From 49c948d01ab1c214efbf67e19ddba4c41960abb9 Mon Sep 17 00:00:00 2001 From: maziggy Date: Sat, 29 Aug 2026 15:29:59 +0200 Subject: [PATCH] Pin the TLS floor on the cleartext-probe test's context CodeQL reports the context as allowing TLS 1.0 and 1.1, and it is right about the mechanism: create_default_context() leaves minimum_version at MINIMUM_SUPPORTED, which is the build's floor rather than a guarantee. That is the reason every context in backend/app pins it, the reason bambu_ftp.py carries a comment saying so, and the reason this same file already pins it for the TLS-1.3 case further down. Line 127 was the one that did not. The floor cannot change what the test measures. The fixture answers with a plain FTP banner and speaks no TLS, so the handshake still fails as WRONG_VERSION_NUMBER, which is the assertion this test exists to make. --- backend/tests/unit/services/test_cleartext_probe_2780.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/backend/tests/unit/services/test_cleartext_probe_2780.py b/backend/tests/unit/services/test_cleartext_probe_2780.py index 247e81201..717c2e77e 100644 --- a/backend/tests/unit/services/test_cleartext_probe_2780.py +++ b/backend/tests/unit/services/test_cleartext_probe_2780.py @@ -125,6 +125,13 @@ def _fast_probe(monkeypatch): def test_a_cleartext_banner_is_what_produces_wrong_version_number(cleartext_printer): """The exact error the affected farm logs, from a non-TLS answer.""" ctx = ssl.create_default_context() + # `create_default_context()` leaves `minimum_version` at MINIMUM_SUPPORTED, + # which is the build's floor rather than a guarantee -- the same reason + # every context in `backend/app` pins it, and the reason the TLS-13 case + # further down this file already does. The listener answers with a plain + # FTP banner and speaks no TLS at all, so the floor cannot change what this + # measures; it only stops the file asking for a protocol we would refuse. + ctx.minimum_version = ssl.TLSVersion.TLSv1_2 ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE raw = socket.create_connection(("127.0.0.1", cleartext_printer.port), 5)