aws: remove hang when signing a dynamic modules bootstrap extension callout during server init (#46930)
Commit Message: aws: remove hang when signing a dynamic modules bootstrap extension callout during server init It is not currently possible to make HTTP callouts that block server initialization from a dynamic modules bootstrap extension to a cluster with an upstream AWS signing filter on it that asynchronously resolves credentials. This is because `MetadataCredentialsProviderBase::setCredentialsToAllThreads` does not notify signers that credentials are available until all worker threads have had their ThreadLocalCredentialsCache updated, but this operation is blocked on worker threads being started, which is itself blocked on the pending server initialization. A cycle! Change setCredentialsToAllThreads to notify signers immediately after starting runOnAllThreads, which synchronously updates only the main thread, in addition to doing it after the completion of that operation across all threads. I believe this to be safe because that notification will itself only be handled in worker threads after the runOnAllThreads dispatch is handled. However, one wrinkle with this strategy is that it's now possible for workers to observe tears between the per-thread credentials and the global "pending" flag. So, I've made the pending flag also be per-thread, next to the credentials. Updates that set that value to `true` are broadcast to all threads from the main thread - all such updates were already happening there, and now runOnAllThreads asserts as much. Additional Description: AI disclosure: this fix comes from a real situation I found trying to use Envoy, but it was investigated by, and the solution and the tests were written by, Claude. I do not have expertise in any of the systems involved (Envoy's threading model, Envoy's AWS credentials implementation, or... C++ in general), so I appreciate careful reviews. Risk Level: Low Testing: I've added an integration test covering the stated use case, and some more targeted tests in credentials_provider_test. All the added tests fail without the changes in `source/`. Docs Changes: N/A Release Notes: Yes. Platform Specific Features: No. Signed-off-by: Ian Kerins <git@isk.haus>
I
Ian Kerins committed
e2f7b98db48c51cd2834d22801662443e94250aa
Parent: 7ab45c9
Committed by GitHub <noreply@github.com>
on 9/3/2026, 8:33:50 PM