镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

fix(bigquery-jdbc): ensure JDBC uses PQC-compliant algorithm by default - #14560

Open
logachev wants to merge 3 commits into
mainfrom
kirl/pqc_fix
Open

logachev wants to merge 3 commits into
mainfrom
kirl/pqc_fix

Conversation

@logachev

@logachev logachev commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR addresses issues with not using PQC-compliant ciphers in both REST and gRPC.

  1. gRPC: excluding one of the dependencies from shading. This is the easiest fix we can do, this library is excluded from shaded jar for Spanner JDBC as well. It breaks some internal dependencies due to relocating java artifacts while c/c++ compiled libraries remain unchanged.
  2. REST: add conscrypt configuration for NetHttpTransport.

Adding 2 integration tests for these scenarios, adding to driver agnostic as well due to the fact that we need to run it against shaded version too.
Note: integration test is obviously generated code, but it seems reasonable. Also, validated that without fixes from this PR relevant tests do fail.

@logachev
logachev requested review from a team as code owners September 30, 2026 18:55

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request integrates Conscrypt as the default security provider for both HTTP and gRPC connections in the BigQuery JDBC driver, falling back to default JDK/gRPC TLS if Conscrypt is unavailable. It also refactors the channel configurator setup in BigQueryConnection to preserve existing configurations. Feedback on these changes highlights a potential issue in the updated unit test, which assumes Conscrypt is always available; it is recommended to conditionally assert the provider's nullability based on whether the Conscrypt native library successfully loads in the test environment.

@logachev

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request configures Conscrypt on the default HTTP transport to enable post-quantum cryptography (PQC) and adds integration tests to verify that both REST and gRPC transports successfully negotiate the X25519MLKEM768 key exchange. The review feedback suggests improving the robustness of the reflection logic used in the tests by traversing the class hierarchy when looking up fields and avoiding unnecessary Class.forName calls for compile-time available classes.

@logachev
logachev force-pushed the kirl/pqc_fix branch 2 times, most recently from 40fbe80 to a4986d0 Compare October 1, 2026 06:46
@Neenu1995
Neenu1995 self-requested a review October 1, 2026 13:27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants