Skip to content

fix(auth): trustworthy s3 checks and non-blocking ssh probe (0.26.0) - #191

Merged
johnyaku merged 1 commit into
mainfrom
fix/auth-check-s3-ssh
Sep 16, 2026
Merged

johnyaku merged 1 commit into
mainfrom
fix/auth-check-s3-ssh

Conversation

@johnyaku

@johnyaku johnyaku commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #190.

dt auth check actively misled a real bcarc_wts R2 credential diagnosis. Three distinct problems, all fixed here.

1. S3 false negatives — _check_s3 rewrite

The old checker probed with aws sts get-caller-identity, which Cloudflare R2 does not implement, so healthy endpoints reported credentials check timed out. It also never used the per-repo AWS profile — it ran against default credentials — so valid creds in a named ~/.aws/credentials profile read as credentials not configured. This is what failed 5 of 6 healthy endpoints in the report.

New _check_s3:

  • Resolves the DVC remote's configured profile and endpoint URL (.dvc/config by remote name, then by URL, then the profile-per-repo naming convention for import children).
  • Issues a lightweight, bounded boto3 list_objects_v2(MaxKeys=1) (connect_timeout=5, read_timeout=10, max_attempts=1) — the same probe the issue found trustworthy. No more aws sts.

2. Actionable verdicts (no more "not configured" for everything)

Outcomes are now typed:

  • missing — no profile / no resolvable credentials
  • rejected — SignatureDoesNotMatch / InvalidAccessKeyId / AccessDenied / …, with the error code surfaced and a "reinstall the secret" hint (the wts case that was misdiagnosed as "not configured")
  • bucket not found — NoSuchBucket / 404
  • unreachable / timed out — connection/timeout errors

3. SSH no longer hangs in non-interactive shells

A named SSH remote used DVC's own (non-BatchMode, un-timed) filesystem via odb.fs.exists(), which blocks on a username prompt in CI / non-tty. _try_check now skips the DVC-native probe for SSH remotes when stdin is not a tty and falls back to the already-bounded _check_ssh (BatchMode=yes, ConnectTimeout=5). Interactive behavior is unchanged.

Notes

  • list_objects_v2 needs ListBucket; a valid write-only key reads as rejected (AccessDenied). This matches the issue's requested behavior and the trustworthy probe used to diagnose it.
  • --json verdicts are now trustworthy since they flow from the corrected statuses.

Tests

Rewrote TestCheckS3 for the boto3 path (missing / profile-not-found / rejected-signature / access-denied / unreachable / bucket-not-found / pass-with-profile+endpoint) plus new _split_s3_url, _profile_from_source, _resolve_s3_remote_settings, and two _try_check SSH-tty-guard tests. tests/unit/test_auth.py 335 passed; test_auth_robustness/setup/credentials_aws (100) and test_doctor (37) green. Also verified live against an unreachable endpoint (real boto3): classified endpoint unreachable / timed out, bounded.

Version bumped 0.26.0 → 0.27.0 (rebased onto main after #189 merged).

🤖 Generated with Claude Code

…190)

`dt auth check` misdiagnosed a real R2 credential problem three ways:

1. S3 endpoints used `aws sts get-caller-identity`, which Cloudflare R2
   does not implement, so healthy endpoints reported "credentials check
   timed out". The probe also never used the per-repo AWS profile, so
   valid credentials in a named `~/.aws/credentials` profile read as
   "credentials not configured".

2. Every failure collapsed to "not configured", so a rejected secret
   (`SignatureDoesNotMatch`) sent the diagnosis looking for a missing
   profile instead of a wrong one.

3. A named SSH remote went through DVC's own (non-BatchMode, un-timed)
   filesystem, which blocks on a username prompt in a non-interactive
   shell / CI.

Rewrite `_check_s3` to resolve the configured profile + endpoint URL and
issue a bounded boto3 `list_objects_v2(MaxKeys=1)`, classifying the
outcome as missing / rejected (code surfaced) / bucket-not-found /
unreachable. Skip the DVC-native probe for SSH remotes when stdin is not
a tty, falling back to the bounded `_check_ssh`.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@johnyaku
johnyaku force-pushed the fix/auth-check-s3-ssh branch from 76573cf to 976782c Compare September 16, 2026 02:54
@johnyaku
johnyaku merged commit c5ec4ce into main Sep 16, 2026
1 check passed
@johnyaku
johnyaku deleted the fix/auth-check-s3-ssh branch September 16, 2026 03:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dt auth check: false negatives + hang make it unreliable for diagnosing credential problems

1 participant