Skip to content

fix(P3): mTLS temp cleanup + shared HTTP TLS material - #8

Closed
songzhendong wants to merge 2 commits into
feat/grpc-http-tls-mtlsfrom
feat/grpc-http-tls-mtls-p3
Closed

songzhendong wants to merge 2 commits into
feat/grpc-http-tls-mtlsfrom
feat/grpc-http-tls-mtls-p3

Conversation

@songzhendong

@songzhendong songzhendong commented Sep 16, 2026 •

Copy link
Copy Markdown
Owner

Summary

Internal fork CI for P3 polish from apache#419 review, without updating the official PR head.

  1. Orphan mTLS cert temp: if key mkstemp fails after cert write, unlink immediately.
  2. HTTP scheme + session/context share one tls_pem_material() load (no scheme/settings TOCTOU).
  3. configure_requests_session fallback prefers configured CA path over system trust.
  4. Remove unused _extract_pem_blocks.
  5. CA snapshot hot-reload left intentional (K8s rotation via unresolved symlink fallback).

Test plan

  • tests/unit/test_tls.py + test_grpc_channel.py locally (88 passed)
  • Fork CI green (this PR)

songzhendong and others added 2 commits September 16, 2026 08:22
When the HTTP CA snapshot cannot be written, fall back to the configured
path without resolving symlinks so K8s secret rotation cannot invalidate
session.verify. Prefer cafile whenever the CA PEM includes TRUSTED
CERTIFICATE so aio cadata cannot silently drop trusted blocks from a
mixed bundle.
Share one PEM material load for HTTP scheme and session/context, prefer
configured CA on requests TLS fallback, drop orphaned cert temps and
unused _extract_pem_blocks. CA snapshot hot-reload left intentional.

Co-authored-by: Cursor <cursoragent@cursor.com>
@songzhendong songzhendong changed the title fix(P2): CA symlink no-temp fallback + mixed TRUSTED cafile fix(P3): mTLS temp cleanup + shared HTTP TLS material Sep 16, 2026
@songzhendong

Copy link
Copy Markdown
Owner Author

Superseded / obsolete on this fork:

Closing to declutter. Active work remains on #7 (DNS) and #9 (CDS).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant