dwsmith1983 commented on code in PR #5872:
URL: https://github.com/apache/datafusion-comet/pull/5872#discussion_r4174430247
##########
native/core/src/parquet/objectstore/s3.rs:
##########
@@ -1000,11 +1174,80 @@ impl CredentialProviderMetadata {
}
}
+/// The STS region the Java SDK falls back to for a role profile when no
region is found.
+const STS_FALLBACK_REGION: &str = "us-east-1";
+
+/// Builds the profile credentials provider on `provider_config`, with
`default_region` standing
+/// in for the SDK's default region chain.
+async fn build_profile_provider(
+ provider_config: ProviderConfig,
+ default_region: &impl ProvideRegion,
+ name: Option<&str>,
+ file: Option<&str>,
+ credentials_only: bool,
+) -> ProfileFileCredentialsProvider {
+ // Hadoop's ProfileAWSCredentialsProvider loads the configured file, or
the shared
+ // credentials file, as a credentials-format file and reads nothing else,
so a same-name
+ // role profile in the SDK's config file never applies.
+ let credentials_file = match (file, credentials_only) {
+ (Some(file), _) => Some(file.to_string()),
+ (None, true) => Some(default_shared_credentials_file(
+ std::env::var("AWS_SHARED_CREDENTIALS_FILE").ok(),
+ std::env::var("HOME").ok(),
+ )),
+ (None, false) => None,
+ };
+ let profile_files = credentials_file.map(|file| {
+ EnvConfigFiles::builder()
+ .with_file(EnvConfigFileKind::Credentials, file)
+ .build()
+ });
+ let region = if credentials_only {
+ // The Java SDK sends a role profile's STS request to the profile's
own `region`, then
+ // to its default region chain's, then to us-east-1. The region
provider here also
+ // tries the profile's `source_profile` chain before the default
chain. A file that
+ // fails to load yields no region here and surfaces from the
credentials provider.
+ let mut region_provider =
ProfileFileRegionProvider::builder().configure(&provider_config);
+ if let Some(name) = name {
+ region_provider = region_provider.profile_name(name);
+ }
+ if let Some(files) = &profile_files {
+ region_provider = region_provider.profile_files(files.clone());
+ }
+ // The default chain can probe IMDS, so it runs only when the profile
has no region.
+ let region = match
ProvideRegion::region(®ion_provider.build()).await {
+ Some(region) => region,
+ None => default_region
+ .region()
+ .await
+ .unwrap_or_else(|| Region::from_static(STS_FALLBACK_REGION)),
Review Comment:
Superseded by aa73a0d6c: the profile provider now resolves through
`HadoopS3ACredentialProviderAdapter`, so the no-region fallback is the Java
SDK's own `sts.amazonaws.com`, signed for us-east-1, including for
`credential_source` chains. Details in
https://github.com/apache/datafusion-comet/pull/5872#discussion_r4173866124.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]