• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

grpc / grpc-java / #20501
89%

Build:
DEFAULT BRANCH: master
Ran 06 Oct 2026 03:52AM UTC
Jobs 1
Files 697
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

06 Oct 2026 03:39AM UTC coverage: 89.371% (+0.002%) from 89.369%
#20501

push

github

web-flow
xds: Keep saved certs and roots after SslContext update (#13085)

Fixes #13058.

`CertProviderSslContextProvider` cleared the saved key, cert chain and
trusted roots after every `SslContext` build (`clearKeysAndCerts()`).
When the identity cert and the CA roots come from separate certificate
provider instances (for example, two `file_watcher` instances with
different refresh intervals), the roots provider usually does not send
another update. The next identity cert rotation then found no roots and
did not rebuild the `SslContext`, so new connections kept the old,
possibly expired, identity cert. The same problem occurred with a single
shared provider instance when only the identity cert changed.

This change removes `clearKeysAndCerts()`. The saved identity
credentials and trust roots are now kept as the latest known values. An
update from either provider rebuilds the `SslContext` with the latest
values from both, as discussed in the issue. This generalizes #12340,
which kept the roots only when using system root certs.

Behavior changes:
- A root-only update now rebuilds the `SslContext`. Before, it did not,
because the key had been cleared.
- When a shared provider instance updates the cert and the roots in the
same refresh, the `SslContext` is built twice. The first build briefly
uses the new identity cert with the old roots. The next update
immediately replaces it.

Tests:
- Updated the existing client and server tests for the new behavior, and
removed assertions on the internal `saved*` fields after a build.
- Added client and server tests for separate cert and root instances:
cert-only updates, root-only updates, and updates that the other
instance must ignore.
- Added client and server tests for a shared instance with cert-only
updates.
- The new `*UpdateOnly` tests fail without the change in
`CertProviderSslContextProvider`.

39259 of 43928 relevant lines covered (89.37%)

0.89 hits per line

Coverage Regressions

Lines Coverage ∆ File
3
95.1
-0.43% ../core/src/main/java/io/grpc/internal/RetriableStream.java
3
76.24
-2.97% ../servlet/src/main/java/io/grpc/servlet/AsyncServletOutputStreamWriter.java
2
75.0
-0.86% ../servlet/src/main/java/io/grpc/servlet/ServletServerStream.java
1
90.97
-0.35% ../core/src/main/java/io/grpc/internal/DelayedClientCall.java
1
97.35
-0.88% ../okhttp/src/main/java/io/grpc/okhttp/OkHttpServerStream.java
Jobs
ID Job ID Ran Files Coverage
1 #20501.1 06 Oct 2026 03:52AM UTC 697
89.37
Source Files on build #20501
  • Tree
  • List 697
  • Changed 9
  • Source Changed 0
  • Coverage Changed 9
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #20501
  • 08bcf601 on github
  • Prev Build on master
  • Next Build on master
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc