TimurRakhmatullin86 opened a new pull request, #73704:
URL: https://github.com/apache/airflow/pull/73704

   ## Summary
   
   Fix resource leaks and missing HTTP request timeouts across multiple 
providers and core modules.
   
   ### Socket leaks (3 fixes)
   
   **Problem:** `socket.socket()` objects were created without context managers 
(`with` statement), causing file descriptor leaks when connections failed or 
exceptions were raised.
   
   - **`standalone_command.py`** — `port_open()` created a socket, but if 
`connect()` raised an exception, the socket was never closed (only 
`sock.close()` was called on the success path inside the `try` block).
   - **`webhdfs.py`** — `_find_valid_server()` created a socket per namenode, 
but `host_socket.close()` was only called on successful connection. When 
`connect_ex()` returned non-zero or `HdfsError` was raised, the socket leaked.
   - **`hive.py`** — `_find_valid_host()` created a socket per host, but 
`host_socket.close()` was only called when `connect_ex()` returned 0. Failed 
connection attempts leaked the socket.
   
   **Fix:** Wrap all `socket.socket()` calls in `with` statements to ensure 
cleanup via `__exit__` regardless of the code path.
   
   ### Missing HTTP request timeouts (22 fixes)
   
   **Problem:** `requests.get/post/put/delete` calls without a `timeout` 
parameter can hang indefinitely if the remote service becomes unresponsive, 
blocking the Airflow worker thread/process.
   
   - **OpenFaaS hook** — 5 HTTP calls (deploy, invoke async, invoke sync, 
update, check existence) had no timeout.
   - **Google Dataprep hook** — 13 HTTP calls across all API methods had no 
timeout.
   - **Google base hook** — OAuth token validation call in `test_connection()` 
had no timeout.
   - **Google external token supplier** — OIDC token request via client 
credentials grant had no timeout.
   - **Google Cloud Functions hook** — Zip file upload via `requests.put()` had 
no timeout.
   - **Amazon S3 filesystem** — REST signer request in `s3v4_rest_signer()` had 
no timeout.
   
   **Fix:** Add explicit `timeout` parameter to all affected calls. Timeout 
values are chosen based on the expected operation:
   - 30 seconds for lightweight API calls (token validation, signing requests, 
OIDC token exchange)
   - 300 seconds for general API operations (OpenFaaS gateway, Dataprep API)
   - 600 seconds for large file uploads (Cloud Functions zip upload, up to 
100MB)
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to