Per-catalog auth state is shared: commit_table mutates the session, and cached S3FileSystem instances share a signer
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 52/100
- Type d'issue
- Bug
- Clarté
- Plutôt claire
- Activité
- Active
- Stack technique
- aws, python
- Domaine
- authentication, backend, cloud
Piste de recherche
Start by tracing RestCatalog.commit_table and FileIO.get_fs, including the fsspec S3FileSystem instance cache and botocore event registration shown in the issue. Verify isolation with requests from multiple tables and catalogs: table tokens must not persist on the shared session, and each catalog must retain its own signer even when filesystem constructor arguments match.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Two places where authentication state configured for one catalog or table persists onto another.
1. commit_table mutates the shared session's headers
headers = self._session.headers # the live session mapping, not a copy
if table_token := table.config.get(TOKEN):
headers[AUTHORIZATION_HEADER] = f"{BEARER_PREFIX} {table_token}"
self._session.headers is the session's own mapping, so assigning into it persists the table-scoped token on the session. Every subsequent request from that RestCatalog carries it, including requests for other tables.
2. fsspec-cached S3FileSystem instances share one signer registration
fs = S3FileSystem(**s3_fs_kwargs)
for event_name, event_function in register_events.items():
fs.s3.meta.events.unregister(event_name, unique_id=1925)
fs.s3.meta.events.register_last(event_name, event_function, unique_id=1925)
The signer is registered as a botocore event handler after construction, under a fixed unique_id. It is not part of s3_fs_kwargs, and fsspec caches filesystem instances by constructor arguments (skip_instance_cache is not set). Two catalogs whose anon / client_kwargs / config_kwargs match therefore receive the same S3FileSystem object, and the second unregister + register_last replaces the first catalog's signer with its own.
Note the per-thread lru_cache in get_fs is not involved — _thread_locals is an instance attribute, so that cache is already per-FileIO. The sharing comes from fsspec's instance cache.
Issue investigation generated via claude, reviewed by Sung, Kevin, Fokko.
- Langage dominant
- Python
- Étoiles
- 1.1k
- Forks
- 589
- Merge moyen
- 1 j 20 h
- PR mergées (30 j)
- 68
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de apache/iceberg-python
-
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
apache/iceberg-python#4010 · 1 réaction ·
-
kind:bug
Difficulté 1/5 Moins d'une heure Accessibilité débutants 92/100
apache/iceberg-python#4006 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
apache/iceberg-python#3996 ·
-
Deletion vector bitmap count is read from the blob and used as a loop bound without validation Ouvertebug
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
apache/iceberg-python#3979 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
apache/iceberg-python#3885 ·
Toutes les issues de apache/iceberg-python
Issues similaires
-
[Bug] reef-hermes tells me to resume with hermes --resume, which does not work from my shell Ouvertearea: harness bug status: needs-triage
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
Human-Agent-Society/reef#625 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
-
Difficulté 1/5 Moins d'une heure Accessibilité débutants 80/100
learningequality/kolibri#15351 · 2 commentaires ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
-
Name consistency Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
eellak/triplestore#65 · 1 commentaire ·