Skip to content

[7.1.1 Cherry-pick] Fix access token expiry eviction in connection pool V2 - #4739

Merged
cheenamalhotra merged 1 commit into
release/7.1from
dev/automation/pr-4734-to-7.1.1
Sep 23, 2026
Merged

cheenamalhotra merged 1 commit into
release/7.1from
dev/automation/pr-4734-to-7.1.1

Conversation

@github-actions

Copy link
Copy Markdown

Cherry-pick of #4734 (7da9d39) into release/7.1.

Validate access token expiry before general checkout, preserving return and transaction-affinity behavior. Cover callback cache refresh and physical reuse across both pool implementations and sync/async opens.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions
github-actions Bot requested a review from a team as a code owner September 23, 2026 18:07
@github-actions github-actions Bot added this to the 7.1.1 milestone Sep 23, 2026
@github-project-automation github-project-automation Bot moved this to To triage in SqlClient Board Sep 23, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@cheenamalhotra cheenamalhotra moved this from To triage to In review in SqlClient Board Sep 23, 2026
@cheenamalhotra

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 2 pipeline(s).

@codecov

codecov Bot commented Sep 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 64.83%. Comparing base (3fded36) to head (653d431).
⚠️ Report is 3 commits behind head on release/7.1.

Additional details and impacted files
@@               Coverage Diff               @@
##           release/7.1    #4739      +/-   ##
===============================================
- Coverage        66.39%   64.83%   -1.56%     
===============================================
  Files              291      285       -6     
  Lines            45110    68089   +22979     
===============================================
+ Hits             29949    44148   +14199     
- Misses           15161    23941    +8780     
Flag Coverage Δ
CI-SqlClient ?
PR-SqlClient-Project 64.83% <100.00%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@mdaigle
mdaigle enabled auto-merge (squash) September 23, 2026 21:33
@cheenamalhotra
cheenamalhotra merged commit e311b90 into release/7.1 Sep 23, 2026
210 checks passed
@cheenamalhotra
cheenamalhotra deleted the dev/automation/pr-4734-to-7.1.1 branch September 23, 2026 23:04
@github-project-automation github-project-automation Bot moved this from In review to Done in SqlClient Board Sep 23, 2026
This was referenced Oct 2, 2026
carndog pushed a commit to carndog/TradingEngine that referenced this pull request Oct 3, 2026
Updated [Microsoft.Data.SqlClient](https://github.com/dotnet/sqlclient)
from 7.1.0 to 7.1.1.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Data.SqlClient's
releases](https://github.com/dotnet/sqlclient/releases)._

## 7.1.1

This servicing release fixes decimal parameter validation, token expiry
handling in connection pool V2, and connection opens that are in
progress when a pool is cleared.

> **Package version alignment:** The SqlClient family packages share the
`7.1.1` version:
>
> - `Microsoft.Data.SqlClient`
> - `Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider`
> - `Microsoft.Data.SqlClient.Extensions.Azure`
> - `Microsoft.Data.SqlClient.Extensions.Abstractions`
> - `Microsoft.Data.SqlClient.Internal.Logging`
>
> `Microsoft.SqlServer.Server` is versioned independently and is not
part of this release. Applications should use matching `7.1.1` versions
of the driver and its companion packages. The aligned assemblies retain
`AssemblyVersion 7.0.0.0`; upgrading from `7.1.0` does not require new
.NET Framework strong-name binding redirects.

### Companion package release notes

- [Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider
7.1.1](https://github.com/dotnet/SqlClient/blob/main/release-notes/add-ons/AzureKeyVaultProvider/7.1/7.1.1.md)
- [Microsoft.Data.SqlClient.Extensions.Azure
7.1.1](https://github.com/dotnet/SqlClient/blob/main/release-notes/Extensions/Azure/7.1/7.1.1.md)
- [Microsoft.Data.SqlClient.Extensions.Abstractions
7.1.1](https://github.com/dotnet/SqlClient/blob/main/release-notes/Extensions/Abstractions/7.1/7.1.1.md)
- [Microsoft.Data.SqlClient.Internal.Logging
7.1.1](https://github.com/dotnet/SqlClient/blob/main/release-notes/Internal/Logging/7.1/7.1.1.md)

## Changes Since
[7.1.0](https://github.com/dotnet/SqlClient/blob/main/release-notes/7.1/7.1.0.md)

### Fixed

- Fixed an `ArgumentException` when sending zero-valued `decimal` or
`SqlDecimal` parameters whose precision equals their scale. Nonzero
precision validation and support for large decimal values are unchanged.
([#​4715](dotnet/SqlClient#4715),
[#​4721](dotnet/SqlClient#4721),
[#​4732](dotnet/SqlClient#4732))

- Fixed connection pool V2 handing out pooled connections with expired
or nearly expired access tokens. The pool now checks token expiry before
reuse, matching the default pool's behavior while preserving
transaction-affine reuse. This affects only applications that opt in to
connection pool V2.
([#​4734](dotnet/SqlClient#4734),
[#​4739](dotnet/SqlClient#4739))

- Fixed connection opens failing when `ClearPool` or `ClearAllPools`
races with an in-flight open. Requests already admitted to the cleared
pool can finish, and connections returned to the retired pool are
discarded rather than reused.
([#​4714](dotnet/SqlClient#4714),
[#​4718](dotnet/SqlClient#4718),
[#​4740](dotnet/SqlClient#4740))

## Target Platform Support

- .NET Framework 4.6.2+ (Windows x86, Windows x64, Windows ARM64)
- .NET 8.0+ (Windows x86, Windows x64, Windows ARM, Windows ARM64,
Linux, macOS)

### Dependencies

#### .NET 9.0

- Microsoft.Bcl.Cryptography 9.0.18
- Microsoft.Data.SqlClient.Extensions.Abstractions 7.1.1
- Microsoft.Data.SqlClient.Internal.Logging 7.1.1
- Microsoft.Data.SqlClient.SNI.runtime 7.1.0
- Microsoft.Extensions.Caching.Memory 9.0.18
- Microsoft.IdentityModel.JsonWebTokens 8.16.0
- Microsoft.IdentityModel.Protocols.OpenIdConnect 8.16.0
- Microsoft.SqlServer.Server 1.0.0
- System.Configuration.ConfigurationManager 9.0.18
- System.Security.Cryptography.Pkcs 9.0.18
- System.Threading.RateLimiting 9.0.18

 ... (truncated)

Commits viewable in [compare
view](dotnet/SqlClient@v7.1.0...v7.1.1).
</details>

Updated
[Microsoft.Data.SqlClient.Extensions.Azure](https://github.com/dotnet/SqlClient)
from 7.1.0 to 7.1.1.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Data.SqlClient.Extensions.Azure's
releases](https://github.com/dotnet/SqlClient/releases)._

## 7.1.1

This servicing release fixes decimal parameter validation, token expiry
handling in connection pool V2, and connection opens that are in
progress when a pool is cleared.

> **Package version alignment:** The SqlClient family packages share the
`7.1.1` version:
>
> - `Microsoft.Data.SqlClient`
> - `Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider`
> - `Microsoft.Data.SqlClient.Extensions.Azure`
> - `Microsoft.Data.SqlClient.Extensions.Abstractions`
> - `Microsoft.Data.SqlClient.Internal.Logging`
>
> `Microsoft.SqlServer.Server` is versioned independently and is not
part of this release. Applications should use matching `7.1.1` versions
of the driver and its companion packages. The aligned assemblies retain
`AssemblyVersion 7.0.0.0`; upgrading from `7.1.0` does not require new
.NET Framework strong-name binding redirects.

### Companion package release notes

- [Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider
7.1.1](https://github.com/dotnet/SqlClient/blob/main/release-notes/add-ons/AzureKeyVaultProvider/7.1/7.1.1.md)
- [Microsoft.Data.SqlClient.Extensions.Azure
7.1.1](https://github.com/dotnet/SqlClient/blob/main/release-notes/Extensions/Azure/7.1/7.1.1.md)
- [Microsoft.Data.SqlClient.Extensions.Abstractions
7.1.1](https://github.com/dotnet/SqlClient/blob/main/release-notes/Extensions/Abstractions/7.1/7.1.1.md)
- [Microsoft.Data.SqlClient.Internal.Logging
7.1.1](https://github.com/dotnet/SqlClient/blob/main/release-notes/Internal/Logging/7.1/7.1.1.md)

## Changes Since
[7.1.0](https://github.com/dotnet/SqlClient/blob/main/release-notes/7.1/7.1.0.md)

### Fixed

- Fixed an `ArgumentException` when sending zero-valued `decimal` or
`SqlDecimal` parameters whose precision equals their scale. Nonzero
precision validation and support for large decimal values are unchanged.
([#​4715](dotnet/SqlClient#4715),
[#​4721](dotnet/SqlClient#4721),
[#​4732](dotnet/SqlClient#4732))

- Fixed connection pool V2 handing out pooled connections with expired
or nearly expired access tokens. The pool now checks token expiry before
reuse, matching the default pool's behavior while preserving
transaction-affine reuse. This affects only applications that opt in to
connection pool V2.
([#​4734](dotnet/SqlClient#4734),
[#​4739](dotnet/SqlClient#4739))

- Fixed connection opens failing when `ClearPool` or `ClearAllPools`
races with an in-flight open. Requests already admitted to the cleared
pool can finish, and connections returned to the retired pool are
discarded rather than reused.
([#​4714](dotnet/SqlClient#4714),
[#​4718](dotnet/SqlClient#4718),
[#​4740](dotnet/SqlClient#4740))

## Target Platform Support

- .NET Framework 4.6.2+ (Windows x86, Windows x64, Windows ARM64)
- .NET 8.0+ (Windows x86, Windows x64, Windows ARM, Windows ARM64,
Linux, macOS)

### Dependencies

#### .NET 9.0

- Microsoft.Bcl.Cryptography 9.0.18
- Microsoft.Data.SqlClient.Extensions.Abstractions 7.1.1
- Microsoft.Data.SqlClient.Internal.Logging 7.1.1
- Microsoft.Data.SqlClient.SNI.runtime 7.1.0
- Microsoft.Extensions.Caching.Memory 9.0.18
- Microsoft.IdentityModel.JsonWebTokens 8.16.0
- Microsoft.IdentityModel.Protocols.OpenIdConnect 8.16.0
- Microsoft.SqlServer.Server 1.0.0
- System.Configuration.ConfigurationManager 9.0.18
- System.Security.Cryptography.Pkcs 9.0.18
- System.Threading.RateLimiting 9.0.18

 ... (truncated)

Commits viewable in [compare
view](dotnet/SqlClient@v7.1.0...v7.1.1).
</details>

Updated [NodaTime](https://github.com/nodatime/nodatime) from 3.3.4 to
3.3.5.

<details>
<summary>Release notes</summary>

_Sourced from [NodaTime's
releases](https://github.com/nodatime/nodatime/releases)._

No release notes found for this version range.

Commits viewable in [compare
view](https://github.com/nodatime/nodatime/commits).
</details>

Updated [NodaTime.Testing](https://github.com/nodatime/nodatime) from
3.3.4 to 3.3.5.

<details>
<summary>Release notes</summary>

_Sourced from [NodaTime.Testing's
releases](https://github.com/nodatime/nodatime/releases)._

No release notes found for this version range.

Commits viewable in [compare
view](https://github.com/nodatime/nodatime/commits).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants