[ 
https://issues.apache.org/jira/browse/HADOOP-19972?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18108085#comment-18108085
 ] 

ASF GitHub Bot commented on HADOOP-19972:
-----------------------------------------

hadoop-yetus commented on PR #8704:
URL: https://github.com/apache/hadoop/pull/8704#issuecomment-5416449068

   :broken_heart: **-1 overall**
   
   
   
   
   
   
   | Vote | Subsystem | Runtime |  Logfile | Comment |
   |:----:|----------:|--------:|:--------:|:-------:|
   | +0 :ok: |  reexec  |   0m 35s |  |  Docker mode activated.  |
   |||| _ Prechecks _ |
   | +1 :green_heart: |  dupname  |   0m  2s |  |  No case conflicting files 
found.  |
   | +0 :ok: |  codespell  |   0m  0s |  |  codespell was not available.  |
   | +0 :ok: |  detsecrets  |   0m  0s |  |  detect-secrets was not available.  
|
   | +0 :ok: |  xmllint  |   0m  0s |  |  xmllint was not available.  |
   | +0 :ok: |  shelldocs  |   0m  0s |  |  Shelldocs was not available.  |
   | +1 :green_heart: |  @author  |   0m  0s |  |  The patch does not contain 
any @author tags.  |
   | +1 :green_heart: |  test4tests  |   0m  0s |  |  The patch appears to 
include 37 new or modified test files.  |
   |||| _ trunk Compile Tests _ |
   | +0 :ok: |  mvndep  |   2m 36s |  |  Maven dependency ordering for branch  |
   | +1 :green_heart: |  mvninstall  |  42m 58s |  |  trunk passed  |
   | +1 :green_heart: |  compile  |  15m 49s |  |  trunk passed with JDK 
Ubuntu-21.0.11+10-1-24.04.2-Ubuntu  |
   | +1 :green_heart: |  compile  |  16m 27s |  |  trunk passed with JDK 
Ubuntu-17.0.19+10-1-24.04.2-Ubuntu  |
   | +1 :green_heart: |  checkstyle  |   5m 35s |  |  trunk passed  |
   | +1 :green_heart: |  mvnsite  |  18m 14s |  |  trunk passed  |
   | +1 :green_heart: |  javadoc  |   9m 47s |  |  trunk passed with JDK 
Ubuntu-21.0.11+10-1-24.04.2-Ubuntu  |
   | +1 :green_heart: |  javadoc  |   9m 38s |  |  trunk passed with JDK 
Ubuntu-17.0.19+10-1-24.04.2-Ubuntu  |
   | +0 :ok: |  spotbugs  |   0m 21s |  |  branch/hadoop-project no spotbugs 
output file (spotbugsXml.xml)  |
   | -1 :x: |  spotbugs  |  34m 50s | 
[/branch-spotbugs-root-warnings.html](https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/artifact/out/branch-spotbugs-root-warnings.html)
 |  root in trunk has 93 extant spotbugs warnings.  |
   | +0 :ok: |  spotbugs  |   0m 30s |  |  
branch/hadoop-client-modules/hadoop-client-minicluster no spotbugs output file 
(spotbugsXml.xml)  |
   | +0 :ok: |  spotbugs  |   0m 31s |  |  
branch/hadoop-client-modules/hadoop-client-runtime no spotbugs output file 
(spotbugsXml.xml)  |
   | -1 :x: |  spotbugs  |   0m 45s | 
[/branch-spotbugs-hadoop-tools_hadoop-resourceestimator-warnings.html](https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/artifact/out/branch-spotbugs-hadoop-tools_hadoop-resourceestimator-warnings.html)
 |  hadoop-tools/hadoop-resourceestimator in trunk has 12 extant spotbugs 
warnings.  |
   | -1 :x: |  spotbugs  |   1m 36s | 
[/branch-spotbugs-hadoop-yarn-project_hadoop-yarn_hadoop-yarn-server_hadoop-yarn-server-nodemanager-warnings.html](https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/artifact/out/branch-spotbugs-hadoop-yarn-project_hadoop-yarn_hadoop-yarn-server_hadoop-yarn-server-nodemanager-warnings.html)
 |  
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager
 in trunk has 1 extant spotbugs warnings.  |
   | +1 :green_heart: |  shadedclient  |  27m 47s |  |  branch has no errors 
when building and testing our client artifacts.  |
   |||| _ Patch Compile Tests _ |
   | +0 :ok: |  mvndep  |   0m 52s |  |  Maven dependency ordering for patch  |
   | +1 :green_heart: |  mvninstall  |  64m 44s |  |  the patch passed  |
   | +1 :green_heart: |  compile  |  16m  4s |  |  the patch passed with JDK 
Ubuntu-21.0.11+10-1-24.04.2-Ubuntu  |
   | +1 :green_heart: |  javac  |  16m  4s |  |  the patch passed  |
   | +1 :green_heart: |  compile  |  16m 31s |  |  the patch passed with JDK 
Ubuntu-17.0.19+10-1-24.04.2-Ubuntu  |
   | +1 :green_heart: |  javac  |  16m 31s |  |  the patch passed  |
   | +1 :green_heart: |  blanks  |   0m  0s |  |  The patch has no blanks 
issues.  |
   | -0 :warning: |  checkstyle  |   5m 36s | 
[/results-checkstyle-root.txt](https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/artifact/out/results-checkstyle-root.txt)
 |  root: The patch generated 2 new + 730 unchanged - 2 fixed = 732 total (was 
732)  |
   | +1 :green_heart: |  mvnsite  |  18m 38s |  |  the patch passed  |
   | +1 :green_heart: |  shellcheck  |   0m  0s |  |  No new issues.  |
   | +1 :green_heart: |  javadoc  |   9m 50s |  |  the patch passed with JDK 
Ubuntu-21.0.11+10-1-24.04.2-Ubuntu  |
   | +1 :green_heart: |  javadoc  |   9m 36s |  |  the patch passed with JDK 
Ubuntu-17.0.19+10-1-24.04.2-Ubuntu  |
   | +0 :ok: |  spotbugs  |   0m 23s |  |  hadoop-project has no data from 
spotbugs  |
   | +0 :ok: |  spotbugs  |   0m 21s |  |  
hadoop-client-modules/hadoop-client-runtime has no data from spotbugs  |
   | +0 :ok: |  spotbugs  |   0m 21s |  |  
hadoop-client-modules/hadoop-client-minicluster has no data from spotbugs  |
   | -1 :x: |  shadedclient  |  61m 47s |  |  patch has errors when building 
and testing our client artifacts.  |
   |||| _ Other Tests _ |
   | -1 :x: |  unit  | 760m  9s | 
[/patch-unit-root.txt](https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/artifact/out/patch-unit-root.txt)
 |  root in the patch failed.  |
   | -1 :x: |  asflicense  |   1m 54s | 
[/results-asflicense.txt](https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/artifact/out/results-asflicense.txt)
 |  The patch generated 1 ASF License warnings.  |
   |  |   | 1238m 46s |  |  |
   
   
   | Reason | Tests |
   |-------:|:------|
   | Failed junit tests | hadoop.http.TestSSLHttpServerMTLS |
   |   | hadoop.security.token.delegation.web.TestWebDelegationToken |
   |   | hadoop.yarn.webapp.TestWebApp |
   |   | hadoop.yarn.appcatalog.application.TestAppCatalogSolrClient |
   |   | 
hadoop.yarn.server.nodemanager.containermanager.logaggregation.TestLogAggregationService
 |
   |   | hadoop.hdfs.web.TestWebHDFS |
   |   | hadoop.hdfs.web.TestWebHdfsFileSystemContract |
   |   | hadoop.hdfs.web.TestWebHdfsWithRestCsrfPreventionFilter |
   |   | hadoop.hdfs.server.namenode.TestCheckpoint |
   |   | hadoop.hdfs.web.TestWebHdfsUrl |
   |   | hadoop.hdfs.server.federation.router.TestRouterWebHdfsMethods |
   |   | 
hadoop.hdfs.server.federation.router.async.TestRouterAsyncWebHdfsMethods |
   
   
   | Subsystem | Report/Notes |
   |----------:|:-------------|
   | Docker | ClientAPI=1.55 ServerAPI=1.55 base: 
https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/artifact/out/Dockerfile
 |
   | GITHUB PR | https://github.com/apache/hadoop/pull/8704 |
   | Optional Tests | dupname asflicense compile javac javadoc mvninstall 
mvnsite unit shadedclient codespell detsecrets xmllint spotbugs checkstyle 
shellcheck shelldocs |
   | uname | Linux efc6bf27a2e3 5.15.0-186-generic #196-Ubuntu SMP Sat Jun 20 
16:09:34 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux |
   | Build tool | maven |
   | Personality | dev-support/bin/hadoop.sh |
   | git revision | trunk / 91ccfd1f69e1b7160b84d4ec5c35bae7c581c8d5 |
   | Default Java | Ubuntu-17.0.19+10-1-24.04.2-Ubuntu |
   | Multi-JDK versions | 
/usr/lib/jvm/java-21-openjdk-amd64:Ubuntu-21.0.11+10-1-24.04.2-Ubuntu 
/usr/lib/jvm/java-17-openjdk-amd64:Ubuntu-17.0.19+10-1-24.04.2-Ubuntu |
   |  Test Results | 
https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/testReport/ |
   | Max. process+thread count | 4001 (vs. ulimit of 10000) |
   | modules | C: hadoop-project hadoop-common-project/hadoop-auth 
hadoop-common-project/hadoop-auth-examples hadoop-common-project/hadoop-common 
hadoop-common-project/hadoop-nfs hadoop-common-project/hadoop-kms 
hadoop-hdfs-project/hadoop-hdfs hadoop-hdfs-project/hadoop-hdfs-httpfs 
hadoop-hdfs-project/hadoop-hdfs-nfs 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-common 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-common 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-applicationhistoryservice
 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-timelineservice
 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-web-proxy 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-resourcemanager
 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager
 hadoop-yarn-project/hadoop-yarn/hadoop-yarn-client 
hadoop-mapreduce-project/hadoop-mapreduce-client 
hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-shuffle
 hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-app 
hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-jobclient
 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-timelineservice-hbase-tests
 hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-router 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-globalpolicygenerator
 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-applications/hadoop-yarn-services/hadoop-yarn-services-api
 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-applications/hadoop-yarn-applications-catalog/hadoop-yarn-applications-catalog-webapp
 hadoop-mapreduce-project/hadoop-mapreduce-examples hadoop-tools/hadoop-sls 
hadoop-tools/hadoop-resourceestimator 
hadoop-client-modules/hadoop-client-runtime 
hadoop-client-modules/hadoop-client-minicluster . U: . |
   | Console output | 
https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8704/1/console |
   | versions | git=2.43.0 maven=3.9.15 spotbugs=4.9.7 shellcheck=0.9.0 |
   | Powered by | Apache Yetus 0.14.1 https://yetus.apache.org |
   
   
   This message was automatically generated.
   
   




> Upgrade to Jetty 12 without changing the servlet namespace
> ----------------------------------------------------------
>
>                 Key: HADOOP-19972
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19972
>             Project: Hadoop Common
>          Issue Type: Sub-task
>          Components: build, common
>            Reporter: Jose Luis López
>            Priority: Major
>              Labels: pull-request-available
>
> WHY
> ===
>  
> Hadoop's web server is Jetty 9.4, which is end of life and no longer receives
> security fixes. Getting off it is normally described as one large change,
> because Jetty 10 and everything after it require the jakarta.servlet 
> namespace.
> That framing makes a security fix wait on an API break: the projects that 
> embed
> Hadoop's web stack - HBase, Hive, Spark, Ozone, Knox - would all have to move 
> on
> the same day.
>  
> Two facts sharpen the timing. Jetty 9.4 is unsupported now, and branch-3.4 and
> branch-3.3 target Java 8 bytecode, so they can never take Jetty 12 - it needs
> Java 17. For users, "off end-of-life Jetty" already means "on 3.5 or later".
>  
> Jetty 12 makes the two changes separable. It ships the servlet container as a
> pluggable environment, and one of those environments, ee8, still serves
> javax.servlet. This takes that route: a supported Jetty now, in an ordinary
> minor release, with nothing for downstream projects to do.
>  
>  
> WHAT CHANGES FOR ANYONE USING HADOOP
> ====================================
>  
> Hadoop runs on a supported web server. That is the whole of it.
>  
> No published method changes shape or disappears. The five public classes that
> expose servlet types in their signatures expose exactly the same ones as 
> before.
> Projects that embed Hadoop's web stack need change nothing and need not 
> rebuild.
> No configuration setting changes.
>  
> Jetty 12 does behave differently from 9.4 in a few places, and those are 
> handled
> rather than passed on: a static file directory that would have started listing
> its contents, a web socket upgrade that would have failed, and a listener that
> could not be restarted once stopped. A deployment should see 9.4's behaviour
> throughout.
>  
>  
> WHAT CHANGES INSIDE
> ===================
>  
> Jetty moves from 9.4.58 to 12.0.37 on the ee8 environment. The servlet 
> container
> artifacts move under org.eclipse.jetty.ee8, and the servlet API now arrives as
> org.eclipse.jetty.toolchain:jetty-servlet-api, which publishes the same
> javax.servlet packages as the one it replaces.
>  
> Hadoop's HTTP server and its metrics, the YARN web application builder, the 
> web
> socket code and the remaining embedded servers - KMS, HttpFS, the scheduler
> simulator and the YARN services API - are ported to the new API. The shaded
> client artifacts and LICENSE-binary follow.
>  
> A new test states the contract this change is promising: the servlet types
> Hadoop offers to the projects that embed it stay javax, and none of them may
> become jakarta. It fails the day that stops being true.
>  
> Across the tree, 126 files still name javax.servlet and none names
> jakarta.servlet - unchanged from today. 85 files changed in total.
>  
>  
> WHAT THIS DOES NOT DO
> =====================
>  
> It does not move Hadoop to jakarta.servlet, does not upgrade Jersey, and does
> not touch the ee9, ee10 or ee11 environments.
>  
> ee8 is a staging post, not a destination. It preserves the namespace, but the
> Jetty API port still had to happen, and ee8 carries a compatibility layer that
> adapts every request. Unlike Jetty 10 and 11 it has a supported vendor behind
> it, which is what makes it a reasonable place to stand for a release or two.
>  
> This is not an alternative to HADOOP-19912 and does not replace it.
> HADOOP-19912 still lands the namespace change, in a major release, judged on 
> its
> own merits and with downstream projects warned. What this does is stop that
> decision from being a precondition for fixing the security problem.
>  
>  
> DEPENDS ON
> ==========
>  
> HADOOP-19970 and HADOOP-19971, in that order. The branch is stacked on both.
>  
> HADOOP-19970 matters functionally: without it, Jersey's test container drags a
> Jetty 9 artifact onto around twenty test classpaths, and moving to Jetty 12
> before that is fixed leaves those modules holding two Jetty versions at once -
> which compiles and then fails at run time.
>  
>  
> HOW IT WAS TESTED
> =================
>  
> Beyond the unit suites, the areas where this kind of change goes wrong need
> exercising against a running server rather than assumed: TLS configuration,
> SPNEGO, WebHDFS, the YARN UI, KMS and HttpFS. HADOOP-19876 was an SSL
> configuration regression on the current line and HADOOP-19848 a 
> NoSuchMethodError
> from a patch-level bump, so that is where the risk sits.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to