aminghadersohi commented on PR #44723: URL: https://github.com/apache/superset/pull/44723#issuecomment-5903297212
### Acceptance at 0afef7e82eb705b517f70789ec61d750b7954454 **PASS — 84/84 live cases, no fix needed.** Tested the worktree's `MySQLEngineSpec.build_sqlalchemy_uri` (toggle), `adjust_engine_params`, and SQLAlchemy `create_engine` in-process; no running web app or mocked driver. MySQL **8.4.11**, SQLAlchemy **2.0.52**, mysqlclient **2.2.8 / MariaDB Connector/C 3.3.19**, PyMySQL **1.2.0**, Connector/Python **9.3.0**. Command: `PYTHONPATH=$PWD:$PWD/superset-core/src:/tmp/r144 SUPERSET_CONFIG_PATH=/tmp/r144/mysql_accept_config.py .venv/bin/python /tmp/r144/accept44723.py` → **84/84 PASS**. Each successful connection executed `SHOW STATUS LIKE 'Ssl_cipher'` and `SELECT 1`. | Criterion / command | Observed result | |---|---| | **PASS: SSL toggle and `?ssl=1`**, all four URI spellings (`mysql://`, `mysql+mysqldb://`, `mysql+pymysql://`, `mysql+mysqlconnector://`), trusted test CA | `Ssl_cipher=TLS_AES_256_GCM_SHA384` in all **16** cases, with server TLS optional and after `SET GLOBAL require_secure_transport=ON`. | | **PASS: fail closed**, same requests against `mysql:8 --tls-version=` | All **8** attempts rejected with error **2026**: mysqlclient “SSL is required, but the server does not support it”; PyMySQL/Connector “SSL is required but the server doesn't support it”. No successful cleartext connection. | | **PASS: additional request/native paths**, `connect_args.ssl=True`; `ssl=1` plus explicit `ssl_mode=REQUIRED` (mysqlclient) / `ssl_verify_cert=True` (other drivers); native verified TLS without toggle | **36/36**: cipher above for TLS optional/required; error 2026 on non-TLS server. mysqlclient REQUIRED correctly becomes VERIFY_CA for the actual linked MariaDB client. | | **PASS: ordinary connections**, no request and explicitly disabled TLS | **24/24**: all non-TLS-server controls connect with empty cipher; explicit TLS-disabled connections also work on TLS-optional server and are rejected with **3159** when secure transport is required. With no request, mysqlclient uses cleartext / gets 3159 when required; the other drivers negotiate TLS on the TLS server. | `python -m pytest tests/unit_tests/db_engine_specs/test_mysql.py tests/unit_tests/db_engine_specs/test_mysql_iam.py -q` → **152 passed**. `pre-commit run --files UPDATING.md superset/db_engine_specs/mysql.py tests/unit_tests/db_engine_specs/test_mysql.py` (with worktree `PYTHONPATH`) → **all applicable hooks passed**, including mypy and pylint. Existing review findings remain addressed: boolean/Aurora Data API/hostname-option fixes at `42404b91a6`; migration/CA/Aurora/SSH guidance, generated-docs source, old-PyMySQL gate and client-library-specific REQUIRED handling at `485c4272bc`; UPDATING placement and further branch tests at `0afef7e82e`. All eight inline threads were already resolved; none reopened. Oracle libmysqlclient behavior is unit-covered, not live-tested here. Cleanup: `docker stop acceptance-44723-tls acceptance-44723-plain && docker rm -v acceptance-44723-tls acceptance-44723-plain` completed; both containers removed. Datadirs used tmpfs; no volumes created. No commits or pushes. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
