Skip to content

fix(plugin-etcd): drop the SSL Mode the driver ignores and import etcds:// into the etcd TLS Mode - #3186

Open
datlechin wants to merge 7 commits into
mainfrom
fix/etcd-ssl-mode-ignored
Open

datlechin wants to merge 7 commits into
mainfrom
fix/etcd-ssl-mode-ignored

Conversation

@datlechin

@datlechin datlechin commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Summary

  • The etcd Network tab showed an SSL Mode picker that did nothing: the etcd driver builds its scheme and certificate trust from its own TLS Mode field only, while the curated snapshot and the plugin both declared generic SSL support.
  • Importing or opening etcds:// (or etcd:// with sslmode= or tls=true, plain or over SSH) reported SSL Required and connected over plain HTTP: the URL parser wrote the scheme's TLS into the generic SSL Mode the driver ignores and had no way to carry the etcdTlsMode field it reads.
  • Copy as URL for an etcd connection dropped its TLS Mode, and exported a stale hidden SSL Mode as sslmode= that re-imported as live TLS: the formatter read etcd TLS from the generic SSL setting instead of etcdTlsMode.

Tests

  • PluginMetadataRegistryCuratedCapabilityTests.etcdDeclaresNoGenericSSL: etcd declares no generic SSL. Fails without the fix.
  • ConnectionURLParserTLSPortTests.etcdURLSetsTheDriverTLSMode: nine etcd URLs, plain and over SSH, each set etcdTlsMode and leave the generic SSL Mode alone, in the parsed URL and the deep-link connection. Fails without the fix.
  • ConnectionURLParserTLSPortTests.etcdFormImportSetsTLSMode: importing etcds:// into the connection form sets TLS Mode to Required, and etcd:// sets it to Disabled. Fails without the fix.
  • ConnectionURLParserTLSPortTests.otherEnginesKeepTheGenericSSLMode: Redis and PostgreSQL keep their generic SSL Mode and carry no plugin field.
  • ConnectionURLFormatterTests.etcdTLSModeRoundTrips: an etcd connection with TLS Mode Required, Verify CA or Verify Identity copies as a URL that imports with the same TLS Mode. Fails without the fix.
  • ConnectionURLFormatterTests.etcdURLIgnoresTheGenericSSLMode: a stale hidden SSL Mode is not written into an etcd URL. Fails without the fix.
  • ConnectionURLParserTests.testEtcdsSchemeEnablesTLSMode and testEtcdSchemeNoTLS: the old testEtcdsSchemeEnablesSSL asserted the bug (sslMode == .required) and now asserts the TLS Mode field.

Docs

The docs rewrite branch covers the user-facing text for etcd TLS Mode and URL import.

Package test failure fix

The Package Tests job failed in SyncRecordMapperTests.unknownWireValueFailsClosed: an unknown Safe Mode wire value decoded as Off rather than Confirm Writes. This was inherited from main. The shared sync mapper duplicated the model decoder and retained its old fallback.

The mapper now uses SafeModeLevel(wireValue:isReadOnly:) for both incoming records and comparisons before updating a record. Unknown values require confirmation, while the legacy read-only restriction still applies. Added regression coverage for a read-only unknown value and a rename that preserves the unknown wire value and confirmation requirement.

Validation for this follow-up:

  • Reproduced the original failure locally before the fix.
  • swift test --package-path Packages/TableProCore: PASS, all Swift Testing and XCTest runs passed. Swift Testing reported 1,197 tests across 142 suites with the local Xcode toolchain.
  • SwiftLint on the two changed Swift files: zero violations.
  • git diff --check: PASS.
  • The verification helper's test parser falsely counts passing test names containing "failed" as failures. Inspected the raw log: exit 0, every run passed, no recorded issues.
  • The lint helper's separate documentation check reports existing stale references in CLAUDE.md and the verification guide. Those files are unchanged by this follow-up.
  • GitHub CI rerun pending after push.

Signed-off-by: Ngô Quốc Đạt <datlechin@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant