Fix OkHttpGrpcSender mTLS when using the platform default trust store - #8758
Draft
thswlsqls wants to merge 1 commit into
Draft
Fix OkHttpGrpcSender mTLS when using the platform default trust store#8758thswlsqls wants to merge 1 commit into
thswlsqls wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8758 +/- ##
=========================================
Coverage 91.29% 91.29%
Complexity 10498 10498
=========================================
Files 1006 1006
Lines 28338 28344 +6
Branches 3581 3582 +1
=========================================
+ Hits 25870 25876 +6
Misses 1675 1675
Partials 793 793 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Pull request dashboard statusWaiting on the author · refreshed 2026-09-02 14:35 UTC Move out of draft to request review. Status above doesn't look right?
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #8754
Description
OkHttpGrpcSenderinstalled the clientSSLSocketFactoryonly when both anSSLContextand anX509TrustManagerwere present.TlsConfigHelper.getTrustManager()stays null unless trusted certificates are configured, sosetClientTls(...)alone skipped the branch and the client certificate was never presented.TlsUtil.defaultTrustManager(), mirroringOkHttpHttpSender, which Fix OkHttp client mTLS when using the platform default trust store #8565 (issue OTLP HTTP exporter (OkHttp sender) silently drops client mTLS certificate when no ca certificates are configured #8562) fixed the same way without touching the gRPC sender.HttpExporterBuilder.build()andGrpcExporterBuilder.build()pass the sameisPlainHttp ? null : getSslContext(), so since Fix OkHttp client mTLS when using the platform default trust store #8565 OTLP HTTP exporters already install an explicitSSLSocketFactoryon https endpoints with no TLS configured; gRPC now matches.Testing done
OkHttpGrpcSenderTest#constructor_usesDefaultTrustManagerWhenTrustManagerIsNulland#constructor_wrapsDefaultTrustManagerFailure, mirroring the tests Fix OkHttp client mTLS when using the platform default trust store #8565 added toOkHttpHttpSenderTest../gradlew :exporters:sender:okhttp:check— 48 tests passed.constructor_wrapsDefaultTrustManagerFailurefail: OkHttp's own trust manager lookup throwsNoSuchAlgorithmExceptioninstead of the wrappedIllegalStateException.constructor_usesDefaultTrustManagerWhenTrustManagerIsNullstill passes, since without the fix the branch is skipped rather than throwing.