Hi Sarah,

Good to know you are working on something.  If you *do* manage to find a 
way to upgrade DSpace 6.4 to use log4j v2, please send us a PR.  We'd be 
open to making this fix for everyone in a new 6.x release.  However, as 
previously implied, I'm not aware of anyone who has managed to get this to 
work properly yet....doesn't mean it's impossible, just that it's not an 
easy fix to make (as it sounds like you've discovered).

If others are also interested in collaborating with you (and it sounds like 
they might be), you are also welcome to create a *draft* PR in our 
https://github.com/DSpace/DSpace (dspace-6_x branch) and invite others to 
collaborate on it with you.   We obviously won't merge anything into the 
core code until it's proven to work (i.e. fully tested/reviewed), but we 
welcome anyone to create draft PRs if they are looking for collaborators / 
early feedback, etc.

Good luck & please do let us know how it goes!

Tim
On Tuesday, January 11, 2022 at 4:25:27 AM UTC-6 [email protected] wrote:

> Hi Tim,
>
> Many thanks for this. For reasons that I won't go into here, it looks like 
> trying to patch 6.4 is something that we need to try. It may be that the 
> v1->v2 bridge that's been mentioned will be a better option for us, but 
> we're looking at both choices right now.
>
> Currently, I have a version of 6.4 that does not directly use log4j v1, 
> but it does still have a handful (<20) of transitive imports of v1 from 
> slf4 and Solr. The patched 6.4 can compile all the front-ends and pass the 
> unit/integration tests, and I can run DSpace locally in a container -- but 
> I haven't tackled converting the configuration files in earnest yet, and 
> I've noticed that the PR for v7 uses XML for some configuration files.
>
> My local PR for this is already approx. 1kloc larger than the PR to 
> upgrade log4j in DSpace v7, and no doubt it'll get larger still before we 
> take a decision to either merge or abandon it.
>
> Sarah
>
>
>
> On Mon, 10 Jan 2022 at 16:28, 'Tim Donohue' via DSpace Technical Support <
> [email protected]> wrote:
>
>> Hi Sarah,
>>
>> Just wanted to note that I'm not aware of anyone who has tried updating 
>> DSpace 6.x (or any prior release) to log4j v2.  As I initially noted in 
>> this log4j summary email (
>> https://groups.google.com/g/dspace-tech/c/QR59bS4nIT0/m/Ze2hyOhhAgAJ), I 
>> believe this upgrade would be extremely complex (and I'm not even sure if 
>> it's possible).  
>>
>> Unfortunately, most of the other dependencies which DSpace 6.x (and 
>> 5.x/4.x or any prior release) use all also rely on log4j v1 (especially 
>> Solr) .  Attempting to upgrade DSpace 6.x to log4j v2 therefore may also 
>> require finding ways to upgrade or patch *all other dependencies which 
>> also rely on log4j v1*....and that likely would be a massive undertaking 
>> (possibly similar effort to a new major release of DSpace).
>>
>> This is why I recommend that anyone who wants to be on log4j v2 please 
>> consider upgrading to DSpace 7.x in the near future (version 7.2 is right 
>> around the corner & due on Feb 7).  It is not always easy (or even 
>> possible) to update dependencies in the DSpace 6.x/5.x platforms, as we are 
>> sometimes blocked / or hampered by the age of the User Interface 
>> technologies (especially Apache Cocoon for XMLUI) and other core 
>> dependencies (older Solr, Spring technologies, etc.)
>>
>> If you or anyone else has further questions on this, let us know on this 
>> list,
>>
>> Tim
>>
>> On Wednesday, January 5, 2022 at 12:42:34 PM UTC-6 [email protected] 
>> wrote:
>>
>>> Hello all,
>>>
>>> I'm aware that DSpace 6.x is not going to get a patch that would allow 
>>> end-users to upgrade to Log4Jv2, but I was wondering whether anyone else is 
>>> likely to be working on this?
>>>
>>> Thanks,
>>>
>>> Sarah
>>>
>> -- 
>> All messages to this mailing list should adhere to the Code of Conduct: 
>> https://www.lyrasis.org/about/Pages/Code-of-Conduct.aspx
>> --- 
>> You received this message because you are subscribed to the Google Groups 
>> "DSpace Technical Support" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email to [email protected].
>> To view this discussion on the web visit 
>> https://groups.google.com/d/msgid/dspace-tech/f81811b6-886c-4947-8234-636a6dba8493n%40googlegroups.com
>>  
>> <https://groups.google.com/d/msgid/dspace-tech/f81811b6-886c-4947-8234-636a6dba8493n%40googlegroups.com?utm_medium=email&utm_source=footer>
>> .
>>
>
>
> -- 
> Dr. Sarah Mount
> Technical Lead, Beautiful Canoe
> Fellow of the Software Sustainability Institute
> twitter: @snim2
>

-- 
All messages to this mailing list should adhere to the Code of Conduct: 
https://www.lyrasis.org/about/Pages/Code-of-Conduct.aspx
--- 
You received this message because you are subscribed to the Google Groups 
"DSpace Technical Support" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/dspace-tech/f7ad728a-14a3-4e3e-9647-cdb7d64cc277n%40googlegroups.com.

Reply via email to