Repository navigation
Keep TLS verify settings ahead of REQUESTS_CA_BUNDLE - #3447
Open
Cherith1222 wants to merge 1 commit into
Open
Cherith1222 wants to merge 1 commit into
Cherith1222 wants to merge 1 commit into
Conversation
requests lets REQUESTS_CA_BUNDLE/CURL_CA_BUNDLE replace a session's verify value, so a ca_cert (or verify=False) configured through TLSConfig was silently ignored when either variable was set. Use the client's verify setting when the request does not pass one. Fixes docker#2433 AI-assisted (Cursor); not yet reviewed by a human.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
requests replaces a session's
verifyvalue withREQUESTS_CA_BUNDLEorCURL_CA_BUNDLEwhen those variables are set. Aca_cert, orverify=False, passed throughTLSConfigwas therefore ignored.APIClientnow overridesmerge_environment_settingsand usesself.verifywhen the request does not passverify. If TLS is not configured, the environment variables still apply.Fixes #2433. #2598 is the same override.
Test Plan
On Windows, Python 3.13:
pytest tests/unit/api_test.py -k TLSVerify→ before the change, 2 failed.tests/unitwas 6 failed and 605 passed. The same command before the change was 8 failed and 603 passed. The remaining 6 failures also happen without this change and come from this machine's~/.docker/ Windows environment.Not run:
tests/integration(needs a Docker daemon), a real TLS daemon, other Python versions, and non-Windows.DCO
docker-py asks for a Developer Certificate of Origin sign-off. This commit does not include a
Signed-off-bytrailer. A human still needs to add that sign-off. It was not forged here.AI assistance
Drafted with Cursor. The account owner authorized opening this pull request. A human has not reviewed the diff. There is no
Co-authored-by,Reviewed-by, orSigned-off-bytrailer.