fix: Kinesis event-source region, EventBridge archive rule ARN, Logs group ARN form, cached Bedrock regexes - #2593
Merged
Conversation
The Kinesis -> Lambda event source mapping poller hardcoded awsRegion to us-east-1 in every record it delivered, so a function reading from a stream in any other region saw the wrong region. Take it from the stream ARN, as the Pipes Kinesis source already does.
CreateArchive always minted the Events-Archive-<name> rule ARN in the default-bus form (rule/<name>), even when the archive's source was a custom bus. Rules on a custom bus are rule/<bus>/<name>, so DescribeRule/ListRules on that bus reported an ARN that named no rule. Build it with rule_arn and the resolved source bus.
CreateLogGroup stored the group ARN with the trailing :* while groups created implicitly (in-process ingest, EventBridge CloudWatch Logs targets) stored it without, and every reader compensated differently. The result was visible on the wire: log streams created by ingest in a CreateLogGroup group got an ARN of log-group:<g>:*:log-stream:<s>, ListSyslogConfigurations logGroupArn and GetTransformer/DescribeFieldIndexes logGroupIdentifier carried :* only for explicitly created groups, and a delivery-source match on the group ARN depended on how the group came to exist. All creation paths now store the :* form (log_group_stored_arn), and LogGroup exposes log_group_arn()/wildcard_arn()/stream_arn() so DescribeLogGroups reports arn with :* and logGroupArn without (as the model documents), stream ARNs hang off the suffix-less ARN, and the logGroupArn/logGroupIdentifier fields use the suffix-less form. The accessors tolerate a stored ARN without the suffix, so snapshots written before this still describe correctly.
The re_* helpers sat under a "Cached regexes" comment but called Regex::new on every invocation, recompiling each identifier pattern on every request (Retrieve also compiled its knowledge-base pattern inline). Hold each pattern in a LazyLock<Regex> and hand out &'static Regex. The pattern strings are unchanged byte-for-byte.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Four independent correctness follow-ups found during the ARN partition campaign, one commit each:
"awsRegion": "us-east-1"; records now carry the stream's region from its ARN.rule_arnwith the source bus (rule/<bus>/Events-Archive-<name>), matching AWS....:log-group:<name>:*while groups created by ingest and EventBridge delivery stored it without:*. Every path now stores the:*form;arn(with:*) andlogGroupArn(without) render from it per the model. Also fixes stream ARNs likelog-group:g:*:log-stream:sfor CreateLogGroup-made groups, and suffixedlogGroupIdentifier/syslog ARNs. Older snapshots (either form) still resolve.LazyLock<Regex>now. Patterns byte-identical (they mirror the Smithy model's ECMA semantics).No surface changes.
Test plan
event_record_carries_stream_region(eu-west-2 + cn-north-1),archive_rule_on_custom_bus_carries_bus_in_arn(custom + default bus),created_and_implicit_log_groups_describe_identically(+ EventBridge delivery assertions).cargo check --workspace --all-targets;cargo teston cloudformation, logs, eventbridge, the server binary and bedrock-agent-runtime; clippy-D warnings; fmt.Summary by cubic
Fixes four correctness issues found while auditing ARN handling across services.
Four independent fixes:
awsRegionwas hardcoded tous-east-1; now taken from the stream ARN.:*, while implicitly created groups stored them without. All creation paths now store the same:*form, and readers use the suffix-less form forlogGroupArn/logGroupIdentifierand stream ARNs. Older snapshots in either form still resolve.LazyLockinstead of on every request. Patterns unchanged.Migration
Written for commit c130ba0. Summary will update on new commits.