Skip to content

[coverage] Conformance findings: AUTH-012 #896

Description

@peco-engineer-bot

Summary

Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-python. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-python) is fixed, then flips green as a tripwire.

Findings

  • AUTH-012 [thrift]: Thrift backend silently forces https:// onto an explicit http:// server_hostname (thrift_backend.py prepends "https://" unless the composed URI already starts with it, yielding https://http://host:port/...), so the explicit plaintext opt-out is never honoured and the cleartext endpoint is never dialed; contradicts common/url_utils.py::normalize_host_with_protocol, which preserves an explicit http:// host. Kernel/SEA honours it correctly.
    • failing test: test_explicit_tls_opt_out_connects_over_plaintext_http (see the coverage PR diff under tests/)
  • AUTH-012: Thrift backend silently forces https:// onto an explicit http:// server_hostname (thrift_backend.py prepends "https://" unless the composed URI already starts with it, yielding https://http://host:port/...), so an explicit plaintext opt-out is never honoured and the cleartext endpoint is never dialed — contradicting common/url_utils.py::normalize_host_with_protocol, which documents that an explicit http:// host is preserved. The kernel/SEA backend honours it correctly.

Reproduce & Expected

AUTH-012 — Verifies the transport-scheme contract for an EXPLICIT TLS opt-out, and that TLS is never downgraded without one.

Reproduce:

  • Local cleartext HTTP listener recording every request it receives.
  • Host = the plaintext listener's host, port = its port, TLS-disable option = canonical
    falsy value (ODBC SSL=0). Attempt to open a session.
  • Same target, TLS-disable option OMITTED entirely.
  • Same target, TLS-disable option set to a non-canonical value (e.g. ture).
  • Host given WITH an explicit https:// scheme, TLS-disable option set falsy.

Expected (per the shared spec):

  • full assertion contract:
result:
- label: explicit_opt_out
  no_unsupported_option_error: true
- label: explicit_opt_out
  plaintext_session_open_request_count: 1
- label: tls_default_absent
  plaintext_session_open_request_count: 0
- label: tls_default_typo
  plaintext_session_open_request_count: 0
- label: explicit_https_host_wins
  plaintext_session_open_request_count: 0

Context

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions