Savonitar opened a new pull request, #29344: URL: https://github.com/apache/flink/pull/29344
## What is the purpose of the change Fix [FLINK-40855](https://issues.apache.org/jira/browse/FLINK-40855): `AbstractS3DelegationTokenProvider` creates an AWS SDK v1 STS client for each token acquisition without explicitly shutting it down. Release its resources on successful and exceptional exits for both Hadoop and Presto S3 providers. Explicit shutdown avoids relying on finalization, which has no guaranteed execution deadline, is deprecated for removal, and can be disabled starting with JDK 18 ([JEP 421](https://openjdk.org/jeps/421)). Related: [#27026](https://github.com/apache/flink/pull/27026) also addresses cleanup as part of the broader Hadoop/AWS SDK migration. This patch fixes the existing implementation independently. The migration should preserve equivalent lifecycle tests and primary-exception suppression, including for Presto. ## Brief change log - Shut down each STS client after token acquisition, covering request and postprocessing failures. - Preserve the primary exception when shutdown also fails; propagate shutdown-only failures. - Add a package-private client factory marked `@VisibleForTesting` and a deterministic test client. - Preserve the existing credentials, expiration, and configuration. ## Verifying this change - Five regression tests cover successful acquisition, request failure, postprocessing failure, simultaneous request/shutdown failure, and shutdown-only failure. - Red-green verification: all five new tests failed without cleanup and passed with the fix. - Fourteen focused token tests passed; the reactor build also compiled the Hadoop and Presto S3 modules. - Spotless, Checkstyle, and `git diff --check` passed. The focused tests, dependent-module compilation, and style checks passed after rebasing onto upstream master `2c425ba1a51`. Full repository `./mvnw clean verify` has not been run. ## Does this pull request potentially affect one of the following parts: - Dependencies: no. - Public API: no. - Serializers: no. - Runtime per-record code paths: no. - Deployment or recovery: yes, resource cleanup during delegation-token acquisition; checkpoint/savepoint behavior is unchanged. - S3 file system connector: yes, Hadoop and Presto delegation-token providers. ## Documentation - Does this pull request introduce a new feature? no. - If yes, how is the feature documented? not applicable. --- ##### Was generative AI tooling used to co-author this PR? - [X] Yes (please specify the tool below) Generated-by: Codex 0.159.0 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
