[ 
https://issues.apache.org/jira/browse/HADOOP-19997?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18124640#comment-18124640
 ] 

ASF GitHub Bot commented on HADOOP-19997:
-----------------------------------------

hadoop-yetus commented on PR #8783:
URL: https://github.com/apache/hadoop/pull/8783#issuecomment-6044095544

   :confetti_ball: **+1 overall**
   
   
   
   
   
   
   | Vote | Subsystem | Runtime |  Logfile | Comment |
   |:----:|----------:|--------:|:--------:|:-------:|
   | +0 :ok: |  reexec  |   0m 25s |  |  Docker mode activated.  |
   |||| _ Prechecks _ |
   | +1 :green_heart: |  dupname  |   0m  0s |  |  No case conflicting files 
found.  |
   | +0 :ok: |  codespell  |   0m  0s |  |  codespell was not available.  |
   | +0 :ok: |  detsecrets  |   0m  0s |  |  detect-secrets was not available.  
|
   | +1 :green_heart: |  @author  |   0m  0s |  |  The patch does not contain 
any @author tags.  |
   | +1 :green_heart: |  test4tests  |   0m  0s |  |  The patch appears to 
include 1 new or modified test files.  |
   |||| _ trunk Compile Tests _ |
   | +1 :green_heart: |  mvninstall  |  28m  9s |  |  trunk passed  |
   | +1 :green_heart: |  compile  |   8m 39s |  |  trunk passed with JDK 
Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu  |
   | +1 :green_heart: |  compile  |   8m 56s |  |  trunk passed with JDK 
Ubuntu-17.0.20.1+1-1-24.04-Ubuntu  |
   | +1 :green_heart: |  checkstyle  |   0m 52s |  |  trunk passed  |
   | +1 :green_heart: |  mvnsite  |   1m  9s |  |  trunk passed  |
   | +1 :green_heart: |  javadoc  |   0m 55s |  |  trunk passed with JDK 
Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu  |
   | +1 :green_heart: |  javadoc  |   0m 54s |  |  trunk passed with JDK 
Ubuntu-17.0.20.1+1-1-24.04-Ubuntu  |
   | +1 :green_heart: |  spotbugs  |   1m 46s |  |  trunk passed  |
   | +1 :green_heart: |  shadedclient  |  16m 54s |  |  branch has no errors 
when building and testing our client artifacts.  |
   |||| _ Patch Compile Tests _ |
   | +1 :green_heart: |  mvninstall  |   0m 46s |  |  the patch passed  |
   | +1 :green_heart: |  compile  |   8m 23s |  |  the patch passed with JDK 
Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu  |
   | +1 :green_heart: |  javac  |   8m 23s |  |  the patch passed  |
   | +1 :green_heart: |  compile  |   9m  0s |  |  the patch passed with JDK 
Ubuntu-17.0.20.1+1-1-24.04-Ubuntu  |
   | +1 :green_heart: |  javac  |   9m  0s |  |  the patch passed  |
   | +1 :green_heart: |  blanks  |   0m  0s |  |  The patch has no blanks 
issues.  |
   | +1 :green_heart: |  checkstyle  |   0m 52s |  |  the patch passed  |
   | +1 :green_heart: |  mvnsite  |   1m 11s |  |  the patch passed  |
   | +1 :green_heart: |  javadoc  |   0m 53s |  |  the patch passed with JDK 
Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu  |
   | +1 :green_heart: |  javadoc  |   0m 54s |  |  the patch passed with JDK 
Ubuntu-17.0.20.1+1-1-24.04-Ubuntu  |
   | +1 :green_heart: |  spotbugs  |   1m 53s |  |  the patch passed  |
   | +1 :green_heart: |  shadedclient  |  16m 53s |  |  patch has no errors 
when building and testing our client artifacts.  |
   |||| _ Other Tests _ |
   | +1 :green_heart: |  unit  |  18m 28s |  |  hadoop-common in the patch 
passed.  |
   | +1 :green_heart: |  asflicense  |   0m 48s |  |  The patch does not 
generate ASF License warnings.  |
   |  |   | 130m  8s |  |  |
   
   
   | Subsystem | Report/Notes |
   |----------:|:-------------|
   | Docker | ClientAPI=1.56 ServerAPI=1.56 base: 
https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8783/5/artifact/out/Dockerfile
 |
   | GITHUB PR | https://github.com/apache/hadoop/pull/8783 |
   | Optional Tests | dupname asflicense compile javac javadoc mvninstall 
mvnsite unit shadedclient spotbugs checkstyle codespell detsecrets |
   | uname | Linux 3023a1f9c6f2 5.15.0-190-generic #200-Ubuntu SMP Fri Aug 7 
15:06:04 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux |
   | Build tool | maven |
   | Personality | dev-support/bin/hadoop.sh |
   | git revision | trunk / 351f410e9f9cd6d1d078dfa79dbcdaaa5e29324f |
   | Default Java | Ubuntu-17.0.20.1+1-1-24.04-Ubuntu |
   | Multi-JDK versions | 
/usr/lib/jvm/java-21-openjdk-amd64:Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu 
/usr/lib/jvm/java-17-openjdk-amd64:Ubuntu-17.0.20.1+1-1-24.04-Ubuntu |
   |  Test Results | 
https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8783/5/testReport/ |
   | Max. process+thread count | 1282 (vs. ulimit of 10000) |
   | modules | C: hadoop-common-project/hadoop-common U: 
hadoop-common-project/hadoop-common |
   | Console output | 
https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8783/5/console |
   | versions | git=2.43.0 maven=3.9.15 spotbugs=4.9.7 |
   | Powered by | Apache Yetus 0.14.1 https://yetus.apache.org |
   
   
   This message was automatically generated.
   
   




> TestSSLHttpServerMTLS.testUntrustedClientIsRejected fails intermittently with 
> SocketException instead of SSLHandshakeException
> ------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: HADOOP-19997
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19997
>             Project: Hadoop Common
>          Issue Type: Test
>          Components: common, test
>            Reporter: Jose Luis López
>            Assignee: Jose Luis López
>            Priority: Major
>              Labels: pull-request-available
>
> The test expects an {{SSLHandshakeException}}. The server rejects the client 
> certificate and drops the connection right away. That close races the 
> client's last handshake flight, and how the refusal reaches the client 
> depends on which side wins and on the TLS version:
> TLSv1.2: {{SSLHandshakeException}}.
> The close wins: the client fails writing its flight and gets a 
> {{SocketException}}.
> TLSv1.3: the client finishes its side of the handshake before the server has 
> verified the certificate. The failure then shows up on the request write as a 
> bare {{IOException}}.
> 7 of 25 runs fail. The server guarantees only that the request is refused, 
> not which exception the client sees. The fix calls {{getResponseCode()}} and 
> asserts that it throws an {{IOException}} other than {{ConnectException}}. 
> Unlike {{getInputStream()}}, {{getResponseCode()}} does not throw on an HTTP 
> error status, so an HTTP 403 or 500 sent over a handshake that should have 
> been refused still fails the test.
> Test-only change. Verified 30/30 under TLSv1.2 and TLSv1.3.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to