Repository navigation
[v3-3-test] Stop shipping broken agent-skill symlinks in the source release (#73107) - #73130
Merged
Merged
Conversation
…t permission (#72627) (#73073) The Edge UI plugin docs say that "can read on Plugins" and "can read on Jobs" let you view the UI and manage the workers, but they do not say how the two permissions differ, and they do not mention what the default Viewer role already holds. Both gaps matter, because the endpoints and the navigation are gated differently: - The worker management endpoints under /edge_worker/ui/ check only AccessView.JOBS, and the check is not method-aware -- the same dependency guards the GET reads and the POST/PATCH/DELETE mutations. - "can read on Plugins" only controls whether the plugin shows up in the UI navigation. It is not required in order to call the endpoints. So "can read on Jobs" alone is enough to shut down, delete, re-queue and retune Edge workers, whether or not the plugin is visible to that user. That is intentional -- AccessView.JOBS is the management permission for the plugin rather than a read-only grant -- but it reads as surprising from the code alone, where a permission named "can read" guards mutating routes. It is more surprising in a default Flask AppBuilder setup, where the Viewer role includes (ACTION_CAN_READ, RESOURCE_JOB) but not the Plugins read: such a user cannot see the Edge plugin and can still reach its management endpoints. Adds a warning to the UI plugin docs stating the intent, the split between the two permissions, the consequence for the default Viewer role, and the concrete action for deployments where Viewers must not manage workers. Points at the existing "fine granular access control" entry in architecture.rst rather than restating it. Documentation only; no behaviour change. (cherry picked from commit 1391b09)
…9444) (#73108) ASF policy does not permit compiled binaries in a source release and the Gradle wrapper is not among the exempted build tools (LEGAL-570), so main stopped shipping java-sdk/gradle/wrapper/gradle-wrapper.jar in #69444. Only half of that change reached this branch. The breeze side already restores gradlew and gradlew.bat after `git archive` drops them, but the java-sdk/.gitattributes side never followed, so nothing is actually dropped and the 43 KB jar is still in the 3.3.2rc1 source tarball. Carrying the rest of the file over also starts shipping java-sdk/.editorconfig, which the root .gitattributes strips today even though ktlint reads it at build time and the build task requires that lint to pass. gradle-wrapper.properties stays in the tarball on purpose: it carries the pinned Gradle version and distribution checksum a verifier needs to regenerate the wrapper. Generated-by: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01DCUVuZ8CCeER1QLhVEKAaZ
…elease (#73107) Excluding .agents from the source tarball (#68851) left .claude behind. Everything under .claude/skills is a relay symlink into .agents/skills, so export-ignore strips the targets while the links themselves still ship: unpacking the source release yields broken symlinks, and .claude/ arrives holding nothing but those dead links. Found while verifying 3.3.2rc1, whose tarball carries five of them. The released 3.3.1 carries the same ones, so this is long-standing rather than something a recent change introduced. .github needs no equivalent entry: its own skills relays are already covered by the existing .github export-ignore. (cherry picked from commit 4b0eb8e) Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
1 task done
vatsrahul1001
force-pushed
the
v3-3-test
branch
2 times, most recently
from
September 21, 2026 15:01
8a9641a to
b40d05b
Compare
potiuk
marked this pull request as ready for review
September 28, 2026 15:39
potiuk
requested review from
dheerajturaga,
jason810496,
jscheffl,
shubhamraj-git and
uranusjr
as code owners
September 28, 2026 15:39
Contributor
Author
|
Hi maintainer, this PR was merged without a milestone set.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Excluding .agents from the source tarball (#68851) left .claude behind.
Everything under .claude/skills is a relay symlink into .agents/skills, so
export-ignore strips the targets while the links themselves still ship:
unpacking the source release yields broken symlinks, and .claude/ arrives
holding nothing but those dead links.
Found while verifying 3.3.2rc1, whose tarball carries five of them. The
released 3.3.1 carries the same ones, so this is long-standing rather than
something a recent change introduced.
.github needs no equivalent entry: its own skills relays are already
covered by the existing .github export-ignore.
(cherry picked from commit 4b0eb8e)
Co-authored-by: Jarek Potiuk jarek@potiuk.com