fix(plugin-etcd): drop the SSL Mode the driver ignores and import etcds:// into the etcd TLS Mode - #3186
Open
datlechin wants to merge 7 commits into
Open
fix(plugin-etcd): drop the SSL Mode the driver ignores and import etcds:// into the etcd TLS Mode#3186datlechin wants to merge 7 commits into
datlechin wants to merge 7 commits into
Conversation
…ds:// into the etcd TLS Mode
Signed-off-by: Ngô Quốc Đạt <datlechin@gmail.com>
Signed-off-by: Ngô Quốc Đạt <datlechin@gmail.com>
This was referenced Sep 30, 2026
Open
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
etcds://(oretcd://withsslmode=ortls=true, plain or over SSH) reported SSL Required and connected over plain HTTP: the URL parser wrote the scheme's TLS into the generic SSL Mode the driver ignores and had no way to carry theetcdTlsModefield it reads.sslmode=that re-imported as live TLS: the formatter read etcd TLS from the generic SSL setting instead ofetcdTlsMode.Tests
PluginMetadataRegistryCuratedCapabilityTests.etcdDeclaresNoGenericSSL: etcd declares no generic SSL. Fails without the fix.ConnectionURLParserTLSPortTests.etcdURLSetsTheDriverTLSMode: nine etcd URLs, plain and over SSH, each setetcdTlsModeand leave the generic SSL Mode alone, in the parsed URL and the deep-link connection. Fails without the fix.ConnectionURLParserTLSPortTests.etcdFormImportSetsTLSMode: importingetcds://into the connection form sets TLS Mode to Required, andetcd://sets it to Disabled. Fails without the fix.ConnectionURLParserTLSPortTests.otherEnginesKeepTheGenericSSLMode: Redis and PostgreSQL keep their generic SSL Mode and carry no plugin field.ConnectionURLFormatterTests.etcdTLSModeRoundTrips: an etcd connection with TLS Mode Required, Verify CA or Verify Identity copies as a URL that imports with the same TLS Mode. Fails without the fix.ConnectionURLFormatterTests.etcdURLIgnoresTheGenericSSLMode: a stale hidden SSL Mode is not written into an etcd URL. Fails without the fix.ConnectionURLParserTests.testEtcdsSchemeEnablesTLSModeandtestEtcdSchemeNoTLS: the oldtestEtcdsSchemeEnablesSSLasserted the bug (sslMode == .required) and now asserts the TLS Mode field.Docs
The docs rewrite branch covers the user-facing text for etcd TLS Mode and URL import.
Package test failure fix
The Package Tests job failed in
SyncRecordMapperTests.unknownWireValueFailsClosed: an unknown Safe Mode wire value decoded as Off rather than Confirm Writes. This was inherited from main. The shared sync mapper duplicated the model decoder and retained its old fallback.The mapper now uses
SafeModeLevel(wireValue:isReadOnly:)for both incoming records and comparisons before updating a record. Unknown values require confirmation, while the legacy read-only restriction still applies. Added regression coverage for a read-only unknown value and a rename that preserves the unknown wire value and confirmation requirement.Validation for this follow-up:
swift test --package-path Packages/TableProCore: PASS, all Swift Testing and XCTest runs passed. Swift Testing reported 1,197 tests across 142 suites with the local Xcode toolchain.git diff --check: PASS.