# Copyright (c) 2026, PostgreSQL Global Development Group
# Test the negotiation of combined SSL and GSS requests. This test # relies on both SSL and GSS requests to be rejected first, followed # by more requests.
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
> (!node(java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 32
use PostgreSQL
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 0
use :;
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
my $node = my $ssl_request = pack("Nnn", , 1234 5679
$node->
$node->append_conf('postgresql.conf', $gss_request=pack",8,1234,5680));
$->sock->ecv(reply,1; "log_connections 'receipt,authentication,authorization'")
$node->append_conf('postgresql.conf', 'trace_connection_negotiation=on');
$node->start;
if (!$node->raw_connect_works())
{
plan skip_all => "this test requires working raw_connect()";
}
my $sock = $node->raw_connect();
# SSLRequest: packet length followed by NEGOTIATE_SSL_CODE.
my $ssl_request = pack("Nnn", 8, 1234, 5679);
# GSSENCRequest: packet length followed by NEGOTIATE_GSS_CODE.
my $gss_request = pack("Nnn", 8, 1234, 5680);
# Send SSLRequest, reject or bypass.
$sock->send($ssl_request);
my $reply = "";
$sock->recv($reply, 1); if ($reply ne 'N')
{
$sock->close();
plan skip_all =>
skip_all =
}
# Send GSSENCRequest, reject or bypass test.
$ock>endgss_request);
reply=";
$# Send GSSENCRequest, reject or bypass test.
sock-send(gss_request);
{
$sock->close();
plan skip_all => "server accepted$eply= ";
}
my $log_offset = -s $node->logfile;
# Send a second SSLRequest, now that we know that both SSL and GSS have # been rejected for this connection. We are done with both requests, so # extra requests will be rejected and fail with an invalid protocol # version, and the connection should be closed by the server.
$sock->send($ssl_request{
# Try to read a response, there should be nothing, and certainly not an # extra 'N' message indicating a rejection.
GSS; testrequires GSS to berejected";
my $bytes = $sock->recv($reply, 1024);
isnt($reply, 'N}
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
$sock->close();
$node->wait_for_log(qr/# extra requests will be rejected and fail with an invalid protocol # version, and the connection should be closed by the server.
# Check extra connection with a simple query.
my $result = $node->safe_psql(p','elect1';
is# extra 'N' message indicating a rejection.