qiuyanjun888 opened a new pull request, #28441:
URL: https://github.com/apache/flink/pull/28441

   ## What is the purpose of the change
   
   This pull request fixes FLINK-39572 by avoiding logging sensitive values 
from Beam PROCESS environment payloads when PyFlink closes or expires Beam 
runner environments.
   
   Jira: https://issues.apache.org/jira/browse/FLINK-39572
   
   ## Brief change log
   
   - Added a logging helper for `DefaultJobBundleFactory` that redacts 
sensitive PROCESS environment values with Flink's existing 
`ConfigurationUtils.hideSensitiveValues`.
   - Applied the helper to the environment close/cleanup/expiration log 
messages that previously logged the raw Beam `Environment`.
   - Made malformed PROCESS payload logging fail closed by omitting the payload 
from the logged environment string.
   - Added focused regression coverage for normal PROCESS env redaction and 
malformed payload fallback.
   
   ## Verifying this change
   
   This change added tests and can be verified as follows:
   
   - Added 
`DefaultJobBundleFactoryTest#getEnvironmentForLoggingHidesSensitiveProcessEnvironmentVariables`.
   - Added 
`DefaultJobBundleFactoryTest#getEnvironmentForLoggingOmitsMalformedProcessPayload`.
   - Ran `./mvnw -pl flink-python -Dtest=DefaultJobBundleFactoryTest 
-DfailIfNoTests=false -Dsurefire.failIfNoSpecifiedTests=false -DskipITs test`.
   - Ran `./mvnw -pl flink-python -DskipTests -DskipITs -Dfast -Drat.skip=true 
spotless:check checkstyle:check`.
   - Ran `git diff --check`.
   
   ## Does this pull request potentially affect one of the following parts:
   
   - Dependencies (does it add or upgrade a dependency): no
   - The public API, i.e., is any changed class annotated with 
`@Public(Evolving)`: no
   - The serializers: no
   - The runtime per-record code paths (performance sensitive): no
   - Anything that affects deployment or recovery: JobManager (and its 
components), Checkpointing, Kubernetes/Yarn, ZooKeeper: no
   - The S3 file system connector: no
   
   ## Documentation
   
   - Does this pull request introduce a new feature? no
   - If yes, how is the feature documented? not applicable
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes (Hermes Agent / OpenAI GPT-5.5)
   
   Generated-by: Hermes Agent / OpenAI GPT-5.5
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to