Fix trustStoreType JVM property consultation in SSL connections (#2691) - #2724
Merged
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #2724 +/- ##
============================================
+ Coverage 51.66% 51.68% +0.02%
+ Complexity 4112 4109 -3
============================================
Files 149 149
Lines 34240 34242 +2
Branches 5718 5719 +1
============================================
+ Hits 17690 17699 +9
+ Misses 14110 14103 -7
Partials 2440 2440 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Mahendra Chavan (machavan)
approved these changes
Aug 5, 2025
Divang Sharma (divang)
approved these changes
Aug 6, 2025
Muskan Gupta (muskan124947)
approved these changes
Aug 6, 2025
Dongjoon Hyun (dongjoon-hyun)
added a commit
to apache/spark
that referenced
this pull request
Nov 3, 2025
### What changes were proposed in this pull request? This PR aims to upgrade `mssql-jdbc` test dependency to `13.2.1.jre11`. ### Why are the changes needed? To use the latest features (like JDK 23 official support) and bug fixed versions during testing. - https://github.com/microsoft/mssql-jdbc/releases/tag/v13.2.1 - microsoft/mssql-jdbc#2801 - https://github.com/microsoft/mssql-jdbc/releases/tag/v13.2.0 - microsoft/mssql-jdbc#2724 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.2 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.1 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.0 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.9.0 - microsoft/mssql-jdbc#2515 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.8.2 ### Does this PR introduce _any_ user-facing change? No. ### How was this patch tested? Pass the CIs. ### Was this patch authored or co-authored using generative AI tooling? No. Closes #52856 from dongjoon-hyun/SPARK-54155. Authored-by: Dongjoon Hyun <dongjoon@apache.org> Signed-off-by: Dongjoon Hyun <dongjoon@apache.org>
Dongjoon Hyun (dongjoon-hyun)
added a commit
to apache/spark
that referenced
this pull request
Nov 3, 2025
### What changes were proposed in this pull request? This PR aims to upgrade `mssql-jdbc` test dependency to `13.2.1.jre11`. ### Why are the changes needed? To use the latest features (like JDK 23 official support) and bug fixed versions during testing. - https://github.com/microsoft/mssql-jdbc/releases/tag/v13.2.1 - microsoft/mssql-jdbc#2801 - https://github.com/microsoft/mssql-jdbc/releases/tag/v13.2.0 - microsoft/mssql-jdbc#2724 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.2 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.1 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.0 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.9.0 - microsoft/mssql-jdbc#2515 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.8.2 ### Does this PR introduce _any_ user-facing change? No. ### How was this patch tested? Pass the CIs. ### Was this patch authored or co-authored using generative AI tooling? No. Closes #52856 from dongjoon-hyun/SPARK-54155. Authored-by: Dongjoon Hyun <dongjoon@apache.org> Signed-off-by: Dongjoon Hyun <dongjoon@apache.org> (cherry picked from commit 34c3dde) Signed-off-by: Dongjoon Hyun <dongjoon@apache.org>
huangxiaoping (huangxiaopingRD)
pushed a commit
to huangxiaopingRD/spark
that referenced
this pull request
Nov 25, 2025
### What changes were proposed in this pull request? This PR aims to upgrade `mssql-jdbc` test dependency to `13.2.1.jre11`. ### Why are the changes needed? To use the latest features (like JDK 23 official support) and bug fixed versions during testing. - https://github.com/microsoft/mssql-jdbc/releases/tag/v13.2.1 - microsoft/mssql-jdbc#2801 - https://github.com/microsoft/mssql-jdbc/releases/tag/v13.2.0 - microsoft/mssql-jdbc#2724 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.2 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.1 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.10.0 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.9.0 - microsoft/mssql-jdbc#2515 - https://github.com/microsoft/mssql-jdbc/releases/tag/v12.8.2 ### Does this PR introduce _any_ user-facing change? No. ### How was this patch tested? Pass the CIs. ### Was this patch authored or co-authored using generative AI tooling? No. Closes apache#52856 from dongjoon-hyun/SPARK-54155. Authored-by: Dongjoon Hyun <dongjoon@apache.org> Signed-off-by: Dongjoon Hyun <dongjoon@apache.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The JDBC driver was not properly consulting the JVM system property
javax.net.ssl.trustStoreTypewhen thetrustStoreTypeconnection property was not explicitly set. This affected all SSL connection scenarios where users expected-Djavax.net.ssl.trustStoreType=Windows-ROOT(or other values) to be honored.Root Cause
The trust manager selection logic in
IOBuffer.enableSSL()was missing the standard fallback hierarchy fortrustStoreTyperesolution when entering the KeyStore loading path.Solution
Added comprehensive JVM system property consultation logic that follows the standard Java property resolution hierarchy:
trustStoreTypejavax.net.ssl.trustStoreTypeChanges
System.getProperty("javax.net.ssl.trustStoreType")fallback logic in lines 1678-1683encrypt=true,encrypt=strict, login-only encryption, etc.Testing
Impact
Fixes #2691