rusackas opened a new pull request, #44910:
URL: https://github.com/apache/superset/pull/44910

   ### SUMMARY
   apache/superset#44723 fixed a silent TLS downgrade: mysqlclient maps 
`ssl_mode=REQUIRED` to *opportunistic* TLS when linked against MariaDB 
Connector/C (the library CI's apt-installed mysqlclient actually links 
against), so a server offering no TLS at all is silently accepted in cleartext 
instead of rejected — exactly the failure mode the fix closes by substituting 
`VERIFY_CA` for that client library. This had zero testcontainers coverage 
before this PR (only pagination/column-mapping tests existed).
   
   A mocked cursor can't observe this: the behavior lives in the C client 
library's own TLS negotiation, decided once, at real connection time, against a 
real server's real TLS posture.
   
   Two containers cover the two-sided property under test:
   - `test_require_mysql_tls_fails_closed_without_server_tls`: a `--ssl=0` 
server must make the connection fail, never silently downgrade.
   - `test_require_mysql_tls_connects_with_verified_tls`: the default 
TLS-capable server must still let a legitimate encrypted connection through — 
asserted via a non-empty `Ssl_cipher`, not just a successful handshake, since a 
fix that merely refused every connection would pass the first check alone and 
hide behind it.
   
   Both go through `MySQLEngineSpec.adjust_engine_params` directly (the real 
production call path, including driver-name resolution from a bare `mysql://` 
URL), not a shortcut around it.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   N/A — test-only change.
   
   ### TESTING INSTRUCTIONS
   Could not be run locally in this environment (mysqlclient has a 
pre-existing, unrelated native-library linking issue against this machine's 
Homebrew-installed libmysqlclient; CI installs it via apt on Linux, where this 
does not occur — see the module docstring). CI's `Testcontainers` workflow will 
run it for real against fresh `mysql:8.0` containers (one with `--ssl=0`, one 
default).
   
   ### ADDITIONAL INFORMATION
   - [ ] Has associated issue:
   - [ ] Required feature flags:
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
     - [ ] Migration is atomic, supports rollback & is backwards-compatible
     - [ ] Confirm DB migration upgrade and downgrade tested
     - [ ] Runtime estimates and downtime expectations provided
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to