SIGN IN SIGN UP

aws: remove hang when signing a dynamic modules bootstrap extension callout during server init (#46930)

Commit Message:
aws: remove hang when signing a dynamic modules bootstrap extension
callout during server init

It is not currently possible to make HTTP callouts that block server
initialization from a dynamic modules bootstrap extension to a cluster
with an upstream AWS signing filter on it that asynchronously resolves
credentials. This is because
`MetadataCredentialsProviderBase::setCredentialsToAllThreads` does not
notify signers that credentials are available until all worker threads
have had their ThreadLocalCredentialsCache updated, but this operation
is blocked on worker threads being started, which is itself blocked on
the pending server initialization. A cycle!

Change setCredentialsToAllThreads to notify signers immediately after
starting runOnAllThreads, which synchronously updates only the main
thread, in addition to doing it after the completion of that operation
across all threads. I believe this to be safe because that notification
will itself only be handled in worker threads after the runOnAllThreads
dispatch is handled.

However, one wrinkle with this strategy is that it's now possible for
workers to observe tears between the per-thread credentials and the
global "pending" flag. So, I've made the pending flag also be
per-thread, next to the credentials. Updates that set that value to
`true` are broadcast to all threads from the main thread - all such
updates were already happening there, and now runOnAllThreads asserts as
much.

Additional Description:
AI disclosure: this fix comes from a real situation I found trying to
use Envoy, but it was investigated by, and the solution and the tests
were written by, Claude. I do not have expertise in any of the systems
involved (Envoy's threading model, Envoy's AWS credentials
implementation, or... C++ in general), so I appreciate careful reviews.

Risk Level: Low
Testing: I've added an integration test covering the stated use case,
and some more targeted tests in credentials_provider_test. All the added
tests fail without the changes in `source/`.
Docs Changes: N/A
Release Notes: Yes.
Platform Specific Features: No.

Signed-off-by: Ian Kerins <git@isk.haus>
I
Ian Kerins committed
e2f7b98db48c51cd2834d22801662443e94250aa
Parent: 7ab45c9
Committed by GitHub <noreply@github.com> on 9/3/2026, 8:33:50 PM