dwsmith1983 commented on code in PR #5872:
URL: https://github.com/apache/datafusion-comet/pull/5872#discussion_r4173867431


##########
native/core/src/parquet/objectstore/s3.rs:
##########
@@ -1000,11 +1174,80 @@ impl CredentialProviderMetadata {
     }
 }
 
+/// The STS region the Java SDK falls back to for a role profile when no 
region is found.
+const STS_FALLBACK_REGION: &str = "us-east-1";
+
+/// Builds the profile credentials provider on `provider_config`, with 
`default_region` standing
+/// in for the SDK's default region chain.
+async fn build_profile_provider(
+    provider_config: ProviderConfig,
+    default_region: &impl ProvideRegion,
+    name: Option<&str>,
+    file: Option<&str>,
+    credentials_only: bool,
+) -> ProfileFileCredentialsProvider {
+    // Hadoop's ProfileAWSCredentialsProvider loads the configured file, or 
the shared
+    // credentials file, as a credentials-format file and reads nothing else, 
so a same-name
+    // role profile in the SDK's config file never applies.
+    let credentials_file = match (file, credentials_only) {
+        (Some(file), _) => Some(file.to_string()),
+        (None, true) => Some(default_shared_credentials_file(
+            std::env::var("AWS_SHARED_CREDENTIALS_FILE").ok(),
+            std::env::var("HOME").ok(),
+        )),
+        (None, false) => None,
+    };
+    let profile_files = credentials_file.map(|file| {
+        EnvConfigFiles::builder()
+            .with_file(EnvConfigFileKind::Credentials, file)
+            .build()
+    });
+    let region = if credentials_only {
+        // The Java SDK sends a role profile's STS request to the profile's 
own `region`, then
+        // to its default region chain's, then to us-east-1. The region 
provider here also
+        // tries the profile's `source_profile` chain before the default 
chain. A file that
+        // fails to load yields no region here and surfaces from the 
credentials provider.
+        let mut region_provider = 
ProfileFileRegionProvider::builder().configure(&provider_config);
+        if let Some(name) = name {
+            region_provider = region_provider.profile_name(name);
+        }
+        if let Some(files) = &profile_files {
+            region_provider = region_provider.profile_files(files.clone());
+        }
+        // The default chain can probe IMDS, so it runs only when the profile 
has no region.
+        let region = match 
ProvideRegion::region(&region_provider.build()).await {

Review Comment:
   Fixed in 84f85450b. Under Hadoop's provider the role chain is now resolved 
one role at a time, as `StsProfileCredentialsProviderFactory` does: each role's 
STS request goes to that role's own `region`, else the default region chain, 
else the global endpoint. The source profile's region is no longer inherited, 
and an intermediate role keeps its own region. The roles are assumed in a loop, 
so a long chain does not grow the stack.
   
   `test_hadoop_profile_provider_sends_sts_to_the_profile_region` now has your 
conflicting-source case (`sts.eu-central-1`, default chain asked once), and 
`test_hadoop_profile_provider_resolves_each_role_region` covers two-role chains 
with and without an intermediate region. Each recorded request is checked for 
host, signing region and signing key.
   
   Chains the walk does not mirror keep the SDK provider and its single region: 
a role that uses `credential_source` or names itself as `source_profile`, or a 
source profile that mixes static keys with other credential settings. The data 
sources page lists them.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to