[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17330868#comment-17330868 ] Hadoop QA commented on OOZIE-3609: -- Testing JIRA OOZIE-3609 Cleaning local git workspace {color:green}+1 PATCH_APPLIES{color} {color:green}+1 CLEAN{color} {color:green}+1 RAW_PATCH_ANALYSIS{color} .{color:green}+1{color} the patch does not introduce any @author tags .{color:green}+1{color} the patch does not introduce any tabs .{color:green}+1{color} the patch does not introduce any trailing spaces .{color:green}+1{color} the patch does not introduce any star imports .{color:green}+1{color} the patch does not introduce any line longer than 132 .{color:green}+1{color} the patch adds/modifies 5 testcase(s) {color:green}+1 RAT{color} .{color:green}+1{color} the patch does not seem to introduce new RAT warnings {color:green}+1 JAVADOC{color} .{color:green}+1{color} Javadoc generation succeeded with the patch .{color:green}+1{color} the patch does not seem to introduce new Javadoc warning(s) {color:green}+1 COMPILE{color} .{color:green}+1{color} HEAD compiles .{color:green}+1{color} patch compiles .{color:green}+1{color} the patch does not seem to introduce new javac warnings {color:red}-1{color} There are [20] new bugs found below threshold in total that must be fixed. .{color:green}+1{color} There are no new bugs found in [fluent-job/fluent-job-api]. .{color:green}+1{color} There are no new bugs found in [docs]. .{color:red}-1{color} There are [5] new bugs found below threshold in [core] that must be fixed. .You can find the SpotBugs diff here (look for the red and orange ones): core/findbugs-new.html .The most important SpotBugs errors are: .At BulkJPAExecutor.java:[line 206]: This use of javax/persistence/EntityManager.createQuery(Ljava/lang/String;)Ljavax/persistence/Query; can be vulnerable to SQL/JPQL injection .At BulkJPAExecutor.java:[line 176]: At BulkJPAExecutor.java:[line 175] .At BulkJPAExecutor.java:[line 205]: At BulkJPAExecutor.java:[line 199] .This use of javax/persistence/EntityManager.createQuery(Ljava/lang/String;)Ljavax/persistence/Query; can be vulnerable to SQL/JPQL injection: At BulkJPAExecutor.java:[line 206] .At BulkJPAExecutor.java:[line 111]: At BulkJPAExecutor.java:[line 127] .{color:green}+1{color} There are no new bugs found in [sharelib/spark]. .{color:green}+1{color} There are no new bugs found in [sharelib/git]. .{color:green}+1{color} There are no new bugs found in [sharelib/sqoop]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive2]. .{color:green}+1{color} There are no new bugs found in [sharelib/streaming]. .{color:green}+1{color} There are no new bugs found in [sharelib/pig]. .{color:green}+1{color} There are no new bugs found in [sharelib/oozie]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive]. .{color:green}+1{color} There are no new bugs found in [sharelib/hcatalog]. .{color:green}+1{color} There are no new bugs found in [sharelib/distcp]. .{color:red}-1{color} There are [15] new bugs found below threshold in [tools] that must be fixed, listing only the first [5] ones. .You can find the SpotBugs diff here (look for the red and orange ones): tools/findbugs-new.html .The top [5] most important SpotBugs errors are: .At OozieDBCLI.java:[line 584]: This use of java/sql/Statement.executeUpdate(Ljava/lang/String;)I can be vulnerable to SQL injection .At OozieDBCLI.java:[line 574]: At OozieDBCLI.java:[line 573] .At OozieDBCLI.java:[line 577]: At OozieDBCLI.java:[line 575] .At OozieDBCLI.java:[line 579]: At OozieDBCLI.java:[line 578] .At OozieDBCLI.java:[line 584]: At OozieDBCLI.java:[line 581] .{color:green}+1{color} There are no new bugs found in [server]. .{color:green}+1{color} There are no new bugs found in [client]. .{color:green}+1{color} There are no new bugs found in [examples]. .{color:green}+1{color} There are no new bugs found in [webapp]. {color:green}+1 BACKWARDS_COMPATIBILITY{color} .{color:green}+1{color} the patch does not change any JPA Entity/Colum/Basic/Lob/Transient annotations .{color:green}+1{color} the patch does not modify JPA files {color:green}+1 TESTS{color} .Tests run: 3217 {color:green}+1 DISTRO{color} .{color:green}+1{color} distro tarball builds with the patch {color:green}+1 MODERNIZER{color} {color:red}*-1 Overall result, please check the reported -1(s)*{color} The full output of the test-patch run is available at . https://ci-hadoop.apache.org/job/PreCommit-OOZIE-Build/12/ > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/brows
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17330441#comment-17330441 ] Hadoop QA commented on OOZIE-3609: -- PreCommit-OOZIE-Build started > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch, OOZIE-3609-002.patch, > OOZIE-3609-003.patch, OOZIE-3609-004.patch, OOZIE-3609-005.patch, > OOZIE-3609-006.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17329314#comment-17329314 ] Hadoop QA commented on OOZIE-3609: -- Testing JIRA OOZIE-3609 Cleaning local git workspace {color:green}+1 PATCH_APPLIES{color} {color:green}+1 CLEAN{color} {color:red}-1 RAW_PATCH_ANALYSIS{color} .{color:green}+1{color} the patch does not introduce any @author tags .{color:green}+1{color} the patch does not introduce any tabs .{color:green}+1{color} the patch does not introduce any trailing spaces .{color:green}+1{color} the patch does not introduce any star imports .{color:red}-1{color} the patch contains 2 line(s) longer than 132 characters .{color:green}+1{color} the patch adds/modifies 5 testcase(s) {color:green}+1 RAT{color} .{color:green}+1{color} the patch does not seem to introduce new RAT warnings {color:green}+1 JAVADOC{color} .{color:green}+1{color} Javadoc generation succeeded with the patch .{color:green}+1{color} the patch does not seem to introduce new Javadoc warning(s) {color:green}+1 COMPILE{color} .{color:green}+1{color} HEAD compiles .{color:green}+1{color} patch compiles .{color:green}+1{color} the patch does not seem to introduce new javac warnings {color:red}-1{color} There are [20] new bugs found below threshold in total that must be fixed. .{color:green}+1{color} There are no new bugs found in [fluent-job/fluent-job-api]. .{color:green}+1{color} There are no new bugs found in [docs]. .{color:red}-1{color} There are [5] new bugs found below threshold in [core] that must be fixed. .You can find the SpotBugs diff here (look for the red and orange ones): core/findbugs-new.html .The most important SpotBugs errors are: .At BulkJPAExecutor.java:[line 206]: This use of javax/persistence/EntityManager.createQuery(Ljava/lang/String;)Ljavax/persistence/Query; can be vulnerable to SQL/JPQL injection .At BulkJPAExecutor.java:[line 176]: At BulkJPAExecutor.java:[line 175] .At BulkJPAExecutor.java:[line 205]: At BulkJPAExecutor.java:[line 199] .This use of javax/persistence/EntityManager.createQuery(Ljava/lang/String;)Ljavax/persistence/Query; can be vulnerable to SQL/JPQL injection: At BulkJPAExecutor.java:[line 206] .At BulkJPAExecutor.java:[line 111]: At BulkJPAExecutor.java:[line 127] .{color:green}+1{color} There are no new bugs found in [sharelib/spark]. .{color:green}+1{color} There are no new bugs found in [sharelib/git]. .{color:green}+1{color} There are no new bugs found in [sharelib/sqoop]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive2]. .{color:green}+1{color} There are no new bugs found in [sharelib/streaming]. .{color:green}+1{color} There are no new bugs found in [sharelib/pig]. .{color:green}+1{color} There are no new bugs found in [sharelib/oozie]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive]. .{color:green}+1{color} There are no new bugs found in [sharelib/hcatalog]. .{color:green}+1{color} There are no new bugs found in [sharelib/distcp]. .{color:red}-1{color} There are [15] new bugs found below threshold in [tools] that must be fixed, listing only the first [5] ones. .You can find the SpotBugs diff here (look for the red and orange ones): tools/findbugs-new.html .The top [5] most important SpotBugs errors are: .At OozieDBCLI.java:[line 584]: This use of java/sql/Statement.executeUpdate(Ljava/lang/String;)I can be vulnerable to SQL injection .At OozieDBCLI.java:[line 574]: At OozieDBCLI.java:[line 573] .At OozieDBCLI.java:[line 577]: At OozieDBCLI.java:[line 575] .At OozieDBCLI.java:[line 579]: At OozieDBCLI.java:[line 578] .At OozieDBCLI.java:[line 584]: At OozieDBCLI.java:[line 581] .{color:orange}0{color} There are [4] new bugs found in [server] that would be nice to have fixed. .You can find the SpotBugs diff here: server/findbugs-new.html .{color:green}+1{color} There are no new bugs found in [client]. .{color:green}+1{color} There are no new bugs found in [examples]. .{color:green}+1{color} There are no new bugs found in [webapp]. {color:green}+1 BACKWARDS_COMPATIBILITY{color} .{color:green}+1{color} the patch does not change any JPA Entity/Colum/Basic/Lob/Transient annotations .{color:green}+1{color} the patch does not modify JPA files {color:green}+1 TESTS{color} .Tests run: 3217 .{color:orange}Tests failed at first run:{color} TestCoordActionInputCheckXCommandNonUTC>TestCoordActionInputCheckXCommand#testNone TestBlockingInputStream#testFastWritingBlockingInputStream TestBlockingInputStream#testLimitedWritingBlockingInputStream .For the complete list of flaky tests, see TEST-SUMMARY-FULL files. {color:green}+1 DISTRO{color} .{color:green}+1{color} distro tarball b
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17329185#comment-17329185 ] Hadoop QA commented on OOZIE-3609: -- PreCommit-OOZIE-Build started > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch, OOZIE-3609-002.patch, > OOZIE-3609-003.patch, OOZIE-3609-004.patch, OOZIE-3609-005.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17204717#comment-17204717 ] Andras Salamon commented on OOZIE-3609: --- I also like this change, the RAT warning can easily be solved. The change also upgrades curator from 2.5.0 to 4.3.0, probably because we need a recent Zookeeper for this feature. Lots of Zookeeper excludes will force to use zookeeper 3.5.7 (personally I prefer using dependencyManagement to fix the a version instead of the excludes but it's not that important). Can we just upgrade curator that easily? We were not brave enough to upgrade to 2.12 or 2.13 (see OOZIE-2231). > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch, OOZIE-3609-002.patch, > OOZIE-3609-003.patch, OOZIE-3609-004.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17190605#comment-17190605 ] Gézapeti commented on OOZIE-3609: - The RAT warning is something we must fix before commit. It means that you've created a new file and it does not have the ASF license header. Please copy a header over to SSLZookeeperFactory. Otherwise the fix looks reasonable > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch, OOZIE-3609-002.patch, > OOZIE-3609-003.patch, OOZIE-3609-004.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17187903#comment-17187903 ] Hadoop QA commented on OOZIE-3609: -- Testing JIRA OOZIE-3609 Cleaning local git workspace {color:green}+1 PATCH_APPLIES{color} {color:green}+1 CLEAN{color} {color:green}+1 RAW_PATCH_ANALYSIS{color} .{color:green}+1{color} the patch does not introduce any @author tags .{color:green}+1{color} the patch does not introduce any tabs .{color:green}+1{color} the patch does not introduce any trailing spaces .{color:green}+1{color} the patch does not introduce any star imports .{color:green}+1{color} the patch does not introduce any line longer than 132 .{color:green}+1{color} the patch adds/modifies 3 testcase(s) {color:red}-1 RAT{color} .{color:red}-1{color} the patch seems to introduce 1 new RAT warning(s) {color:green}+1 JAVADOC{color} .{color:green}+1{color} Javadoc generation succeeded with the patch .{color:green}+1{color} the patch does not seem to introduce new Javadoc warning(s) {color:green}+1 COMPILE{color} .{color:green}+1{color} HEAD compiles .{color:green}+1{color} patch compiles .{color:green}+1{color} the patch does not seem to introduce new javac warnings {color:red}-1{color} There are [19] new bugs found below threshold in total that must be fixed. .{color:green}+1{color} There are no new bugs found in [fluent-job/fluent-job-api]. .{color:green}+1{color} There are no new bugs found in [docs]. .{color:red}-1{color} There are [3] new bugs found below threshold in [core] that must be fixed. .You can find the SpotBugs diff here (look for the red and orange ones): core/findbugs-new.html .The most important SpotBugs errors are: .At BulkJPAExecutor.java:[line 206]: This use of javax/persistence/EntityManager.createQuery(Ljava/lang/String;)Ljavax/persistence/Query; can be vulnerable to SQL/JPQL injection .At BulkJPAExecutor.java:[line 176]: At BulkJPAExecutor.java:[line 175] .At BulkJPAExecutor.java:[line 205]: At BulkJPAExecutor.java:[line 199] .java/io/File.(Ljava/lang/String;Ljava/lang/String;)V reads a file whose location might be specified by user input: At BulkJPAExecutor.java:[line 206] .At AuthorizationService.java:[line 189]: At AuthorizationService.java:[line 192] .{color:green}+1{color} There are no new bugs found in [sharelib/spark]. .{color:green}+1{color} There are no new bugs found in [sharelib/git]. .{color:green}+1{color} There are no new bugs found in [sharelib/sqoop]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive2]. .{color:green}+1{color} There are no new bugs found in [sharelib/streaming]. .{color:green}+1{color} There are no new bugs found in [sharelib/pig]. .{color:red}-1{color} There are [1] new bugs found below threshold in [sharelib/oozie] that must be fixed. .You can find the SpotBugs diff here (look for the red and orange ones): sharelib/oozie/findbugs-new.html .The most important SpotBugs errors are: .At ShellMain.java:[line 93]: This usage of java/lang/ProcessBuilder. (Ljava/util/List;)V can be vulnerable to Command Injection .At ShellMain.java:[line 91]: At ShellMain.java:[line 90] .At ShellMain.java:[line 92] .{color:green}+1{color} There are no new bugs found in [sharelib/hive]. .{color:green}+1{color} There are no new bugs found in [sharelib/hcatalog]. .{color:green}+1{color} There are no new bugs found in [sharelib/distcp]. .{color:red}-1{color} There are [15] new bugs found below threshold in [tools] that must be fixed, listing only the first [5] ones. .You can find the SpotBugs diff here (look for the red and orange ones): tools/findbugs-new.html .The top [5] most important SpotBugs errors are: .At OozieDBCLI.java:[line 584]: This use of java/sql/Statement.executeUpdate(Ljava/lang/String;)I can be vulnerable to SQL injection .At OozieDBCLI.java:[line 574]: At OozieDBCLI.java:[line 573] .At OozieDBCLI.java:[line 577]: At OozieDBCLI.java:[line 575] .At OozieDBCLI.java:[line 579]: At OozieDBCLI.java:[line 578] .At OozieDBCLI.java:[line 584]: At OozieDBCLI.java:[line 581] .{color:orange}0{color} There are [4] new bugs found in [server] that would be nice to have fixed. .You can find the SpotBugs diff here: server/findbugs-new.html .{color:green}+1{color} There are no new bugs found in [client]. .{color:green}+1{color} There are no new bugs found in [examples]. .{color:green}+1{color} There are no new bugs found in [webapp]. {color:green}+1 BACKWARDS_COMPATIBILITY{color} .{color:green}+1{color} the patch does not change any JPA Entity/Colum/Basic/Lob/Transient annotations .{color:green}+1{color} the patch does not modify JPA files {color:green}+1 TESTS{color} .Tests run:
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17187803#comment-17187803 ] Hadoop QA commented on OOZIE-3609: -- PreCommit-OOZIE-Build started > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch, OOZIE-3609-002.patch, > OOZIE-3609-003.patch, OOZIE-3609-004.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17186793#comment-17186793 ] Gézapeti commented on OOZIE-3609: - Wow, this looks nice > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch, OOZIE-3609-002.patch, > OOZIE-3609-003.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17185423#comment-17185423 ] Hadoop QA commented on OOZIE-3609: -- Testing JIRA OOZIE-3609 Cleaning local git workspace {color:green}+1 PATCH_APPLIES{color} {color:green}+1 CLEAN{color} {color:green}+1 RAW_PATCH_ANALYSIS{color} .{color:green}+1{color} the patch does not introduce any @author tags .{color:green}+1{color} the patch does not introduce any tabs .{color:green}+1{color} the patch does not introduce any trailing spaces .{color:green}+1{color} the patch does not introduce any star imports .{color:green}+1{color} the patch does not introduce any line longer than 132 .{color:green}+1{color} the patch adds/modifies 1 testcase(s) {color:red}-1 RAT{color} .{color:red}-1{color} the patch seems to introduce 1 new RAT warning(s) {color:green}+1 JAVADOC{color} .{color:green}+1{color} Javadoc generation succeeded with the patch .{color:green}+1{color} the patch does not seem to introduce new Javadoc warning(s) {color:green}+1 COMPILE{color} .{color:green}+1{color} HEAD compiles .{color:green}+1{color} patch compiles .{color:green}+1{color} the patch does not seem to introduce new javac warnings {color:red}-1{color} There are [6] new bugs found below threshold in total that must be fixed. .{color:green}+1{color} There are no new bugs found in [docs]. .{color:green}+1{color} There are no new bugs found in [client]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive2]. .{color:green}+1{color} There are no new bugs found in [sharelib/distcp]. .{color:green}+1{color} There are no new bugs found in [sharelib/pig]. .{color:green}+1{color} There are no new bugs found in [sharelib/git]. .{color:green}+1{color} There are no new bugs found in [sharelib/streaming]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive]. .{color:green}+1{color} There are no new bugs found in [sharelib/oozie]. .{color:green}+1{color} There are no new bugs found in [sharelib/sqoop]. .{color:green}+1{color} There are no new bugs found in [sharelib/hcatalog]. .{color:green}+1{color} There are no new bugs found in [sharelib/spark]. .{color:green}+1{color} There are no new bugs found in [webapp]. .{color:green}+1{color} There are no new bugs found in [examples]. .{color:green}+1{color} There are no new bugs found in [server]. .{color:green}+1{color} There are no new bugs found in [fluent-job/fluent-job-api]. .{color:red}-1{color} There are [6] new bugs found below threshold in [core] that must be fixed, listing only the first [5] ones. .You can find the SpotBugs diff here (look for the red and orange ones): core/findbugs-new.html .The top [5] most important SpotBugs errors are: .At BulkJPAExecutor.java:[line 206]: This use of javax/persistence/EntityManager.createQuery(Ljava/lang/String;)Ljavax/persistence/Query; can be vulnerable to SQL/JPQL injection .At BulkJPAExecutor.java:[line 176]: At BulkJPAExecutor.java:[line 175] .At BulkJPAExecutor.java:[line 205]: At BulkJPAExecutor.java:[line 199] .This use of javax/persistence/EntityManager.createQuery(Ljava/lang/String;)Ljavax/persistence/Query; can be vulnerable to SQL/JPQL injection: At BulkJPAExecutor.java:[line 206] .At BulkJPAExecutor.java:[line 111]: At BulkJPAExecutor.java:[line 127] .{color:green}+1{color} There are no new bugs found in [tools]. {color:green}+1 BACKWARDS_COMPATIBILITY{color} .{color:green}+1{color} the patch does not change any JPA Entity/Colum/Basic/Lob/Transient annotations .{color:green}+1{color} the patch does not modify JPA files {color:red}-1 TESTS{color} .Tests run: 3215 .Tests failed : 0 .Tests in error : 2 .Tests timed out : 0 {color:red}-1{color} [ERROR] There are [2] test errors in [zookeeper-security-tests]. Listing only the first [5] ones testCheckAndSetACLs:org.apache.oozie.util.TestZKUtilsWithSecurity testNewUsingACLs:org.apache.oozie.util.TestZKUtilsWithSecurity Check console output for the full list of errors/failures {color:green}+1 DISTRO{color} .{color:green}+1{color} distro tarball builds with the patch {color:green}+1 MODERNIZER{color} {color:red}*-1 Overall result, please check the reported -1(s)*{color} The full output of the test-patch run is available at . https://ci-hadoop.apache.org/job/PreCommit-OOZIE-Build/4/ > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-36
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17185298#comment-17185298 ] Hadoop QA commented on OOZIE-3609: -- PreCommit-OOZIE-Build started > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch, OOZIE-3609-002.patch, > OOZIE-3609-003.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17184707#comment-17184707 ] Hadoop QA commented on OOZIE-3609: -- Testing JIRA OOZIE-3609 Cleaning local git workspace {color:green}+1 PATCH_APPLIES{color} {color:green}+1 CLEAN{color} {color:red}-1 RAW_PATCH_ANALYSIS{color} .{color:green}+1{color} the patch does not introduce any @author tags .{color:green}+1{color} the patch does not introduce any tabs .{color:green}+1{color} the patch does not introduce any trailing spaces .{color:green}+1{color} the patch does not introduce any star imports .{color:green}+1{color} the patch does not introduce any line longer than 132 .{color:red}-1{color} the patch does not add/modify any testcase {color:red}-1 RAT{color} .{color:red}-1{color} the patch seems to introduce 1 new RAT warning(s) {color:green}+1 JAVADOC{color} .{color:green}+1{color} Javadoc generation succeeded with the patch .{color:green}+1{color} the patch does not seem to introduce new Javadoc warning(s) {color:green}+1 COMPILE{color} .{color:green}+1{color} HEAD compiles .{color:green}+1{color} patch compiles .{color:green}+1{color} the patch does not seem to introduce new javac warnings {color:red}-1{color} There are [3] new bugs found below threshold in total that must be fixed. .{color:orange}0{color} There are [4] new bugs found in [server] that would be nice to have fixed. .You can find the SpotBugs diff here: server/findbugs-new.html .{color:red}-1{color} There are [3] new bugs found below threshold in [core] that must be fixed. .You can find the SpotBugs diff here (look for the red and orange ones): core/findbugs-new.html .The most important SpotBugs errors are: .At BulkJPAExecutor.java:[line 206]: This use of javax/persistence/EntityManager.createQuery(Ljava/lang/String;)Ljavax/persistence/Query; can be vulnerable to SQL/JPQL injection .At BulkJPAExecutor.java:[line 176]: At BulkJPAExecutor.java:[line 175] .At BulkJPAExecutor.java:[line 205]: At BulkJPAExecutor.java:[line 199] .java/io/File.(Ljava/lang/String;Ljava/lang/String;)V reads a file whose location might be specified by user input: At BulkJPAExecutor.java:[line 206] .At AuthorizationService.java:[line 189]: At AuthorizationService.java:[line 192] .{color:green}+1{color} There are no new bugs found in [client]. .{color:green}+1{color} There are no new bugs found in [sharelib/streaming]. .{color:green}+1{color} There are no new bugs found in [sharelib/git]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive2]. .{color:green}+1{color} There are no new bugs found in [sharelib/hcatalog]. .{color:green}+1{color} There are no new bugs found in [sharelib/sqoop]. .{color:green}+1{color} There are no new bugs found in [sharelib/oozie]. .{color:green}+1{color} There are no new bugs found in [sharelib/pig]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive]. .{color:green}+1{color} There are no new bugs found in [sharelib/spark]. .{color:green}+1{color} There are no new bugs found in [sharelib/distcp]. .{color:green}+1{color} There are no new bugs found in [webapp]. .{color:green}+1{color} There are no new bugs found in [docs]. .{color:green}+1{color} There are no new bugs found in [tools]. .{color:green}+1{color} There are no new bugs found in [fluent-job/fluent-job-api]. .{color:green}+1{color} There are no new bugs found in [examples]. {color:green}+1 BACKWARDS_COMPATIBILITY{color} .{color:green}+1{color} the patch does not change any JPA Entity/Colum/Basic/Lob/Transient annotations .{color:green}+1{color} the patch does not modify JPA files {color:red}-1 TESTS{color} .Tests run: 3215 .Tests failed : 1 .Tests in error : 2 .Tests timed out : 0 {color:red}-1{color} [ERROR] There are [1] test failures in [core]. Listing only the first [5] ones testMetaData:org.apache.oozie.util.TestZKUtils {color:red}-1{color} [ERROR] There are [2] test errors in [zookeeper-security-tests]. Listing only the first [5] ones testCheckAndSetACLs:org.apache.oozie.util.TestZKUtilsWithSecurity testNewUsingACLs:org.apache.oozie.util.TestZKUtilsWithSecurity Check console output for the full list of errors/failures .{color:orange}Tests failed at first run:{color} TestBlockingInputStream#testFastWritingBlockingInputStream TestBlockingInputStream#testLimitedWritingBlockingInputStream .For the complete list of flaky tests, see TEST-SUMMARY-FULL files. {color:green}+1 DISTRO{color} .{color:green}+1{color} distro tarball builds with the patch {color:green}+1 MODERNIZER{color} {color:red}*-1 Overall result, please check the reported -1(s)*{color} The full output of the test
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17184626#comment-17184626 ] Hadoop QA commented on OOZIE-3609: -- PreCommit-OOZIE-Build started > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch, OOZIE-3609-002.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17183387#comment-17183387 ] Hadoop QA commented on OOZIE-3609: -- Testing JIRA OOZIE-3609 Cleaning local git workspace {color:green}+1 PATCH_APPLIES{color} {color:green}+1 CLEAN{color} {color:red}-1 RAW_PATCH_ANALYSIS{color} .{color:green}+1{color} the patch does not introduce any @author tags .{color:green}+1{color} the patch does not introduce any tabs .{color:green}+1{color} the patch does not introduce any trailing spaces .{color:green}+1{color} the patch does not introduce any star imports .{color:red}-1{color} the patch contains 1 line(s) longer than 132 characters .{color:red}-1{color} the patch does not add/modify any testcase {color:green}+1 RAT{color} .{color:green}+1{color} the patch does not seem to introduce new RAT warnings {color:red}-1 JAVADOC{color} .{color:red}-1{color} build with Javadoc generation fails with the patch {color:red}-1 COMPILE{color} .{color:green}+1{color} HEAD compiles .{color:red}-1{color} patch does not compile .{color:green}+1{color} the patch does not seem to introduce new javac warnings {color:green}+1{color} There are no new bugs found in total. .{color:green}+1{color} There are no new bugs found in [webapp]. .{color:green}+1{color} There are no new bugs found in [fluent-job/fluent-job-api]. .{color:green}+1{color} There are no new bugs found in [sharelib/streaming]. .{color:green}+1{color} There are no new bugs found in [sharelib/spark]. .{color:green}+1{color} There are no new bugs found in [sharelib/sqoop]. .{color:green}+1{color} There are no new bugs found in [sharelib/hcatalog]. .{color:green}+1{color} There are no new bugs found in [sharelib/git]. .{color:green}+1{color} There are no new bugs found in [sharelib/distcp]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive]. .{color:green}+1{color} There are no new bugs found in [sharelib/pig]. .{color:green}+1{color} There are no new bugs found in [sharelib/hive2]. .{color:green}+1{color} There are no new bugs found in [sharelib/oozie]. .{color:green}+1{color} There are no new bugs found in [tools]. .{color:green}+1{color} There are no new bugs found in [server]. .{color:green}+1{color} There are no new bugs found in [examples]. .{color:green}+1{color} There are no new bugs found in [docs]. .{color:green}+1{color} There are no new bugs found in [client]. .{color:green}+1{color} There are no new bugs found in [core]. {color:green}+1 BACKWARDS_COMPATIBILITY{color} .{color:green}+1{color} the patch does not change any JPA Entity/Colum/Basic/Lob/Transient annotations .{color:green}+1{color} the patch does not modify JPA files {color:red}-1 TESTS{color} - patch does not compile, cannot run test cases {color:red}-1 DISTRO{color} .{color:red}-1{color} distro tarball fails with the patch {color:red}-1 MODERNIZER{color} .{color:red}-1{color} Error during executing modernizer plugin on PATCH {color:red}*-1 Overall result, please check the reported -1(s)*{color} The full output of the test-patch run is available at . https://ci-hadoop.apache.org/job/PreCommit-OOZIE-Build/2/ > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)
[jira] [Commented] (OOZIE-3609) Zookeeper SSL/TLS support
[ https://issues.apache.org/jira/browse/OOZIE-3609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17183378#comment-17183378 ] Hadoop QA commented on OOZIE-3609: -- PreCommit-OOZIE-Build started > Zookeeper SSL/TLS support > - > > Key: OOZIE-3609 > URL: https://issues.apache.org/jira/browse/OOZIE-3609 > Project: Oozie > Issue Type: New Feature >Reporter: Adam Arvai >Assignee: Adam Arvai >Priority: Major > Attachments: OOZIE-3609-001.patch > > > Zookeeper 3.5.5 server can operate with SSL/TLS secure connection with its > clients. > We need to ensure Oozie can communicate with Zookeeper quorum via secure > SSL/TLS connection. -- This message was sent by Atlassian Jira (v8.3.4#803005)