merge
- 21h 29m
- Merged PRs (30d)
- 12
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from databricks/databricks-sql-go
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
databricks/databricks-sql-go#476 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 64/100
databricks/databricks-sql-go#490 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 55/100
databricks/databricks-sql-go#481 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 52/100
databricks/databricks-sql-go#480 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 65/100
databricks/databricks-sql-go#474 ·
Maintainers usually reply within 1 day
All issues in databricks/databricks-sql-go
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
linonetwo/cpa-session-archive#25 ·
Maintainers usually reply within 1 day
-
area/testing kind/bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
agent-butler-finding bug
Difficulty 1/5 Under an hour Newbie friendliness 94/100
jordansmall/spindrift#4367 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day