Repository navigation
fix(auth): trustworthy s3 checks and non-blocking ssh probe (0.26.0) - #191
Merged
Merged
Conversation
…190) `dt auth check` misdiagnosed a real R2 credential problem three ways: 1. S3 endpoints used `aws sts get-caller-identity`, which Cloudflare R2 does not implement, so healthy endpoints reported "credentials check timed out". The probe also never used the per-repo AWS profile, so valid credentials in a named `~/.aws/credentials` profile read as "credentials not configured". 2. Every failure collapsed to "not configured", so a rejected secret (`SignatureDoesNotMatch`) sent the diagnosis looking for a missing profile instead of a wrong one. 3. A named SSH remote went through DVC's own (non-BatchMode, un-timed) filesystem, which blocks on a username prompt in a non-interactive shell / CI. Rewrite `_check_s3` to resolve the configured profile + endpoint URL and issue a bounded boto3 `list_objects_v2(MaxKeys=1)`, classifying the outcome as missing / rejected (code surfaced) / bucket-not-found / unreachable. Skip the DVC-native probe for SSH remotes when stdin is not a tty, falling back to the bounded `_check_ssh`. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
johnyaku
force-pushed
the
fix/auth-check-s3-ssh
branch
from
September 16, 2026 02:54
76573cf to
976782c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #190.
dt auth checkactively misled a realbcarc_wtsR2 credential diagnosis. Three distinct problems, all fixed here.1. S3 false negatives —
_check_s3rewriteThe old checker probed with
aws sts get-caller-identity, which Cloudflare R2 does not implement, so healthy endpoints reportedcredentials check timed out. It also never used the per-repo AWS profile — it ran against default credentials — so valid creds in a named~/.aws/credentialsprofile read ascredentials not configured. This is what failed 5 of 6 healthy endpoints in the report.New
_check_s3:.dvc/configby remote name, then by URL, then the profile-per-repo naming convention for import children).list_objects_v2(MaxKeys=1)(connect_timeout=5,read_timeout=10,max_attempts=1) — the same probe the issue found trustworthy. No moreaws sts.2. Actionable verdicts (no more "not configured" for everything)
Outcomes are now typed:
SignatureDoesNotMatch/InvalidAccessKeyId/AccessDenied/ …, with the error code surfaced and a "reinstall the secret" hint (thewtscase that was misdiagnosed as "not configured")NoSuchBucket/ 4043. SSH no longer hangs in non-interactive shells
A named SSH remote used DVC's own (non-BatchMode, un-timed) filesystem via
odb.fs.exists(), which blocks on a username prompt in CI / non-tty._try_checknow skips the DVC-native probe for SSH remotes whenstdinis not a tty and falls back to the already-bounded_check_ssh(BatchMode=yes,ConnectTimeout=5). Interactive behavior is unchanged.Notes
list_objects_v2needsListBucket; a valid write-only key reads asrejected (AccessDenied). This matches the issue's requested behavior and the trustworthy probe used to diagnose it.--jsonverdicts are now trustworthy since they flow from the corrected statuses.Tests
Rewrote
TestCheckS3for the boto3 path (missing / profile-not-found / rejected-signature / access-denied / unreachable / bucket-not-found / pass-with-profile+endpoint) plus new_split_s3_url,_profile_from_source,_resolve_s3_remote_settings, and two_try_checkSSH-tty-guard tests.tests/unit/test_auth.py335 passed;test_auth_robustness/setup/credentials_aws(100) andtest_doctor(37) green. Also verified live against an unreachable endpoint (real boto3): classifiedendpoint unreachable / timed out, bounded.Version bumped 0.26.0 → 0.27.0 (rebased onto main after #189 merged).
🤖 Generated with Claude Code