Ref: VC-54664
Problem
VCert doesn't wrap transport errors with %w, which makes it impossible to match underlying network error types using errors.As(). The reason I want to match on specific network error types is because we need to distinguish between retriable and non-retriable errors.
Root cause: Line 1148 in pkg/venafi/ngts/connector.go uses %v instead of %w when wrapping transport errors:
err = fmt.Errorf("%w: %v", verror.ServerUnavailableError, err)
This flattens the underlying *url.Error and *net.OpError types. Consumers like cert-manager that use errors.As() to check for network errors cannot match these types.
Reproduction
package main
import (
"errors"
"fmt"
"net"
"net/url"
"github.com/Venafi/vcert/v5/pkg/endpoint"
"github.com/Venafi/vcert/v5/pkg/venafi/ngts"
)
func main() {
connector, err := ngts.NewConnector("https://invalid-dns-name-that-will-fail.example.com", "", false, nil)
if err != nil {
panic(err)
}
auth := &endpoint.Authentication{
ClientId: "test-client-id",
ClientSecret: "test-client-secret",
TokenURL: "https://invalid-dns-name-that-will-fail.example.com/oauth/token",
Scope: "tsg_id:1461462636",
}
_, err = connector.GetAccessToken(auth)
var urlErr *url.Error
ok := errors.As(err, &urlErr)
fmt.Printf("errors.As for %T: %v, result: %v\n", urlErr, ok, urlErr)
var opErr *net.OpError
ok = errors.As(err, &opErr)
fmt.Printf("errors.As for %T: %v, result: %v\n", opErr, ok, opErr)
}
Run it with:
go mod init test-vcert-error
go mod tidy
go run main.go
You will see:
errors.As for *url.Error: false, result: <nil>
errors.As for *net.OpError: false, result: <nil>
Ref: VC-54664
Problem
VCert doesn't wrap transport errors with
%w, which makes it impossible to match underlying network error types usingerrors.As(). The reason I want to match on specific network error types is because we need to distinguish between retriable and non-retriable errors.Root cause: Line 1148 in
pkg/venafi/ngts/connector.gouses%vinstead of%wwhen wrapping transport errors:This flattens the underlying
*url.Errorand*net.OpErrortypes. Consumers like cert-manager that useerrors.As()to check for network errors cannot match these types.Reproduction
Run it with:
You will see: