kaxil opened a new pull request, #73897:
URL: https://github.com/apache/airflow/pull/73897

   A connection password that shows up in a database error or a hook's return 
value reached the model, the model provider and any trace unmasked: the task 
log masks it, but tool results and the error text handed back to the model did 
not pass through the masker. The SQL, hook, DataFusion, MCP, sandbox and 
managed-agent toolsets now pass what they return, and any exception they raise, 
through Airflow's secret masker, and `AgentOperator` wraps every other toolset 
it runs, including toolsets the Dag author wrote.
   
   - **Structured results are masked before they are serialized.** JSON escapes 
quotes, backslashes and non-ASCII characters, so a password containing any of 
them no longer matches the registered value once it is inside a JSON string.
   - **An exception keeps its type but loses its cause chain.** Frameworks and 
tracing record a failed call's traceback, cause included, so the original is 
logged to the (masked) task log and the chain is dropped. A retry rule can 
still match the exception's type. `OSError` fields and whatever a custom 
`__str__` reads are masked too; if the message still holds a secret, a 
`RuntimeError` carrying the masked message takes its place.
   - **Blocking hook calls run in a worker thread, one at a time per process.** 
Agent frameworks run tool calls concurrently, and before Airflow 3.2 the 
channel to the supervisor that resolves connections and variables has no lock 
of its own.
   
   Only secrets Airflow has registered are masked, such as connection passwords 
and sensitive connection extras. Prompts and model output are not tool output 
and are not masked; the agent security page says so.
   
   
   ---
   
   * Read the **[Pull Request 
Guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#pull-request-guidelines)**
 for more information. Note: commit author/co-author name and email in commits 
become permanently public when merged.
   * For fundamental code changes, an Airflow Improvement Proposal 
([AIP](https://cwiki.apache.org/confluence/display/AIRFLOW/Airflow+Improvement+Proposals))
 is needed.
   * When adding dependency, check compliance with the [ASF 3rd Party License 
Policy](https://www.apache.org/legal/resolved.html#category-x).
   * For significant user-facing changes create newsfragment: 
`{pr_number}.significant.rst`, in 
[airflow-core/newsfragments](https://github.com/apache/airflow/tree/main/airflow-core/newsfragments).
 You can add this file in a follow-up commit after the PR is created so you 
know the PR number.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to