Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

google-auth: Thread safety race condition during 401 client certificate rotation in transports

Đang mở
#17,756 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
72/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
python
Lĩnh vực
networking, security

Hướng nghiên cứu

Bắt đầu trong google.auth.transport.requests và google.auth.transport.urllib3, tập trung vào các trình xử lý HTTP transport gọi configure_mtls_channel sau phản hồi 401. Theo dõi các đường dẫn cấu hình lại shared-session và pool-manager, sau đó xác minh rằng các lần xoay vòng chứng chỉ đồng thời được tuần tự hóa và không có đột biến nào đối với adapter hoặc pool-manager xảy ra đồng thời.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

auth priority: p2 type: bug

When handling 401 Unauthorized responses, the HTTP transport interceptors in google.auth.transport.requests and google.auth.transport.urllib3 attempt to auto-rotate expired mTLS client certificates by calling configure_mtls_channel().

In multi-threaded environments, if multiple threads share an authorized session and hit a 401 concurrently, they will trigger the certificate rotation at the same time. Because there is no synchronization lock, this leads to race conditions. Multiple threads will redundantly read the updated certificates and concurrently mutate the underlying session's adapter mappings (requests.Session.adapters) or pool managers, which is not thread-safe and can cause runtime exceptions.

We should introduce a lock (e.g., using threading.Lock) around the configure_mtls_channel reconfiguration block inside the transport handlers to ensure that certificate rotation is performed serially.

Ngôn ngữ chính
Python
Star
5.4k
Fork
1.8k
Merge trung bình
2 ngày 12 giờ
Pull request đã merge (30 ngày)
143

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của googleapis/google-cloud-python

Tất cả issue của googleapis/google-cloud-python

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.