$ the-wire · showcase
google-auth 2.58.0 ships mTLS reconfiguration, JAX raises mpmath floor
By RepoJournal · Filed · About Google · Composed from the cited sources · methodology
google-auth v2.58.0 adds aiohttp mTLS reconfiguration when a certificate mismatch occurs and brings async session retry behavior in line with the synchronous client, while JAX now requires mpmath>=1.4.1 and drops its workarounds.
google-auth v2.58.0 lands with one behavioral change worth reading before you upgrade. The aiohttp transport now reconfigures mTLS when a certificate mismatch is detected, and the async session triggers a credential refresh plus request retry on all 401 Unauthorized responses rather than only mTLS ones, matching what the synchronous session already does [1]. The release also covers Agent Identity workloads and existing credentials, per the release notes [2][3].
On the JAX side, the test suite now pins mpmath>=1.4.1 in test-requirements.txt, and the complex infinity evaluation workarounds in numpy_with_mpmath inside test_util.py have been deleted because they are no longer needed at that version [4]. If your environment pins mpmath 1.3, your JAX test runs will fail on the floor requirement rather than on the removed workarounds, so bump the pin before running the suite [5].
Pallas gained LLO annotations on TPU, landed across two commits [6][7]. Mosaic GPU picked up lax.optimization_barrier support for warp primitive semantics, so kernels relying on that barrier under warp-level semantics no longer need a workaround [8]. Separately, python-genai's live.py receive() now supports dynamic turn completion via interaction_status [9][10].
google-cloud-python also refreshed its generated API sources, covering google/ads/admanager/v1, the AlloyDB v1alpha and v1beta surfaces, chronicle/v1, compute v1 and v1beta, geminidataanalytics/v1alpha, and retail/v2alpha [11][12]. That is a regeneration, not a behavior change to chase today unless you consume one of those specific clients.
Action items
- → Pin mpmath>=1.4.1 in your JAX test environment before running the suite jax-ml/jax [plan]
- → Upgrade google-auth to 2.58.0 if you use the aiohttp transport and need mTLS certificate-mismatch reconfiguration googleapis/google-cloud-python [plan]
- → Re-pull google-cloud-python generated clients if you consume alloydb, compute, chronicle, retail, admanager, or geminidataanalytics surfaces googleapis/google-cloud-python [monitor]
References
- [1] feat(auth): [aiohttp] Add mTLS reconfiguration logic when certificate mismatch for existing credentials & Agent Identity workloads ↗ googleapis/google-cloud-python
- [2] google-auth: v2.58.0 ↗ googleapis/google-cloud-python
- [3] chore(main): release google-auth 2.58.0 (#18325) ↗ googleapis/google-cloud-python
- [4] Require mpmath>=1.4.1 and remove mpmath 1.3 workarounds. ↗ google/jax
- [5] Require mpmath>=1.4.1 and remove mpmath 1.3 workarounds. ↗ google/jax
- [6] Add LLO annotations to Pallas TPU ↗ google/jax
- [7] Add LLO annotations to Pallas TPU ↗ google/jax
- [8] [Pallas:MGPU] Enable lax.optimization_barrier support for warp primitive semantics in Mosaic GPU. ↗ google/jax
- [9] feat: support dynamic turn completion via interaction_status in live.py receive() ↗ googleapis/python-genai
- [10] feat: support dynamic turn completion via interaction_status in live.py receive() ↗ googleapis/python-genai
- [11] feat: update API sources and regenerate ↗ googleapis/google-cloud-python
- [12] feat: update API sources and regenerate (#18324) ↗ googleapis/google-cloud-python