JingsongLi commented on PR #10141: URL: https://github.com/apache/paimon/pull/10141#issuecomment-5832214278
Re-reviewed the updated head after the negative-window feedback. The shared PyPaimon duration helper now rejects a typed negative `timedelta` before either `RESTTokenFileIO` or PVFS can use it; PVFS captures the validated value at construction. Java rejects a negative duration as well. The default 5-minute window solves the repeated re-vending caused by the former one-hour window for common one-hour STS tokens, while both REST paths retain the operation-specific minimum-validity check. This has direct production value. Local verification on `aaee1a1`: Java `RESTTokenFileIOTest` passed 16/16; `MockRESTCatalogTest#testRefreshFileIOWhenExpired` passed 1/1 against the REST catalog fixture; Python REST-token and PVFS tests passed 44/44; `git diff --check` passed. The previously reported typed-negative issue is resolved. I found no remaining code blocker in the changed paths. The current CI run is still red because the Python 3.10–3.13 and Native CI jobs fail in unchanged `interval_partition_test.py` cases with `SimpleNamespace` lacking `path_factory`; the Java matrix and Python 3.6/3.7 jobs passed. That unrelated gate needs a fixed base/re-run before merge. Operationally, an already-open stream keeps its original credentials; a stream opened just above the 5-minute threshold can outlive them. Please retain the discussed server-side token-lifetime guidance and watch stream authentication failures during rollout; per-request credential refresh is a separate follow-up. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
