refactor(proxy): match ssl_verify off detection to runtime str_to_bool semantics

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
yucheng 2026-09-23 07:31:01 +00:00
parent 67895955f6
commit 5c237840f4
3 changed files with 16 additions and 9 deletions

View file

@ -6,6 +6,8 @@ from typing import Final
from typing_extensions import assert_never
from litellm.secret_managers.main import str_to_bool
FIPS_MODE_ENV_VAR: Final = "LITELLM_FIPS_MODE"
SSL_VERIFY_ENV_VAR: Final = "SSL_VERIFY"
SSL_VERIFY_SETTING: Final = "litellm_settings.ssl_verify"
@ -146,6 +148,6 @@ def _is_off(value: object) -> bool:
case bool():
return value is False
case str():
return value.strip().lower() in _FALSE_VALUES - {""}
return str_to_bool(value) is False
case _:
return False

View file

@ -140,6 +140,13 @@ def launched_proxy(
assert root_stopped and not remaining, "Owned proxy required forced cleanup"
def _is_ready(client: httpx.Client) -> bool:
try:
return client.get("/health/readiness", timeout=2).status_code == 200
except httpx.TransportError:
return False
def refused_boot_log(
gateway: Gateway,
directory: Path,
@ -152,11 +159,9 @@ def refused_boot_log(
with httpx.Client(base_url=f"http://127.0.0.1:{launched.port}", timeout=15, trust_env=False) as client:
deadline: Final = time.monotonic() + 70
while launched.process.poll() is None:
try:
ready: Final = client.get("/health/readiness", timeout=2).status_code == 200
except httpx.TransportError:
ready = False
assert not ready, f"Proxy became ready instead of refusing to boot:\n{launched.log.read_text()}"
assert not _is_ready(client), (
f"Proxy became ready instead of refusing to boot:\n{launched.log.read_text()}"
)
assert time.monotonic() < deadline, "Proxy neither exited nor became ready within the deadline"
time.sleep(0.1)
assert launched.process.returncode != 0, (

View file

@ -85,10 +85,10 @@ def test_on_with_a_non_enforcing_provider_is_refused_and_names_the_fix():
"ssl_env, ssl_setting, sources",
[
("false", True, ("SSL_VERIFY",)),
("0", True, ("SSL_VERIFY",)),
(" FALSE ", True, ("SSL_VERIFY",)),
(None, False, ("litellm_settings.ssl_verify",)),
(None, "False", ("litellm_settings.ssl_verify",)),
("no", False, ("SSL_VERIFY", "litellm_settings.ssl_verify")),
("false", False, ("SSL_VERIFY", "litellm_settings.ssl_verify")),
],
)
def test_disabled_tls_verification_is_refused_naming_every_source(ssl_env, ssl_setting, sources):
@ -99,7 +99,7 @@ def test_disabled_tls_verification_is_refused_naming_every_source(ssl_env, ssl_s
assert "TLS certificate verification is disabled by " + " and ".join(sources) in str(refused.value)
@pytest.mark.parametrize("ssl_setting", [True, "true", "/etc/ssl/certs/ca.pem", None, ""])
@pytest.mark.parametrize("ssl_setting", [True, "true", "/etc/ssl/certs/ca.pem", None, "", "0", "no"])
def test_verified_or_custom_bundle_tls_settings_are_not_treated_as_disabled(ssl_setting):
assert _verdict("true", enforcing=True, ssl_setting=ssl_setting) == FipsModeOn()