potiuk commented on PR #72204:
URL: https://github.com/apache/airflow/pull/72204#issuecomment-5752031966

   Closing this in favour of #71711, which fixes the same 
quadratic-backtracking problem in `_mask_cmd`. Thanks for spotting the issue — 
the diagnosis was right, and the slowdown is real (I measured the current 
pattern at 0.03s / 0.19s / 0.70s for 2k / 5k / 10k-character tokens).
   
   I ran all three patterns — current `main`, this PR, and #71711 — over the 
same inputs:
   
   | input | `main` | this PR | #71711 |
   |---|---|---|---|
   | `--conf spark.hadoop.fs.s3a.secret.key=AKIAxyz` | masked | **leaks** | 
same as `main` |
   | `--secret-key=abc` | masked | **leaks** | same as `main` |
   | `--password='my secret pass' --foo bar` | `--password='******' --foo bar` 
| **partial leak** | same as `main` |
   | `password="my pass" next` | `password="******" next` | **partial leak** | 
same as `main` |
   | `--password=` | masked | unmasked | same as `main` |
   
   The root cause is in the review above: `\b\w*` cannot cross `.` or `-`, so 
dotted and hyphenated keys stop matching, and `(\S+)` drops the old "quoted 
values may contain whitespace" handling. #71711 preserves `main`'s output 
byte-for-byte on all of these while getting the same speedup, and it arrived 
first with tests and a round of review.
   
   If you would like to keep working in this area, the anchored one-liner from 
my review above is still a valid alternative approach, and #71711 has one open 
gap of its own (a second sensitive key inside the same whitespace-free token is 
not masked) that I have asked its author to close — a review there would be 
welcome.
   
   ---
   
   > *This message was drafted by an AI-assisted tool and
   > confirmed by an Apache Airflow maintainer. If you think
   > something here is mistaken, please reply on the PR and a
   > maintainer will weigh in.*
   >
   > *More on how Apache Airflow handles maintainer review:*
   > 
[contributing-docs/05_pull_requests.rst](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to