Repository navigation
Conversation
Move the KMS connect plumbing out of the encryption modules into dedicated private modules, prep for the CSFLE HTTP proxy KMS connect helpers (PYTHON-6147): - pymongo/_kms_connect.py holds KMSConnectContext, the callback type aliases, and _close_rejected_kms_socket, shared by both APIs. - pymongo/{asynchronous,synchronous}/_kms_connect.py hold _connect_kms and _KMS_CONNECT_TIMEOUT; the synchronous module is generated by synchro. - encryption_options.py re-exports the public names unchanged. - test/asynchronous/test_kms_connect.py is expanded to cover the new helpers and test/test_kms_connect.py is its synchro-generated mirror.
blink1073
commented
Oct 8, 2026
|
|
||
| """KMS connection helpers, shared by both the synchronous and asynchronous APIs. | ||
|
|
||
| Holds the ``KMSConnectContext`` passed to ``kms_connect_callback`` and the |
Owner
Author
There was a problem hiding this comment.
This should be more generic, it will get out of date
| @@ -1,44 +1,58 @@ | |||
| """Tests for the KMS connect callback.""" | |||
| """Tests for the KMS connect callback and HTTP proxy support.""" | |||
Owner
Author
There was a problem hiding this comment.
Why are there tests added in this PR?
blink1073
force-pushed
the
PYTHON-6154
branch
2 times, most recently
from
October 8, 2026 20:39
413ab61 to
5659901
Compare
Deliver the PR's stated goals:
- Rename pymongo/_kms_connect.py to pymongo/_kms_connect_shared.py, so
the shared module reads naturally next to the per-flavor
pymongo/{asynchronous,synchronous}/_kms_connect.py modules.
- Genericize the shared module docstring: it enumerated the module's
exact contents, which would go stale as helpers move in.
- Drop the PYTHON-6147 feature tests (HTTP proxy helpers and the prose
class) that leaked into this refactor and broke test collection: they
import HTTPProxyKMSConnect/AsyncHTTPProxyKMSConnect, which are added
by PYTHON-6147, not by this PR.
- Replace the synchro-mirrored test pair with a single hand-written
test/test_kms_connect.py, written once and parameterized over both
APIs through a Flavor facade (the 18 pre-existing tests, 32 variants,
byte-identical bodies). The async-side file is gone, so synchro no
longer mirrors it.
Deliver the PR's stated goals:
- Rename pymongo/_kms_connect.py to pymongo/_kms_connect_shared.py, so
the shared module reads naturally next to the per-API
pymongo/{asynchronous,synchronous}/_kms_connect.py modules.
- Genericize the shared module docstring: it enumerated the module's
exact contents, which would go stale as helpers move in.
- Drop the PYTHON-6147 feature tests (HTTP proxy helpers and the prose
class) that leaked into this refactor and broke test collection: they
import HTTPProxyKMSConnect/AsyncHTTPProxyKMSConnect, which are added
by PYTHON-6147, not by this PR.
- Replace the synchro-mirrored test pair with a single hand-written
test/test_kms_connect.py, written once and parameterized over both
APIs through a Facade class (the 18 pre-existing tests, 32 variants,
byte-identical bodies). The async-side file is gone, so synchro no
longer mirrors it.
- Tighten the docstrings and comments across the touched modules and
the test file.
Deliver the PR's stated goals:
- Rename pymongo/_kms_connect.py to pymongo/_kms_connect_shared.py, so
the shared module reads naturally next to the per-API
pymongo/{asynchronous,synchronous}/_kms_connect.py modules.
- Genericize the shared module docstring: it enumerated the module's
exact contents, which would go stale as helpers move in.
- Drop the PYTHON-6147 feature tests (HTTP proxy helpers and the prose
class) that leaked into this refactor and broke test collection: they
import HTTPProxyKMSConnect/AsyncHTTPProxyKMSConnect, which are added
by PYTHON-6147, not by this PR.
- Replace the synchro-mirrored test pair with a single hand-written
test/test_kms_connect.py, written once and parameterized over both
APIs through a Facade class (the 18 pre-existing tests, 32 variants,
byte-identical bodies). The async-side file is gone, so synchro no
longer mirrors it.
- Tighten the docstrings and comments across the touched modules and
the test file.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Moves the KMS connect plumbing out of the encryption modules into dedicated private modules. This prepares for the CSFLE HTTP proxy KMS connect helpers (PYTHON-6147).
Motivation
The encryption modules mix encryption orchestration with socket-level connect code. The dedicated modules let the proxy work extend the connect path without touching the encryption modules.
Changes
pymongo/_kms_connect.py.Testing
just lintandjust typingpass.pytest test/test_kms_connect.py -m ""passes all 33 tests.