Repository navigation
fix(schema): drop bare 'ssl' substring match in TLS error classifier - #50
Closed
Danny-Dasilva wants to merge 2 commits into
Closed
Danny-Dasilva wants to merge 2 commits into
Danny-Dasilva wants to merge 2 commits into
Conversation
2 tasks done
… match
The keyword set ('certificate', 'x509:', 'tls: failed to verify', 'ssl') was matched
against the entire error message including the request URL. Any host containing 'ssl'
in its name (e.g. self-signed.bad**ssl**.com) caused every non-TLS error (EOF,
idle-close) to be tagged TLSError instead of ConnectionError/CycleTLSError.
Drop the bare 'ssl' term — Go's actual TLS error vocabulary is covered by the other
three markers ('certificate', 'x509:', 'tls: failed to verify'). The status==495 +
'handshake' branch above remains unchanged.
Includes 5 regression tests in tests/test_error_classification.py covering both
the bug case and existing-behavior preservation.
Danny-Dasilva
force-pushed
the
fix/classifier-substring-leak
branch
from
April 27, 2026 19:11
76f31fa to
c398d21
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The keyword set
('certificate', 'x509:', 'tls: failed to verify', 'ssl')incycletls/schema.py:567-576was substring-matched against the entire error message including the request URL. Any host containingsslin its name (e.g.self-signed.badssl.com) caused every non-TLS error (EOF, idle-close) to be misclassified asTLSErrorinstead ofConnectionError/CycleTLSError.Fix: drop the bare
'ssl'term — Go's actual TLS error vocabulary is fully covered by the other three markers. The status==495 + 'handshake' branch above remains unchanged.Why
Confirmed by the source-tracer investigator while triaging the recurring badssl flake. Exact reproduction: `'Get "https://self-signed.badssl.com\": http: server closed idle connection'` was being raised as TLSError when it's a transport idle-close.
Test plan
Part of the badssl-flake remediation series (#48 marks tests as @LiVe; this is the root-cause Python fix).