lets-order-some-fries commented on PR #68395:
URL: https://github.com/apache/doris/pull/68395#issuecomment-5856944095

   Updated — this now covers every sensitive FE config, not only the two from 
#67338.
   
   Looking at the group properly, three more operator secrets had no test at 
all:
   `mysql_ssl_default_ca_certificate_password`, 
`mysql_ssl_default_server_certificate_password` and
   `initial_root_password`. One test now pins all seven, and asserts the 
annotation is still present
   rather than only that the value comes back masked — a check driven off the 
annotation alone cannot
   notice the annotation being *removed*, which is the case actually worth 
guarding.
   
   Verified locally with the branch merged up to master `bdb165d6`:
   
   - `mvn -pl fe-common test -Dtest=ConfigTest` — 12 tests, 0 failures (master 
alone runs 11), build
     cache disabled so surefire really ran
   - `mvn -pl fe-common checkstyle:check` — 0 violations
   - fails as intended in both directions: dropping `sensitive = true` from 
`key_store_password`, and
     marking an unlisted config sensitive
   
   All seven pass as master stands, so this is a test gap rather than a bug 
report.
   
   @starocean999 — you added these annotations in #67338 and backported them in 
#67920, so this is the
   missing test for your change. Would you mind triggering `run buildall`? It 
is test-only, one file,
   +49/-0, no production code touched. If anything comes back red I will fix it 
the same day.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to