Repository navigation
feat(query): SHOW/TERMINATE SESSIONS - #1814
katarinasupe wants to merge 2 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
andrejtonev
left a comment
There was a problem hiding this comment.
Thanks for writing this up! I checked every statement against current master (6e9c79da3), on a live instance as well as in the code. Most of it is accurate. The inline comments cover two statements that are wrong for 3.14 (SESSIONS isn't reserved, and the forced-DROP DATABASE example no longer applies after #4843), a few that overstate what happens (killed: true, "running query is aborted"), and some behaviour that's missing: open-transaction rollback, what the client sees and driver retries, auth disabled, Community vs Enterprise, impersonation, coordinators, LOGOFF and $id parameters. Every suggestion was re-run against master.
Three things outside this diff:
TERMINATE TRANSACTIONS $id(around line 340): "A parameterized id is treated exactly like a literal one, so runningTERMINATE TRANSACTIONS $idwith$id = "*"also terminates everything." This has never worked. The grammar only accepts a literal there (transactionId : literal, unchanged since the query was added), soTERMINATE TRANSACTIONS $idis a syntax error (extraneous input '$' expecting ...) whatever$idis. The sentence came in with v3.13 (#1689). Suggested replacement: "Transaction ids, including"*", must be string literals. Query parameters such as$idaren't supported and cause a syntax error."SHOW TRANSACTIONScolumns (line 95): since memgraph#4571 (3.14, listed under breaking changes in #1764),SHOW TRANSACTIONSreturns an 8th column,database, afterelapsed_ms. The page still says "contains seven columns", and the column table and example outputs don't include it. Suggested row:| database | String | The database the transaction is running on. |- PR description: it says the
SHOW TRANSACTIONSfix is internal and "the release note already covers it". It doesn't: onrelease/3.14the only #4577 entry is the feature line. I've suggested a bug-fix line on #1764.
Documents the session management queries from memgraph/memgraph#4577: listing open Bolt sessions and terminating them from another connection, who can see and terminate which sessions, the result columns, and the SESSIONS reserved keyword. Adds both queries to the query privileges table. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Also fix the TERMINATE TRANSACTIONS parameter claim and add the database column of SHOW TRANSACTIONS.
5f68665 to
54ce812
Compare
| | `SHOW TRANSACTIONS` | `TRANSACTION_MANAGEMENT` | `SHOW TRANSACTIONS` | | ||
| | `TERMINATE TRANSACTIONS` | `TRANSACTION_MANAGEMENT` | `TERMINATE TRANSACTIONS 'transaction_id'` | | ||
| | `TERMINATE TRANSACTIONS "*"` | `TRANSACTION_MANAGEMENT` | `TERMINATE TRANSACTIONS "*"` terminates every transaction the user may terminate. Without the privilege, only the user's own transactions are terminated. | | ||
| | `SHOW SESSIONS` | **None** | `SHOW SESSIONS` lists the user's own sessions. With `TRANSACTION_MANAGEMENT`, it also lists other users' sessions on the databases where the user has the privilege. | |
There was a problem hiding this comment.
| | `SHOW SESSIONS` | **None** | `SHOW SESSIONS` lists the user's own sessions. With `TRANSACTION_MANAGEMENT`, it also lists other users' sessions on the databases where the user has the privilege. | | |
| | `SHOW SESSIONS` | **None** | `SHOW SESSIONS` lists the user's own sessions. With `TRANSACTION_MANAGEMENT` privilege, it also lists other users' sessions on the databases where the user has the privilege. | |
There was a problem hiding this comment.
In general, for me to be able to understand what this sentence was trying to convey, I had to go to /database-management/authentication-and-authorization/role-based-access-control to understand what does "With 'TRANSACTION_MANAGEMENT'" even mean.
This is maybe a comment for a wider revamp, but here it helped to even mention this is a privilege of some kind.
There was a problem hiding this comment.
Maybe the suggestion I'm trying to make is to add a descriptive noun when mentioning a part of the code
'this()' function
'THIS' clause
'THIS' privilege
'--this' flag
| A session is one client connection to Memgraph over Bolt. You can list the | ||
| open sessions and close any of them from another connection, for example an | ||
| idle (often pooled) connection that still has a database selected and makes | ||
| [`DROP DATABASE`](/database-management/multi-tenancy#drop-database-with-force) |
There was a problem hiding this comment.
| [`DROP DATABASE`](/database-management/multi-tenancy#drop-database-with-force) | |
| [`DROP DATABASE`](/database-management/multi-tenancy#drop-database-with-force) query |
| open sessions and close any of them from another connection, for example an | ||
| idle (often pooled) connection that still has a database selected and makes | ||
| [`DROP DATABASE`](/database-management/multi-tenancy#drop-database-with-force) | ||
| fail with `Cannot delete <name>, it is currently being used.` Available since |
There was a problem hiding this comment.
| fail with `Cannot delete <name>, it is currently being used.` Available since | |
| fail with `Cannot delete <name>, it is currently being used.` error message. Available since |
|
|
||
| Session queries run on data instances (MAIN and REPLICA), and each instance | ||
| lists and closes only the sessions connected to it. On a high availability | ||
| coordinator they fail with `Coordinator can run only coordinator queries!`. |
There was a problem hiding this comment.
| coordinator they fail with `Coordinator can run only coordinator queries!`. | |
| coordinator they fail with `Coordinator can run only coordinator queries!` error message. |
| They run as implicit transactions only; running them inside an explicit | ||
| transaction raises an error. |
There was a problem hiding this comment.
In the old days, I would've changed this to "...only, so running them..." or even better "..., so don't run them inside explicit transactions (such as: ...) "
What are explicit transactions? bo - might be good to have an example, explanation?
|
|
||
| | Column | Type | Description | | ||
| |---|---|---| | ||
| | `session_id` | `String` | Unique id of the session. Use this value with `TERMINATE SESSIONS`. | |
There was a problem hiding this comment.
"'TERMINATE SESSIONS' query to terminate it"?
| | `database` | `String` | The database the session is using, or `""` if it isn't using one. | | ||
| | `login_timestamp` | `String` | UTC time of the session's most recent login, formatted as `YYYY-MM-DD HH:MM:SS.ffffff` (no time zone suffix). | | ||
|
|
||
| You see your own sessions, and the sessions on every database where you have |
There was a problem hiding this comment.
| You see your own sessions, and the sessions on every database where you have | |
| Running the 'SHOW SESSION;' query will show your own sessions, and the sessions on every database where you have |
| a connection counts as the impersonated user, and its queries are checked | ||
| against that user's privileges. | ||
|
|
||
| In the following example, `admin` has `TRANSACTION_MANAGEMENT` on every |
There was a problem hiding this comment.
| In the following example, `admin` has `TRANSACTION_MANAGEMENT` on every | |
| In the following example, `admin` has `TRANSACTION_MANAGEMENT` privilege on every |
|
|
||
| In the following example, `admin` has `TRANSACTION_MANAGEMENT` on every | ||
| database, and `alice` has two idle connections open, one on `analytics` and | ||
| one on `memgraph`. The session running the query is listed too: |
There was a problem hiding this comment.
| one on `memgraph`. The session running the query is listed too: | |
| one on `memgraph` database. The session running the query is listed too: |
| TERMINATE SESSIONS 'SESSION_ID' [, 'SESSION_ID' ...]; | ||
| ``` | ||
|
|
||
| `SESSION_ID` is a `session_id` from `SHOW SESSIONS`, written as a string |
There was a problem hiding this comment.
| `SESSION_ID` is a `session_id` from `SHOW SESSIONS`, written as a string | |
| `SESSION_ID` is a `session_id` from `SHOW SESSIONS` output, written as a string |
| An idle session is closed immediately. For a session that is running a query, | ||
| Memgraph aborts its transaction and closes the connection as soon as that | ||
| query returns. Most queries stop right away, but one that doesn't check for | ||
| termination (for example, a long-running function call) runs until it | ||
| finishes, and its transaction is then not committed. If the session has an | ||
| open explicit transaction (it ran `BEGIN` but hasn't committed), that | ||
| transaction is rolled back: its uncommitted changes are discarded and any | ||
| writes it holds are released, so conflicting transactions can proceed. A | ||
| transaction that is already committing isn't interrupted; it completes. |
There was a problem hiding this comment.
This is very hard for me to grasp all the information it's trying to convey. I would need a bullet point list. This makes it easier to understand what IF IF ELSE structure is happening here
When I'm reading this block of text I'm unsure where one scenario ends and another one ends
The termination of the session depends on the session type:
- Idle session - closes immediately
- Session running a query - Memgraph will abort transactions and close the session (why connection?) as soon as the query returns. If the query doesn't check for termination (like, for example, a long-running function call), the transaction will not be committed once it finishes running.
- Session with an open explicit transaction - If SOMETHING SOMETHING happened (description of an explicit transaction) the transaction is rolled back and uncommitted changes are discarded. If the transaction is already committing, it isn't interrupted and it can complete committing.
There was a problem hiding this comment.
I also feel like this paragraph, and the two after it require some kind of subtitle or intro... so this is describing the termination behavior based on session type
below is Client behavior upon session termination
and i guess i would first explain how to terminate all kinds of sessions, mine or other ppls, then explain behaviour?
Description
Documents
SHOW SESSIONSandTERMINATE SESSIONSon the Transactions page and in the query privileges table. Also fixes two older statements on the same page:TERMINATE TRANSACTIONS $id(parameters were never accepted) and the newdatabasecolumn ofSHOW TRANSACTIONS(memgraph/memgraph#4571).Not done:
SHOW TRANSACTIONSexample outputs still show seven columns; I don't know whatdatabaseshows on snapshot and GC rows.SHOW ACTIVE USERSalso gained columns in #4571 (server-stats page).Product PR
memgraph/memgraph#4577
Checklist
featureorbugfixlabel added