Repository navigation
Conversation
… loads (issue #176) DuckDB's JDBC driver loads a ~107 MB native library via System::load, which Java 24+ flags as a restricted method and future JDKs will deny without --enable-native-access. The warnings also pollute connection error messages surfaced to users (see issue #176 screenshot). The bridge launcher now passes --enable-native-access=ALL-UNNAMED to every bridge JVM, version-gated to JDK 17+ so launch paths without the Java 25 requirement (the settings-page driver download) stay safe on older JREs. Verified end to end with the cached 0.8.8 bridge + DuckDB 1.5.6.0 on Java 25: the issue's exact error reproduces with ssl_mode sent, the connection succeeds without it, and the stderr warnings are gone with the flag.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #176
Root cause
The error in #176 —
Failed to initialize pool: Invalid Input Error: The following options were not recognized: ssl— was produced by the v0.8.8 bridge, whoseSslPropertyMapperblindly injectedssl=truefor unknown JDBC drivers. DuckDB rejects unknown connection options, so every DuckDB connection failed. That bug was already fixed on master by #158 (frontend blacklist, Rustssl_supported()guard, Java mapper no-op), but it landed after v0.8.8 shipped, so reporters on the release still hit it.The screenshot in #176 also shows a second, forward-looking hazard: Java 25's restricted-method warnings for
java.lang.System::load, which the DuckDB driver uses to map its ~107 MB native library. Today those warnings pollute the connection error text (appended via the bridge's stderr snapshot); in a future JDK they become hard denials and DuckDB would stop connecting even without thesslbug.Change
JdbcBridgeLaunchernow launches every bridge JVM with--enable-native-access=ALL-UNNAMED, gated to JDK 17+ (older JVMs reject the option at startup — this protects the settings-pagedownload_driverpath, which has no Java 25 version check).Verification
All done locally with the cached v0.8.8 bridge JAR, DuckDB JDBC 1.5.6.0, and the managed JRE 25 (exact reproduction of the reporter's setup):
ssl_mode: "prefer"ssl_mode(master Rust behavior)SELECT 42returns 42SslPropertyMappervs DuckDB--enable-native-access=ALL-UNNAMEDcargo test --libFull
mvn package/mvn teststill needs JDK 25 — left to CI.