CalvinKirs opened a new pull request, #68824:
URL: https://github.com/apache/doris/pull/68824
### What problem does this PR solve?
Problem Summary: Improve Doris FE compatibility with MySQL 9 clients and
Connector/J 8/9. Clients can consume multiple statements correctly,
authenticate through caching_sha2 full authentication, query
authentication_policy, and bind binary TIME parameters in server-side prepared
statements.
| Area | Supported behavior | Coverage |
|---|---|---|
| B1: Multiple statements | Advertise CLIENT_MULTI_STATEMENTS,
CLIENT_MULTI_RESULTS and CLIENT_PS_MULTI_RESULTS; allowMultiQueries clients
receive all results and can continue using the connection. |
Handshake/capability unit tests, existing raw-protocol regression, JDBC
multiple result sets and mixed SELECT/SET responses. |
| A1: caching_sha2 full authentication | Support full authentication over
TLS or RSA, empty passwords, incorrect-password rejection, and COM_CHANGE_USER.
Use the established channel's actual TLS state during login and change-user. |
Password resolver unit tests; forced caching_sha2 JDBC login and real
changeUser over both TLS and RSA, including nonempty → empty → nonempty
accounts. |
| A1: Client selection | Add mysql_caching_sha2_password_clients: auto
(default, client major version ≥9 via _client_version), all (all clients
requesting this plugin), none (native fallback). Normalize and validate options
during startup and dynamic updates. | Client routing and configuration unit
tests; JDBC auto routing and none/native fallback. |
| D3: authentication_policy | Expose the read-only variable with value `*,,`
through SHOW VARIABLES and SELECT @@authentication_policy. | Variable unit
tests and JDBC SHOW/SELECT checks. |
| F1: Binary TIME parameters | Decode MYSQL_TYPE_TIME/TIME2 in server-side
prepared statements, including fractional seconds, signed durations, zero and
NULL. Reject malformed lengths, truncated payloads and out-of-range unsigned
days without consuming adjacent parameter data. | Literal unit tests for
malformed framing, overflow and ±838:59:59.999999; genuine JDBC
ServerPreparedStatement tests for setTime, LocalTime, microseconds, NULL, reuse
and a following integer parameter. |
Authentication uses full authentication and existing Doris password
verification; this change does not add a SHA-256 fast-auth cache. Versioned
JDBC acceptance cases live in the companion selectdb-qa PR, with isolated
Connector/J jars rather than a Connector/J 9 dependency in Doris
regression-test.
### Release note
Improve MySQL 9 client and Connector/J 8/9 compatibility for authentication,
multi-statement results, authentication_policy and prepared TIME parameters.
Reject invalid authentication client options at startup.
### Check List (For Author)
- Test
- [x] Unit Test: 31 targeted FE tests passed via run-fe-ut.sh
(ConfigTest, NativePasswordResolverTest, TimeV2LiteralTest and
MysqlChannelTest).
- [x] Manual test: 28 JDBC cases passed with Connector/J 8.4.0 and 9.7.0
against the rebuilt FE and BE 4.1.3-rc02. Both TLS changeUser cases failed with
1045 before the fix and passed afterward. Independent checks confirmed
database/user cleanup and restoration of the authentication mode.
- Build: build.sh --fe passed, including Checkstyle.
- Existing raw-protocol regression coverage is retained; it was not
rerun in the final validation round.
- Behavior changed:
- [x] Yes, as listed in the functionality table.
- Does this need documentation?
- [x] Yes, the new authentication client selection setting needs user
documentation; no documentation PR has been opened yet.
### Check List (For Reviewer who merge this PR)
- [ ] Confirm the release note
- [ ] Confirm test cases
- [ ] Confirm document
- [ ] Add branch pick label
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]