Skip to content

Fix pending SSL data handling in stream client - #2646

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes-client:masterfrom
mihirduvedi:fix-2414-ssl-pending
Aug 7, 2026
Merged

Fix pending SSL data handling in stream client#2646
kubernetes-prow[bot] merged 1 commit into
kubernetes-client:masterfrom
mihirduvedi:fix-2414-ssl-pending

Conversation

@mihirduvedi

Copy link
Copy Markdown
Contributor

What type of PR is this?

/kind bug

What this PR does / why we need it:

WSClient.update() can wait on poll() or select() even when an SSL socket already has decrypted data buffered internally. This can delay stream output indefinitely when no additional network event arrives.

This change checks SSLSocket.pending() before polling and immediately processes a WebSocket frame when buffered SSL data is available. It also adds a deterministic regression test using timeout=None that verifies neither polling path is entered.

Which issue(s) this PR fixes:

Fixes #2414

Special notes for your reviewer:

This addresses the unit-test request from #2422 and the review feedback to avoid calling poll() or select() when SSL data is already pending.

Tests:

  • python -m pytest -q kubernetes/base/stream/ws_client_test.py — 17 passed
  • python -m pytest -q kubernetes/base --ignore=kubernetes/base/dynamic/test_client.py --ignore=kubernetes/base/dynamic/test_discovery.py — 143 passed

The two excluded dynamic-client modules require a live Kubernetes cluster.

Does this PR introduce a user-facing change?

Fixed stream operations over SSL to process buffered WebSocket data without waiting for another socket event.

Additional documentation e.g., KEPs (Kubernetes Enhancement Proposals), usage docs, etc.:

NONE

@kubernetes-prow kubernetes-prow Bot added release-note Denotes a PR that will be considered when it comes time to generate release notes. kind/bug Categorizes issue or PR as related to a bug. labels Jul 22, 2026
@linux-foundation-easycla

linux-foundation-easycla Bot commented Jul 22, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: mihirduvedi / name: mihirduvedi (730aa78)

@kubernetes-prow kubernetes-prow Bot added the cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. label Jul 22, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

Welcome @mihirduvedi!

It looks like this is your first PR to kubernetes-client/python 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes-client/python has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@kubernetes-prow kubernetes-prow Bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Jul 22, 2026
@kubernetes-prow
kubernetes-prow Bot requested review from fabianvf and roycaihw July 22, 2026 23:17
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. and removed cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Jul 22, 2026
@roycaihw

Copy link
Copy Markdown
Member

/assign

@mihirduvedi Can you also check if the asyncio client needs the same fix? https://github.com/kubernetes-client/python/tree/master/kubernetes/aio

@mihirduvedi

Copy link
Copy Markdown
Contributor Author

Thanks for the review. I checked the asyncio client carefully. The reported issue is fixed in the synchronous client, and the asyncio client does not require the same change.

kubernetes/aio/stream/ws_client.py delegates WebSocket reads to aiohttp through async for msg in ws rather than polling the raw SSL socket. aiohttp drains decrypted data into its WebSocket parser and queues each complete frame.

I also tested the equivalent edge case over WSS by sending two channel frames in a single TLS transport write through the Kubernetes WsApiClient; both frames were received correctly.

Validation:

  • Async stream tests: 5 passed
  • Combined sync and async stream tests: 22 passed

Therefore, no asyncio source change is necessary.

@yliaog

yliaog commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

/lgtm

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 6, 2026
@mihirduvedi

Copy link
Copy Markdown
Contributor Author

@roycaihw The failed GitHub Actions jobs stopped during setup because GitHub could not download the required actions (Service Unavailable); no tests were executed in those jobs. Could you rerun the failed jobs?

@yliaog

yliaog commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

/close

@kubernetes-prow kubernetes-prow Bot closed this Aug 7, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

@yliaog: Closed this PR.

Details

In response to this:

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@yliaog

yliaog commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

/reopen

@kubernetes-prow kubernetes-prow Bot reopened this Aug 7, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

@yliaog: Reopened this PR.

Details

In response to this:

/reopen

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@yliaog

yliaog commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

thanks for the PR
/lgtm
/approve

@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: mihirduvedi, yliaog

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 7, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit baa6d8c into kubernetes-client:master Aug 7, 2026
13 of 18 checks passed
@mihirduvedi
mihirduvedi deleted the fix-2414-ssl-pending branch August 7, 2026 05:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/bug Categorizes issue or PR as related to a bug. lgtm "Looks good to me", indicates that a PR is ready to be merged. release-note Denotes a PR that will be considered when it comes time to generate release notes. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

stream api will lose data when use sslsocket

3 participants