1fanwang opened a new pull request, #4019: URL: https://github.com/apache/iceberg-python/pull/4019
<!-- Closes #3866 --> Closes https://github.com/apache/iceberg-python/issues/3866 # Rationale for this change The PyArrow FileIO path accepted s3.ssl.ca-cert in catalog properties, but it did not pass the value into PyArrow's S3 client. Users with private S3 endpoints or self signed certificates could still hit curlCode: 60 during PyArrow reads and writes. This change maps the existing Iceberg property to PyArrow's TLS CA file argument for S3 and OSS filesystems. PyArrow added that argument in 21.0.0, so older PyArrow versions now fail fast only when the CA certificate property is set. ## Are these changes tested? Yes. <details><summary>Raw logs</summary> Before 545cb661: ```text $ uv run python -m pytest tests/io/test_pyarrow.py::test_pyarrow_s3_session_properties -v FAILED [100%] E Expected: S3FileSystem(..., tls_ca_file_path='/path/to/ca.pem') E Actual: S3FileSystem(..., region='us-east-1') 1 failed in 0.63s ``` After 545cb661: ```text $ uv run python -m pytest tests/io/test_pyarrow.py::test_pyarrow_s3_session_properties tests/io/test_pyarrow.py::test_pyarrow_s3_ssl_ca_cert_requires_supported_pyarrow_version -v PASSED [ 50%] PASSED [100%] 2 passed in 0.40s ``` Adjacent S3 property checks passed: 4 passed, 241 deselected in 1.54s. </details> ## Are there any user-facing changes? Yes. s3.ssl.ca-cert now takes effect for PyArrow-backed S3 and OSS file operations when PyArrow is 21.0.0 or newer. # AI Disclosure AI disclosure: GitHub Copilot CLI (Claude Opus 5.5) wrote this change and its tests, and an automated coordinator reviewed the diff and test output before submission. Areas of uncertainty: none known. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
