Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
/*
* The contents of this file are subject to the terms of the Common Development and
* Distribution License (the License). You may not use this file except in compliance with the
* License.
*
* You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the
* specific language governing permission and limitations under the License.
*
* When distributing Covered Software, include this CDDL Header Notice in each file and include
* the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL
* Header, with the fields enclosed by brackets [] replaced by your own identifying
* information: "Portions copyright [year] [name of copyright owner]".
*
* Copyright 2026 3A Systems, LLC.
*/
package org.forgerock.opendj.ldap;

import static org.testng.Assert.assertEquals;

import org.testng.annotations.Test;

/**
* Pins the test argLine flag that keeps bc-fips from seeding its DRBG from the CPU's RDSEED
* instruction, see issue #1161. {@link LDAPServer} generates its key pairs with bc-fips, and this
* module takes the argLine of the root pom as it is: the default one below JDK 17, the
* jdk17.options one from JDK 17 on.
*/
@SuppressWarnings("javadoc")
public class BcFipsNativeLibrariesOffTestCase extends SdkTestCase {
@Test
public void testJvmRunsWithoutTheNativeLibraries() {
assertEquals(System.getProperty("org.bouncycastle.native.cpu_variant"), "java",
"the test argLine lost the bc-fips cpu_variant flag, see #1161");
}
}
9 changes: 9 additions & 0 deletions opendj-server-legacy/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -1282,6 +1282,15 @@
<!-- Matched against the name of the test class, see org.opends.server.TestListener.onStart(). -->
<org.opends.test.trace.pattern>(org\.opends\.server\.replication\.service\..*)|(org\.opends\.server\.replication\.GenerationIdTest)|(org\.opends\.server\.types\.HostPortTest)|(org\.openidentityplatform\.opendj\.AliasTestCase)</org.opends.test.trace.pattern>
</systemPropertyVariables>
<!--
The argLine flag that keeps bc-fips off RDSEED (issue #1161) does not reach the JVMs
the tests start from the built package: setup, and start-ds through ServerController,
which keeps the environment of this fork and drops only OPENDJ_JAVA_ARGS and CLASSPATH.
Every JVM reads JAVA_TOOL_OPTIONS, so they pick the flag up from here.
-->
<environmentVariables>
<JAVA_TOOL_OPTIONS>-Dorg.bouncycastle.native.cpu_variant=java</JAVA_TOOL_OPTIONS>
</environmentVariables>
<argLine>@{argLine}</argLine>
<reuseForks>false</reuseForks>
<forkCount>1</forkCount>
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
/*
* The contents of this file are subject to the terms of the Common Development and
* Distribution License (the License). You may not use this file except in compliance with the
* License.
*
* You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the
* specific language governing permission and limitations under the License.
*
* When distributing Covered Software, include this CDDL Header Notice in each file and include
* the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL
* Header, with the fields enclosed by brackets [] replaced by your own identifying
* information: "Portions copyright [year] [name of copyright owner]".
*
* Copyright 2026 3A Systems, LLC.
*/
package org.opends.server.util;

import static org.testng.Assert.assertEquals;
import static org.testng.Assert.assertNotNull;
import static org.testng.Assert.assertTrue;

import java.util.Arrays;

import org.opends.server.DirectoryServerTestCase;
import org.testng.annotations.Test;

/**
* Pins the flag that keeps bc-fips from seeding its DRBG from the CPU's RDSEED instruction in the
* test JVMs and in the JVMs they start from the built package, see issue #1161.
*/
@SuppressWarnings("javadoc")
public class BcFipsNativeLibrariesOffTest extends DirectoryServerTestCase
{
private static final String FLAG = "-Dorg.bouncycastle.native.cpu_variant=java";

@Test
public void theTestJvmRunsWithoutTheNativeLibraries()
{
assertEquals(System.getProperty("org.bouncycastle.native.cpu_variant"), "java",
"the test JVM lost the bc-fips cpu_variant flag, see #1161");
}

/** setup, and start-ds through ServerController, inherit the environment of the failsafe fork. */
@Test
public void theJvmsStartedFromThePackageInheritTheFlag()
{
final String toolOptions = System.getenv("JAVA_TOOL_OPTIONS");
assertNotNull(toolOptions, "the failsafe fork lost JAVA_TOOL_OPTIONS, see #1161");
assertTrue(Arrays.asList(toolOptions.trim().split("\\s+")).contains(FLAG),
"JAVA_TOOL_OPTIONS of the failsafe fork lost the bc-fips cpu_variant flag, see #1161: " + toolOptions);
}
}
11 changes: 9 additions & 2 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,14 @@
<checkstylePluginVersion>2.9.1</checkstylePluginVersion>
<checkstyleVersion>5.5</checkstyleVersion>
<ant.contrib.version>1.0b3</ant.contrib.version>
<argLine>-Xmx512m</argLine>
<!--
org.bouncycastle.native.cpu_variant=java keeps bc-fips from loading its native libraries in the
test JVMs, so its DRBG is seeded from the JDK instead of the CPU's RDSEED instruction, which
runs dry on busy CI hosts ("RDSEED persistently failed to produce entropy"), see issue #1161.
Keep it in the jdk17.options argLine below as well; BcFipsNativeLibrariesOffTestCase in
opendj-core fails when either argLine loses it.
-->
<argLine>-Xmx512m -Dorg.bouncycastle.native.cpu_variant=java</argLine>
<maven.cargo.containerId>tomcat10x</maven.cargo.containerId>

<docHomepageUrl>https://doc.openidentityplatform.org/opendj/</docHomepageUrl>
Expand Down Expand Up @@ -735,7 +742,7 @@
<jdk>[17,)</jdk>
</activation>
<properties>
<argLine>-Xmx512m --add-opens java.base/java.lang=ALL-UNNAMED --add-opens java.base/java.lang.reflect=ALL-UNNAMED --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/java.net=ALL-UNNAMED --add-opens java.base/java.io=ALL-UNNAMED --add-opens java.base/java.util.regex=ALL-UNNAMED --add-opens java.base/java.security=ALL-UNNAMED --add-opens java.naming/javax.naming.spi=ALL-UNNAMED</argLine>
<argLine>-Xmx512m -Dorg.bouncycastle.native.cpu_variant=java --add-opens java.base/java.lang=ALL-UNNAMED --add-opens java.base/java.lang.reflect=ALL-UNNAMED --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/java.net=ALL-UNNAMED --add-opens java.base/java.io=ALL-UNNAMED --add-opens java.base/java.util.regex=ALL-UNNAMED --add-opens java.base/java.security=ALL-UNNAMED --add-opens java.naming/javax.naming.spi=ALL-UNNAMED</argLine>
<maven.cargo.containerId>tomcat11x</maven.cargo.containerId>
</properties>
</profile>
Expand Down
Loading