JingsongLi commented on PR #10178:
URL: https://github.com/apache/paimon/pull/10178#issuecomment-5831454120

   Reviewed 93f7fc7. The REST-token/open-stream problem has clear end-to-end 
value, and the per-request OSS signing path is plausible. I found one 
production blocker in the supplier lifecycle:
   
   **[P1] Keep the supplier alive for the lifetime of an open OSS stream.** 
`CachedFileIO.close()` unregisters its supplier when `FILE_IO_CACHE` evicts a 
delegate (10-hour access expiry or 1,000-entry size limit). The delegate 
returned by `FileIO.get(oss://...)` is `OSSLoader.OSSPluginFileIO`; 
`PluginFileIO` does not override `FileIO.close()`, whose default is a no-op. 
Thus eviction removes the supplier while the underlying OSS client and any open 
streams may still be live. `RegisteredCredentialsProvider` then silently falls 
back to its last credentials, and the next token expiry recreates the same 
mid-read failure this PR targets. The underlying uncached OSS filesystem is 
also not closed. Please make wrapper close reach the delegate and tie supplier 
removal to the actual lifetime of streams/requests, with a regression test that 
evicts the cache while a stream remains open and crosses a token refresh.
   
   Validation: `RegisteredCredentialsProviderTest` (4), `OSSLoaderTest` (1), 
and `RESTTokenFileIOTest` (11) passed locally; `git diff --check` passed. CI 
run 36106203387 failed only in JDK 8/11 Core jobs because the unrelated 
S3FileIOTest could not pull the pinned MinIO image; its other selected jobs 
passed. The first local REST test attempt hit macOS sandbox denial of Mockito 
agent attachment; rerunning it with attachment allowed passed all 11 tests.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to