LuciferYang opened a new issue, #13439:
URL: https://github.com/apache/gravitino/issues/13439

   ### Version
   
   main branch
   
   ### Describe what's wrong
   
   Write-through secret alter preparation deletes the old secret eagerly (a 
`setSecretReference` that replaces a binding, a `removeProperty`, or a 
cross-provider binding replacement), while rollback only deletes the newly 
written materials. If a later step in the same batch fails, or the store update 
fails, the persisted entity is left referencing a deleted secret URN, so every 
read of that property fails permanently.
   
   Same-provider secret rotation has the mirror bug: the deterministic URN is 
overwritten in place and listed for rollback, so a failed rotation deletes the 
still-referenced secret.
   
   ### How to reproduce
   
   - Batch alter `[RemoveProperty(P), SetProperty(Q, "******")]` (or a 
cross-provider binding replacement) that aborts after the remove: the persisted 
property still references the now-deleted secret and can no longer be read.
   - Or rotate a same-provider secret and have the alter abort: rollback 
deletes the deterministic URN the persisted entity still references.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to