Skip to content

fix(jdbc-bridge): grant native access to bridge JVM for DuckDB native loads (issue #176) - #178

Open
Blankll wants to merge 1 commit into
masterfrom
fix/issue-176-duckdb-ssl
Open

Blankll wants to merge 1 commit into
masterfrom
fix/issue-176-duckdb-ssl

Conversation

@Blankll

@Blankll Blankll commented Oct 10, 2026

Copy link
Copy Markdown
Member

Closes #176

Root cause

The error in #176 — Failed to initialize pool: Invalid Input Error: The following options were not recognized: ssl — was produced by the v0.8.8 bridge, whose SslPropertyMapper blindly injected ssl=true for unknown JDBC drivers. DuckDB rejects unknown connection options, so every DuckDB connection failed. That bug was already fixed on master by #158 (frontend blacklist, Rust ssl_supported() guard, Java mapper no-op), but it landed after v0.8.8 shipped, so reporters on the release still hit it.

The screenshot in #176 also shows a second, forward-looking hazard: Java 25's restricted-method warnings for java.lang.System::load, which the DuckDB driver uses to map its ~107 MB native library. Today those warnings pollute the connection error text (appended via the bridge's stderr snapshot); in a future JDK they become hard denials and DuckDB would stop connecting even without the ssl bug.

Change

JdbcBridgeLauncher now launches every bridge JVM with --enable-native-access=ALL-UNNAMED, gated to JDK 17+ (older JVMs reject the option at startup — this protects the settings-page download_driver path, which has no Java 25 version check).

Verification

All done locally with the cached v0.8.8 bridge JAR, DuckDB JDBC 1.5.6.0, and the managed JRE 25 (exact reproduction of the reporter's setup):

Scenario Result
v0.8.8 bridge + ssl_mode: "prefer" reproduces #176's exact error + 4 stderr warnings
no ssl_mode (master Rust behavior) DuckDB connects, SELECT 42 returns 42
master SslPropertyMapper vs DuckDB injects nothing under prefer/require/verify-full
--enable-native-access=ALL-UNNAMED stderr warnings gone entirely
cargo test --lib 501 passed (3 new launcher tests)
bridge JUnit tests (compiled from master) 5 passed

Full mvn package/mvn test still needs JDK 25 — left to CI.

… loads (issue #176)

DuckDB's JDBC driver loads a ~107 MB native library via System::load,
which Java 24+ flags as a restricted method and future JDKs will deny
without --enable-native-access. The warnings also pollute connection
error messages surfaced to users (see issue #176 screenshot).

The bridge launcher now passes --enable-native-access=ALL-UNNAMED to
every bridge JVM, version-gated to JDK 17+ so launch paths without the
Java 25 requirement (the settings-page driver download) stay safe on
older JREs.

Verified end to end with the cached 0.8.8 bridge + DuckDB 1.5.6.0 on
Java 25: the issue's exact error reproduces with ssl_mode sent, the
connection succeeds without it, and the stderr warnings are gone with
the flag.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

duckdb无法连接

1 participant