kaxil opened a new pull request, #73897: URL: https://github.com/apache/airflow/pull/73897
A connection password that shows up in a database error or a hook's return value reached the model, the model provider and any trace unmasked: the task log masks it, but tool results and the error text handed back to the model did not pass through the masker. The SQL, hook, DataFusion, MCP, sandbox and managed-agent toolsets now pass what they return, and any exception they raise, through Airflow's secret masker, and `AgentOperator` wraps every other toolset it runs, including toolsets the Dag author wrote. - **Structured results are masked before they are serialized.** JSON escapes quotes, backslashes and non-ASCII characters, so a password containing any of them no longer matches the registered value once it is inside a JSON string. - **An exception keeps its type but loses its cause chain.** Frameworks and tracing record a failed call's traceback, cause included, so the original is logged to the (masked) task log and the chain is dropped. A retry rule can still match the exception's type. `OSError` fields and whatever a custom `__str__` reads are masked too; if the message still holds a secret, a `RuntimeError` carrying the masked message takes its place. - **Blocking hook calls run in a worker thread, one at a time per process.** Agent frameworks run tool calls concurrently, and before Airflow 3.2 the channel to the supervisor that resolves connections and variables has no lock of its own. Only secrets Airflow has registered are masked, such as connection passwords and sensitive connection extras. Prompts and model output are not tool output and are not masked; the agent security page says so. --- * Read the **[Pull Request Guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#pull-request-guidelines)** for more information. Note: commit author/co-author name and email in commits become permanently public when merged. * For fundamental code changes, an Airflow Improvement Proposal ([AIP](https://cwiki.apache.org/confluence/display/AIRFLOW/Airflow+Improvement+Proposals)) is needed. * When adding dependency, check compliance with the [ASF 3rd Party License Policy](https://www.apache.org/legal/resolved.html#category-x). * For significant user-facing changes create newsfragment: `{pr_number}.significant.rst`, in [airflow-core/newsfragments](https://github.com/apache/airflow/tree/main/airflow-core/newsfragments). You can add this file in a follow-up commit after the PR is created so you know the PR number. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
