potiuk commented on PR #72204: URL: https://github.com/apache/airflow/pull/72204#issuecomment-5752031966
Closing this in favour of #71711, which fixes the same quadratic-backtracking problem in `_mask_cmd`. Thanks for spotting the issue — the diagnosis was right, and the slowdown is real (I measured the current pattern at 0.03s / 0.19s / 0.70s for 2k / 5k / 10k-character tokens). I ran all three patterns — current `main`, this PR, and #71711 — over the same inputs: | input | `main` | this PR | #71711 | |---|---|---|---| | `--conf spark.hadoop.fs.s3a.secret.key=AKIAxyz` | masked | **leaks** | same as `main` | | `--secret-key=abc` | masked | **leaks** | same as `main` | | `--password='my secret pass' --foo bar` | `--password='******' --foo bar` | **partial leak** | same as `main` | | `password="my pass" next` | `password="******" next` | **partial leak** | same as `main` | | `--password=` | masked | unmasked | same as `main` | The root cause is in the review above: `\b\w*` cannot cross `.` or `-`, so dotted and hyphenated keys stop matching, and `(\S+)` drops the old "quoted values may contain whitespace" handling. #71711 preserves `main`'s output byte-for-byte on all of these while getting the same speedup, and it arrived first with tests and a round of review. If you would like to keep working in this area, the anchored one-liner from my review above is still a valid alternative approach, and #71711 has one open gap of its own (a second sensitive key inside the same whitespace-free token is not masked) that I have asked its author to close — a review there would be welcome. --- > *This message was drafted by an AI-assisted tool and > confirmed by an Apache Airflow maintainer. If you think > something here is mistaken, please reply on the PR and a > maintainer will weigh in.* > > *More on how Apache Airflow handles maintainer review:* > [contributing-docs/05_pull_requests.rst](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
