Skip to content

[coverage] Conformance findings: AUTH-012,AUTH-015 #892

Description

@peco-engineer-bot

Summary

Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-python. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-python) is fixed, then flips green as a tripwire.

Findings

  • AUTH-012 [sea]: kernel (SEA) rejects the untrusted server cert but the error drops rustls's UnknownIssuer cause, reporting only "http request failed after N attempts: error sending request for url (…)" — a TLS-trust misconfiguration is indistinguishable from a network outage
    • failing test: test_server_certificate_validation_enabled_by_default (see the coverage PR diff under tests/)
  • AUTH-015 [thrift]: mTLS client-identity options get no both-or-neither validation: an unpaired _tls_client_cert_file reaches SSLContext.load_cert_chain(certfile=…, keyfile=None) and surfaces OpenSSL's opaque "[SSL] PEM lib", naming neither the supplied option nor the missing private key
    • failing test: test_mutual_tls_client_certificate_options_validated (see the coverage PR diff under tests/)
  • AUTH-012: kernel (SEA) backend rejects an untrusted server certificate but its error drops the rustls cause, reporting only "http request failed after N attempts: error sending request for url (…)" — a TLS-trust misconfiguration is indistinguishable from a network outage
  • AUTH-015: mTLS client-identity options get no both-or-neither validation: an unpaired _tls_client_cert_file reaches load_cert_chain(certfile=…, keyfile=None) on the Thrift path and surfaces OpenSSL's opaque [SSL] PEM lib, naming neither the supplied option nor the missing private key

Reproduce & Expected

AUTH-012 — Verifies the driver is secure-by-default: with NO TLS options supplied, the driver performs full chain + hostname verification of the server certificate, and a server whose certificate does NOT chain…

Expected (per the shared spec):

  • [thrift] exactly 0 OpenSession call(s)
  • [sea] exactly 0 CreateSession call(s)
  • full assertion contract:
result:
- error:
    contains:
    - certificate
    - cert
    - self-signed
    - self signed
    - unable to verify
    - unable to get local issuer
    - tls
    - ssl
    - handshake
protocol:
  thrift:
  - call_count:
      method: OpenSession
      expected: 0
  sea:
  - call_count:
      operation: CreateSession
      expected: 0

AUTH-015 — Verifies that the mutual-TLS (mTLS) client-identity options are validated on the client side with clear, actionable errors instead of failing opaquely deep in the TLS handshake.

Expected (per the shared spec):

  • [thrift] exactly 0 OpenSession call(s)
  • [sea] exactly 0 CreateSession call(s)
  • full assertion contract:
result:
- label: both_or_neither
  error:
    contains:
    - client cert
    - clientcert
    - client key
    - clientkey
    - private key
    - mutual
    - mtls
    - both
- label: malformed_pem
  error:
    contains:
    - pem
    - certificate
    - client cert
    - clientcert
protocol:
  thrift:
  - call_count:
      method: OpenSession
      expected: 0
  sea:
  - call_count:
      operation: CreateSession
      expected: 0

Context

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions