risingwavelabs/risingwave · critical

internal error: entered unreachable code

Error message

internal error: entered unreachable code

What it means

When enforce_secret is enabled in system parameters, the create connection payload is expected to always be ConnectionParams; any other payload variant is an invariant violation and hits unreachable!(), surfacing as 'internal error: entered unreachable code'.

Solutions

  1. Disable enforce_secret temporarily (ALTER SYSTEM SET enforce_secret = false) and retry to confirm payload mismatch
  2. Upgrade the client/CLI/SDK to match the server's protobuf definitions
  3. Send the request via the standard psql CREATE CONNECTION flow instead of a hand-built RPC
Defensive patterns

Strategy: try-catch

Validate before calling

-- Check secret enforcement setting first
SHOW PARAMETERS enforce_secret;

Try / catch

try {
  await conn.query("CREATE CONNECTION c WITH (...)");
} catch (e) {
  if (String(e.message).includes('unreachable')) {
    // check client/server version skew and payload type
  }
}

Prevention

When it happens

Trigger: CREATE CONNECTION issued while enforce_secret=true, but the RPC payload is not ConnectionParams — i.e. a client/CLI built against a different proto payload variant or a proxy rewriting the request.

Common situations: Version-skewed clients (older risectl/SDK) sending legacy payloads after the server enabled secret enforcement; custom tools constructing CreateConnectionRequest manually.

Understand the failure class

Background: "This is a bug, please report it": internal invariant violations, unreachable panics, and SNH errors explained — this error's family across 47 libraries.

Related errors


AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11). Data as JSON: /api/errors/832850bb606630e3. Report an issue: GitHub.

Appendix: source

Thrown at src/frontend/src/handler/create_connection.rs:133

        };
    }
    let (database_id, schema_id) = session.get_database_and_schema_id_for_create(schema_name)?;
    let mut with_properties = handler_args.with_options.clone().into_connector_props();
    resolve_privatelink_in_with_option(&mut with_properties)?;
    let create_connection_payload = resolve_create_connection_payload(with_properties, &session)?;

    let catalog_writer = session.catalog_writer()?;

    if session
        .env()
        .system_params_manager()
        .get_params()
        .load()
        .enforce_secret()
    {
        use risingwave_pb::ddl_service::create_connection_request::Payload::ConnectionParams;
        let ConnectionParams(cp) = &create_connection_payload else {
            unreachable!()
        };
        enforce_secret_connection(
            &cp.connection_type(),
            cp.properties.keys().map(|s| s.as_str()),
        )?;
    }

    catalog_writer
        .create_connection(
            connection_name,
            database_id,
            schema_id,
            session.user_id(),
            create_connection_payload,
        )
        .await?;

    Ok(PgResponse::empty_result(StatementType::CREATE_CONNECTION))

View on GitHub (pinned to 6469eb736d)