Skip to content

fix(deps): exclude sentry-sdk 2.69.0, which corrupts SigV4-signed headers - #263

Merged
lesnik512 merged 1 commit into
mainfrom
fix/sentry-2690-exclusion
Sep 27, 2026
Merged

lesnik512 merged 1 commit into
mainfrom
fix/sentry-2690-exclusion

Conversation

@lesnik512

@lesnik512 lesnik512 commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

sentry-sdk 2.69.0 breaks every AWS call made through aiobotocore while a Sentry transaction is
active. Nothing in our metadata stops a user resolving onto it.

The bug

getsentry/sentry-python#7050, released in 2.69.0, moved boto3 trace propagation into botocore's
before-sign event, so sentry-trace and baggage are set before SigV4 signing and land in
SignedHeaders. The same PR taught the stdlib client to leave signed propagation headers alone,
but not the aiohttp client. AioHttpIntegration.on_request_start still overwrites sentry-trace
and appends to baggage after signing, so the bytes sent no longer match the bytes signed and the
service answers SignatureDoesNotMatch.

Both integrations auto-enable, and Boto3Integration keys off botocore, not boto3, so
installing aiobotocore alone turns on both. Sync boto3 is unaffected, and the failure only appears
while a transaction is open, which makes it look intermittent.

Upstream: getsentry/sentry-python#7426, fixed by getsentry/sentry-python#7427, released in 2.69.1
on 2026-09-08. 2.69.0 is the only affected release.

Why an exclusion rather than a floor raise

!=2.69.0 removes the broken release and nothing else. Raising the floor to >=2.69.1 would also
close a second variant, where anything else signs a baggage header before sentry sees the request
(ddtrace >= 4.12 per getsentry/sentry-python#7050), which affects every version below 2.69.1. That
variant rests on one upstream description rather than a report against this project, and the raise
would cost 68 minor versions of SDK support, so it is not worth it here.

The tradeoff to note: this is library metadata, so it binds every consumer, and an app pinning
2.69.0 for unrelated reasons would now conflict. Excluding a single known-broken release with a
one-patch fix available is the narrowest form that guard can take.

The exclusion goes on all three marker lines. 2.69.0 sits above every declared floor
(>=2.1, >=2.11, >=2.59), so it was reachable on every supported interpreter.

Mitigations for users who cannot upgrade

Through sentry_additional_params, in decreasing order of how much they keep:

  • trace_propagation_targets excluding the AWS endpoints, which keeps spans everywhere and
    propagation everywhere else. Works back to 2.1.
  • disabled_integrations=[AioHttpIntegration()], which loses all aiohttp client spans and
    propagation, not only for AWS. Needs 2.11, where the option was added.

Passing AioHttpIntegration() explicitly in sentry_integrations does not help: the explicit
instance installs the same client hook.

Verified

Resolution, on this checkout, capping sentry-sdk to force the broken release into range:

constraint before after
<2.69.1 2.69.0 2.68.1
<2.70 2.69.2 2.69.2
none 2.70.0 2.70.0
--resolution lowest-direct 2.59.0 2.59.0

The floors are untouched, which the last row shows: lowest-direct still picks the declared floor
for the interpreter (2.59.0 on 3.14 here).

eof-fixer --check, ruff format --check, ruff check --no-fix and ty check clean.
pytest: 331 passed. mkdocs build --strict passes.

@lesnik512
lesnik512 force-pushed the fix/sentry-2690-exclusion branch from 6ae710e to 9b9480d Compare September 27, 2026 17:55
@lesnik512
lesnik512 merged commit 74e5da9 into main Sep 27, 2026
37 checks passed
@lesnik512
lesnik512 deleted the fix/sentry-2690-exclusion branch September 27, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant