Skip to content

[v3-3-test] Stop shipping broken agent-skill symlinks in the source release (#73107) - #73130

Merged
potiuk merged 3 commits into
v3-3-testfrom
backport-4b0eb8e-v3-3-test
Sep 28, 2026
Merged

potiuk merged 3 commits into
v3-3-testfrom
backport-4b0eb8e-v3-3-test

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Excluding .agents from the source tarball (#68851) left .claude behind.
Everything under .claude/skills is a relay symlink into .agents/skills, so
export-ignore strips the targets while the links themselves still ship:
unpacking the source release yields broken symlinks, and .claude/ arrives
holding nothing but those dead links.

Found while verifying 3.3.2rc1, whose tarball carries five of them. The
released 3.3.1 carries the same ones, so this is long-standing rather than
something a recent change introduced.

.github needs no equivalent entry: its own skills relays are already
covered by the existing .github export-ignore.
(cherry picked from commit 4b0eb8e)

Co-authored-by: Jarek Potiuk jarek@potiuk.com

…t permission (#72627) (#73073)

The Edge UI plugin docs say that "can read on Plugins" and "can read on
Jobs" let you view the UI and manage the workers, but they do not say how
the two permissions differ, and they do not mention what the default
Viewer role already holds.

Both gaps matter, because the endpoints and the navigation are gated
differently:

- The worker management endpoints under /edge_worker/ui/ check only
  AccessView.JOBS, and the check is not method-aware -- the same
  dependency guards the GET reads and the POST/PATCH/DELETE mutations.
- "can read on Plugins" only controls whether the plugin shows up in the
  UI navigation. It is not required in order to call the endpoints.

So "can read on Jobs" alone is enough to shut down, delete, re-queue and
retune Edge workers, whether or not the plugin is visible to that user.

That is intentional -- AccessView.JOBS is the management permission for
the plugin rather than a read-only grant -- but it reads as surprising
from the code alone, where a permission named "can read" guards mutating
routes. It is more surprising in a default Flask AppBuilder setup, where
the Viewer role includes (ACTION_CAN_READ, RESOURCE_JOB) but not the
Plugins read: such a user cannot see the Edge plugin and can still reach
its management endpoints.

Adds a warning to the UI plugin docs stating the intent, the split
between the two permissions, the consequence for the default Viewer role,
and the concrete action for deployments where Viewers must not manage
workers. Points at the existing "fine granular access control" entry in
architecture.rst rather than restating it.

Documentation only; no behaviour change.
(cherry picked from commit 1391b09)
…9444) (#73108)

ASF policy does not permit compiled binaries in a source release and the
Gradle wrapper is not among the exempted build tools (LEGAL-570), so main
stopped shipping java-sdk/gradle/wrapper/gradle-wrapper.jar in #69444.

Only half of that change reached this branch. The breeze side already
restores gradlew and gradlew.bat after `git archive` drops them, but the
java-sdk/.gitattributes side never followed, so nothing is actually dropped
and the 43 KB jar is still in the 3.3.2rc1 source tarball.

Carrying the rest of the file over also starts shipping java-sdk/.editorconfig,
which the root .gitattributes strips today even though ktlint reads it at
build time and the build task requires that lint to pass.

gradle-wrapper.properties stays in the tarball on purpose: it carries the
pinned Gradle version and distribution checksum a verifier needs to
regenerate the wrapper.

Generated-by: Claude Opus 5
Claude-Session: https://claude.ai/code/session_01DCUVuZ8CCeER1QLhVEKAaZ
…elease (#73107)

Excluding .agents from the source tarball (#68851) left .claude behind.
Everything under .claude/skills is a relay symlink into .agents/skills, so
export-ignore strips the targets while the links themselves still ship:
unpacking the source release yields broken symlinks, and .claude/ arrives
holding nothing but those dead links.

Found while verifying 3.3.2rc1, whose tarball carries five of them. The
released 3.3.1 carries the same ones, so this is long-standing rather than
something a recent change introduced.

.github needs no equivalent entry: its own skills relays are already
covered by the existing .github export-ignore.
(cherry picked from commit 4b0eb8e)

Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
@vatsrahul1001
vatsrahul1001 force-pushed the v3-3-test branch 2 times, most recently from 8a9641a to b40d05b Compare September 21, 2026 15:01
@potiuk
potiuk marked this pull request as ready for review September 28, 2026 15:39
@potiuk
potiuk merged commit f719f88 into v3-3-test Sep 28, 2026
2 of 3 checks passed
@potiuk
potiuk deleted the backport-4b0eb8e-v3-3-test branch September 28, 2026 15:39
@github-actions github-actions Bot added this to the Airflow 3.3.3 milestone Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor Author

Hi maintainer, this PR was merged without a milestone set.
We've automatically set the milestone to Airflow 3.3.3 based on: merged to version branch
If this milestone is not correct, please update it to the appropriate milestone.

This comment was generated by Milestone Tag Assistant.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant