Skip to content

Re-raise and stop interrupted queries in the SQL cursors, sharing the Spark handling - #853

Draft
laughingman7743 wants to merge 6 commits into
masterfrom
fix/840-sql-cursor-interrupt
Draft

laughingman7743 wants to merge 6 commits into
masterfrom
fix/840-sql-cursor-interrupt

Conversation

@laughingman7743

@laughingman7743 laughingman7743 commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

WHAT

With kill_on_interrupt enabled (the default), SQL cursors now handle an interrupt the way the Spark cursors do since #833 and #861, and the SQL and Spark cursors share one implementation of that handling.

  • Polling phase (BaseCursor._poll(), AioBaseCursor._poll()): after the interrupt, the cursor requests StopQueryExecution and waits for a terminal state as before. It then re-raises the original KeyboardInterrupt / asyncio.CancelledError, whatever the terminal state is. Before, the cursor returned the final execution.
    • A failure to cancel or wait becomes the interrupt's __cause__.
    • The final execution is not stored, and no result set is built. query_id keeps the query's ID.
  • Start phase (BaseCursor._execute(), AioBaseCursor._execute()), new for SQL: StartQueryExecution runs on a short-lived helper thread (sync) or is shielded from task cancellation (asyncio).
    • On an interrupt, the cursor waits for the request to finish, records the query ID on cursors that expose query_id, stops the query, waits for a terminal state, and re-raises.
    • If the helper thread has not begun the request when the interrupt is handled, the request is abandoned and never sent (sync).
    • Before, the interrupt aborted the request (sync) or left it running in a worker thread (asyncio). A query could therefore start with no ID on the cursor and keep running.
  • Shared implementation: _start_interruptibly() / _poll_interruptibly() in pyathena/common.py, and their asyncio counterparts in pyathena/aio/common.py, hold the helper-thread / asyncio.shield() logic that Cancel a Spark calculation interrupted while it is being started #861 added to the Spark cursors.
    • SparkBaseCursor and AioSparkCursor now call these helpers with their own start / poll / stop callables.
    • Spark behavior is unchanged. The one visible difference is that the "Query canceled by user." warning is now logged by the pyathena.common / pyathena.aio.common loggers.
    • _set_interrupted_query_id() is a no-op hook on BaseCursor, overridden in WithFetch / WithAsyncFetch to set query_id.
  • Affected cursors:
    • Polling and start phases: Cursor, DictCursor, the pandas/arrow/polars/s3fs cursors, and the Aio* cursors.
    • Start phase only: the thread-pool Async* cursors, whose execute() starts the query on the caller's thread. They poll on worker threads, which never receive KeyboardInterrupt.
  • kill_on_interrupt=False: unchanged. The request runs on the caller's thread or directly in the task, and the interrupt propagates immediately.
  • Tokens: the SQL path does not generate a ClientRequestToken, unlike the Spark path in Cancel a Spark calculation interrupted while it is being started #861. botocore auto-generates it for StartQueryExecution (idempotencyToken in the service model; not for StartCalculationExecution), and PyAthena's own retries default to throttling errors, which do not start a query.
  • Spark cursor state: SparkCursor.execute() and AioSparkCursor.execute() now clear calculation_id and the previous calculation execution before starting. Before, a failed execution (for example, a failed cancel request after an interrupt) left the earlier calculation's state and outputs next to the new calculation_id.
  • executemany(): it stops at the interrupted execution and re-raises, with rowcount == -1 and query_id kept. Before, an interrupted execution that ended SUCCEEDED let the loop continue.
  • dbt-athena: its legacy PyAthena cursor calls _execute(), so it gets the start-phase handling. It overrides _poll(), so its polling behavior is unchanged. Its current connection manager uses boto3 directly.
  • Docs: "Query cancellation on interrupt" in docs/usage.md and "Task cancellation" in docs/aio.md.

Behavior change (release note):

  • With the default kill_on_interrupt=True, an interrupt during execute() now propagates as KeyboardInterrupt / asyncio.CancelledError. Before, it surfaced as OperationalError (query ended CANCELLED/FAILED) or was lost (query ended SUCCEEDED). Callers that caught OperationalError after Ctrl-C or task cancellation need to handle the interrupt instead. asyncio.wait_for() now raises TimeoutError.
  • An interrupt while a query is being started now waits for StartQueryExecution and stops the query it started.
  • With kill_on_interrupt=True, each StartQueryExecution of a synchronous cursor runs on a short-lived daemon thread.
  • After a failed execute() on SparkCursor / AioSparkCursor, state and the other calculation properties return None (or the new calculation's values) instead of the previous calculation's.

WHY

Closes #840. Swallowing the interrupt lost Ctrl-C when the query finished first. In asyncio, task.cancel() did not end with a cancelled task, and a timeout from asyncio.wait_for() surfaced as the query's OperationalError, or as a normal return, instead of TimeoutError.
After #861 fixed the start phase for Spark (#841), the maintainer asked this PR to cover the SQL start phase as well and to share the implementation with the Spark cursors.

TEST

Tested commit: 10f7a83.

  • just format, just lint: passed (ruff, format check, mypy, cfn-lint, license headers). just docs lint: 0 errors.
  • Offline, no AWS: uv run --env-file .env pytest --noconftest -p no:xdist .... --noconftest skips the session setup that creates AWS resources.
    • SQL (tests/pyathena/test_cursor.py, tests/pyathena/aio/test_cursor.py, -k "interrupt or starting or on_poll_invoked or on_poll_none or legacy_kwargs_passthrough"): 26 passed on Python 3.13.1 and 3.10.16.
    • Spark (tests/pyathena/spark tests/pyathena/aio/spark, excluding tests that need AWS fixtures): 105 passed on 3.13.1. On 3.10.16, a combined SQL and Spark selection passed (138 tests). The Cancel a Spark calculation interrupted while it is being started #861 tests pass unchanged except that the patch targets moved to pyathena.common and the wait-interrupting helper moved to tests/pyathena/util.py.
  • New SQL start-phase tests:
    • Sync: an interrupt injected while StartQueryExecution is blocked. The request is sent once, the stop uses the returned ID, and the states RUNNING → terminal are polled before the same interrupt is re-raised. query_id is set, and no result set is built.
    • Sync: a start or cancel failure becomes __cause__. Without kill_on_interrupt, no helper thread is created. AsyncCursor.execute() also stops the query.
    • asyncio: task.cancel() while the start is blocked keeps the task pending until the request finishes, then stops the query, and task.cancelled() is true. asyncio.wait_for() raises TimeoutError after the stop. Failures become __cause__. Without kill_on_interrupt, the cancellation propagates at once.
  • Spark reuse: the Define best-effort Spark calculation cancellation #833 poll-phase failure tests (sync and asyncio) now start with a previous calculation on the cursor and assert that it was cleared. Without the reset, all 4 fail.
  • The asyncio start-phase timeout tests (SQL and Spark) now release the start request only after an asyncio.sleep() that ends after the timeout. They passed 30 of 30 repeated runs.
  • Regression check: with the new start-phase tests on the previous head (ef17dec), 10 of 11 fail. The one that passes covers the unchanged asyncio kill_on_interrupt=False path.
  • Real SIGINT (probe outside the repository, mocked client) while Cursor.execute() was blocked in StartQueryExecution, on 3.13.1 and 3.10.16: one start request, stop with the returned ID, query_id set, and KeyboardInterrupt re-raised without a cause.
  • The polling-phase tests and the live StopQueryExecution check from the earlier revision of this PR still apply: a stop on a SUCCEEDED query returns HTTP 200 and the state stays SUCCEEDED.
  • A local run of all of tests/pyathena with --noconftest also sent some queries to Athena from tests that call connect() directly. Its failures were missing-schema errors caused by the skipped setup (two checked). It is not used as evidence here. The AWS suites run in CI once the PR is Ready.

🤖 Generated with Claude Code

Comment thread pyathena/common.py Outdated
return query_execution
self.__poll(query_id)
except Exception as e:
raise interrupt from e

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Self-review round 1: implementation behavior. Result: CLEAN

Scope: c01c56f73c7dbf973fe73b52b6093f0a32952321..2de91e768196dc061251f7609ae0d9b9be2905cd (full diff: pyathena/common.py, pyathena/aio/common.py, both test files, docs/usage.md, docs/aio.md).

Covered:

  • Callers of the shared _poll(): execute() of Cursor/DictCursor, pandas/arrow/polars/s3fs (sync), and AioCursor plus the aio pandas/arrow/polars/s3fs cursors. The thread-pool Async* cursors call _poll() from executor threads (pyathena/async_cursor.py:153, pyathena/pandas/async_cursor.py:131, etc.), which never receive KeyboardInterrupt, so they are unaffected. The Spark cursors override _poll(). SQLAlchemy does not call _poll() directly.
  • Cursor state after an interrupt: _reset_state() already cleared result_set and rowcount, query_id is set before polling, and no result set is built on the interrupt path, so nothing is left open.
  • executemany(): both pyathena/result_set.py:1064 and pyathena/aio/common.py:651 catch BaseException, close, and re-raise, so an interrupt stops the loop with rowcount == -1 and query_id kept. Before this change, an interrupted execution that ended SUCCEEDED let the loop continue with the next parameters.
  • Exception flow: the bare raise after the inner try/except Exception re-raises the outer interrupt. A second interrupt or cancellation during the wait is a BaseException, so it propagates instead of becoming a cause (same as Define best-effort Spark calculation cancellation #833).
  • Tests: the new tests fail on the original _poll() for the defect itself. The SUCCEEDED cases fail with DID NOT RAISE, because the fake result-set class lets the old code return normally.

No actionable findings. Round two will add the executemany() consequence to the PR description.

assert cursor.query_id == "query_id"
assert cursor.result_set is None

async def test_execute_kill_on_interrupt_timeout(self):

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Self-review round 1: test determinism

The first status request blocks on an event that is never set, so the 0.01 s timeout always fires while polling.
The re-poll after the stop request returns at once, so asyncio.wait_for() sees CancelledError and raises asyncio.TimeoutError on both the 3.10 wait_for implementation and the timeout()-based one from 3.12.
asyncio.TimeoutError is used instead of the builtin TimeoutError, because the two are distinct on 3.10.

Comment thread docs/usage.md

With `kill_on_interrupt` enabled, which is the default, a `KeyboardInterrupt` while `execute()` waits for the query
requests cancellation, waits until the query reaches a terminal state, and then propagates.
Cancellation is a best-effort request, so the query can still end as `SUCCEEDED` or `FAILED`.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Self-review round 2: claims, callers, and operations. Result: FINDINGS (PR description only, repaired)

Scope: c01c56f73c7dbf973fe73b52b6093f0a32952321..2de91e768196dc061251f7609ae0d9b9be2905cd, all claims in the PR description, commit message, _poll() docstrings, docs/usage.md, and docs/aio.md.

Claims checked:

  • Best-effort stop can still end SUCCEEDED: measured with one SELECT 1 on the CI account. StopQueryExecution on an already SUCCEEDED query returns HTTP 200 and the state stays SUCCEEDED. So the race re-raises the interrupt without a cause, and this sentence and the _poll() docstrings hold.
  • "If the cancellation request fails, ... as its cause": covered by the failure[cancel] tests on both bases.
  • kill_on_interrupt=False keeps the query running: no stop request is made (test_execute_without_kill_on_interrupt).
  • Timeouts: the commit message claim holds. On the original code, asyncio.wait_for() surfaces OperationalError (the new timeout test fails this way), and CPython's Timeout.__aexit__ converts only CancelledError into TimeoutError.
  • Existing callers: dbt-athena's current connection manager uses boto3 directly, and its legacy PyAthena cursor overrides _poll() (dbt-athena/src/dbt/adapters/athena/connections_legacy.py:167), so it is unaffected. The kill_on_interrupt parameter descriptions in pyathena/connection.py:228 and the cursor docstrings remain accurate.

Findings, repaired in the PR description:

  1. The WHY claimed that TaskGroup could not handle the cancellation. A TaskGroup still raises its ExceptionGroup when a sibling fails, so this is narrowed to the verified asyncio.wait_for() effect.
  2. The description omitted the executemany() consequence: it now stops at the interrupted execution, where an interrupted execution that ended SUCCEEDED used to let the loop continue. This is added, along with the dbt-athena compatibility note and the live stop measurement.

Deferred (pre-existing, out of scope): the thread-pool Async* cursor docstrings (e.g. pyathena/arrow/async_cursor.py:91) say kill_on_interrupt cancels on keyboard interrupt, but their polling runs in executor threads, which never receive KeyboardInterrupt. This PR does not change that path.

Comment thread pyathena/common.py Outdated
if not self._kill_on_interrupt:
raise
_logger.warning("Query canceled by user.")
try:

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review (relayed): Codex CLI 0.157.0, model gpt-6-sol, reasoning effort high, session 01a0dcbd-22a4-7b63-b2a6-f2802f6e8c27. Result: FINDINGS

Scope: c01c56f73c7dbf973fe73b52b6093f0a32952321..2de91e768196dc061251f7609ae0d9b9be2905cd. The reviewer ran in a --sandbox read-only detached snapshot of the head with no .env. The prompt contained only the diff range, a file list, and the review questions; it had no PR number, description, commit message, or prior findings. Static review: the reviewer ran no tests. The snapshot and the PR worktree were unchanged afterwards.

Covered (reviewer's words): "synchronous and native asyncio execute() and executemany() paths through the default, dict, pandas, Arrow, Polars, and S3FS cursors; cursor state and exception chaining; the thread-backed async and Spark overrides; the new tests and both documentation examples."

[P2] Pre-existing, exposed by the new contract: "A second KeyboardInterrupt or task cancellation during the stop request or follow-up poll escapes the handler because both are BaseException subclasses, outside except Exception. With the query still running, execute() exits before observing a terminal state. ... The behavior predates the diff, while the new documentation states the wait without this qualification." (also pyathena/aio/common.py:155)

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Disposition: documented; behavior kept (pre-existing). Verified: a second KeyboardInterrupt or task cancellation raised during _cancel() or the follow-up poll is a BaseException, so except Exception does not catch it and it propagates with the first interrupt as its context. This predates the diff, matches the Spark contract from #833, and gives users a way to stop waiting on a query that does not stop. da16975 documents it: docs/usage.md says "A second KeyboardInterrupt during that wait propagates without waiting for the terminal state.", and docs/aio.md has the equivalent sentence for a repeated task cancellation.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent follow-up review (relayed): Codex CLI, model gpt-6-sol, reasoning effort high, session 01a0dcc3-f3ef-7833-a415-86e914ba8fa2. Scope: 2de91e768196dc061251f7609ae0d9b9be2905cd..da169757662dda486e41349789ce7a77e67ddc91 (same base c01c56f73c7dbf973fe73b52b6093f0a32952321), read-only snapshot, static review.

Covered surfaces: the four files changed in 2de91e7..da16975, traced through pyathena/aio/cursor.py, pyathena/aio/common.py, pyathena/aio/util.py, pyathena/cursor.py, and pyathena/common.py. This was a static, read-only review; I did not run tests.

FINDINGS

  • P2 — docs/aio.md:142, docs/usage.md:511: The new qualification covers a second interruption while polling for the terminal state, but says nothing about one during the stop request. Both handlers call _cancel before that follow-up poll, and their except Exception blocks do not catch a second CancelledError or KeyboardInterrupt. For example, a second task cancellation while the stop request is awaiting its worker thread exits the handler without confirming that the stop request ran or that the query became terminal. The documentation still implies the first interruption completes those steps unless interrupted “during that wait.”

Prior items

  1. Resolved. docs/aio.md:145 limits the timeout claim to polling and explains that cancellation during startup can leave query_id unset while the worker-thread request continues.
  2. Not an actual defect. In this test, _execute is an immediately completing AsyncMock; the first status request then enters an Event.wait() and suspends. On Python 3.10, wait_for() schedules the child task before its timeout can cancel it; on 3.11–3.14, it awaits the coroutine inside the timeout context. The event loop therefore reaches that blocked status request before delivering the 10 ms timeout. A separate barrier is unnecessary for this fixture.
  3. Resolved. Both tests now return RUNNING before a terminal state and assert that the polling callback saw both states before the original interruption propagated.
  4. Unresolved for the stop-request window; resolved for follow-up polling. The source behavior described in the finding remains possible, and the added wording qualifies only “that wait.”

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in f528d50. The repeated-interrupt note now covers the cancellation request as well as the follow-up wait, in both docs/usage.md and docs/aio.md, and says the query can keep running.

Independent follow-up review (relayed): Codex CLI, model gpt-6-sol, reasoning effort high, session 01a0dcc8-cb13-7712-8373-34cdcfc3f7e1. Scope: da169757662dda486e41349789ce7a77e67ddc91..f528d50bc242ccacb06631081a7f21bda31d70a2, read-only snapshot, static review.

Covered surfaces: docs/aio.md “Task cancellation” and docs/usage.md “Query cancellation on interrupt,” checked against the five named source files. The new wording covers a second interruption during both the cancellation request and the follow-up poll.

CLEAN. No actionable inaccuracies found in either section. This was a read-only source review; no tests were run.

Comment thread docs/aio.md Outdated
If the cancellation request fails, `asyncio.CancelledError` is raised with the error as its cause.
With `kill_on_interrupt=False`, `asyncio.CancelledError` is raised immediately and the query keeps running.

A timeout from `asyncio.wait_for()` therefore cancels the query and raises `asyncio.TimeoutError`:

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review (relayed, Codex gpt-6-sol): [P2] introduced

"The wait_for() example says a timeout cancels the query. If the timeout occurs while start_query_execution is running in a worker thread, execute() has not assigned query_id; cancellation cannot stop the request, and Athena may start a query after the task exits. The example can print None while that query keeps running."

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Disposition: fixed in da16975. Verified: aio StartQueryExecution runs through asyncio.to_thread() (pyathena/aio/util.py:42), and query_id is assigned only when _execute() returns. The docs now limit the cancellation to a timeout that expires while execute() waits for the query, and state that a timeout during the start leaves query_id as None while the pending start request can still start the query. execute() has no await between the query_id assignment and _poll(), so there is no third window. The example prints query_id as a value that may be None.

kill_on_interrupt=True, final_state=AthenaQueryExecution.STATE_CANCELLED
)
with pytest.raises(asyncio.TimeoutError):
await asyncio.wait_for(cursor.execute("SELECT 1"), timeout=0.01)

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review (relayed, Codex gpt-6-sol): [P2] introduced

"The 10 ms timeout test has no barrier confirming that the task reached polling. Under a scheduling delay, it can time out before a query ID is assigned; cancel is then never awaited and the assertion fails intermittently."

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Disposition: rejected with evidence. No await in execute() yields to the event loop before the first status request blocks. _execute is an AsyncMock, which completes without suspending, and _call_on_start_query_execution is synchronous, so query_id is always assigned before the loop can run the timeout callback. On 3.12+, wait_for() awaits the coroutine inside the calling task under timeouts.timeout(), so the timer can fire only at the first suspension, the blocked poll. On 3.10/3.11, wait_for() wraps the coroutine in a task whose first step call_soon places in _ready before _run_once moves any expired timer into _ready, so that step runs first even after a scheduling delay. The test passed on 3.13.1 and 3.10.16 locally.

def test_execute_kill_on_interrupt(self, final_state):
"""An interrupt cancels the query, waits for it, and is re-raised (no AWS)."""
cursor, cancel = _offline_cursor(kill_on_interrupt=True)
cursor._get_query_execution = MagicMock(

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review (relayed, Codex gpt-6-sol): [P3] introduced

"The follow-up status is immediately terminal in the new tests. Given a query that stays RUNNING after the stop request, an implementation that polls once and raises before terminal state could still satisfy these tests. They exercise the prior implementation's failing path, but do not assert the promised wait through a nonterminal state." (also tests/pyathena/aio/test_cursor.py:197)

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Disposition: fixed in da16975. Both test_execute_kill_on_interrupt tests now report RUNNING after the stop request, then the terminal state. They assert through the on_poll hook that the polled states were [RUNNING, final_state] before the interrupt or cancellation was re-raised. Mutation check: replacing the follow-up __poll() with a single _get_query_execution() call in both _poll() implementations makes all 4 of these tests fail. With the real implementation, 13 targeted tests pass on 3.13.1, and 11 interrupt tests pass on 3.10.16.

@laughingman7743
laughingman7743 marked this pull request as ready for review September 26, 2026 08:34
laughingman7743 and others added 3 commits September 28, 2026 15:26
With kill_on_interrupt enabled, the shared _poll() of the SQL cursors
requested StopQueryExecution after a KeyboardInterrupt or task
cancellation, waited for a terminal state, and then returned the final
execution instead of re-raising. Callers saw an OperationalError for a
CANCELLED or FAILED query, or a normal return when the query SUCCEEDED
first, and asyncio.wait_for()/asyncio.timeout() could not turn the
cancellation into a timeout.

Re-raise the original interrupt after the stop request and the wait,
as #833 does for the Spark cursors, with a failure to stop or wait as
its cause.

Closes #840

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Limit the documented asyncio timeout behavior to a timeout while the
query is being waited for, note that a repeated interrupt or task
cancellation skips the wait, and make the tests assert that the
interrupt is re-raised only after a non-terminal poll reaches a
terminal state.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A second interrupt or task cancellation also escapes while the
cancellation request is in progress, not only during the follow-up wait.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@laughingman7743
laughingman7743 force-pushed the fix/840-sql-cursor-interrupt branch from f528d50 to ef17dec Compare September 28, 2026 06:26
Move the Spark start-phase interrupt handling from #861 into shared
helpers and use them for the SQL cursors too. With kill_on_interrupt,
StartQueryExecution now runs on a helper thread (sync) or is shielded
from task cancellation (asyncio); an interrupt waits for the request,
records the query ID on cursors that expose query_id, stops the query,
waits for a terminal state, and re-raises. A request the helper has not
begun is abandoned and never sent.

The polling-phase recovery of the SQL and Spark cursors now goes through
the same helpers, so the Spark cursors keep their behavior with less
duplicated code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@laughingman7743
laughingman7743 marked this pull request as draft September 28, 2026 06:47
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@laughingman7743 laughingman7743 changed the title Re-raise the interrupt after kill_on_interrupt cancellation Re-raise and stop interrupted queries in the SQL cursors, sharing the Spark handling Sep 28, 2026
Comment thread pyathena/common.py
_INTERRUPT_CHECK_INTERVAL = 0.1


def _start_interruptibly(

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Self-review round 1 (expanded scope: start phase + shared helpers): implementation behavior. Result: FINDINGS (1, repaired)

Scope: full diff 659676c07e2c09397b7cbc5740cc10bfe6fe41cb..d66c6994034894313f6b68f23f9f5d421ac13632 (rebased onto #861). Because the contract expanded, this is a full pass, not a range-diff.

Covered:

  • _execute() callers: only the cursors' execute(). That is Cursor, the pandas/arrow/polars/s3fs sync cursors, their Async* thread-pool variants (start on the caller's thread), and the five Aio* cursors. SQLAlchemy calls execute() only. dbt-athena legacy calls _execute() and gets the start-phase handling.
  • Shared helpers: the sync helper keeps Cancel a Spark calculation interrupted while it is being started #861's abandon check (Future.set_running_or_notify_cancel() / cancel()) and its interruptible wait. Name mangling inside the lambda resolves per class (_BaseCursor__start_query_execution, _AioBaseCursor__..., _SparkBaseCursor__...). The bare raise after the inner except Exception re-raises the outer interrupt.
  • Spark: _poll/_calculate now pass their own poll/stop callables. __stop_started_calculation sets calculation_id before the cancel, as before, so a cancel failure still leaves the ID on the cursor. All Cancel a Spark calculation interrupted while it is being started #861 tests pass with only their patch targets moved.
  • SQL state: _set_interrupted_query_id() is a no-op on BaseCursor (AsyncCursor has no query_id) and sets query_id in WithFetch/WithAsyncFetch. It is called before the cancel. On a start failure, query_id stays None.
  • Poll-phase aio tests: they keep a mocked _execute, so the earlier determinism argument for the 10 ms wait_for test still holds. The start-phase tests use a separate helper with the real _execute().

Finding (repaired in d66c699): docs/aio.md said query_id is None only if the timeout expires before the query is started, but a start request that fails after the timeout also leaves it None. Reworded to "only if no query was started".

Out of scope, same as the Spark cursors since #861: in asyncio, a start task that has not begun when the cancellation arrives still sends its request, which is then stopped. The sync helper abandons it.

Comment thread docs/usage.md
The `query_id` property returns that query's ID.
If the request has not been sent yet when the interrupt is handled, it is never sent.
`AsyncCursor` and its variants also stop a query whose start is interrupted in `execute()`.
They wait for queries on worker threads, which do not receive `KeyboardInterrupt`.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Self-review round 2 (expanded scope): claims, callers, and operations. Result: CLEAN

Scope: 659676c07e2c09397b7cbc5740cc10bfe6fe41cb..d66c6994034894313f6b68f23f9f5d421ac13632, the rewritten PR description, docstrings, and docs/usage.md / docs/aio.md.

Claims checked:

  • No SQL token generation needed: botocore's Athena model marks StartQueryExecution.ClientRequestToken as idempotencyToken (auto-generated per call) and StartCalculationExecution's not. RetryConfig defaults to THROTTLING_ERROR_CODES, which do not start a query.
  • "AsyncCursor and its variants also stop a query whose start is interrupted": pyathena/async_cursor.py:225 and the pandas/arrow/polars/s3fs async cursors call self._execute() on the caller's thread. Polling runs in self._executor.
  • "If the request has not been sent yet ..., it is never sent": this is the sync abandon path, covered by the Cancel a Spark calculation interrupted while it is being started #861 tests test_calculate_interrupted_before_request_is_sent[False/True], which now exercise the shared helper.
  • Real signal: a SIGINT via os.kill while Cursor.execute() was blocked in a mocked StartQueryExecution produced one start request, a stop with the returned ID, query_id set, and KeyboardInterrupt without a cause. Checked on 3.13.1 and 3.10.16.
  • Operational: one short-lived daemon thread per StartQueryExecution with kill_on_interrupt, and no extra AWS calls on the normal path. The start still goes through retry_api_call with the same config.
  • Evidence scope: local results are offline only (3.13.1 and 3.10.16). The AWS suites were not run locally for this revision. An accidental local run of all of tests/pyathena with --noconftest sent some queries from tests that call connect() directly; its missing-schema failures are not used as evidence, and the PR description says so.

No corrections were needed beyond the round 1 repair.

Clear the previous calculation when a Spark cursor starts a new one, so
that a failed execution no longer leaves the earlier calculation's state
next to the new calculation ID. Make the asyncio start-phase timeout
tests wait for the timeout before releasing the start request, and state
when an asyncio timeout leaves query_id unset without implying that no
query started.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Comment thread tests/pyathena/aio/test_cursor.py Outdated
async def test_execute_timeout_while_starting(self):
"""A timeout during the start request stops the query and raises TimeoutError (no AWS)."""
cursor, cancel, started, release = _starting_cursor()
timer = threading.Timer(0.2, release.set)

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review (relayed): Codex CLI 0.157.0, reported model gpt-6-astra, reasoning effort high, session 01a0e6c8-41ad-7423-a641-afcd8c29f7fc. Result: FINDINGS

Scope: 659676c07e2c09397b7cbc5740cc10bfe6fe41cb..d66c6994034894313f6b68f23f9f5d421ac13632 (full expanded scope). The reviewer ran in a --sandbox read-only detached snapshot with no .env. The prompt contained no PR number, description, commit message, or prior findings. Static review. The snapshot and the PR worktree were unchanged afterwards.

Covered (reviewer's words): "the full diff and the sync, thread-pool async, and native asyncio cursor families, including pandas/Arrow/Polars/S3FS and Spark. Traced start/poll/cancel handling, exception identity/chaining, repeated interruption, helper lifecycle, cursor state, legacy methods and overrides, Python ≥3.10 compatibility, tests, and documentation." It found "No additional defect ... in the shared-helper refactor or legacy method signatures."

1. [P2] introduced: "The release timer starts before wait_for() establishes its timeout. If the test thread is descheduled for over 200 ms after timer.start(), the request is released before execution begins. The mocked query then reaches CANCELLED and raises OperationalError, failing the expected TimeoutError assertion despite correct implementation."

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Disposition: fixed in 10f7a83, together with the same pattern in the Spark test from #861 (tests/pyathena/aio/spark/test_cursor.py). Both tests now start wait_for() as a task, wait for the start request to begin, and then await asyncio.sleep(0.1) before releasing the request. The sleep begins after wait_for() scheduled its 0.05 s deadline, so its timer is due later. The event loop therefore runs the timeout callback first, and the cancellation reaches the task before the test resumes and releases the request. threading.Timer is gone. Both tests passed 30 of 30 repeated runs.

Comment thread docs/aio.md Outdated
With `kill_on_interrupt=False`, `asyncio.CancelledError` is raised immediately and the query keeps running.

A timeout from `asyncio.wait_for()` therefore cancels the query and raises `asyncio.TimeoutError`.
`query_id` is `None` only if no query was started, for example when the timeout expires while looking up a cached result.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review (relayed, Codex gpt-6-astra): 2. [P3] introduced

"With kill_on_interrupt=False, a timeout during StartQueryExecution cancels the await while its underlying thread continues. Athena can start the query, but the cursor retains query_id=None. Repeated cancellation during the protected start wait can also abandon ID recovery. Document None as an unavailable ID, rather than evidence that no query exists."

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Disposition: fixed in 10f7a83. Verified: with kill_on_interrupt=False, or after a second cancellation during the shielded start, a query can start while query_id stays None. The sentence is now one-directional: "query_id is None if the timeout expires before the start request is sent, for example while looking up a cached result." The preceding paragraph already says that with kill_on_interrupt=False the query keeps running, and that another cancellation during the waits leaves it running.

Comment thread pyathena/spark/common.py
)

future: Future[str] = Future()
def __stop_started_calculation(self, calculation_id: str) -> None:

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review (relayed, Codex gpt-6-astra): 3. [P2] pre-existing, preserved by the Spark refactor

Anchored here because the lines are outside the diff: pyathena/spark/cursor.py:147, pyathena/aio/spark/cursor.py:351.

"Execute calculation A successfully, then start B on the same cursor. Interrupt/cancel B while polling and make _cancel() fail. The exception propagates, but calculation_id identifies B while calculation_execution, state, and output accessors still describe A. Neither execution path clears the previous calculation object."

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Disposition: fixed in 10f7a83 (pre-existing; folded in as a contained Spark consistency fix). Verified: SparkCursor.execute() and AioSparkCursor.execute() overwrote _calculation_id without clearing _calculation_execution. Both now set them to None before _calculate(), like the SQL cursors' _reset_state(). The #833 poll-phase failure tests (sync and asyncio) now start with a previous calculation on the cursor and assert that calculation_id is the new one and calculation_execution is None. Without the reset, all 4 fail. Side effect, checked: cancel() during a new start now raises ProgrammingError instead of stopping the previous, finished calculation. The live test_cancel tests wait for an ID that is neither None nor the previous one, so they are unaffected. This is recorded as a release-note item in the PR description.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent follow-up review (relayed): Codex CLI, reported model gpt-6-astra, reasoning effort high, session 01a0e710-57c6-7d73-b6b3-e9bb82e625e4. Scope: d66c6994034894313f6b68f23f9f5d421ac13632..10f7a832ebbac10440706167d1e370f90b23c2ab (same base 659676c07e2c09397b7cbc5740cc10bfe6fe41cb), read-only snapshot, static review. The snapshot and the PR worktree were unchanged afterwards.

Covered surfaces: all six changed files; Spark start/poll/cancellation paths; calculation_id, calculation_execution, state, and output accessors; repository callers; documentation; and local CPython asyncio sources for 3.10–3.14.

CLEAN — no actionable defects found in d66c699..10f7a832.

  1. Timeout-test race: resolved. Both rewritten tests wait for the start request to begin, then release it only after the event-loop sleep.

    • Python 3.10–3.11: wait_for() registers its timeout before execution starts. Its deadline precedes the subsequently registered sleep deadline. Even if both timers become overdue together, the timeout callback queues the wait_for() continuation first; that continuation requests cancellation before the test resumes and releases the worker.
    • Python 3.12–3.14: wait_for() uses the timeout context manager, whose earlier timer directly cancels the executing task before the sleep continuation releases the worker.

    The pending-task assertion, subsequent TimeoutError, cancellation-call assertion, and retained-ID assertion collectively exercise the intended behavior. The existing 10-second worker watchdog remains a finite scheduling limit; the original independent-thread release race is removed.

  2. query_id documentation: resolved. docs/aio.md:148 removes the exclusivity claim. It gives the pre-start/cache-lookup case without asserting that None proves no query started, allowing the documented disabled-cleanup and repeated-cancellation cases.

  3. Stale Spark calculation: resolved. pyathena/spark/cursor.py:148 and pyathena/aio/spark/cursor.py:352 clear both fields before starting another calculation. Start failures leave no previous ID/result; failures after obtaining the new ID retain that ID without the previous execution. Successful interruption cleanup still stores the current terminal execution.

    Compatibility is consistent: state and execution-derived properties already support None; cancel() rejects an unknown ID and targets the current calculation once known. The strengthened tests seed previous state and verify its removal for both cancellation-request and cleanup-wait failures. They directly protect the stale-execution regression, though they do not independently test clearing a previous ID when startup fails.

Static review only: no tests, builds, writes, or network access. HEAD remained 10f7a832; the worktree remained clean.


Author note: the remark that no test separately covers clearing a previous ID when the start fails is not taken up. The reset runs unconditionally before _calculate() (pyathena/spark/cursor.py:148, pyathena/aio/spark/cursor.py:352), and the new assertions already fail without it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cursors swallow the interrupt after kill_on_interrupt cancellation

1 participant