LuciferYang opened a new pull request, #13440: URL: https://github.com/apache/gravitino/pull/13440
### What changes were proposed in this pull request? Replaced/removed secret URNs are now collected during alter preparation and deleted by the caller only after the alter commits, filtered against the final properties so an in-batch re-bind of the same key keeps its secret. Rollback now deletes only materials whose URN the original properties cannot reference, so a failed same-URN rotation or a remove-and-rebind batch leaves the persisted URN resolvable. The change spans `SecretManager`, `SecretAlterChanges`, `SecretMaterialsHolder`, and the three alter call sites in `CatalogManager`, `FilesetOperationDispatcher`, and `SchemaOperationDispatcher`. ### Why are the changes needed? Eager deletion during preparation, plus a rollback that only removed newly written materials, left the persisted entity pointing at a deleted secret URN whenever a later step failed, making the property permanently unreadable. Same-provider rotation had the mirror bug where rollback deleted the still-referenced URN. Fix: #13439 ### Does this PR introduce _any_ user-facing change? No. ### How was this patch tested? Added tests in `TestSecretManagerAlter`: deferred deletion on catalog/schema/fileset alter-remove (`testAlterRemovePropertyDefersWriteThroughSecretDeletion` and the schema/fileset variants), and the failure paths `testFailedPrepareKeepsReplacedSecretReadable`, `testFailedSameProviderRotationKeepsUrnResolvable`, and `testFailedRemoveAndRebindKeepsUrnResolvable`. They fail against the pre-fix code. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
