fix(auth): serialize credential lifecycle by key#6478
Open
tylergibbs1 wants to merge 1 commit into
Open
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
tylergibbs1
marked this pull request as ready for review
July 25, 2026 15:20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Root cause
CredentialManager.get_auth_credential()performed the load → exchange/refresh → save lifecycle without coordination. Concurrent managers could therefore load the same stale credential, independently exchange or refresh it, and race while saving the result.The new key-scoped lock keeps that lifecycle atomic within an event loop. A waiter reloads the credential after acquiring the lock, so it observes the result saved by the preceding request instead of repeating the external operation.
Closes #6475.
User impact
Concurrent agent/tool calls using the same OAuth credential no longer duplicate token exchange or refresh requests. Calls using different credential keys are not serialized.
Testing plan
pytest tests/unittests/auth— 195 passedtest_credential_manager.pytox runs on Python 3.10, 3.12, 3.13, and 3.14 — all passedpre-commit run --files src/google/adk/auth/credential_manager.py tests/unittests/auth/test_credential_manager.pyuv build