This is an automated email from the ASF dual-hosted git repository.

potiuk pushed a commit to branch v3-3-test
in repository https://gitbox.apache.org/repos/asf/airflow.git


The following commit(s) were added to refs/heads/v3-3-test by this push:
     new f719f884bc6 [v3-3-test] Stop shipping broken agent-skill symlinks in 
the source release (#73107) (#73130)
f719f884bc6 is described below

commit f719f884bc601cfb7c62790ba16f5cfe95ce4638
Author: github-actions[bot] 
<41898282+github-actions[bot]@users.noreply.github.com>
AuthorDate: Mon Sep 28 17:39:15 2026 +0200

    [v3-3-test] Stop shipping broken agent-skill symlinks in the source release 
(#73107) (#73130)
    
    * [v3-3-test] Clarify that AccessView.JOBS is the Edge worker management 
permission (#72627) (#73073)
    
    The Edge UI plugin docs say that "can read on Plugins" and "can read on
    Jobs" let you view the UI and manage the workers, but they do not say how
    the two permissions differ, and they do not mention what the default
    Viewer role already holds.
    
    Both gaps matter, because the endpoints and the navigation are gated
    differently:
    
    - The worker management endpoints under /edge_worker/ui/ check only
      AccessView.JOBS, and the check is not method-aware -- the same
      dependency guards the GET reads and the POST/PATCH/DELETE mutations.
    - "can read on Plugins" only controls whether the plugin shows up in the
      UI navigation. It is not required in order to call the endpoints.
    
    So "can read on Jobs" alone is enough to shut down, delete, re-queue and
    retune Edge workers, whether or not the plugin is visible to that user.
    
    That is intentional -- AccessView.JOBS is the management permission for
    the plugin rather than a read-only grant -- but it reads as surprising
    from the code alone, where a permission named "can read" guards mutating
    routes. It is more surprising in a default Flask AppBuilder setup, where
    the Viewer role includes (ACTION_CAN_READ, RESOURCE_JOB) but not the
    Plugins read: such a user cannot see the Edge plugin and can still reach
    its management endpoints.
    
    Adds a warning to the UI plugin docs stating the intent, the split
    between the two permissions, the consequence for the default Viewer role,
    and the concrete action for deployments where Viewers must not manage
    workers. Points at the existing "fine granular access control" entry in
    architecture.rst rather than restating it.
    
    Documentation only; no behaviour change.
    (cherry picked from commit 1391b0934240aa70c90d7cad186d71a235bdfdd2)
    
    * [v3-3-test] Keep the Gradle wrapper jar out of the source release 
(#69444) (#73108)
    
    ASF policy does not permit compiled binaries in a source release and the
    Gradle wrapper is not among the exempted build tools (LEGAL-570), so main
    stopped shipping java-sdk/gradle/wrapper/gradle-wrapper.jar in #69444.
    
    Only half of that change reached this branch. The breeze side already
    restores gradlew and gradlew.bat after `git archive` drops them, but the
    java-sdk/.gitattributes side never followed, so nothing is actually dropped
    and the 43 KB jar is still in the 3.3.2rc1 source tarball.
    
    Carrying the rest of the file over also starts shipping 
java-sdk/.editorconfig,
    which the root .gitattributes strips today even though ktlint reads it at
    build time and the build task requires that lint to pass.
    
    gradle-wrapper.properties stays in the tarball on purpose: it carries the
    pinned Gradle version and distribution checksum a verifier needs to
    regenerate the wrapper.
    
    Generated-by: Claude Opus 5
    Claude-Session: https://claude.ai/code/session_01DCUVuZ8CCeER1QLhVEKAaZ
    
    * [v3-3-test] Stop shipping broken agent-skill symlinks in the source 
release (#73107)
    
    Excluding .agents from the source tarball (#68851) left .claude behind.
    Everything under .claude/skills is a relay symlink into .agents/skills, so
    export-ignore strips the targets while the links themselves still ship:
    unpacking the source release yields broken symlinks, and .claude/ arrives
    holding nothing but those dead links.
    
    Found while verifying 3.3.2rc1, whose tarball carries five of them. The
    released 3.3.1 carries the same ones, so this is long-standing rather than
    something a recent change introduced.
    
    .github needs no equivalent entry: its own skills relays are already
    covered by the existing .github export-ignore.
    (cherry picked from commit 4b0eb8e02060a73a3358ac2778b552a71252c38a)
    
    Co-authored-by: Jarek Potiuk <[email protected]>
    
    ---------
    
    Co-authored-by: Jarek Potiuk <[email protected]>

Reply via email to