Hi,

I agree with deprecating the druid-handler module and targeting its removal
in the next major release.

Best regards,
Raghav Aggarwal


On Thu, Jul 16, 2026 at 10:14 PM Sai Hemanth Gantasala <
[email protected]> wrote:

> Hello team,
>
> I support deprecating druid-handler and targeting removal in a future
> major release.
>
> I worked on HIVE-29707 (upgrade Druid 0.17.1 --> 26.0.0) to address CVE
> exposure from the 2020-era dependency. The handler itself can be made to
> compile, but keeping it current is costly and the blast radius is wide:
> 1) Large API drift across storage handler, indexing, serde, and Kafka
> supervisor classes
> 2) hive-it-druid (~200 MB shaded jar) is pulled into unrelated qfile
> drivers (e.g. TestMiniLlapCliDriver), causing collateral test failures
> 3) Ongoing shading conflicts with Hive's stack (Calcite/Jackson/Guava),
> consistent with the CALCITE-6393 issues mentioned above
> Combined with minimal recent development and no clear maintainer/user
> base, I'd deprecate in docs/build now and remove in the next major. I
> wouldn't invest in a full upgrade unless someone commits to long-term
> ownership.
>
> Happy to share HIVE-29707 details if useful for a formal deprecation
> proposal.
>
> On 2026/07/15 11:38:13 Ruben Q L wrote:
> > Hello!
> >
> > In the context of a WIP Calcite upgrade [1] I ran into shading issues in
> > druid-handler (an ASM failure when relocating Calcite's
> SqlFunctions.class,
> > tracked upstream in CALCITE-6393). I worked around it by dropping the
> > Calcite relocation in druid-handler/pom.xml, but it prompted me to
> re-open
> > an earlier discussion [2] about whether we should still be carrying this
> > module at all.
> >
> > Nothing seems to have changed since it was last raised: we're still on
> > Druid 0.17.1 [3] (released in 2020), which has a number of unpatched CVEs
> > [4], and there's been essentially no meaningful development in the module
> > [5].
> >
> > So the same questions remain open:
> > - Are there any active users of druid-handler?
> > - If there are users but no maintainers, should we deprecate the module
> > (docs + build) and target removal in a future major release?
> > - If there are neither, shall we drop it now?
> >
> > Best,
> > Ruben
> >
> > [1] https://issues.apache.org/jira/browse/HIVE-29641
> > [2] https://lists.apache.org/thread/1swonwzts4rztz0vdjhllbzmotsdx8ro
> > [3]
> >
> https://github.com/apache/hive/blob/c4791205d84201b351a8353e9eacadbc3c972c3e/pom.xml#L137
> > [4] https://mvnrepository.com/artifact/org.apache.druid/druid/0.17.1
> > [5]
> >
> https://github.com/search?q=repo%3Aapache%2Fhive+druid&type=commits&s=committer-date&o=desc
> >
>


-- 
Thanks,
Raghav Aggarwal

Reply via email to