ArpeOracle — Compatibility
Which Oracle versions, cloud services, auth methods, and client platforms ArpeOracle is known to work with. The support states used across the Arpeio driver family:
| State | Meaning |
|---|---|
| ✅ Validated | Verified directly against a live server or service. |
| 🟢 Supported | Expected to work and covered by the same protocol surface, but not run continuously. Report issues and they will be treated as bugs. |
| 🟡 Not yet validated | Should be compatible on protocol grounds, but unverified. No promise yet. |
| ❌ Not supported | Refused by the driver. |
ArpeOracle speaks TNS (Oracle Net) + TTC (Two-Task Common) natively over TCP (+ optional TCPS/TLS or Native Network Encryption). The primary target is Oracle 19c and Oracle Cloud Autonomous Database; the type mapping is in Data types.
Oracle Database (on-premises / IaaS)
| Version | State | Notes |
|---|---|---|
| Oracle 19c | ✅ Validated | Primary target. Password, TLS, NNE, OCI IAM token, OAuth2/Entra all verified live. |
| Oracle 18c | ✅ Validated | Type-matrix round-trip verified live (18c XE). |
| Oracle 12c | ✅ Validated | Type-matrix round-trip verified live (Enterprise 12.2.0.1), including the 12c O5LOGON password verifier. |
| Oracle 21c | ✅ Validated | Type-matrix round-trip verified live (21c XE). |
| Oracle 23ai | ✅ Validated | Type-matrix round-trip verified live. Native BOOLEAN, JSON, and VECTOR column types decode and round-trip. |
| Oracle 26ai (23.26) | ✅ Validated | Oracle's rebrand of 23ai — same protocol family; full type-matrix and native BOOLEAN/JSON/VECTOR verified live. |
| Oracle 11g and older | ❌ Not supported | Refused at connect with a clear "Oracle 12.1 or later is required" error. Oracle 12.1 is the minimum. |
Oracle Spatial (MDSYS.SDO_GEOMETRY, on 19c EE + Spatial) is ✅ Validated end
to end: an SDO_GEOMETRY column reads as geoarrow.wkb, and a geoarrow.wkb
column ingests back as SDO_GEOMETRY — SRID included. See
Data types for the supported geometry
kinds (read handles 2D point / line / single-ring polygon; write additionally
supports interior rings and the multi-part kinds).
There is no z/OS / mainframe Oracle edition — that concept is specific to the Db2/DRDA sibling (ArpeDb2) and does not apply to Oracle.
19c is the primary target; 12c, 18c, 21c, 23ai, and 26ai are all validated live — the type-matrix round-trip passes on each.
Oracle Cloud
| Service | State | Auth | Notes |
|---|---|---|---|
| Autonomous Database (ADB) | ✅ Validated | password, OCI IAM token, OAuth2/Entra | Verified live over mutual TLS with the downloaded instance wallet (ewallet.pem). Use a _low/_tp/… service on port 1522 and ssl_mode=verify-full. |
ADB requires mutual TLS — pair every ADB connection with the wallet
(wallet_location + wallet_password). See
Connection.
Authentication methods
All verified live (on-prem 19c and/or Autonomous Database):
| Method | State | Notes |
|---|---|---|
| Password (O5LOGON, 12c PBKDF2-HMAC-SHA512 and 11g SHA-1 verifiers) | ✅ Validated | Password never crosses the wire in clear, even without TLS. |
Proxy authentication (CONNECT THROUGH) | ✅ Validated | Rides the O5LOGON login, no extra round trip. |
| Change-password-at-connect | ✅ Validated | The way in past an expired password. |
| OCI IAM database token | ✅ Validated | Oracle Cloud; token + RSA proof-of-possession signature. |
| OAuth2 / Microsoft Entra ID bearer token | ✅ Validated | Global user resolved from the token's upn claim. |
| TLS (TCPS), incl. downloaded ADB wallet | ✅ Validated | require / verify-ca / verify-full; mutual TLS with wallets. |
| Native Network Encryption (AES-256 + SHA-256/SHA-1) | ✅ Validated | No TCPS required; connects a SQLNET.ENCRYPTION_SERVER=REQUIRED server. |
Not implemented: NTS/NTLM and Windows integrated authentication (SSPI). See
Authentication.
Client platforms
| Platform | State | Notes |
|---|---|---|
| Linux x64 | ✅ Validated | Primary platform. The released .so is self-contained and runs on RHEL 8 / Rocky 8 and newer. |
| Windows x64 | 🟢 Supported | Password/O5LOGON, TLS, OCI IAM token, and OAuth2/Entra all work. The released win-x64 .dll is self-contained. |
| macOS | — | No released binary. |
ADBC conformance
ArpeOracle implements the ADBC 1.1.0 surface: query, prepared statements +
bound parameters, DML/DDL update, transactions (commit/rollback + autocommit),
bulk ingest, LOB streaming, query cancellation, and catalog/metadata (GetInfo,
GetObjects, GetTableSchema, GetTableTypes, GetStatisticNames).
ExecuteSchema returns a query's result schema without running it (queries
only, without bound parameters). Other statements, a statement with
Bind/BindStream data, or a query the server describes without a column list
return NOT_IMPLEMENTED, so the caller can fall back to executing the query.
Without an explicit arpeoracle.sdo.srid, an SDO_GEOMETRY column's CRS is not
part of the described schema (ExecuteQuery takes it from the first fetched row).
GetStatistics and GetParameterSchema are not yet implemented; partitioned
execution and Substrait plans are not supported.
See also
- Connection — connecting to each of the above
- Data types — the Oracle → Arrow type mapping
- Troubleshooting — when a supported target does not connect