[#1161] Keep bc-fips from seeding its DRBG from RDSEED in the test JVMs (#1168)
Fixes #1161
### Problem
On the Linux `build-maven` legs the embedded test server sometimes fails
to start: bc-fips 2.1.3 seeds its DRBG from the CPU's RDSEED instruction
through its native libraries, and on a busy CI host RDSEED runs dry
while the server generates its self-signed certificates (`RDSEED
persistently failed to produce entropy`). The class that starts the
server fails in `@BeforeClass` and the rest of it is skipped.
### Change
Both test `argLine` values in the root `pom.xml` (the default one and
the `jdk17.options` one) now carry
`-Dorg.bouncycastle.native.cpu_variant=java`. With it bc-fips does not
load its native libraries, and
`FipsDRBG.getDefaultEntropySourceProvider()` falls back to
`SecureRandom.getInstanceStrong()` from the JDK. The
`opendj-server-legacy` failsafe configuration picks it up through
`@{argLine}`.
The argLine does not cross a process boundary.
`AdsTrustStoreInstallTestCase` and `QuickSetupTestCase` start the
packaged `setup`, and `ServerControllerTest` starts `start-ds` through
`ServerController`, which keeps the environment of the fork and drops
only `OPENDJ_JAVA_ARGS` and `CLASSPATH`. Those servers generate their
certificates through bc-fips too, so the `opendj-server-legacy` failsafe
execution also sets `JAVA_TOOL_OPTIONS` to the same flag in
`<environmentVariables>`, and every JVM started from the fork reads it.
Two pins:
- `BcFipsNativeLibrariesOffTestCase` (`opendj-core`) fails when either
root argLine loses the flag. `LDAPServer` generates its key pairs with
bc-fips in that module, and the module takes the root argLine as it is:
the default one below JDK 17, the `jdk17.options` one from JDK 17 on.
- `BcFipsNativeLibrariesOffTest` (`opendj-server-legacy`) fails when the
failsafe fork loses `JAVA_TOOL_OPTIONS`.
Only the test JVMs and the JVMs they start change. The product (start
scripts, `setup`) keeps loading the native libraries, and the "Test on
Unix FIPS" step in `build.yml`, which runs the packaged server outside
Maven, still exercises that path.
### Verification
- `mvn help:evaluate -Dexpression=argLine` shows the property with
`jdk17.options` active, with it disabled, and in `opendj-server-legacy`.
- A small program that makes the same `KeyPairGenerator` call as
`Platform.newKeyPair()`, run against bc-fips 2.1.3 in an
`eclipse-temurin:17` linux/amd64 container on a CPU with `rdseed`:
| | without the property | `cpu_variant=java` |
|---|---|---|
| native status / variant | `READY` / `avx` | `UNSUPPORTED` / none |
| native DRBG / NRBG | `true` / `true` | `false` / `false` |
| entropy source | `FipsDRBG$1` (`NativeEntropySource`, RDSEED) |
`BasicEntropySourceProvider` (JDK) |
| RSA 2048 key pair | OK | OK |
- Reactor run (JDK 26): `BcFipsNativeLibrariesOffTestCase` 1/1,
`AdsTrustStoreInstallTestCase` 6/6, `ServerControllerTest` 2/2,
`BcFipsNativeLibrariesOffTest` 2/2. The JVM's `Picked up
JAVA_TOOL_OPTIONS` line breaks nothing.
- The built package's `setup` and `start-ds`, run with the fork's
environment: `setup`, `start-ds` and the server's `logs/server.out` all
print `Picked up JAVA_TOOL_OPTIONS:
-Dorg.bouncycastle.native.cpu_variant=java`, and the server generates
`ads-certificate`.
- Mutants: flag removed from the default argLine → `opendj-core` pin red
on JDK 11; removed from the `jdk17.options` argLine → red on JDK 26
(both green at the head); `JAVA_TOOL_OPTIONS` missing →
`BcFipsNativeLibrariesOffTest` red.
The RDSEED failure itself cannot be reproduced on demand, so the CI legs
are the end-to-end check.
### Follow-up, not in this PR
bc-fips 2.1.4 (a release candidate, see bcgit/bc-java#2434, not yet on
Maven Central) adds `org.bouncycastle.native.rand=NONE`, which turns off
only the hardware RNG and keeps the native AES/SHA acceleration, and
raises the RDSEED retry limit to 1500. That is the better fit for the
product side (start scripts, `setup`) once it is released.