Skip to content

Replace JNA with java.lang.foreign in equinox.security.linux - #1348

Merged
akurtakov merged 1 commit into
eclipse-equinox:masterfrom
akurtakov:ffm-security-linux
Sep 14, 2026
Merged

akurtakov merged 1 commit into
eclipse-equinox:masterfrom
akurtakov:ffm-security-linux

Conversation

@akurtakov

Copy link
Copy Markdown
Member

Use FFM downcalls to libsecret/GIO instead of JNA mappings and drop the com.sun.jna requirement.

Needs BREE JavaSE-25, so the fragment no longer resolves on older JREs.

Assisted-by: Anthropic Claude Code (claude-opus-5[1m])

@akurtakov

Copy link
Copy Markdown
Member Author

@jjohnstn I would appreciate your review and testing

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Native lists use the wrong destructor, risking crashes, while several owned native allocations are leaked.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Replaces JNA-based Linux secure storage integration with Java FFM bindings for libsecret and GLib/GIO.

Changes:

  • Adds FFM layouts, native bindings, and helper utilities.
  • Removes obsolete JNA structures and dependency.
  • Raises the fragment requirement to Java 25 and version to 1.2.0.
File summaries
File Description
SecretSchemaAttributeType.java Removes obsolete JNA constants.
SecretSchemaAttribute.java Removes obsolete JNA structure.
SecretSchema.java Implements the native schema with FFM layouts.
LinuxPasswordProvider.java Migrates secure-storage operations to FFM.
LibSecret.java Adds libsecret downcall bindings.
LibGio.java Adds GLib/GIO downcall bindings.
GList.java Removes the JNA list structure.
GError.java Reads native errors through FFM.
Foreign.java Adds shared FFM loading and invocation utilities.
pom.xml Bumps the bundle version.
META-INF/MANIFEST.MF Removes JNA and requires Java 25.
.settings/org.eclipse.jdt.core.prefs Configures Java 25 compilation.
.classpath Selects the Java 25 runtime.
Review details

Suppressed comments (2)

bundles/org.eclipse.equinox.security.linux/src/org/eclipse/equinox/internal/security/linux/LinuxPasswordProvider.java:94

  • secret_password_lookup_sync transfers ownership of the returned native string to the caller. Converting it to a Java string without then calling secret_password_free (or g_free) leaks the password allocation on every secure-storage read; add the corresponding binding and release the pointer in a finally block after copying it.
			return Foreign.readString(password);

bundles/org.eclipse.equinox.security.linux/src/org/eclipse/equinox/internal/security/linux/LinuxPasswordProvider.java:75

  • unlocked and list are GList* values, not GError* values. Passing either to g_error_free invokes the wrong native destructor and can corrupt the GLib allocator or crash whenever an unlock is attempted. Bind g_list_free and use it for both list containers instead.
				fLibGio.errorFree(unlocked.get(ValueLayout.ADDRESS, 0));
				fLibGio.errorFree(list);
  • Files reviewed: 13/13 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Test Results

  231 files    231 suites   45m 23s ⏱️
2 219 tests 2 170 ✅  49 💤 0 ❌
6 420 runs  6 307 ✅ 113 💤 0 ❌

Results for commit b8c7017.

♻️ This comment has been updated with latest results.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

CI lacks the required Java 25 toolchain, and the migrated native path has no active automated coverage.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 13/13 changed files
  • Comments generated: 2
  • Review effort level: Balanced

Comment thread bundles/org.eclipse.equinox.security.linux/META-INF/MANIFEST.MF
@akurtakov
akurtakov force-pushed the ffm-security-linux branch 2 times, most recently from 7f2fe79 to 4b9f6b8 Compare September 2, 2026 19:33
akurtakov added a commit to akurtakov/eclipse.platform.releng.aggregator that referenced this pull request Sep 2, 2026
It's a prereq to allow using Java 25 in
eclipse-equinox/equinox#1348 . It will require
that all verification builds are migrated to use Java 25 to keep them
working.
akurtakov added a commit to akurtakov/eclipse.platform.releng.aggregator that referenced this pull request Sep 2, 2026
It's a prereq to allow using Java 25 in
eclipse-equinox/equinox#1348 . It will require
that all verification builds are migrated to use Java 25 to keep them
working.
@akurtakov akurtakov mentioned this pull request Sep 2, 2026
akurtakov added a commit to akurtakov/eclipse.platform.releng.aggregator that referenced this pull request Sep 3, 2026
It's a prereq to allow using Java 25 in
eclipse-equinox/equinox#1348 . It will require
that all verification builds are migrated to use Java 25 to keep them
working.
@akurtakov
akurtakov requested a balanced review from Copilot September 3, 2026 21:42

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Critical native ABI and error-handling defects remain, while the FFM bindings lack effective test coverage.

Review details

Suppressed comments (1)

bundles/org.eclipse.equinox.security.linux/src/org/eclipse/equinox/internal/security/linux/LibSecret.java:59

  • No automated test currently exercises these new downcall descriptors: LinuxPreferencesTest is absent from AllSecurityTests, and ObsoletesTest skips whenever isValid() detects a broken binding. A wrong SONAME, descriptor, variadic boundary, or schema layout can therefore make CI green by skipping. Add a binding-level test using a controlled native fixture, or otherwise ensure failures in the FFM path fail the suite.
	private LibSecret() {
		SymbolLookup library = Foreign.load(SONAME);
		serviceGetSyncHandle = Foreign.downcall(library, "secret_service_get_sync", //$NON-NLS-1$
				FunctionDescriptor.of(ValueLayout.ADDRESS, ValueLayout.JAVA_INT, ValueLayout.ADDRESS,
						ValueLayout.ADDRESS));
  • Files reviewed: 13/13 changed files
  • Comments generated: 2
  • Review effort level: Balanced

@HannesWell

Copy link
Copy Markdown
Member

Thanks for working on this.
Have you considered to generate the FFM bindings with jextract, based on existing C header files? Iike done in

@akurtakov

Copy link
Copy Markdown
Member Author

Honestly no, I haven't looked into jextract at all. I left it for exercise for later as this one is noisy already to get Java 25 ready.

@akurtakov

Copy link
Copy Markdown
Member Author

It is in good shape according to my testing so unless there are concerns I plan to push this one early next week.

@merks

merks commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

I think everyone has been supporting moving in this direction so it looks like a good plan and now is the best time to make such changes.

Use FFM downcalls to libsecret/GIO instead of JNA mappings and drop the
com.sun.jna requirement.

Needs BREE JavaSE-25, so the fragment no longer resolves on older JREs.

Assisted-by: Anthropic Claude Code (claude-opus-5[1m])
@akurtakov
akurtakov merged commit fff3578 into eclipse-equinox:master Sep 14, 2026
29 of 30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants