Skip to content

Validate GCP storage transfer job body after template rendering - #70529

Merged
shahar1 merged 2 commits into
apache:mainfrom
mitre88:fix-storage-transfer-create-job
Sep 23, 2026
Merged

shahar1 merged 2 commits into
apache:mainfrom
mitre88:fix-storage-transfer-create-job

Conversation

@mitre88

@mitre88 mitre88 commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Part of the template-field validation burn-down tracked in #70296.

CloudDataTransferServiceCreateJobOperator lists body in template_fields but deep-copies and validates it in __init__. With a fully templated body (a Jinja expression or XComArg), the validator ran against the un-rendered expression, so TransferJobValidator's checks — the AWS-credential restriction and the single-data-source rule — were silently bypassed. The deep copy and validation now run at the start of execute(), against the rendered value, right before TransferJobPreprocessor mutates the body.

Added a test constructing the operator with a templated body that renders to a body embedding AWS credentials — with the previous implementation the credential check never fires and the job is created; now it raises before calling the hook. The class is removed from the exemption list and the validate-operators-init check passes locally.

Per the discussion in #70505 this is a genuine value read (validation of the rendered dict), not an argument-provision check.


Was generative AI tooling used to co-author this PR?
  • Yes — Claude Code (Fable 5)

Generated-by: Claude Code (Fable 5) following the guidelines

@potiuk potiuk left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks — correct move. body is in template_fields, so _validate_inputs() in __init__ was running TransferJobValidator against the un-rendered value; a templated body could never pass validation and a bad one broke Dag parsing instead of failing the task. Deferring both the deepcopy and the validation to execute fixes that, and removing the exemptions entry closes it out.

Good that the test asserts create_transfer_job.assert_not_called() — that shows it bails before touching the API.

One coverage gap inline.


Drafted-by: Claude Code (Opus 5); reviewed by @potiuk before posting

@github-actions

Copy link
Copy Markdown
Contributor

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed in 5 days if no further activity occurs. Thank you for your contributions.

@github-actions github-actions Bot added the stale Stale PRs per the .github/workflows/stale.yml policy file label Sep 21, 2026
@shahar1 shahar1 removed the stale Stale PRs per the .github/workflows/stale.yml policy file label Sep 21, 2026
The operator's body is a template field, but it was deep-copied and
validated in __init__, so a fully templated body skipped validation
entirely — the checks ran against the Jinja expression instead of the
rendered dict, silently bypassing the AWS-credential restriction. Part
of the burn-down tracked in apache#70296.
Copying the body into a local keeps the AWS access key and secret that
TransferJobPreprocessor injects off the live task object, and leaves the
operator's own body pristine so a retry validates the value the user
passed rather than the credential-laden one from the previous attempt.

The regression test now drives real Jinja rendering through a Dag with
render_template_as_native_obj, so it proves validation sees the rendered
mapping instead of standing in for rendering with a direct assignment.
The Dag-level flag also keeps the test working on the Airflow versions
in the provider compatibility matrix, where the operator-level override
does not exist yet.
@shahar1
shahar1 force-pushed the fix-storage-transfer-create-job branch from eb56680 to 1c52845 Compare September 23, 2026 06:56
@shahar1
shahar1 merged commit 7c47cc4 into apache:main Sep 23, 2026
81 checks passed
@shahar1 shahar1 changed the title Validate storage transfer job body after template rendering Validate GCP storage transfer job body after template rendering Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:dev-tools area:providers provider:google Google (including GCP) related issues ready for maintainer review Set after triaging when all criteria pass.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants