[ 
https://issues.apache.org/jira/browse/HADOOP-19997?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18122164#comment-18122164
 ] 

ASF GitHub Bot commented on HADOOP-19997:
-----------------------------------------

joseluisll opened a new pull request, #8780:
URL: https://github.com/apache/hadoop/pull/8780

   ### Description of PR
   
   https://issues.apache.org/jira/browse/HADOOP-19997
   
   Split out of HADOOP-19979 (#8717). Unchanged from the version reviewed there.
   
   `testUntrustedClientIsRejected` expects an `SSLHandshakeException`. When the 
server rejects the client certificate, it closes the connection while the 
client is still sending its last handshake message. Depending on timing and TLS 
version, the client sees an `SSLHandshakeException`, a `SocketException`, or a 
plain `IOException`. The test only accepts the first, so it fails 
intermittently.
   
   The test now checks that the request is refused, whatever the exception:
   
   - `getResponseCode()` must throw an `IOException`. It returns HTTP error 
codes instead of throwing, so a 403 or 500 would still fail the test.
   - The exception must not be a `ConnectException`, which would mean the 
server was never reached.
   
   Test-only change, one file.
   
   ### How was this patch tested?
   
   OpenJDK 21, 50 runs each:
   
   | Client protocol | trunk | patch |
   |---|---|---|
   | JDK default | 48/50 (2 × `SocketException`) | 50/50 |
   | TLSv1.2 | 42/50 (8 × `SocketException`) | 50/50 |
   
   `TestSSLHttpServerMTLS` passes under `mvn test`. Checkstyle is clean.
   
   ### For code changes:
   
   - [x] Does the title of this PR start with the corresponding JIRA issue id 
(e.g. 'HADOOP-17799. Your PR title ...')?
   - [ ] Object storage: Have the integration tests been executed and the 
endpoint
         declared according to the connector-specific documentation? *(N/A)*
   - [ ] If adding new dependencies to the code, are these dependencies 
licensed in a way that is compatible for inclusion under [ASF 
2.0](http://www.apache.org/legal/resolved.html#category-a)? *(N/A)*
   - [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`, 
`NOTICE-binary` files? *(N/A)*
   
   ### AI Tooling
   
   If an AI tool was used:
   
   - [x] The PR includes the phrase "Contains content generated by <tool>"
         where <tool> is the name of the AI tool used.
   - [x] My use of AI contributions follows the ASF legal policy
         https://www.apache.org/legal/generative-tooling.html
   
   Contains content generated by Claude Code.




> TestSSLHttpServerMTLS.testUntrustedClientIsRejected fails intermittently with 
> SocketException instead of SSLHandshakeException
> ------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: HADOOP-19997
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19997
>             Project: Hadoop Common
>          Issue Type: Test
>          Components: common, test
>            Reporter: Jose Luis López
>            Priority: Major
>
> The test expects an {{SSLHandshakeException}}. The server rejects the client 
> certificate and drops the connection right away. That close races the 
> client's last handshake flight, and how the refusal reaches the client 
> depends on which side wins and on the TLS version:
> TLSv1.2: {{SSLHandshakeException}}.
> The close wins: the client fails writing its flight and gets a 
> {{SocketException}}.
> TLSv1.3: the client finishes its side of the handshake before the server has 
> verified the certificate. The failure then shows up on the request write as a 
> bare {{IOException}}.
> 7 of 25 runs fail. The server guarantees only that the request is refused, 
> not which exception the client sees. The fix calls {{getResponseCode()}} and 
> asserts that it throws an {{IOException}} other than {{ConnectException}}. 
> Unlike {{getInputStream()}}, {{getResponseCode()}} does not throw on an HTTP 
> error status, so an HTTP 403 or 500 sent over a handshake that should have 
> been refused still fails the test.
> Test-only change. Verified 30/30 under TLSv1.2 and TLSv1.3.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to