You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
serialize credential validation, loading, exchange, refresh, and saving for concurrent requests that share a credential key
keep unrelated credential keys concurrent
scope locks to their asyncio event loop and hold them weakly so completed credentials and closed loops do not accumulate in memory
Root cause
CredentialManager.get_auth_credential() performed the load → exchange/refresh → save lifecycle without coordination. Concurrent managers could therefore load the same stale credential, independently exchange or refresh it, and race while saving the result.
The new key-scoped lock keeps that lifecycle atomic within an event loop. A waiter reloads the credential after acquiring the lock, so it observes the result saved by the preceding request instead of repeating the external operation.
Concurrent agent/tool calls using the same OAuth credential no longer duplicate token exchange or refresh requests. Calls using different credential keys are not serialized.
Testing plan
pytest tests/unittests/auth — 195 passed
full Python 3.11 unit suite using the CI exclusions — 8,831 passed, 64 skipped, 18 xfailed, 1 xpassed
focused test_credential_manager.py tox runs on Python 3.10, 3.12, 3.13, and 3.14 — all passed
pre-commit run --files src/google/adk/auth/credential_manager.py tests/unittests/auth/test_credential_manager.py
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).
CI note: the mypy matrix reports 2,562 errors on both main and this PR, then identifies three “new” errors in evaluation_generator.py and lite_llm.py; neither file is touched here. All unit-test, A2A, pre-commit, CLA, and header checks pass. I cannot rerun the failed jobs without repository admin rights—could a maintainer rerun or refresh the mypy baseline? The Copybara submission gate is also maintainer-only.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
core[Component] This issue is related to the core interface and implementation
3 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Root cause
CredentialManager.get_auth_credential()performed the load → exchange/refresh → save lifecycle without coordination. Concurrent managers could therefore load the same stale credential, independently exchange or refresh it, and race while saving the result.The new key-scoped lock keeps that lifecycle atomic within an event loop. A waiter reloads the credential after acquiring the lock, so it observes the result saved by the preceding request instead of repeating the external operation.
Closes #6475.
User impact
Concurrent agent/tool calls using the same OAuth credential no longer duplicate token exchange or refresh requests. Calls using different credential keys are not serialized.
Testing plan
pytest tests/unittests/auth— 195 passedtest_credential_manager.pytox runs on Python 3.10, 3.12, 3.13, and 3.14 — all passedpre-commit run --files src/google/adk/auth/credential_manager.py tests/unittests/auth/test_credential_manager.pyuv build