Skip to content

PYTHON-6154 Extract KMS connect helpers into dedicated modules - #34

Open
blink1073 wants to merge 4 commits into
mainfrom
PYTHON-6154
Open

blink1073 wants to merge 4 commits into
mainfrom
PYTHON-6154

Conversation

@blink1073

Copy link
Copy Markdown
Owner

Summary

Moves the KMS connect plumbing out of the encryption modules into dedicated private modules. This prepares for the CSFLE HTTP proxy KMS connect helpers (PYTHON-6147).

Motivation

The encryption modules mix encryption orchestration with socket-level connect code. The dedicated modules let the proxy work extend the connect path without touching the encryption modules.

Changes

  • Extracted the shared KMS connect types and helpers into pymongo/_kms_connect.py.
  • Moved the per-API connect logic into dedicated async and sync modules, with the public re-exports unchanged.
  • Replaced the mirrored KMS connect tests with one file parametrized over both APIs.

Testing

  • just lint and just typing pass.
  • pytest test/test_kms_connect.py -m "" passes all 33 tests.

Move the KMS connect plumbing out of the encryption modules into
dedicated private modules, prep for the CSFLE HTTP proxy KMS connect
helpers (PYTHON-6147):

- pymongo/_kms_connect.py holds KMSConnectContext, the callback type
  aliases, and _close_rejected_kms_socket, shared by both APIs.
- pymongo/{asynchronous,synchronous}/_kms_connect.py hold _connect_kms
  and _KMS_CONNECT_TIMEOUT; the synchronous module is generated by
  synchro.
- encryption_options.py re-exports the public names unchanged.
- test/asynchronous/test_kms_connect.py is expanded to cover the new
  helpers and test/test_kms_connect.py is its synchro-generated mirror.
Comment thread pymongo/_kms_connect.py Outdated

"""KMS connection helpers, shared by both the synchronous and asynchronous APIs.

Holds the ``KMSConnectContext`` passed to ``kms_connect_callback`` and the

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should be more generic, it will get out of date

Comment thread test/asynchronous/test_kms_connect.py Outdated
@@ -1,44 +1,58 @@
"""Tests for the KMS connect callback."""
"""Tests for the KMS connect callback and HTTP proxy support."""

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why are there tests added in this PR?

@blink1073
blink1073 force-pushed the PYTHON-6154 branch 2 times, most recently from 413ab61 to 5659901 Compare October 8, 2026 20:39
Deliver the PR's stated goals:

- Rename pymongo/_kms_connect.py to pymongo/_kms_connect_shared.py, so
  the shared module reads naturally next to the per-flavor
  pymongo/{asynchronous,synchronous}/_kms_connect.py modules.
- Genericize the shared module docstring: it enumerated the module's
  exact contents, which would go stale as helpers move in.
- Drop the PYTHON-6147 feature tests (HTTP proxy helpers and the prose
  class) that leaked into this refactor and broke test collection: they
  import HTTPProxyKMSConnect/AsyncHTTPProxyKMSConnect, which are added
  by PYTHON-6147, not by this PR.
- Replace the synchro-mirrored test pair with a single hand-written
  test/test_kms_connect.py, written once and parameterized over both
  APIs through a Flavor facade (the 18 pre-existing tests, 32 variants,
  byte-identical bodies). The async-side file is gone, so synchro no
  longer mirrors it.
Deliver the PR's stated goals:

- Rename pymongo/_kms_connect.py to pymongo/_kms_connect_shared.py, so
  the shared module reads naturally next to the per-API
  pymongo/{asynchronous,synchronous}/_kms_connect.py modules.
- Genericize the shared module docstring: it enumerated the module's
  exact contents, which would go stale as helpers move in.
- Drop the PYTHON-6147 feature tests (HTTP proxy helpers and the prose
  class) that leaked into this refactor and broke test collection: they
  import HTTPProxyKMSConnect/AsyncHTTPProxyKMSConnect, which are added
  by PYTHON-6147, not by this PR.
- Replace the synchro-mirrored test pair with a single hand-written
  test/test_kms_connect.py, written once and parameterized over both
  APIs through a Facade class (the 18 pre-existing tests, 32 variants,
  byte-identical bodies). The async-side file is gone, so synchro no
  longer mirrors it.
- Tighten the docstrings and comments across the touched modules and
  the test file.
Deliver the PR's stated goals:

- Rename pymongo/_kms_connect.py to pymongo/_kms_connect_shared.py, so
  the shared module reads naturally next to the per-API
  pymongo/{asynchronous,synchronous}/_kms_connect.py modules.
- Genericize the shared module docstring: it enumerated the module's
  exact contents, which would go stale as helpers move in.
- Drop the PYTHON-6147 feature tests (HTTP proxy helpers and the prose
  class) that leaked into this refactor and broke test collection: they
  import HTTPProxyKMSConnect/AsyncHTTPProxyKMSConnect, which are added
  by PYTHON-6147, not by this PR.
- Replace the synchro-mirrored test pair with a single hand-written
  test/test_kms_connect.py, written once and parameterized over both
  APIs through a Facade class (the 18 pre-existing tests, 32 variants,
  byte-identical bodies). The async-side file is gone, so synchro no
  longer mirrors it.
- Tighten the docstrings and comments across the touched modules and
  the test file.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant