LuciferYang opened a new pull request, #13440:
URL: https://github.com/apache/gravitino/pull/13440

   ### What changes were proposed in this pull request?
   
   Replaced/removed secret URNs are now collected during alter preparation and 
deleted by the caller only after the alter commits, filtered against the final 
properties so an in-batch re-bind of the same key keeps its secret. Rollback 
now deletes only materials whose URN the original properties cannot reference, 
so a failed same-URN rotation or a remove-and-rebind batch leaves the persisted 
URN resolvable. The change spans `SecretManager`, `SecretAlterChanges`, 
`SecretMaterialsHolder`, and the three alter call sites in `CatalogManager`, 
`FilesetOperationDispatcher`, and `SchemaOperationDispatcher`.
   
   ### Why are the changes needed?
   
   Eager deletion during preparation, plus a rollback that only removed newly 
written materials, left the persisted entity pointing at a deleted secret URN 
whenever a later step failed, making the property permanently unreadable. 
Same-provider rotation had the mirror bug where rollback deleted the 
still-referenced URN.
   
   Fix: #13439
   
   ### Does this PR introduce _any_ user-facing change?
   
   No.
   
   ### How was this patch tested?
   
   Added tests in `TestSecretManagerAlter`: deferred deletion on 
catalog/schema/fileset alter-remove 
(`testAlterRemovePropertyDefersWriteThroughSecretDeletion` and the 
schema/fileset variants), and the failure paths 
`testFailedPrepareKeepsReplacedSecretReadable`, 
`testFailedSameProviderRotationKeepsUrnResolvable`, and 
`testFailedRemoveAndRebindKeepsUrnResolvable`. They fail against the pre-fix 
code.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to