[
https://issues.apache.org/jira/browse/HADOOP-19979?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18112162#comment-18112162
]
ASF GitHub Bot commented on HADOOP-19979:
-----------------------------------------
joseluisll commented on code in PR #8717:
URL: https://github.com/apache/hadoop/pull/8717#discussion_r3946983778
##########
hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/http/TestSSLHttpServerMTLS.java:
##########
@@ -145,6 +148,15 @@ public void testUntrustedClientIsRejected() throws
Exception {
HttpsURLConnection conn = (HttpsURLConnection) url.openConnection();
// presents untrustedCert; server cert is trusted via no-op TrustManager
KeyStoreTestUtil.setAllowAllSSL(conn, untrustedCert, untrustedKeyPair);
- assertThrows(SSLHandshakeException.class, () -> conn.getInputStream());
+ // The server rejects the certificate as soon as it arrives and drops the
+ // connection, which races the client's own last handshake flight. When
+ // the close wins the client fails writing that flight and never reads
+ // the alert, so the refusal reaches it as a SocketException rather than
+ // an SSLHandshakeException. What the server guarantees is that the
+ // request is refused, not which of the two the client gets to see.
+ IOException e =
+ assertThrows(IOException.class, () -> conn.getInputStream());
+ assertTrue(e instanceof SSLException || e instanceof SocketException,
Review Comment:
Adopted, thanks for the @RepeatedTest(50) data. Now asserts IOException and
excludes only ConnectException. Naming one cost: SocketTimeoutException extends
InterruptedIOException, not SocketException, so a timeout used to fail here and
now passes. Worth it to drop the dependence on hadoop.ssl.enabled.protocols,
and a wrongly-accepted cert is still caught since getInputStream() wouldn't
throw at all.
> Fix four tests that assert on work owned by another thread
> ----------------------------------------------------------
>
> Key: HADOOP-19979
> URL: https://issues.apache.org/jira/browse/HADOOP-19979
> Project: Hadoop Common
> Issue Type: Test
> Components: common, test
> Reporter: Jose Luis López
> Priority: Critical
> Labels: pull-request-available
>
> Four tests assert on, or tear down around, work owned by another thread
> without
> waiting for it or stopping it. All four fail intermittently, and none of the
> failures say anything about the code under test.
> * {{TestSSLHttpServerMTLS.testUntrustedClientIsRejected}} (common) expects an
> SSLHandshakeException, but the server's close races the client's last
> handshake
> flight; when the close wins the client gets a SocketException instead. 7 of 25
> runs fail. Assert that the request is refused rather than which exception
> carries it.
> * {{TestLogAggregationService.testLocalFileDeletionAfterUpload}}
> (nodemanager)
> waits for each log file to go, then asserts on the parent directory with no
> wait; DeletionService removes files before the directories holding them. Hit 4
> of the 60 most recent PRs, including unrelated ones. Wait for the directory
> too.
> * {{TestStandbyCheckpoints.testLastCheckpointTime}} (hdfs) waits for the
> active
> to hold the new image, then reads a standby's checkpoint time, which that wait
> does not cover: any standby may be the uploader, and it stamps
> lastCheckpointTime only after doCheckpoint() returns, so the interval can
> read 0
> against an expected 3000. Wait for that value to move.
> * {{TestTimelineReaderHBaseDown}} (timelineservice-hbase-tests) starts a
> TimelineReaderServer in all five tests and never stops one, leaking the
> TimelineStorageMonitor it schedules: non-daemon threads polling a minicluster
> the test has torn down. The module builds with forkCount 0, so these
> accumulate
> across its eleven test classes. Stop the server in a finally, as every other
> test in the module already does.
> Test-only change.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]