I'm happy to announce that we have unanimously approved this release.

There are 5 approving votes, 5 of which are binding:

- Patrick Hunt (binding)
- Szalay-Beko Mate (binding)
- Andor Molnar (binding)
- tison (binding)
- Flavio Junqueira (binding)

There are no disapproving votes.

I will promote the artifacts and complete the release procedure.

Thanks to every one who contributed to this great release !

Andor



> On Sep 14, 2026, at 02:59, Flavio Junqueira <[email protected]> 
> wrote:
> 
> +1
> 
> Thanks, Andor.
> 
> Verified:
> 
> * SHA-512 checksums for both source and binary tarballs.
> * GPG signatures on both tarballs and on the staged Maven artifacts
>  (jar, pom, sources) — all good, signed with
>  3F7A1D16FA4217B1DC75E1C9FFE35B7F15DFA1BA, which is in the project
>  KEYS file.
> * The source tarball matches the release-3.8.7-0 tag. The only
>  difference is that .gitattributes and .gitignore are not included in
>  the tarball (1402 files vs 1404 in the tag); everything present is
>  identical. Note this differs from 3.9.6, whose tarball does include
>  those two files — harmless, but the two branches' source assemblies
>  are inconsistent if anyone cares to align them.
> * The zookeeper-3.8.7.jar in the Maven staging repo is byte-identical
>  (same SHA-256) to the one in the binary tarball.
> * The running server reports version 3.8.7-9085db92..., matching the
>  tag commit.
> * branch-3.8 contains only "Prepared 3.8.8-SNAPSHOT" after the tag, so
>  nothing was left out of the candidate.
> * The set of bundled jars and per-jar LICENSE files in the binary
>  tarball is identical to released 3.8.6.
> * Release notes are complete and consistent: all 12 issues with
>  fixVersion 3.8.7 map to commits in the tag, the staged website matches
>  JIRA, and the reverted logback change (ZOOKEEPER-5057) is correctly
>  absent. I also checked the 3.9.6 fixes that are not in 3.8.7
>  (ZOOKEEPER-5043, 5044, 5045, 5049, 5052, 4912) — all are scoped to
>  3.10.0 and 3.9.6 in JIRA, so those omissions look deliberate.
> * Built from source on JDK 11. Test suite: 3036 tests, 1 failure,
>  1 error, 4 skipped — see below, none attributable to the candidate.
> * Standalone smoke test from the binary tarball: CRUD, four-letter
>  words and AdminServer all fine. ACL enforcement verified in both
>  directions — an unauthenticated read of a digest-restricted znode is
>  denied, and the same read succeeds after addauth.
> * Three-node ensemble: quorum formed, writes on a follower replicated to
>  all members, killed the leader and re-election succeeded, data
>  survived, writes continued on a 2/3 quorum, and the restarted member
>  rejoined and caught up on data written while it was down. No
>  unexpected errors in the server logs.
> * zkCli works on JDK 8, 11 and 21.
> 
> Tested on macOS (arm64).
> 
> On the three test problems, none of which I think are release blockers:
> 
> 1. ClientSSLTest.testClientServerSSL_negative[2] (fipsEnabled=false)
>   fails reproducibly for me, but released 3.8.6 fails the identical
>   test, same parameterisation, same line on the same machine, so it is
>   pre-existing rather than a 3.8.7 regression. The cause is
>   environmental: this host's name resolves to 127.0.0.1, which is in
>   the test certificate's iPAddress SAN, so with FIPS off ZKTrustManager
>   matches on the resolved address and the connection the test expects to
>   fail actually succeeds. With FIPS on, the JDK checks the hostname
>   string and correctly rejects. The test implicitly assumes the local
>   hostname does not resolve to loopback, which is not true everywhere.
>   Might be worth a JIRA to make it robust.
> 
> 2. SaslAuthTest.testDisconnectNotCreatingLoginThread timed out under
>   parallel forks but passes in isolation.
> 
> 3. QuorumZxidSyncTest had its surefire fork die under load. It is
>   untouched by this release and passes consistently on its own. I saw
>   the same thing on the 3.9.6 candidate.
> 
> -Flavio
> 
>> On 11 Sep 2026, at 22:27, Andor Molnár <[email protected]> wrote:
>> 
>> +1 (binding)
>> 
>> - verified checksum and gpg signature of the artifacts
>> - built source code with JDK 8, 11, 17
>> - all the java unit tests passed for me
>> - all the C-client tests passed too
>> - checkstyle and spotbugs passed
>> - apache-rat passed
>> - 3-node quorum with standard smoke tests works fine (w/ and w/o TLS)
>> - zk-smoketest.py passed
>> - zk-latencies.py passed
>> 
>> Andor
>> 
>> 
>> 
>>> On Sep 3, 2026, at 13:14, Andor Molnár <[email protected]> wrote:
>>> 
>>> Hi, 
>>> 
>>> This is a release candidate for 3.8.7
>>> 
>>> This is a minor release with bug- and security fixes. 
>>> 
>>> The full release notes is available at:
>>> 
>>> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310801&version=12356710
>>> 
>>> *** Please download, test and vote by September 11th 2026, 23:59 UTC+0. ***
>>> 
>>> Source files:
>>> https://dist.apache.org/repos/dist/dev/zookeeper/zookeeper-3.8.7-candidate-0/
>>> 
>>> Maven staging repo:
>>> https://repository.apache.org/content/repositories/orgapachezookeeper-1116/
>>> 
>>> The release candidate tag in git to be voted upon: release-3.8.7-0
>>> https://github.com/apache/zookeeper/tree/release-3.8.7-0
>>> 
>>> ZooKeeper's KEYS file containing PGP keys we use to sign the release:
>>> https://www.apache.org/dist/zookeeper/KEYS
>>> 
>>> The staging version of the website is:
>>> https://dist.apache.org/repos/dist/dev/zookeeper/zookeeper-3.8.7-candidate-0/website/index.html
>>> 
>>> 
>>> Should we release this candidate?
>>> 
>>> Andor
>>> 
>>> 
>> 
> 

Reply via email to