Repository navigation
Remove the duplicate GCS signing cache from orch.py - #198
Conversation
|
Still need readability approvals from:
|
6dbbedc to
d824f9e
Compare
orch.py and util/gcs_wrapper.py contained two copies of the same GCS IAM signing-credential caching logic. PR #195 fixed only the gcs_wrapper.py copy, leaving the hot path in orch.py (upload URLs, single GETs, and batch signing) running the stale, un-locked copy with dead refresh-on-expiry logic. Delete the duplicate caching logic in orch.py and delegate to the single public get_signing_context() in util/gcs_wrapper.py. In addition, fix util/gcs_wrapper.py to detect non-service-account ADC credentials from local development and raise a clear, actionable RuntimeError explaining that URL signing requires a service account identity (pointing to impersonation or service account key instructions in DEVELOPING.md) rather than raising an unhelpful AttributeError. TAG=agy CONV=ec862d59-a9a7-4a7c-9eae-b59095e8cd08
d824f9e to
6ec31b0
Compare
|
Still need readability approvals from:
|
|
Still need readability approvals from:
|
|
Still need readability approvals from:
|
|
Still need readability approvals from:
|
PR #198 — P1 — signing identity captured before refreshReviewed head: Please read With the real pinned Reproduced independently against exact base/head implementations, using real Google credentials and mocked metadata transport—no live cloud call. Existing tests install the final email on the mock before refresh, so they miss this lifecycle. Smallest fix: refresh, then read/validate the email; keep the current cache/lock. Add a regression with a real credential instance whose email changes during refresh, checking that the signer and signing credential use the resolved identity. Then rerun GCS/front-door tests and CI. No auth/cache redesign needed. |
Review: merge after small fixesMulti-agent review (reviewer → independent critique agent re-verifying each claim against the code). One first-pass finding was overturned by the critique agent and is recorded below so it doesn't resurface. The orch.py side is exactly right. −41/+10, every call site converted, Worth fixing before merge
Overturned: there is no local-ADC regressionThe first-pass review flagged the new
'url': _signed_url(blob, 'GET', _SIGNED_GET_TTL)Pre-PR, Minor note for completeness: Explicitly not recommended
PR descriptionThe body says |
Consolidated ReviewVerdict: Fix one blocker, then merge. This reconciles the 19:29 and 19:50 comments against head Do before merge
Optional, does not block
Rejected or superseded, do not re-litigate
Evidence
Way forward
|
|
Still need readability approvals from:
|
Follow-up on Consolidated ReviewI addressed the required identity-refresh fix and the timezone-sensitive test fixtures from the Consolidated Review on head
Verification: all 10 GCS-wrapper tests passed under UTC, Los Angeles, and Kiritimati; the signing/signed-URL/ADC selection across GCS and frontdoor tests passed with 9 tests. The independent Compute Engine credential probe confirmed both signer consumers receive the refreshed email. No live deployment or IAM signing call was performed. Current-head GitHub CI is complete: Python 3.11/3.12/3.13, UI build/lint/tests, deploy checks and security scans passed. Conditional zizmor jobs were skipped. |
* Remove the duplicate GCS signing cache from orch.py orch.py and util/gcs_wrapper.py contained two copies of the same GCS IAM signing-credential caching logic. PR #195 fixed only the gcs_wrapper.py copy, leaving the hot path in orch.py (upload URLs, single GETs, and batch signing) running the stale, un-locked copy with dead refresh-on-expiry logic. Delete the duplicate caching logic in orch.py and delegate to the single public get_signing_context() in util/gcs_wrapper.py. In addition, fix util/gcs_wrapper.py to detect non-service-account ADC credentials from local development and raise a clear, actionable RuntimeError explaining that URL signing requires a service account identity (pointing to impersonation or service account key instructions in DEVELOPING.md) rather than raising an unhelpful AttributeError. TAG=agy CONV=ec862d59-a9a7-4a7c-9eae-b59095e8cd08 * Treat an absent storyboard key as no change SM-6: In orch.py, _write_project_doc and _write_editor_project_doc previously coerced an absent storyboard key in a PATCH payload to [], causing keep_ids to be empty and deleting every scene document in the scenes subcollection. Distinguish absent storyboard from an explicit empty list. When 'storyboard' is omitted from the PATCH payload, leave the scenes subcollection completely untouched. An explicit 'storyboard': [] continues to delete all scenes. Existing create semantics are preserved. Reachability: Not reachable from the shipped UI: there is exactly one project PATCH call site (ui/.../config.ts:1293) and it always sends a full cloned ProjectConfig where storyboard is required (config.ts:295) and initialised to [] (config.ts:604). Every .patch( in ui/src, scripts and tools was audited. It matters because a partial PATCH is the most natural third-party call to make against a documented endpoint. Stacked on #198. * Clarify omitted root fields in project PATCH contract * Use refreshed service account identity for signed URLs * Add return type annotation, docstring, and DEVELOPING.md signing note * Reject unresolved default service account email after refresh * Only write or prune scenes for an explicit storyboard list A PATCH carrying "storyboard": null (or any non-list value) was treated like [] and deleted every scene. Both the full and editor write paths now touch the scenes subcollection only when storyboard is a list, and the editor path always pins the root storyboard placeholder to [] so a non-list value can never be stored on the root document. Tests assert the stored root placeholder directly (GET rebuilds storyboard from the subcollection and would mask a regression) and cover null, string and object storyboard values on all three PATCH routes. Addresses review feedback from victor-paunescu on #203.
Summary
orch.pyandutil/gcs_wrapper.pypreviously contained two copies of the same GCS IAM signing-credential caching logic. PR #195 fixed only thegcs_wrapper.pycopy, leaving the hot path inorch.py(upload URLs, single GETs, and batch signing) running the stale copy without thread-safety locks and with dead refresh-on-expiry logic.This change:
_storage_client,_signing_credentials, and_get_signing_credentialsfromorch.py, delegating to the single cached signing context inutil/gcs_wrapper.py.gcs_wrapper.get_signing_context()and updates its callers; the old private accessor is removed.util/gcs_wrapper.pyso that non-service-account ADC credentials (fromgcloud auth application-default login) raise an immediate, actionableRuntimeErrorat the point of detection explaining that URL signing requires a service account identity, and providing the exact impersonation or service account key instructions needed for local setup._CACHED_SIGNING_CREDENTIALS is Nonecheck in the caching guard.defaultplaceholder.test/test_gcs_wrapper.py, and verifiesorchdelegation with no second cache intest/test_frontdoor_data.py.Deployment note
Deploy a new image after merging to activate the shared signing-context and refreshed-identity fixes. This PR update does not deploy them.
TAG=agy
CONV=ec862d59-a9a7-4a7c-9eae-b59095e8cd08