Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

[coverage] Conformance findings: AUTH-015,AUTH-016

已關閉
#942 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
58/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
活躍
技術堆疊
python

研究方向

先閱讀 SSLOptions.create_ssl_context()、backend/kernel/client.py::_kernel_tls_kwargs 和 _read_pem_bytes,然後檢查 UnifiedHttpClient._setup_pool_managers。使用 coverage PR 中列出的 xfail 測試作為驗收檢查。完成表示 AUTH-015 在連線前拒絕不完整的 mTLS 設定,且 AUTH-016 在檔案遺失或為空時回報受影響的憑證或私密金鑰輸入。

由索引模型根據 Issue 內容生成。

描述

Summary

Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-python. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-python) is fixed, then flips green as a tripwire.

Findings

  • AUTH-015 [thrift, sea]: a lone _tls_client_cert_key_file (private key without client cert) is silently dropped and the connection proceeds over one-way TLS with no client identity instead of failing fast; both SSLOptions.create_ssl_context() and _kernel_tls_kwargs gate solely on if cert_file:, so the kernel's own cert/key pairing check is never reached
    • failing test: test_mutual_tls_requires_client_certificate_alongside_private_key (see the coverage PR diff under tests/)
  • AUTH-016 [thrift]: an unreadable or empty mTLS client-identity file fails with a raw stdlib error that does not identify which input failed (bare FileNotFoundError for a missing path, SSLError: [SSL] PEM lib for an empty file) because UnifiedHttpClient._setup_pool_managers calls ssl_context.load_cert_chain with no try/except
    • failing test: test_mutual_tls_rejects_unreadable_or_empty_client_identity_file (see the coverage PR diff under tests/)
  • AUTH-016 [sea]: an unreadable or empty mTLS client-identity file fails with a raw stdlib error that does not identify which input failed; the kernel path's own diagnostics in _read_pem_bytes (which name tls_client_cert_file / tls_client_cert_key_file and the path) never surface because the unconditional UnifiedHttpClient build throws load_cert_chain's raw error first
    • failing test: test_mutual_tls_rejects_unreadable_or_empty_client_identity_file (see the coverage PR diff under tests/)
  • AUTH-015: a lone _tls_client_cert_key_file (private key without client cert) is silently dropped and the connection proceeds over one-way TLS with no client identity instead of failing fast; both SSLOptions.create_ssl_context() and backend/kernel/client.py::_kernel_tls_kwargs gate solely on if cert_file:, so the kernel's own "client_key_pem is set without client_cert_pem" pairing check is never reached
  • AUTH-016: an unreadable or empty mTLS client-identity file fails with a raw stdlib error that does not identify which input failed (FileNotFoundError: [Errno 2] No such file or directory for a missing path, SSLError: [SSL] PEM lib for an empty file) because UnifiedHttpClient._setup_pool_managers calls ssl_context.load_cert_chain(cert, key, password) with no try/except; the kernel path's own diagnostics in _read_pem_bytes (which do name tls_client_cert_file / tls_client_cert_key_file and the path) never surface since the unconditional UnifiedHttpClient build throws first

Reproduce & Expected

AUTH-015 — Verifies that enabling mutual TLS with an incomplete or contradictory configuration is rejected at connect time, before any connection is established — the driver fails fast rather than silently fall…

Expected (per the shared spec):

  • full assertion contract:
result:
- label: missing_both
  error:
    contains:
    - clientcert
    - client cert
    - certificate
    - clientprivatekey
    - private key
    - required
    - missing
- label: missing_both
  connection_not_established: true
- label: missing_key
  error:
    contains:
    - clientprivatekey
    - private key
    - required
    - missing
- label: missing_key
  connection_not_established: true
- label: missing_cert
  error:
    contains:
    - clientcert
    - client cert
    - certificate
    - required
    - missing
- label: missing_cert
  connection_not_established: true
- label: plaintext
  error:
    contains:
    - ssl
    - tls
    - https
    - requires
- label: plaintext
  connection_not_established: true
- label: http_scheme
  error:
    contains:
    - https
    - ssl
    - tls
    - scheme
    - requires
- label: http_scheme
  connection_not_established: true
AUTH-016 — Verifies that with mutual TLS enabled and both client-identity inputs supplied, a client certificate or private key that cannot be loaded is rejected at connect time: the driver reports which input f…

Expected (per the shared spec):

  • full assertion contract:
result:
- label: cert_path_missing
  error:
    contains:
    - clientcert
    - client cert
    - certificate
- label: cert_path_missing
  connection_not_established: true
- label: key_path_missing
  error:
    contains:
    - clientprivatekey
    - private key
- label: key_path_missing
  connection_not_established: true
- label: cert_file_empty
  error:
    contains:
    - clientcert
    - client cert
    - certificate
- label: cert_file_empty
  connection_not_established: true
- label: key_file_empty
  error:
    contains:
    - clientprivatekey
    - private key
- label: key_file_empty
  connection_not_established: true

Context

主要語言
Python
星號
233
分支
152
平均合併
21 小時 5 分鐘
30 天內合併 PR
10

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

databricks/databricks-sql-python 的其他 Issue

查看 databricks/databricks-sql-python 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。