google-auth: connection leaks in urllib3 transport and metadata helper during mTLS updates
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 72/100
Línea de trabajo
Lee google/auth/transport/urllib3.py y google/auth/compute_engine/_metadata.py, comenzando por configure_mtls_channel y la ruta de montaje de MdsMtlsAdapter por solicitud. Confirma que el PoolManager antiguo se limpia y que el adaptador de metadatos se reutiliza o se cierra en lugar de acumular sockets; después, añade o ejecuta pruebas de regresión específicas para ambas rutas.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
When mTLS is configured or dynamically updated, the SDK creates and mounts new HTTP adapters/transports but leaves the old ones hanging. While PR #17689 addressed this for the requests transport, the leak still exists in two other places:
-
urllib3 transport (
google/auth/transport/urllib3.py)
Inconfigure_mtls_channel,self.http = new_httpreplaces the old PoolManager. We need to call.clear()on the oldPoolManagerinstance before overwriting it so that the active connection pool is cleaned up. -
Compute Engine metadata (
google/auth/compute_engine/_metadata.py)
If mTLS is enabled,_metadata.pyinstantiates and mounts a newMdsMtlsAdapteron the session for every single request. Overwriting the mounted adapter without closing the old one leaks sockets. We should either cache and reuse the adapter or close the old one before mounting.
- Lenguaje dominante
- Python
- Estrellas
- 5.4k
- Forks
- 1.8k
- Merge medio
- 2 d 14 h
- PR fusionados (30 d)
- 142
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de googleapis/google-cloud-python
-
api: spanner type: feature request
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
googleapis/google-cloud-python#18584 ·
Los mantenedores suelen responder en 1 día
-
ci: remove UV_PRERELEASE workaround once Python 3.15 is officially releasedPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
googleapis/google-cloud-python#18532 ·
Los mantenedores suelen responder en 1 día
-
auth: call_client_cert_callback() discards passphrase for encrypted keysPosiblemente ocupada @kwy404 la tomó hace 9 días. Abierto
Dificultad 1/5 1-3 horas Aptitud para principiantes 92/100
googleapis/google-cloud-python#18467 ·
Los mantenedores suelen responder en 1 día
-
auth: `impersonated_credentials` loses `subject` on copy, so `with_scopes()` and `with_quota_project()` turn off domain wide delegationPosiblemente ocupada @Om-singhaI la tomó hace 21 días. Abiertoauth priority: p2 type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
googleapis/google-cloud-python#18428 ·
Los mantenedores suelen responder en 1 día
-
priority: p2 type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
googleapis/google-cloud-python#18375 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de googleapis/google-cloud-python
Issues similares
-
feedback simulation workshop
Dificultad 2/5 1-3 horas Aptitud para principiantes 73/100
githubnext/gh-aw-workshop#4455 ·
Los mantenedores suelen responder en 1 día
-
Triage 🩺
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día
-
[BUG] Container scenario crashes without expected_recovery_time, kube DNS example uses retry_waitAbiertoneeds-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 77/100
krkn-chaos/krkn#1627 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
NousResearch/hermes-agent#136483 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día