vinodkc opened a new pull request, #57320:
URL: https://github.com/apache/spark/pull/57320

   <!--
   Thanks for sending a pull request!  Here are some tips for you:
     1. If this is your first time, please read our contributor guidelines: 
https://spark.apache.org/contributing.html
     2. Ensure you have added or run the appropriate tests for your PR: 
https://spark.apache.org/developer-tools.html
     3. If the PR is unfinished, add '[WIP]' in your PR title, e.g., 
'[WIP][SPARK-XXXX] Your PR title ...'.
     4. Be sure to keep the PR description updated to reflect all changes.
     5. Please write your PR title to summarize what this PR proposes.
     6. If possible, provide a concise example to reproduce the issue for a 
faster review.
     7. If you want to add a new configuration, please read the guideline first 
for naming configurations in
        
'core/src/main/scala/org/apache/spark/internal/config/ConfigEntry.scala'.
     8. If you want to add or modify an error type or message, please read the 
guideline first in
        'common/utils/src/main/resources/error/README.md'.
   -->
   
   ### What changes were proposed in this pull request?
   <!--
   Please clarify what changes you are proposing. The purpose of this section 
is to outline the changes and how this PR fixes the issue. 
   If possible, please consider writing useful notes for better and faster 
reviews in your PR. See the examples below.
     1. If you refactor some codes with changing classes, showing the class 
hierarchy will help reviewers.
     2. If you fix some SQL features, you can provide some references of other 
DBMSes.
     3. If there is design documentation, please add the link.
     4. If there is a discussion in the mailing list, please add the link.
   -->
   When a Spark Connect client runs a query, it stays connected to the server 
through a "reattach" mechanism that can reconnect if the stream drops. If 
certain errors happen during that reconnect, the client throws an internal 
RetryException and tries again. 
   
   The problem: this particular retry has no limit — no max attempts, no 
waiting between tries, no time cap. If the error keeps happening, the client 
retries forever and the query just hangs.
   
   This can happen in two situations:
   1. The server says it can't find the operation or session (for example, a 
load balancer sent the request to the wrong server that never got it).
   2. The reconnect keeps timing out (the connection is dead but nobody 
noticed).
   
   This PR puts a time limit on that retry loop:
   
   - It adds a setting, `maxRetryExceptionElapsedTime`, that defaults to 1 
hour. The client keeps retrying as before, but once it has spent a total of 1 
hour retrying this specific error, it gives up.
   - When it gives up, it reports the real underlying error (like a timeout) 
instead of a confusing internal marker, so the user knows what actually went 
wrong.
   - The same fix is applied to both the Scala client and the Python (PySpark) 
client so they behave identically.
   - The 1-hour limit can be changed by advanced users through the client 
builder (Scala) or a constructor argument (Python). There's no new config file 
setting or command-line flag.
   - The 1-hour limit only counts time spent stuck in the RetryException retry 
loop — not the total runtime of your query.
   - The clock starts on the first RetryException and only accumulates while 
the client is repeatedly failing to reattach (connection dead, operation not 
found, reconnect timing out).
   - As long as the server is making progress and sending results back, no 
RetryException is being thrown, so the clock never starts. A query can run for 
6 hours, 12 hours, or longer with zero impact.
   
   ### Why are the changes needed?
   <!--
   Please clarify why the changes are needed. For instance,
     1. If you propose a new API, clarify the use case for a new API.
     2. If you fix a bug, you can clarify why it is a bug.
   -->
   Today, the only reason this loop ever stops is that a separate feature — 
gRPC keepalive, which detects dead connections — happens to be on and working. 
That is not something the retry logic should depend on:
   - The "operation/session not found" case doesn't benefit from keepalive at 
all; it can spin forever regardless.
   - If keepalive is turned off or misconfigured on the client, the loop can 
hang even against a perfectly healthy server.
   
   Under the default setup the hang is usually avoided, so this is best seen as 
closing a hidden gap and hardening the client — the retry loop now stops on its 
own instead of depending on another feature being configured correctly 
everywhere.
   
   ### Does this PR introduce _any_ user-facing change?
   <!--
   Note that it means *any* user-facing change including all aspects such as 
new features, bug fixes, or other behavior changes. Documentation-only updates 
are not considered user-facing changes.
   
   If yes, please clarify the previous behavior and the change this PR proposes 
- provide the console output, description and/or an example to show the 
behavior difference if possible.
   If possible, please also clarify if this is a user-facing change compared to 
the released Spark versions or within the unreleased branches such as master.
   If no, write 'No'.
   -->
   Yes. Behavior is unchanged until the 1-hour default limit is reached — at 
which point a previously infinite hang now surfaces the real underlying error 
instead. Advanced users can adjust the limit via the new Builder method / 
constructor argument.
   
   Scope of the limit: the timer is measured within a single next()/hasNext() 
call and only advances on consecutive DEADLINE_EXCEEDED-driven reattaches with 
no successful response in between — it is not a cumulative counter across a 
job's lifetime. Idle streams are unaffected: the server completes an idle 
reattach stream cleanly every senderMaxStreamDuration (default 2 min, well 
under the client's ~10-min reattach deadline), which the client handles as a 
graceful reattach that does not touch the timer. The limit therefore only trips 
when a single call fails continuously for the full hour, i.e. a genuinely dead 
connection.
   
   
   ### How was this patch tested?
   <!--
   If tests were added, say they were added here. Please make sure to add some 
test cases that check the changes thoroughly including negative and positive 
cases if possible.
   If it was tested in a way different from regular unit tests, please clarify 
how you tested step by step, ideally copy and paste-able, so that other 
reviewers can test and check, and descendants can verify in the future.
   If tests were not added, please describe why they were not added and/or why 
it was difficult to add.
   If benchmark tests were added, please run the benchmarks in GitHub Actions 
for the consistent environment, and the instructions could accord to: 
https://spark.apache.org/developer-tools.html#github-workflow-benchmarks.
   -->
   Added tests in `SparkConnectClientRetriesSuite`, `test_client_retries.py`  
covering: the limit is enforced, below-limit retries still work 
(non-regression), the fallback when no underlying cause is attached, the timer 
starting only at the first `RetryException`, and the default value. 
   One `SparkConnectClientSuite` test exercises the whole path end-to-end 
against a test server that never responds. 
   Each test was checked to hang without the fix reproducing the original bug 
and confirming they are real regression guards.
   
   ### Was this patch authored or co-authored using generative AI tooling?
   <!--
   If generative AI tooling has been used in the process of authoring this 
patch, please include the
   phrase: 'Generated-by: ' followed by the name of the tool and its version.
   If no, write 'No'.
   Please refer to the [ASF Generative Tooling 
Guidance](https://www.apache.org/legal/generative-tooling.html) for details.
   -->
   Yes, Generated-by: Claude Code (sonnet-5)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to