fix(backend): extract poll_ca_cert helper and fix PRD port docs
test / stage-firecracker-inputs (pull_request) Successful in 1s
tracker-policy-pr / check-pr (pull_request) Successful in 10s
test / unit (pull_request) Successful in 32s
test / integration-docker (pull_request) Successful in 34s
lint / lint (push) Successful in 42s
test / build-infra (pull_request) Successful in 3m58s
test / integration-firecracker (pull_request) Successful in 1m33s
test / coverage (pull_request) Failing after 1m50s
test / publish-infra (pull_request) Has been skipped

Extract the shared CA cert polling loop into `backend/util.poll_ca_cert`
(firecracker and macos backends were duplicating deadline/sleep/raise logic).
Each caller now wraps a fetch lambda and converts TimeoutError to its own
error type. Also corrects the PRD port publication line from {port}:{port}
to {host_port}:8099.
This commit is contained in:
2026-07-20 23:26:01 +00:00
parent abd3fedcea
commit 5550bb75ad
4 changed files with 40 additions and 20 deletions
+20
View File
@@ -7,6 +7,8 @@ from __future__ import annotations
import hashlib
import os
import ssl
import time
from collections.abc import Callable
from pathlib import Path
from typing import TYPE_CHECKING
@@ -15,6 +17,24 @@ from ..log import die, info
if TYPE_CHECKING:
from ..egress import EgressPlan
_CA_POLL_INTERVAL = 0.5
def poll_ca_cert(fetch: Callable[[], str | None], *, timeout: float) -> str:
"""Poll `fetch` until it returns a non-empty PEM string or `timeout` expires.
`fetch` should return the PEM on success and `None` (or empty string) when
the cert is not yet available. Raises `TimeoutError` if the cert never
appears within `timeout` seconds."""
deadline = time.monotonic() + timeout
while True:
result = fetch()
if result:
return result
if time.monotonic() >= deadline:
raise TimeoutError(f"CA cert not available after {timeout:g}s")
time.sleep(_CA_POLL_INTERVAL)
# Debian-family CA layout, shared by every backend (all guest images
# are Debian-family). AGENT_CA_PATH is the source path that