Skip to content

test(bigquery-jdbc): add PQC validation tests - #14564

Draft
logachev wants to merge 3 commits into
mainfrom
kirl/pqc_it
Draft

logachev wants to merge 3 commits into
mainfrom
kirl/pqc_it

Conversation

@logachev

@logachev logachev commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request configures the Conscrypt security provider for the default HTTP transport in BigQueryJdbcProxyUtility and excludes shaded Netty from gRPC relocation in pom.xml. It also introduces a new integration test, ITPqcValidationTest, to verify that both REST and gRPC transports negotiate post-quantum hybrid key exchange (X25519MLKEM768). Feedback on the test code suggests optimizing reflection calls by retrieving fields outside of the loop to improve efficiency.

Comment on lines +320 to +347
List<Object> contexts = findInstancesInGraph(readClient, openSslCtxClass, 25);
for (Object ctx : contexts) {
Field enginesField = openSslCtxClass.getDeclaredField("engines");
enginesField.setAccessible(true);
Map<?, ?> engines = (Map<?, ?>) enginesField.get(ctx);
for (Object engineObj : engines.values()) {
if (openSslEngineClass.isInstance(engineObj)) {
SSLEngine engine = (SSLEngine) engineObj;
SSLSession session = engine.getSession();
Field groupsField = openSslEngineClass.getDeclaredField("groups");
groupsField.setAccessible(true);
String[] engineGroups = (String[]) groupsField.get(engineObj);
if (engineGroups == null || engineGroups.length == 0) {
engineGroups = defaultGroups;
}
String primaryKeyShare =
(engineGroups != null && engineGroups.length > 0) ? engineGroups[0] : "unknown";
results.add(
new HandshakeRecord(
session.getPeerHost(),
engine.getClass().getName(),
false,
session.getProtocol(),
session.getCipherSuite(),
primaryKeyShare));
}
}
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

To improve efficiency and maintainability, retrieve the enginesField and groupsField reflectively once outside the loops rather than repeatedly calling getDeclaredField and setAccessible(true) on every iteration.

    List<Object> contexts = findInstancesInGraph(readClient, openSslCtxClass, 25);
    if (!contexts.isEmpty()) {
      Field enginesField = openSslCtxClass.getDeclaredField("engines");
      enginesField.setAccessible(true);
      Field groupsField = openSslEngineClass.getDeclaredField("groups");
      groupsField.setAccessible(true);
      for (Object ctx : contexts) {
        Map<?, ?> engines = (Map<?, ?>) enginesField.get(ctx);
        for (Object engineObj : engines.values()) {
          if (openSslEngineClass.isInstance(engineObj)) {
            SSLEngine engine = (SSLEngine) engineObj;
            SSLSession session = engine.getSession();
            String[] engineGroups = (String[]) groupsField.get(engineObj);
            if (engineGroups == null || engineGroups.length == 0) {
              engineGroups = defaultGroups;
            }
            String primaryKeyShare = 
                (engineGroups != null && engineGroups.length > 0) ? engineGroups[0] : "unknown";
            results.add(
                new HandshakeRecord(
                    session.getPeerHost(),
                    engine.getClass().getName(),
                    false,
                    session.getProtocol(),
                    session.getCipherSuite(),
                    primaryKeyShare));
          } 
        }
      }
    }
References
  1. Avoid adding defensive null checks for values that are guaranteed to be non-null by design, as this can hide invariant breaks.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant