JingsongLi commented on PR #10141:
URL: https://github.com/apache/paimon/pull/10141#issuecomment-5832214278

   Re-reviewed the updated head after the negative-window feedback. The shared 
PyPaimon duration helper now rejects a typed negative `timedelta` before either 
`RESTTokenFileIO` or PVFS can use it; PVFS captures the validated value at 
construction. Java rejects a negative duration as well. The default 5-minute 
window solves the repeated re-vending caused by the former one-hour window for 
common one-hour STS tokens, while both REST paths retain the operation-specific 
minimum-validity check. This has direct production value.
   
   Local verification on `aaee1a1`: Java `RESTTokenFileIOTest` passed 16/16; 
`MockRESTCatalogTest#testRefreshFileIOWhenExpired` passed 1/1 against the REST 
catalog fixture; Python REST-token and PVFS tests passed 44/44; `git diff 
--check` passed. The previously reported typed-negative issue is resolved. I 
found no remaining code blocker in the changed paths.
   
   The current CI run is still red because the Python 3.10–3.13 and Native CI 
jobs fail in unchanged `interval_partition_test.py` cases with 
`SimpleNamespace` lacking `path_factory`; the Java matrix and Python 3.6/3.7 
jobs passed. That unrelated gate needs a fixed base/re-run before merge. 
Operationally, an already-open stream keeps its original credentials; a stream 
opened just above the 5-minute threshold can outlive them. Please retain the 
discussed server-side token-lifetime guidance and watch stream authentication 
failures during rollout; per-request credential refresh is a separate follow-up.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to