joseluisll commented on code in PR #8717:
URL: https://github.com/apache/hadoop/pull/8717#discussion_r3946983778


##########
hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/http/TestSSLHttpServerMTLS.java:
##########
@@ -145,6 +148,15 @@ public void testUntrustedClientIsRejected() throws 
Exception {
     HttpsURLConnection conn = (HttpsURLConnection) url.openConnection();
     // presents untrustedCert; server cert is trusted via no-op TrustManager
     KeyStoreTestUtil.setAllowAllSSL(conn, untrustedCert, untrustedKeyPair);
-    assertThrows(SSLHandshakeException.class, () -> conn.getInputStream());
+    // The server rejects the certificate as soon as it arrives and drops the
+    // connection, which races the client's own last handshake flight.  When
+    // the close wins the client fails writing that flight and never reads
+    // the alert, so the refusal reaches it as a SocketException rather than
+    // an SSLHandshakeException.  What the server guarantees is that the
+    // request is refused, not which of the two the client gets to see.
+    IOException e =
+        assertThrows(IOException.class, () -> conn.getInputStream());
+    assertTrue(e instanceof SSLException || e instanceof SocketException,

Review Comment:
   Adopted, thanks for the @RepeatedTest(50) data. Now asserts IOException and 
excludes only ConnectException. Naming one cost: SocketTimeoutException extends 
InterruptedIOException, not SocketException, so a timeout used to fail here and 
now passes. Worth it to drop the dependence on hadoop.ssl.enabled.protocols, 
and a wrongly-accepted cert is still caught since getInputStream() wouldn't 
throw at all.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to