Skip to content

[fix](distributed) Disable insecure Flight transport by default - #233

Open
QuakeWang wants to merge 3 commits into
AstroVela:mainfrom
QuakeWang:fix/disable-insecure-flight-default
Open

[fix](distributed) Disable insecure Flight transport by default#233
QuakeWang wants to merge 3 commits into
AstroVela:mainfrom
QuakeWang:fix/disable-insecure-flight-default

Conversation

@QuakeWang

Copy link
Copy Markdown
Collaborator

Summary

Local-disk shuffle previously started and published a process-wide plaintext Arrow Flight listener on 0.0.0.0 by default, without TLS or client authentication.

This PR disables that transport by default. It adds an explicit development opt-in, serializes the decision with exchange plans, prevents disabled plans from publishing process-global endpoints, and rejects remote local-disk reads before connecting. Same-process and object-storage shuffle remain network-free.

Related issue

Refs #57

Documentation impact

  • No user-facing documentation update is required.
  • Documentation is updated in this PR or in a linked website PR.
  • A follow-up issue is required in
    AstroVela/vane-website.

Validation

  • scripts/format workspace --changed
  • pre-commit run --from-ref upstream/main --to-ref HEAD
  • Incremental native build and installation
  • python -m pytest tests/fast/test_vane_config.py — 40 passed
  • Native distributed and serialization tests — 119 cases passed
  • scripts/run_release_tests.sh — 438 passed, 1 skipped

Checklist

  • The change is focused and includes tests or a reason tests are unnecessary.
  • Public behavior and compatibility impact are documented.
  • New dependencies, copied code, model assets, and datasets have compatible
    licenses and are recorded where required.
  • No credentials, private endpoints, personal paths, generated data, model
    weights, or build artifacts are included.
  • Security implications of UDFs, serialization, remote code, network access,
    and untrusted input have been considered.
  • Native changes were compiled; Python-only, documentation, and workflow
    changes passed relevant checks.

Local-disk shuffle started and published a process-wide plaintext Flight listener by default even though it binds to 0.0.0.0 without TLS or client authentication.

Require an explicit development opt-in, serialize it with exchange plans, and keep same-process and object-storage shuffle network-free. Reject remote local-disk reads before connecting when the opt-in is absent.

Refs AstroVela#57

Signed-off-by: QuakeWang <wangfuzheng0814@foxmail.com>
@QuakeWang
QuakeWang requested a review from kaka11chen as a code owner July 28, 2026 02:30

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b08c9085a4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread README.md Outdated
The insecure Flight opt-in is serialized with exchange plans, so existing Ray workers do not need to be recreated. Align the public documentation, configuration help, and runtime errors with that plan-scoped behavior.

Signed-off-by: QuakeWang <wangfuzheng0814@foxmail.com>
Signed-off-by: QuakeWang <wangfuzheng0814@foxmail.com>
@kaka11chen

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🎉

Reviewed commit: 3a877d03a5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants