Skip to content

Deprecate TCPConnector ssl - #13829

Merged
Dreamsorcerer merged 1 commit into
masterfrom
deprecate-conn-ssl
Sep 27, 2026
Merged

Dreamsorcerer merged 1 commit into
masterfrom
deprecate-conn-ssl

Conversation

@Dreamsorcerer

Copy link
Copy Markdown
Member

No description provided.

@Dreamsorcerer Dreamsorcerer added the backport:skip Skip backport bot label Sep 27, 2026
@codecov

codecov Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.03%. Comparing base (a921cfd) to head (f027278).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #13829      +/-   ##
==========================================
- Coverage   99.04%   99.03%   -0.01%     
==========================================
  Files         135      135              
  Lines       51378    51399      +21     
  Branches     2693     2694       +1     
==========================================
+ Hits        50885    50904      +19     
- Misses        371      372       +1     
- Partials      122      123       +1     
Flag Coverage Δ
Autobahn 21.91% <10.20%> (-0.01%) ⬇️
CI-GHA 98.86% <100.00%> (-0.01%) ⬇️
OS-Linux 98.65% <100.00%> (+<0.01%) ⬆️
OS-Windows 97.27% <100.00%> (-0.01%) ⬇️
OS-macOS 98.13% <100.00%> (-0.01%) ⬇️
Py-3.10 98.08% <95.91%> (+<0.01%) ⬆️
Py-3.11 98.30% <100.00%> (-0.01%) ⬇️
Py-3.12 98.39% <100.00%> (-0.01%) ⬇️
Py-3.13 98.37% <100.00%> (-0.01%) ⬇️
Py-3.14 98.41% <100.00%> (-0.01%) ⬇️
Py-3.15 98.41% <100.00%> (+<0.01%) ⬆️
Py-3.15t 97.78% <100.00%> (-0.01%) ⬇️
Py-pypy-3.11 97.37% <100.00%> (+0.01%) ⬆️
VM-macos 98.13% <100.00%> (-0.01%) ⬇️
VM-ubuntu 98.65% <100.00%> (+<0.01%) ⬆️
VM-windows 97.27% <100.00%> (-0.01%) ⬇️
cython-coverage 83.22% <75.00%> (-0.03%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@greptile-apps

greptile-apps Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Medium risk] Deprecates TCPConnector ssl parameter, moves it to ClientSession.

The loss of functional coverage is non-blocking; connector-level pinning still works.

Reviews (1) · Last reviewed commit: "Deprecate TCPConnector ssl"

Comment thread tests/test_client_functional.py
@greptile-apps

greptile-apps Bot commented Sep 27, 2026

Copy link
Copy Markdown

Comments Outside Diff

These findings sit on lines the diff does not cover, so they could not be posted inline. Each one leaves this list once its file changes.

  • P2 Real-HTTPS coverage for deprecated connector-level fingerprint pinning was removed ▶

    • Bug
      • The migrations at tests/test_client_functional.py:857-865 and :883-891 leave the functional success and mismatch tests exercising session-level pins. The new tests/test_connector.py:2732-2741 test checks _get_fingerprint with a mock request, but does not establish HTTPS or verify certificate acceptance and rejection. This is a meaningful regression-test gap for a deprecated API that remains supported; the executed repro found no current compatibility failure.
    • Cause
      • Both real-HTTPS tests were migrated away from connector-level ssl without retaining equivalent end-to-end cases.
    • Fix
      • Retain real-HTTPS matching-pin and mismatched-pin tests using TCPConnector(ssl=Fingerprint(...)), explicitly expecting its deprecation warning.

@codspeed

codspeed Bot commented Sep 27, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 97 untouched benchmarks
⏩ 83 skipped benchmarks1


Comparing deprecate-conn-ssl (f027278) with master (a921cfd)

Open in CodSpeed

Footnotes

  1. 83 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@Dreamsorcerer
Dreamsorcerer merged commit 25f3057 into master Sep 27, 2026
60 of 61 checks passed
@Dreamsorcerer
Dreamsorcerer deleted the deprecate-conn-ssl branch September 27, 2026 18:18
ishan-1010 added a commit to ishan-1010/aiohttp that referenced this pull request Sep 27, 2026
Upstream deprecated TCPConnector's ssl parameter in favor of
ClientSession/per-request ssl. Both still resolve to the same
module-level _SSL_CONTEXT_VERIFIED default, so kept the truststore
note alongside the new deprecation notice instead of dropping either.
ishan-1010 added a commit to ishan-1010/aiohttp that referenced this pull request Sep 27, 2026
…nector ssl)

That commit stopped constructing a TCPConnector in
test_static_file_ssl, passing ssl straight to aiohttp_client instead,
so the leftover conn.aclose() teardown call had nothing left to
close. Dropped it.

It also added three new tests that call conn.close() as plain
teardown, not intentionally exercising the deprecation. Since
BaseConnector.close() now warns, filterwarnings=error turned that
into a failure. Switched those three to aclose(), matching the same
fix already applied to every other internal call site in this rename.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport:skip Skip backport bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant