Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion .github/workflows/test-rabbitmq-alphas.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,8 +26,10 @@ jobs:
matrix:
include:
- rabbitmq-image: pivotalrabbitmq/rabbitmq:v4.3.x-otp27
erlang-version: 27
rabbitmq-branch: 4.3
- rabbitmq-image: pivotalrabbitmq/rabbitmq:main-otp27
- rabbitmq-image: pivotalrabbitmq/rabbitmq:main-otp28
erlang-version: 28
rabbitmq-branch: 4.4
name: Test against ${{ matrix.rabbitmq-image }}
steps:
Expand All @@ -51,6 +53,7 @@ jobs:
run: ci/start-cluster.sh
env:
RABBITMQ_IMAGE: ${{ matrix.rabbitmq-image }}
ERLANG_VERSION: ${{ matrix.erlang-version }}
- name: Get dependencies
run: make deps
- name: Test with Netty
Expand All @@ -59,6 +62,7 @@ jobs:
-Dtest-broker.A.nodename=rabbit@node0 -Dtest-broker.B.nodename=rabbit@node1 \
-Dca.certificate=./tls-gen/basic/result/ca_certificate.pem \
-Dclient.certificate=./tls-gen/basic/result/client_$(hostname)_certificate.pem \
-Dclient.key=./tls-gen/basic/result/client_$(hostname)_key.pem \
-Dmaven.javadoc.skip=true \
--no-transfer-progress
- name: Test with blocking IO
Expand All @@ -67,6 +71,7 @@ jobs:
-Dtest-broker.A.nodename=rabbit@node0 -Dtest-broker.B.nodename=rabbit@node1 \
-Dca.certificate=./tls-gen/basic/result/ca_certificate.pem \
-Dclient.certificate=./tls-gen/basic/result/client_$(hostname)_certificate.pem \
-Dclient.key=./tls-gen/basic/result/client_$(hostname)_key.pem \
-Dmaven.javadoc.skip=true \
--no-transfer-progress
- name: Get broker logs
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/test-supported-java-versions-5.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ jobs:
-Dtest-broker.A.nodename=rabbit@$(hostname) -Dmaven.javadoc.skip=true \
-Dca.certificate=./tls-gen/basic/result/ca_certificate.pem \
-Dclient.certificate=./tls-gen/basic/result/client_$(hostname)_certificate.pem \
-Dclient.key=./tls-gen/basic/result/client_$(hostname)_key.pem \
-Dit.test=ClientTestSuite,FunctionalTestSuite,ServerTestSuite,SslTestSuite \
--no-transfer-progress
- name: Test with blocking IO
Expand All @@ -55,6 +56,7 @@ jobs:
-Dtest-broker.A.nodename=rabbit@$(hostname) -Dmaven.javadoc.skip=true \
-Dca.certificate=./tls-gen/basic/result/ca_certificate.pem \
-Dclient.certificate=./tls-gen/basic/result/client_$(hostname)_certificate.pem \
-Dclient.key=./tls-gen/basic/result/client_$(hostname)_key.pem \
-Dit.test=ClientTestSuite,FunctionalTestSuite,ServerTestSuite,SslTestSuite \
--no-transfer-progress \
-Dnet.bytebuddy.experimental=true
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/test-supported-java-versions-main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@ jobs:
-Dtest-broker.A.nodename=rabbit@$(hostname) -Dmaven.javadoc.skip=true \
-Dca.certificate=./tls-gen/basic/result/ca_certificate.pem \
-Dclient.certificate=./tls-gen/basic/result/client_$(hostname)_certificate.pem \
-Dclient.key=./tls-gen/basic/result/client_$(hostname)_key.pem \
-Dit.test=ClientTestSuite,FunctionalTestSuite,ServerTestSuite,SslTestSuite \
--no-transfer-progress
- name: Test with blocking IO
Expand All @@ -53,6 +54,7 @@ jobs:
-Dtest-broker.A.nodename=rabbit@$(hostname) -Dmaven.javadoc.skip=true \
-Dca.certificate=./tls-gen/basic/result/ca_certificate.pem \
-Dclient.certificate=./tls-gen/basic/result/client_$(hostname)_certificate.pem \
-Dclient.key=./tls-gen/basic/result/client_$(hostname)_key.pem \
-Dit.test=ClientTestSuite,FunctionalTestSuite,ServerTestSuite,SslTestSuite \
--no-transfer-progress \
-Dnet.bytebuddy.experimental=true
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ jobs:
-Dtest-broker.A.nodename=rabbit@node0 -Dtest-broker.B.nodename=rabbit@node1 \
-Dca.certificate=./tls-gen/basic/result/ca_certificate.pem \
-Dclient.certificate=./tls-gen/basic/result/client_$(hostname)_certificate.pem \
-Dclient.key=./tls-gen/basic/result/client_$(hostname)_key.pem \
-Dmaven.javadoc.skip=true \
--no-transfer-progress
- name: Test with blocking IO
Expand All @@ -61,6 +62,7 @@ jobs:
-Dtest-broker.A.nodename=rabbit@node0 -Dtest-broker.B.nodename=rabbit@node1 \
-Dca.certificate=./tls-gen/basic/result/ca_certificate.pem \
-Dclient.certificate=./tls-gen/basic/result/client_$(hostname)_certificate.pem \
-Dclient.key=./tls-gen/basic/result/client_$(hostname)_key.pem \
-Dmaven.javadoc.skip=true \
--no-transfer-progress
- name: Get broker logs
Expand Down
26 changes: 26 additions & 0 deletions ci/cluster/advanced.config
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
[
{rabbit, [
{ssl_options, [
{cacertfile, "/etc/rabbitmq/tls/ca_certificate.pem"},
{certfile, "/etc/rabbitmq/tls/server_certificate.pem"},
{keyfile, "/etc/rabbitmq/tls/server_key.pem"},
{verify, verify_peer},
{fail_if_no_peer_cert, false},
{depth, 1},
{versions, ['tlsv1.3', 'tlsv1.2']},
{supported_groups, [x25519mlkem768, x25519, secp256r1]},
{honor_cipher_order, true},
{ciphers, [
%% TLS 1.3 Ciphers
"TLS_AES_256_GCM_SHA384",
"TLS_CHACHA20_POLY1305_SHA256",
"TLS_AES_128_GCM_SHA256",
%% TLS 1.2 Ciphers
"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384",
"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384",
"TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256",
"TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
]}
]}
]}
].
13 changes: 13 additions & 0 deletions ci/cluster/rabbitmq_post_erlang_28.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
cluster_formation.peer_discovery_backend = rabbit_peer_discovery_classic_config
cluster_formation.classic_config.nodes.1 = rabbit@node0
cluster_formation.classic_config.nodes.2 = rabbit@node1
cluster_formation.classic_config.nodes.3 = rabbit@node2
loopback_users = none

listeners.ssl.default = 5671

auth_mechanisms.1 = PLAIN
auth_mechanisms.2 = ANONYMOUS
auth_mechanisms.3 = AMQPLAIN
auth_mechanisms.4 = EXTERNAL
auth_mechanisms.5 = RABBIT-CR-DEMO
48 changes: 48 additions & 0 deletions ci/start-broker.sh
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
LOCAL_SCRIPT="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"

RABBITMQ_IMAGE=${RABBITMQ_IMAGE:-rabbitmq:4.3}
ERLANG_VERSION=${ERLANG_VERSION:-27}

wait_for_message() {
while ! docker logs "$1" | grep -q "$2";
Expand All @@ -23,6 +24,10 @@ cp -R "${PWD}"/tls-gen/basic/result/* rabbitmq-configuration/tls
chmod o+r rabbitmq-configuration/tls/*
chmod g+r rabbitmq-configuration/tls/*

if [ "$ERLANG_VERSION" -lt 28 ]; then

# Erlang < 28

echo "loopback_users = none

listeners.ssl.default = 5671
Expand All @@ -40,6 +45,49 @@ auth_mechanisms.3 = AMQPLAIN
auth_mechanisms.4 = EXTERNAL
auth_mechanisms.5 = RABBIT-CR-DEMO" >> rabbitmq-configuration/rabbitmq.conf

else

# Erlang >= 28

echo "loopback_users = none

listeners.ssl.default = 5671

auth_mechanisms.1 = PLAIN
auth_mechanisms.2 = ANONYMOUS
auth_mechanisms.3 = AMQPLAIN
auth_mechanisms.4 = EXTERNAL
auth_mechanisms.5 = RABBIT-CR-DEMO" >> rabbitmq-configuration/rabbitmq.conf

echo "[
{rabbit, [
{ssl_options, [
{cacertfile, \"/etc/rabbitmq/tls/ca_certificate.pem\"},
{certfile, \"/etc/rabbitmq/tls/server_$(hostname)_certificate.pem\"},
{keyfile, \"/etc/rabbitmq/tls/server_$(hostname)_key.pem\"},
{verify, verify_peer},
{fail_if_no_peer_cert, false},
{depth, 1},
{versions, ['tlsv1.3']},
{supported_groups, [x25519mlkem768, x25519, secp256r1]},
{honor_cipher_order, true},
{ciphers, [
%% TLS 1.3 Ciphers
\"TLS_AES_256_GCM_SHA384\",
\"TLS_CHACHA20_POLY1305_SHA256\",
\"TLS_AES_128_GCM_SHA256\",
%% TLS 1.2 Ciphers
\"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\",
\"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\",
\"TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256\",
\"TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256\"
]}
]}
]}
]." >> rabbitmq-configuration/advanced.config

fi

echo "Running RabbitMQ ${RABBITMQ_IMAGE}"

docker rm -f rabbitmq 2>/dev/null || echo "rabbitmq was not running"
Expand Down
19 changes: 18 additions & 1 deletion ci/start-cluster.sh
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
#!/usr/bin/env bash

export RABBITMQ_IMAGE=${RABBITMQ_IMAGE:-rabbitmq:4.3}
RABBITMQ_IMAGE=${RABBITMQ_IMAGE:-rabbitmq:4.3}
ERLANG_VERSION=${ERLANG_VERSION:-27}

wait_for_message() {
while ! docker logs "$1" | grep -q "$2";
Expand All @@ -23,6 +24,22 @@ mv rabbitmq-configuration/tls/server_$(hostname)_key.pem rabbitmq-configuration/
chmod o+r rabbitmq-configuration/tls/*
chmod g+r rabbitmq-configuration/tls/*

rm -rf "${PWD}"/ci/cluster/configuration
mkdir "${PWD}"/ci/cluster/configuration

if [ "$ERLANG_VERSION" -lt 28 ]; then

# Erlang < 28
cp "${PWD}"/ci/cluster/rabbitmq_pre_erlang_28.conf "${PWD}"/ci/cluster/configuration/rabbitmq.conf

else

# Erlang >= 28
cp "${PWD}"/ci/cluster/rabbitmq_post_erlang_28.conf "${PWD}"/ci/cluster/configuration/rabbitmq.conf
cp "${PWD}"/ci/cluster/advanced.config "${PWD}"/ci/cluster/configuration/advanced.config

fi

docker compose --file ci/cluster/docker-compose.yml down
docker compose --file ci/cluster/docker-compose.yml up --detach

Expand Down
31 changes: 30 additions & 1 deletion pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@
<micrometer-tracing-test.version>1.7.1</micrometer-tracing-test.version>
<micrometer-docs-generator.version>1.0.4</micrometer-docs-generator.version>
<jetty.version>9.4.58.v20250814</jetty.version>
<bouncycastle.version>1.86</bouncycastle.version>
<bouncycastle.version>1.85</bouncycastle.version>
<netcrusher.version>0.10</netcrusher.version>
<gson.version>2.14.0</gson.version>

Expand All @@ -92,6 +92,7 @@
<jshell-maven-plugin.version>1.4</jshell-maven-plugin.version>
<spotless.version>3.10.2</spotless.version>
<google-java-format.version>1.36.1</google-java-format.version>
<netty-tcnative.version>2.0.84.Final</netty-tcnative.version>
<!--
These groovy scripts are used later in this POM file to generate
source files and resources for the library itself and for the
Expand Down Expand Up @@ -462,6 +463,18 @@
<version>${bouncycastle.version}</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcprov-jdk18on</artifactId>
<version>${bouncycastle.version}</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bctls-jdk18on</artifactId>
<version>${bouncycastle.version}</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>com.github.netcrusherorg</groupId>
<artifactId>netcrusher-core</artifactId>
Expand Down Expand Up @@ -515,6 +528,21 @@
<scope>test</scope>
</dependency>

<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-tcnative-boringssl-static</artifactId>
<version>${netty-tcnative.version}</version>
<classifier>linux-x86_64</classifier>
<scope>test</scope>
</dependency>

<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-tcnative-boringssl-static</artifactId>
<version>${netty-tcnative.version}</version>
<classifier>osx-aarch_64</classifier>
<scope>test</scope>
</dependency>

<!-- add explicitly to update automatically with dependabot -->
<dependency>
Expand Down Expand Up @@ -790,6 +818,7 @@
<include>src/main/java/com/rabbitmq/client/impl/Environment.java</include>
<include>src/main/java/com/rabbitmq/client/observation/**/*.java</include>
<include>src/test/java/com/rabbitmq/client/AmqpClientTestExtension.java</include>
<include>src/test/java/com/rabbitmq/client/test/ssl/Pqc.java</include>
<include>src/test/java/com/rabbitmq/client/test/ssl/TlsTestUtils.java</include>
<include>src/test/java/com/rabbitmq/client/test/functional/MicrometerObservationCollectorMetrics.java</include>
<include>src/test/java/com/rabbitmq/client/test/functional/DurableOnTransient.java</include>
Expand Down
4 changes: 2 additions & 2 deletions src/main/java/com/rabbitmq/client/ConnectionFactory.java
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
import static java.util.concurrent.TimeUnit.MINUTES;

import com.rabbitmq.client.impl.*;
import com.rabbitmq.client.impl.nio.NioParams;

Check warning on line 21 in src/main/java/com/rabbitmq/client/ConnectionFactory.java

View workflow job for this annotation

GitHub Actions / Test against pivotalrabbitmq/rabbitmq:main-otp28

com.rabbitmq.client.impl.nio.NioParams in com.rabbitmq.client.impl.nio has been deprecated

Check warning on line 21 in src/main/java/com/rabbitmq/client/ConnectionFactory.java

View workflow job for this annotation

GitHub Actions / build

com.rabbitmq.client.impl.nio.NioParams in com.rabbitmq.client.impl.nio has been deprecated

Check warning on line 21 in src/main/java/com/rabbitmq/client/ConnectionFactory.java

View workflow job for this annotation

GitHub Actions / Test against pivotalrabbitmq/rabbitmq:v4.3.x-otp27

com.rabbitmq.client.impl.nio.NioParams in com.rabbitmq.client.impl.nio has been deprecated
import com.rabbitmq.client.impl.nio.SocketChannelFrameHandlerFactory;
import com.rabbitmq.client.impl.recovery.AutorecoveringConnection;
import com.rabbitmq.client.impl.recovery.RecoveredQueueNameSupplier;
Expand Down Expand Up @@ -120,9 +120,9 @@
/** The default timeout for work pool enqueueing: no timeout */
public static final int DEFAULT_WORK_POOL_TIMEOUT = -1;

private static final String PREFERRED_TLS_PROTOCOL = "TLSv1.2";
private static final String PREFERRED_TLS_PROTOCOL = "TLSv1.3";

private static final String FALLBACK_TLS_PROTOCOL = "TLSv1";
private static final String FALLBACK_TLS_PROTOCOL = "TLSv1.2";

private String virtualHost = DEFAULT_VHOST;
private String host = DEFAULT_HOST;
Expand Down Expand Up @@ -168,7 +168,7 @@

// lazily created, so the Netty classes it references are loaded only when Netty is activated
private NettyConfiguration nettyConf;
private NioParams nioParams = new NioParams();

Check warning on line 171 in src/main/java/com/rabbitmq/client/ConnectionFactory.java

View workflow job for this annotation

GitHub Actions / Test against pivotalrabbitmq/rabbitmq:main-otp28

com.rabbitmq.client.impl.nio.NioParams in com.rabbitmq.client.impl.nio has been deprecated

Check warning on line 171 in src/main/java/com/rabbitmq/client/ConnectionFactory.java

View workflow job for this annotation

GitHub Actions / build

com.rabbitmq.client.impl.nio.NioParams in com.rabbitmq.client.impl.nio has been deprecated

Check warning on line 171 in src/main/java/com/rabbitmq/client/ConnectionFactory.java

View workflow job for this annotation

GitHub Actions / Test against pivotalrabbitmq/rabbitmq:v4.3.x-otp27

com.rabbitmq.client.impl.nio.NioParams in com.rabbitmq.client.impl.nio has been deprecated

private SslContextFactory sslContextFactory;

Expand Down
Loading
Loading