activeloopai / activeloopai/deeplake

S3: GetBucketLocation required despite explicit aws_region, and the raised error names the wrong cause

未关闭
#3,163 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
C++
星标
9.2k
派生
722
PR 合并指标
30 天内没有已合并 PR

描述

**Version:** 4.7.0 · Linux aarch64, Python 3.12 · S3 storage

Two small things, same failure.

## 1. `s3:GetBucketLocation` is required even when the region is supplied

```python
creds = {"aws_access_key_id": ..., "aws_secret_access_key": ...,
"aws_session_token": ..., "aws_region": "us-east-1"} # region given
deeplake.create(url, creds=creds, schema={...})
```

```
[S3] Failed to get bucket region for URL: // with error:
[S3] Access denied: User: ... is not authorized to perform:
s3:GetBucketLocation on resource: "arn:aws:s3:::"
```

If the caller states the region, the lookup should be skipped. It is an extra permission on the bucket resource (not the object prefix), which means a least-privilege policy has to grant a bucket-level action purely to satisfy a call that was not needed.

## 2. The exception names the wrong cause

The message above goes to **stderr**. What the caller catches is:

```
deeplake._deeplake.StorageAccessDenied:
[S3] Access denied: _deeplake_log/_meta/0000000001c00000000.jsonl No response body.
```

So a program sees "cannot read `_deeplake_log/_meta/…`" when the actual denial was `s3:GetBucketLocation` on the bucket. Debugging a policy from that message sends you to the wrong statement — we first widened object permissions, twice, before finding the real one on stderr.

`No response body` is also misleading: there was a response, it was a 403.

## Ask

1. Skip the region lookup when `aws_region` is supplied.
2. Carry the underlying S3 error — action, resource, status — in the raised exception, not only on stderr.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。