Skip to content

Conversation

DarshitChanpura
Copy link
Member

Depends on: opensearch-project/security#5677

Description

Adds capability to automatically switch to old access-control if model-group is excluded from protected resources setting.

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

@DarshitChanpura DarshitChanpura changed the title Adds check to enable resource sharing for protected types supplied in cluster setting Adds capability to automatically switch to old access-control if model-group is excluded from protected resources setting Oct 2, 2025
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 2, 2025 04:05 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 2, 2025 04:05 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 2, 2025 04:05 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 2, 2025 04:05 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval October 14, 2025 15:49 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval October 14, 2025 15:49 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval October 14, 2025 15:49 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval October 14, 2025 15:49 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 14, 2025 18:59 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 14, 2025 18:59 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 14, 2025 18:59 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 14, 2025 18:59 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 14, 2025 23:11 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 14, 2025 23:11 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 14, 2025 23:11 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 14, 2025 23:11 — with GitHub Actions Failure
@DarshitChanpura
Copy link
Member Author

blocked by:
#4279

@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 15:32 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 15:32 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 15:32 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 15:32 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 18:44 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 18:44 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 18:44 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval October 15, 2025 20:54 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval October 15, 2025 20:54 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval October 15, 2025 20:54 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval October 15, 2025 20:54 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 21:34 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 21:34 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 21:34 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 15, 2025 21:34 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura mentioned this pull request Oct 16, 2025
5 tasks
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 16, 2025 21:23 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 16, 2025 21:23 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 16, 2025 21:23 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 16, 2025 21:23 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 16, 2025 21:37 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 16, 2025 21:37 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 16, 2025 21:37 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 16, 2025 21:37 — with GitHub Actions Failure
@DarshitChanpura
Copy link
Member Author

DarshitChanpura commented Oct 17, 2025

Unable to reproduce the tests failures locally:

Tests with failures:
 - org.opensearch.ml.action.model_group.DeleteModelGroupTransportActionTests.test_ValidationFailedException
 - org.opensearch.ml.action.model_group.TransportUpdateModelGroupActionTests.test_UserSpecifiedRestrictedButNoBackendRolesField
 - org.opensearch.ml.action.model_group.TransportUpdateModelGroupActionTests.test_NoAccessUserUpdatingModelGroupException

@DarshitChanpura
Copy link
Member Author

Found the root cause:
Since ResourceSharingClientAccessor is static and I added tests here that changes the value inside those tests it caused flaky-ness; as tests are run inside same jvm and if the last test that ran left the accessor assigned to some value, next test that didn't expect it would fail.

./gradlew :opensearch-ml-plugin:test                                                                                    
=======================================
OpenSearch Build Hamster says Hello!
  Gradle Version        : 8.14.3
  OS Info               : Mac OS X 15.7.1 (aarch64)
  JDK Version           : 21 (Eclipse Temurin JDK)
  JAVA_HOME             : /Users/dchanp/.sdkman/candidates/java/21.0.4-tem
  Random Testing Seed   : FE9A768CB2E8A43F
  Crypto Standard       : any-supported
=======================================

> Task :opensearch-ml-plugin:compileTestJava
Note: Some input files use or override a deprecated API.
Note: Recompile with -Xlint:deprecation for details.
Note: Some input files use unchecked or unsafe operations.
Note: Recompile with -Xlint:unchecked for details.

...

BUILD SUCCESSFUL in 54s
27 actionable tasks: 2 executed, 25 up-to-date

@DarshitChanpura DarshitChanpura force-pushed the conditional-resource-sharing branch from e476c18 to 505ce49 Compare October 17, 2025 17:58
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 17, 2025 18:01 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 17, 2025 18:01 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura temporarily deployed to ml-commons-cicd-env-require-approval October 17, 2025 18:01 — with GitHub Actions Inactive
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval October 17, 2025 18:01 — with GitHub Actions Failure
@DarshitChanpura
Copy link
Member Author

DarshitChanpura commented Oct 17, 2025

integTest failure:

Tests with failures:
 - org.opensearch.ml.rest.RestMLRAGSearchProcessorIT.testBM25WithCohere

not related to this PR.

Seems flaky as well since it passed on another run:
https://github.com/opensearch-project/ml-commons/actions/runs/18600818784/job/53038758361?pr=4244

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant