Skip to content

Keep the test CA in memory - #857

Draft
ilyazub wants to merge 1 commit into
httprb:mainfrom
serpapi:test-ca-in-memory
Draft

ilyazub wants to merge 1 commit into
httprb:mainfrom
serpapi:test-ca-in-memory

Conversation

@ilyazub

@ilyazub ilyazub commented Oct 3, 2026

Copy link
Copy Markdown

SSLHelper generates its CA once per process but writes it to the shared tmp/certs/ca.crt, and OpenSSL reads ca_file only when a context sets up a handshake. With several test processes running at once, as mutant's workers do, the last one to write the file replaces everyone else's CA, and their TLS tests fail with "certificate verify failed (certificate signature failure)".

This trusts the CA through an in-memory OpenSSL::X509::Store instead. The server context drops ca_file too, since it doesn't verify clients, and tmp/certs isn't written anymore.

.mutant.yml ignores the TLS-touching subjects today, so CI doesn't hit this. I did when mutating HTTP::Client code for another branch:

  • mutant -j 16 without this: neutral failures, "certificate signature failure"
  • with it: 95/95 killed in 10.5 s, vs about 115 s at -j 1
  • MRI 3.4.8: 2332 runs, 0 failures on seeds 4242 and 777, 100% line and branch coverage, rubocop clean
  • JRuby 10.1.2.0: 2331 runs, 0 failures

SSLHelper generates its CA once per process but wrote it to the shared
tmp/certs/ca.crt, and OpenSSL only reads ca_file when a context is set
up for a handshake. When tests run in several processes at once, as
mutant's workers do, the last process to write the file replaces every
other process's CA, and their handshakes fail with "certificate verify
failed (certificate signature failure)".

Trust the CA through an in-memory certificate store instead. The server
context no longer sets ca_file, since it does not verify clients.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant