rusackas opened a new pull request, #44910: URL: https://github.com/apache/superset/pull/44910
### SUMMARY apache/superset#44723 fixed a silent TLS downgrade: mysqlclient maps `ssl_mode=REQUIRED` to *opportunistic* TLS when linked against MariaDB Connector/C (the library CI's apt-installed mysqlclient actually links against), so a server offering no TLS at all is silently accepted in cleartext instead of rejected — exactly the failure mode the fix closes by substituting `VERIFY_CA` for that client library. This had zero testcontainers coverage before this PR (only pagination/column-mapping tests existed). A mocked cursor can't observe this: the behavior lives in the C client library's own TLS negotiation, decided once, at real connection time, against a real server's real TLS posture. Two containers cover the two-sided property under test: - `test_require_mysql_tls_fails_closed_without_server_tls`: a `--ssl=0` server must make the connection fail, never silently downgrade. - `test_require_mysql_tls_connects_with_verified_tls`: the default TLS-capable server must still let a legitimate encrypted connection through — asserted via a non-empty `Ssl_cipher`, not just a successful handshake, since a fix that merely refused every connection would pass the first check alone and hide behind it. Both go through `MySQLEngineSpec.adjust_engine_params` directly (the real production call path, including driver-name resolution from a bare `mysql://` URL), not a shortcut around it. ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF N/A — test-only change. ### TESTING INSTRUCTIONS Could not be run locally in this environment (mysqlclient has a pre-existing, unrelated native-library linking issue against this machine's Homebrew-installed libmysqlclient; CI installs it via apt on Linux, where this does not occur — see the module docstring). CI's `Testcontainers` workflow will run it for real against fresh `mysql:8.0` containers (one with `--ssl=0`, one default). ### ADDITIONAL INFORMATION - [ ] Has associated issue: - [ ] Required feature flags: - [ ] Changes UI - [ ] Includes DB Migration (follow approval process in [SIP-59](https://github.com/apache/superset/issues/13351)) - [ ] Migration is atomic, supports rollback & is backwards-compatible - [ ] Confirm DB migration upgrade and downgrade tested - [ ] Runtime estimates and downtime expectations provided - [ ] Introduces new feature or API - [ ] Removes existing feature or API 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
