Hi Tim,

Many thanks for this. For reasons that I won't go into here, it looks like
trying to patch 6.4 is something that we need to try. It may be that the
v1->v2 bridge that's been mentioned will be a better option for us, but
we're looking at both choices right now.

Currently, I have a version of 6.4 that does not directly use log4j v1, but
it does still have a handful (<20) of transitive imports of v1 from slf4
and Solr. The patched 6.4 can compile all the front-ends and pass the
unit/integration tests, and I can run DSpace locally in a container -- but
I haven't tackled converting the configuration files in earnest yet, and
I've noticed that the PR for v7 uses XML for some configuration files.

My local PR for this is already approx. 1kloc larger than the PR to upgrade
log4j in DSpace v7, and no doubt it'll get larger still before we take a
decision to either merge or abandon it.

Sarah



On Mon, 10 Jan 2022 at 16:28, 'Tim Donohue' via DSpace Technical Support <
[email protected]> wrote:

> Hi Sarah,
>
> Just wanted to note that I'm not aware of anyone who has tried updating
> DSpace 6.x (or any prior release) to log4j v2.  As I initially noted in
> this log4j summary email (
> https://groups.google.com/g/dspace-tech/c/QR59bS4nIT0/m/Ze2hyOhhAgAJ), I
> believe this upgrade would be extremely complex (and I'm not even sure if
> it's possible).
>
> Unfortunately, most of the other dependencies which DSpace 6.x (and
> 5.x/4.x or any prior release) use all also rely on log4j v1 (especially
> Solr) .  Attempting to upgrade DSpace 6.x to log4j v2 therefore may also
> require finding ways to upgrade or patch *all other dependencies which
> also rely on log4j v1*....and that likely would be a massive undertaking
> (possibly similar effort to a new major release of DSpace).
>
> This is why I recommend that anyone who wants to be on log4j v2 please
> consider upgrading to DSpace 7.x in the near future (version 7.2 is right
> around the corner & due on Feb 7).  It is not always easy (or even
> possible) to update dependencies in the DSpace 6.x/5.x platforms, as we are
> sometimes blocked / or hampered by the age of the User Interface
> technologies (especially Apache Cocoon for XMLUI) and other core
> dependencies (older Solr, Spring technologies, etc.)
>
> If you or anyone else has further questions on this, let us know on this
> list,
>
> Tim
>
> On Wednesday, January 5, 2022 at 12:42:34 PM UTC-6 [email protected]
> wrote:
>
>> Hello all,
>>
>> I'm aware that DSpace 6.x is not going to get a patch that would allow
>> end-users to upgrade to Log4Jv2, but I was wondering whether anyone else is
>> likely to be working on this?
>>
>> Thanks,
>>
>> Sarah
>>
> --
> All messages to this mailing list should adhere to the Code of Conduct:
> https://www.lyrasis.org/about/Pages/Code-of-Conduct.aspx
> ---
> You received this message because you are subscribed to the Google Groups
> "DSpace Technical Support" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/dspace-tech/f81811b6-886c-4947-8234-636a6dba8493n%40googlegroups.com
> <https://groups.google.com/d/msgid/dspace-tech/f81811b6-886c-4947-8234-636a6dba8493n%40googlegroups.com?utm_medium=email&utm_source=footer>
> .
>


-- 
Dr. Sarah Mount
Technical Lead, Beautiful Canoe
Fellow of the Software Sustainability Institute
twitter: @snim2

-- 
All messages to this mailing list should adhere to the Code of Conduct: 
https://www.lyrasis.org/about/Pages/Code-of-Conduct.aspx
--- 
You received this message because you are subscribed to the Google Groups 
"DSpace Technical Support" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/dspace-tech/CALG3WZ%3D6FLLQSvYO%3DsB%2BgB42rsDNLvo%3DcmqQdQhtBYNkJK7BZw%40mail.gmail.com.

Reply via email to