Skip to content

Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.17 to 1.19.19 - #850

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/credentials-1.19.19
Closed

Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.17 to 1.19.19#850
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/credentials-1.19.19

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 2, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/aws/aws-sdk-go-v2/credentials from 1.19.17 to 1.19.19.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) from 1.19.17 to 1.19.19.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@credentials/v1.19.17...credentials/v1.19.19)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.19.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependabot dependencies Pull requests that update a dependency file labels Jun 2, 2026
@dependabot
dependabot Bot requested a review from VijayanB as a code owner June 2, 2026 05:57
@dependabot dependabot Bot added the dependabot label Jun 2, 2026
@dependabot
dependabot Bot requested review from Jakob3xD, VachaShah and sean- as code owners June 2, 2026 05:57
@dependabot @github

dependabot Bot commented on behalf of github Jun 2, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot attempted to update this pull request, but because the branch dependabot/go_modules/github.com/aws/aws-sdk-go-v2/credentials-1.19.19 is protected it was unable to do so.

@sean-

sean- commented Jun 2, 2026

Copy link
Copy Markdown
Collaborator

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Jun 2, 2026

Copy link
Copy Markdown
Contributor Author

Oh no! Something went wrong on our end. Please try again later.

If the problem persists, please contact GitHub support for assistance 🙇

sean- added a commit to sean-/opensearch-go that referenced this pull request Jun 3, 2026
- github.com/aws/aws-sdk-go-v2/config from 1.32.18 to 1.32.20
- github.com/aws/aws-sdk-go-v2/credentials from 1.19.17 to 1.19.19
- github.com/getkin/kin-openapi from v0.139.0 to v0.140.0

Fixes: opensearch-project#852, opensearch-project#850

Signed-off-by: Sean Chittenden <sean.chittenden@crowdstrike.com>
sean- added a commit to sean-/opensearch-go that referenced this pull request Jun 3, 2026
- github.com/aws/aws-sdk-go-v2/config from 1.32.18 to 1.32.20
- github.com/aws/aws-sdk-go-v2/credentials from 1.19.17 to 1.19.19
- github.com/getkin/kin-openapi from v0.139.0 to v0.140.0

Fixes: opensearch-project#852, opensearch-project#850

Signed-off-by: Sean Chittenden <sean.chittenden@crowdstrike.com>
@sean-

sean- commented Jun 3, 2026

Copy link
Copy Markdown
Collaborator

This will be fixed via #844

sean- added a commit to sean-/opensearch-go that referenced this pull request Jun 3, 2026
- github.com/aws/aws-sdk-go-v2/config from 1.32.18 to 1.32.20
- github.com/aws/aws-sdk-go-v2/credentials from 1.19.17 to 1.19.19
- github.com/getkin/kin-openapi from v0.139.0 to v0.140.0

Fixes: opensearch-project#852, opensearch-project#850

Signed-off-by: Sean Chittenden <sean.chittenden@crowdstrike.com>
sean- added a commit that referenced this pull request Jun 4, 2026
…n classifier, default router, and union decode overhaul

Consolidates the gh-816 burn-down: a partial-failure error model with
fine-grained masking, an HTTP-layer operation classifier, blocking
node discovery with default-router injection, a generator overhaul
(idiomatic naming, single-pass union decode, request-body union
constructors), and the v5preview regeneration plus integration
coverage and user docs that go with it.

## Partial-failure error model

OpenSearch returns HTTP 200 for partial successes (bulk item failures,
shard failures, single-doc replica failures), forcing callers to
double-check responses after `err == nil`. New typed errors expose
these through the standard Go `if err != nil` idiom; both `(resp, err)`
are non-nil on partial failure and the response is fully populated.

- Adds `PartialBulkError`, `PartialSearchError`, `ShardFailureError`,
  and helpers `IsPartialFailure`, `ToleratePartialFailures`,
  `RequireSuccessRate` for threshold-based tolerance.
- Replaces the initial `Config.ReturnQueryErrors` boolean with
  `internal/errmask.ErrorMask`, a 15-bit field where each bit masks
  one wrapper schema in the proposed `x-error-responses` OpenAPI
  extension (`BulkItems`, `SearchShards`, `WriteShards`,
  `BroadcastShards`, `NodeFailures`, `BulkByScrollFailures`,
  `TaskFailures`, `MultiSearchItems`, `MultiDocItems`,
  `Snapshot{Create,Get}ShardFailures`, `SimulateDocFailures`,
  `RankEvalFailures`, `IngestionShardFailures`, `PitNodeFailures`).
  A set bit suppresses that category; the zero value reports every
  category.
- Callers configure policy via `Config.Errors = errmask.BulkItems |
  errmask.SearchShards` or `OPENSEARCH_GO_ERROR_MASK` with `+/-`
  tokens (e.g. `+all,-bulk_items`).

Lifecycle:
- v4 default `errmask.All` preserves existing behavior.
  `Config.ReturnQueryErrors=true` is honored as a deprecated alias
  for `errmask.None`.
- v5 default flips to `errmask.None` (safe by default).
- v6 removes `Config.Errors` / `OPENSEARCH_GO_ERROR_MASK`;
  behavior is unconditionally `errmask.None`.

Spec side: `opensearch-openapi.yaml` is patched with 15
`_common.errors___<Wrapper>` schemas and 115 operations gain an
`x-error-responses` annotation, mirroring the upstream proposal in
`opensearch-api-specification`. The local patch goes away cleanly
once that PR lands and we re-bundle from source.

Generator side: `cmd/osgen` reads `x-error-responses` into
`ir.Operation.ErrorWrappers`; `cmd/osgen/errwrap` supplies a fallback
for plugin operations the spec does not yet annotate. The dispatch
fragment carries a data-driven `wrappers` map of `{Template, Applies}`,
so generated code stays compilable when annotations land before the
underlying response schema models the relevant field.

## OperationClassifier and bit-packed OperationID

Adds a zero-allocation HTTP method+path classifier (reusing the
existing `routeTrie`) that maps requests to structured
`OperationID` values. Enables transparent metrics, tracing, and
access-control middleware at the `http.RoundTripper` layer without
per-operation wrappers.

- `OperationID` is a bit-packed `int64` encoding R/W flag, category,
  and minor operation. `IsWrite`, `Category`, `Minor` support
  efficient bitwise filtering. `String()` returns Prometheus-friendly
  labels.
- `OperationClassifier` is built from the canonical route table and
  is safe for concurrent use. Returns `OpOther` for unrecognized
  patterns.
- `OperationID` field added to `trieLeaf`/`trieMatch`, `OpID()` to
  `Route`, `.Op()` to `RouteBuilder`. All 124 routes are tagged.

## Blocking DiscoverNodes and default Router injection

- `DiscoverNodes` now waits for an in-flight discovery to complete
  (or for the context to be cancelled) instead of returning `nil`
  immediately, letting callers block until topology data is
  available after client construction.
- `DiscoverNodesOnStart` becomes `*bool`. Auto-enabled when
  `OPENSEARCH_GO_ROUTER=true` and the caller did not set it.
- `v5preview/opensearchapi.NewClient` and `NewDefaultClient` inject
  `opensearchtransport.NewDefaultRouter` when `config.Client.Router`
  is `nil`, opting v5preview clients into role-aware dispatch,
  RTT-based scoring, AIMD congestion-window, and shard-cost
  weighting by default.
- `OPENSEARCH_GO_ROUTER` is a symmetric override: a falsy value
  (`false`/`0`) suppresses injection so `Router` stays `nil`,
  matching v4 behavior. Caller-provided Routers are preserved.
- `internal/envvars.Falsy(name)` distinguishes "unset" from
  "explicitly opted out" so the v5preview rule reads as
  `!envvars.Falsy(envvars.Router)` without re-implementing parse
  logic.

## Generator: idiomatic naming, request-body unions, single-pass decode

Naming rewrites at PascalCase boundaries:

| Spec form     | Idiomatic Go    |
|---------------|-----------------|
| `Msearch`     | `MSearch`       |
| `Mget`        | `MGet`          |
| `Mtermvectors`| `MTermVectors`  |
| `Termvectors` | `TermVectors`   |
| `Forcemerge`  | `ForceMerge`    |
| `Response`    | `Resp`          |

The `Response -> Resp` rule additionally requires the trailing
character to be uppercase, so standalone `SearchResponse` (a spec
wrapper) does not collide with the operation-level `<Op>Resp` name.
Hand-written types renamed for v4/v5 consistency:
`BulkResponseItem -> BulkRespItem`, `ErrorResponseBase ->
ErrorRespBase`, `MsearchErrors -> MSearchErrors`,
`MsearchTemplateErrors -> MSearchTemplateErrors`.

Request-body unions:
- `splitUnionsFromSiblings` partitions request-body subtree unions
  (e.g. `ReindexSourceSort`) so they are routed to `UnionFragment`
  instead of being emitted as empty structs.
- Plumbs `Op + Registry` into `UnionFragment` so plugin-package
  unions qualify cross-package branches as
  `opensearchapi.FieldSort`.
- Each generated discriminated union gains
  `New<Union>From<Branch>(v <branch type>) <Union>` constructors
  per branch and a `SetRaw(json.RawMessage)` typed escape hatch.
  `SetRaw` clears the typed branch so `MarshalJSON` returns the
  raw bytes verbatim.

Single-pass union decode:
- Case A (merged): object unions with one permissive primary branch
  plus discriminated branch(es) (mget, msearch, indices-open). The
  primary is embedded and the common case decodes in a single
  `json.Unmarshal`; each discriminated branch is detected by the
  presence of its distinguishing key and decoded only when matched.
  Drops the `build.HasJSONKeys` map probe and per-item raw copy.
- Case B (lazy `As<T>()`): aggregation/suggest result unions carry
  no wire discriminator, so they cannot be auto-selected.
  `UnmarshalJSON` only retains the raw bytes; generated
  `As<ConcreteType>()` accessors decode on demand.
- Unions fitting neither (reindex bodies, plugin-defined task
  status) keep the existing try-each decoder; the classifier logs
  once per union name when it declines.
- All union `UnmarshalJSON` aliases the owned response buffer
  (`u.raw = data`) rather than copying it; `RawJSON()` documents
  the borrowed-buffer contract.

Measured impact on mget (1000 docs): decode allocations down ~2.7x
(~43k -> ~16k allocs/op), time down ~1.7x (4.2ms -> 2.5ms).

Bulk wrapper template now resolves its walked element type from the
IR (via `bulkInnerItemType`) instead of hardcoding `BulkRespItem`,
so future spec or naming changes propagate automatically.

## v5preview regeneration

Mechanical output of `cmd/osgen` against the patched spec:

- `clients_gen.go` declares `errors errmask.ErrorMask` on `Client`
  and `clientInit` takes the mask as a second arg.
- 19 operation dispatch files emit per-wrapper post-`do()` blocks
  that return typed errors when the corresponding `errmask` bit is
  unset and the wire data carries a partial failure
  (`BulkItems`, `SearchShards`, `WriteShards`, `MultiSearchItems`).
- Reserved-but-unemitted wrappers (`BroadcastShards`, `NodeFailures`,
  `BulkByScrollFailures`, `TaskFailures`, `MultiDocItems`,
  `Snapshot{Create,Get}ShardFailures`, `SimulateDocFailures`,
  `RankEvalFailures`, `IngestionShardFailures`, `PitNodeFailures`)
  carry annotations but no emission until detection logic lands.
- Operations whose typed response shape lacks the field path a
  wrapper needs (`CreateResp` lacks `_shards`; msearch union items
  lack a top-level `Shards`) are silently skipped by the
  `Applies` guard; emission starts automatically once the response
  types catch up.
- Idiomatic-naming pass touches every generated type containing
  `Msearch`, `Mget`, `Mtermvectors`, `Termvectors`, `Forcemerge`,
  or compound `*Response*` substrings.
- Single-pass union decode applied to mget/msearch/indices-open
  success|error items and `As<T>()` accessors generated for
  aggregation and suggest result unions.

## Integration coverage and CI hardening

v5preview integration tests drive real requests and assert decoded
shape per server version:

- aggregation: lazy `As<T>()` accessors (terms, date_histogram,
  stats, avg, sum, min, max, value_count, cardinality).
- mget: merged success|error decode (`GetResult` found/not-found
  vs `MGetMultiGetError`).
- msearch: merged success|error decode
  (`MSearchMultiSearchItem` vs `ErrorRespBase`), the
  first-byte-switch `SearchHitsMetadataTotal` union, and the
  `MultiSearchItemError` partial-failure surface.

CI matrix changes:

- Skip multi-node clusters on OpenSearch <=2.17.x to avoid the
  node-join/node-left coordinator race
  (`opensearch-project/OpenSearch#15521`, backported via #16118
  on the 2.x line). Affected versions run with
  `OPENSEARCH_NODE_COUNT=1`.
- `.github/workflows/test-compatibility.yml` adds a per-entry
  `node_count` matrix field: `1` for 1.3.20 through 2.17.1, `3`
  for 2.18.0 and later. Comment cites the upstream PRs so the
  cutoff is greppable.
- `Makefile cluster.docker-up` respects `OPENSEARCH_NODE_COUNT`
  and passes `--scale opensearch-nodeN=0` to docker compose.
  Defaults to 3 for local development.
- Widen the existing 2.1.0-only shard-routing test skip to all
  versions below 2.2.0 (security plugin
  `java.io.OptionalDataException` from non-thread-safe `User`
  serialization, fixed by
  `opensearch-project/security#1970`).
- Generated-code emit/path test fixtures converted from raw
  `"GET"`/`"POST"` to `net/http http.Method*` constants for
  consistency with the rest of the suite.
- `testutil.PollUpdate()` decouples jitter calculation from
  runtime backoff execution to fix a flake.

## Dependency bumps

- `github.com/aws/aws-sdk-go-v2/config` 1.32.18 -> 1.32.20
- `github.com/aws/aws-sdk-go-v2/credentials` 1.19.17 -> 1.19.19
- `github.com/getkin/kin-openapi` v0.139.0 -> v0.140.0

Fixes: #852, #850

## Documentation

- `v5preview/opensearchapi/README.md`: Partial Failure Errors
  (Config.Errors, errmask, `OPENSEARCH_GO_ERROR_MASK`, typed errors,
  `opensearchapi.Errors` helper, per-Resp helpers, helper functions,
  operation constants) and Default Router Injection (truth table
  for `OPENSEARCH_GO_ROUTER`, opt-out semantics).
- `v5preview/opensearchapi/MIGRATING.md`: v4 -> v5preview surface
  delta (import path, `Indices -> Index` on multi-index Req types,
  `DocumentID -> ID` on `IndexReq`, optional `Params` becomes
  `*Params`, optional `bool` query params become `*bool`,
  partial-failure type renames, errmask default flip, default
  Router injection).
- `guides/error_handling.md`: Bulk/Search/Write partial-failure
  examples as paired v4/v5preview blocks; per-Resp helper
  subsection (`BulkItemFailures`, `SearchShardFailures`,
  `WriteShardFailures`, `MultiSearchItemFailures`,
  `PartialFailures(mask)`); error type reference covering v4 vs
  v5preview internal-field-type divergence.
- `guides/bulk.md`: v4/v5preview field-name and `BulkResp.Items`
  shape divergences with paired error-iteration examples for v4's
  `[]map[string]BulkRespItem` and v5preview's `[]BulkItem`.
- `UPGRADING.md`: keeps version-history essentials for the >=5.0
  partial-failure model and v5preview Router injection;
  forward-links to the new package docs.

Ref: #816
Ref: opensearch-project/opensearch-api-specification/pull/1137
@dependabot @github

dependabot Bot commented on behalf of github Jun 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like github.com/aws/aws-sdk-go-v2/credentials is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependabot dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant