[ 
https://issues.apache.org/jira/browse/HADOOP-19912?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123166#comment-18123166
 ] 

Jose Luis López commented on HADOOP-19912:
------------------------------------------

I propose to use this Jira as the UMBRELLA ticket for jetty12-ee8 migration, 
and use the 19395 for the namespace change from javax to jakarta (ee10/ee11)

Move Hadoop's web servers off Jetty 9.4, which is end of life: its releases are 
now rare and sponsored, and its CVEs keep coming (HADOOP-19910, HADOOP-19915).

JDK17 is already supported.
h3. Approach

Jetty 12 serves two servlet APIs side by side: the ee8 environment serves 
{{{}javax.servlet{}}}, ee10/ee11 serve {{{}jakarta.servlet{}}}. This issue 
moves Hadoop to Jetty 12 on ee8, so the servlet namespace, Jersey 2 and every 
public signature stay as they are. The move to the jakarta namespace (ee10, 
Jersey 3, JAXB 4) is a separate decision, tracked in HADOOP-19395, which starts 
from here.
Jetty 12 needs Java 17, so this is for trunk (4.0). Release lines that stay on 
Jetty 9.4 are covered by HADOOP-19915.
h3. Sub-tasks
||Issue||Scope||State||
|HADOOP-19970|Resolve one Jetty release and one servlet API on every module 
classpath. No version change.|Patch available (PR #8699)|
|HADOOP-19972|Jetty 9.4.58 → 12.1.12 on ee8: {{{}HttpServer2{}}}, KMS, HttpFS, 
the YARN web apps, WebSocket, SLS, the services API, shaded clients, 
LICENSE-binary. Keeps trunk's behaviour wherever Jetty 12 allows; lists the 
rest for the release note.|Patch available (PR #8704)|
|HADOOP-19951|Drop jetty-util-ajax in favour of Jackson.|Fixed (3.6.0)|
|*new:* Move the app catalog off Jetty 
9.4|{{hadoop-yarn-applications-catalog-webapp}} stays on Jetty 9.4.58 because 
Solr 8 needs it, and it is the last Jetty 9.4 in the build. Either upgrade to a 
Solr release built on Jetty 12, if one fits, or retire the module.|Open|
h3. Behaviour changes

HADOOP-19972 is marked Incompatible. Its release note covers what Jetty 12 
changes for callers:
 * no custom HTTP reason phrase; refusal messages travel in the response body;
 * stricter URI parsing, adjustable with 
{{{}hadoop.http.uri.compliance.violations{}}};
 * TLS 1.2 renegotiation off by default, adjustable with 
{{{}hadoop.http.ssl.renegotiation.allowed{}}};
 * the five async HTTP metrics read 0;
 * Jetty's own error-page markup and default headers.

h3. Done when
 * No Jetty 9.4 artifact is left on any module classpath of the trunk build.
 * Every daemon serves on Jetty 12, and the full test suite passes.
 * The release note of HADOOP-19972 lists every incompatible change.

h3. Out of scope
 * The jakarta namespace, Jetty ee10/ee11, Jersey 3 and JAXB 4: HADOOP-19395.
 * Jetty 9.4 security updates on 3.x release lines: HADOOP-19915.

 

 

> Upgrade to Jetty 12
> -------------------
>
>                 Key: HADOOP-19912
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19912
>             Project: Hadoop Common
>          Issue Type: Task
>            Reporter: PJ Fanning
>            Assignee: Jose Luis López
>            Priority: Major
>              Labels: pull-request-available
>
> See HADOOP-19910 - there is a CVE in Jetty but releases of 9.4 are rare and 
> are 'sponsored' - Jetty 9.4 is not actively maintained. There are some 
> commercial forks.
> Jetty 12 needs Java 17+.
> Will also force Jersey to upgraded to 3 or 4.
> And to replace many javax classes/jars with their jakarta equivalents.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to