Skip to content

hadoop 3.3.4漏洞修复 - #8710

Closed
Sun-Sandy wants to merge 2 commits into
apache:branch-3.3.4from
Sun-Sandy:branch-3.3.4
Closed

hadoop 3.3.4漏洞修复#8710
Sun-Sandy wants to merge 2 commits into
apache:branch-3.3.4from
Sun-Sandy:branch-3.3.4

Conversation

@Sun-Sandy

Copy link
Copy Markdown

Description of PR


dnsjava:dnsjava 2.1.7 ->3.6.0 已完成

org.eclipse.jetty:jetty-servlets 9.4.44.V20210927 ->9.4.54

io.netty:netty-handler 4.1.101.Final ->4.1.118.Final 已完成

org.apache.kerby:kerber-server 1.0.1 ->2.1.2 已完成

org.apache.avro:avro 1.7.7 ->1.11.4 已完成

commons-beanutils:commons-beanutils 1.9.4 ->1.11.0 已完成

org.jboss.xnio:xnio-api 3.8.7.Final ->3.8.14

org.eclipse.jetty:jetty-server 9.4.53.V20231009 ->12.0.38

How was this patch tested?

For code changes:

  • Does the title of this PR start with the corresponding JIRA issue id (e.g. 'HADOOP-17799. Your PR title ...')?
  • Object storage: Have the integration tests been executed and the endpoint
    declared according to the connector-specific documentation? Note: Automated CI
    testing doesn't cover all cases so manual testing with cloud storage is still
    required.
  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0?
  • If applicable, have you updated the LICENSE, LICENSE-binary, NOTICE-binary files?

AI Tooling

If an AI tool was used:

@hadoop-yetus

Copy link
Copy Markdown

💔 -1 overall

Vote Subsystem Runtime Logfile Comment
+0 🆗 reexec 4m 7s Docker mode activated.
_ Prechecks _
+1 💚 dupname 0m 0s No case conflicting files found.
+0 🆗 codespell 0m 0s codespell was not available.
+1 💚 @author 0m 0s The patch does not contain any @author tags.
+1 💚 test4tests 0m 0s The patch appears to include 4 new or modified test files.
_ branch-3.3.4 Compile Tests _
+0 🆗 mvndep 15m 28s Maven dependency ordering for branch
-1 ❌ mvninstall 15m 5s /branch-mvninstall-root.txt root in branch-3.3.4 failed.
-1 ❌ compile 6m 39s /branch-compile-root.txt root in branch-3.3.4 failed.
+1 💚 checkstyle 1m 32s branch-3.3.4 passed
-1 ❌ mvnsite 3m 54s /branch-mvnsite-root.txt root in branch-3.3.4 failed.
+1 💚 javadoc 5m 48s branch-3.3.4 passed
+0 🆗 spotbugs 0m 18s branch/hadoop-project no spotbugs output file (spotbugsXml.xml)
-1 ❌ spotbugs 0m 17s /branch-spotbugs-hadoop-yarn-project_hadoop-yarn_hadoop-yarn-applications_hadoop-yarn-applications-catalog_hadoop-yarn-applications-catalog-webapp.txt hadoop-yarn-applications-catalog-webapp in branch-3.3.4 failed.
+0 🆗 spotbugs 0m 16s branch/hadoop-client-modules/hadoop-client-runtime no spotbugs output file (spotbugsXml.xml)
-1 ❌ spotbugs 16m 48s /branch-spotbugs-root.txt root in branch-3.3.4 failed.
+1 💚 shadedclient 12m 55s branch has no errors when building and testing our client artifacts.
_ Patch Compile Tests _
+0 🆗 mvndep 1m 40s Maven dependency ordering for patch
-1 ❌ mvninstall 0m 39s /patch-mvninstall-hadoop-common-project_hadoop-common.txt hadoop-common in the patch failed.
-1 ❌ mvninstall 0m 12s /patch-mvninstall-hadoop-common-project_hadoop-registry.txt hadoop-registry in the patch failed.
-1 ❌ mvninstall 0m 24s /patch-mvninstall-hadoop-mapreduce-project_hadoop-mapreduce-client_hadoop-mapreduce-client-core.txt hadoop-mapreduce-client-core in the patch failed.
-1 ❌ mvninstall 0m 40s /patch-mvninstall-hadoop-yarn-project_hadoop-yarn_hadoop-yarn-applications_hadoop-yarn-applications-catalog_hadoop-yarn-applications-catalog-webapp.txt hadoop-yarn-applications-catalog-webapp in the patch failed.
-1 ❌ mvninstall 0m 20s /patch-mvninstall-hadoop-tools_hadoop-rumen.txt hadoop-rumen in the patch failed.
-1 ❌ mvninstall 1m 43s /patch-mvninstall-hadoop-client-modules_hadoop-client-runtime.txt hadoop-client-runtime in the patch failed.
-1 ❌ mvninstall 0m 21s /patch-mvninstall-root.txt root in the patch failed.
-1 ❌ compile 1m 15s /patch-compile-root.txt root in the patch failed.
-1 ❌ javac 1m 15s /patch-compile-root.txt root in the patch failed.
+1 💚 blanks 0m 0s The patch has no blanks issues.
-0 ⚠️ checkstyle 1m 22s /results-checkstyle-root.txt root: The patch generated 10 new + 469 unchanged - 2 fixed = 479 total (was 471)
-1 ❌ mvnsite 11m 31s /patch-mvnsite-root.txt root in the patch failed.
+1 💚 xml 0m 4s The patch has no ill-formed XML file.
+1 💚 javadoc 5m 22s the patch passed
+0 🆗 spotbugs 0m 16s hadoop-project has no data from spotbugs
-1 ❌ spotbugs 0m 16s /patch-spotbugs-hadoop-common-project_hadoop-registry.txt hadoop-registry in the patch failed.
-1 ❌ spotbugs 1m 1s /new-spotbugs-hadoop-mapreduce-project_hadoop-mapreduce-client_hadoop-mapreduce-client-core.html hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-core generated 1 new + 0 unchanged - 0 fixed = 1 total (was 0)
+0 🆗 spotbugs 0m 14s hadoop-client-modules/hadoop-client-runtime has no data from spotbugs
-1 ❌ spotbugs 2m 20s /patch-spotbugs-root.txt root in the patch failed.
-1 ❌ shadedclient 0m 56s patch has errors when building and testing our client artifacts.
_ Other Tests _
-1 ❌ unit 9m 17s /patch-unit-root.txt root in the patch failed.
+1 💚 asflicense 0m 33s The patch does not generate ASF License warnings.
133m 0s
Reason Tests
SpotBugs module:hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-core
A known null value is checked to see if it is an instance of org.apache.avro.util.Utf8 in org.apache.hadoop.mapreduce.jobhistory.JobSubmitted.customDecode(ResolvingDecoder) At JobSubmitted.java:checked to see if it is an instance of org.apache.avro.util.Utf8 in org.apache.hadoop.mapreduce.jobhistory.JobSubmitted.customDecode(ResolvingDecoder) At JobSubmitted.java:[line 1246]
Failed junit tests hadoop.security.authentication.util.TestZKSignerSecretProvider
Subsystem Report/Notes
Docker ClientAPI=1.55 ServerAPI=1.55 base: https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8710/1/artifact/out/Dockerfile
GITHUB PR #8710
Optional Tests dupname asflicense compile javac javadoc mvninstall mvnsite unit shadedclient codespell xml spotbugs checkstyle
uname Linux acf08e645c61 5.15.0-190-generic #200-Ubuntu SMP Fri Aug 7 15:06:04 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux
Build tool maven
Personality dev-support/bin/hadoop.sh
git revision branch-3.3.4 / e918fff
Default Java Private Build-1.8.0_362-8u372-gaus1-0ubuntu118.04-b09
Test Results https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8710/1/testReport/
Max. process+thread count 538 (vs. ulimit of 5500)
modules C: hadoop-project hadoop-common-project/hadoop-common hadoop-common-project/hadoop-registry hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-core hadoop-yarn-project/hadoop-yarn/hadoop-yarn-applications/hadoop-yarn-applications-catalog/hadoop-yarn-applications-catalog-webapp hadoop-tools/hadoop-rumen hadoop-client-modules/hadoop-client-runtime . U: .
Console output https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8710/1/console
versions git=2.17.1 maven=3.6.0 spotbugs=4.2.2
Powered by Apache Yetus 0.14.0-SNAPSHOT https://yetus.apache.org

This message was automatically generated.

@hadoop-yetus

Copy link
Copy Markdown

💔 -1 overall

Vote Subsystem Runtime Logfile Comment
+0 🆗 reexec 0m 23s Docker mode activated.
_ Prechecks _
+1 💚 dupname 0m 0s No case conflicting files found.
+0 🆗 codespell 0m 0s codespell was not available.
+1 💚 @author 0m 0s The patch does not contain any @author tags.
+1 💚 test4tests 0m 0s The patch appears to include 4 new or modified test files.
_ branch-3.3.4 Compile Tests _
+0 🆗 mvndep 15m 12s Maven dependency ordering for branch
-1 ❌ mvninstall 14m 38s /branch-mvninstall-root.txt root in branch-3.3.4 failed.
-1 ❌ compile 7m 15s /branch-compile-root.txt root in branch-3.3.4 failed.
+1 💚 checkstyle 1m 33s branch-3.3.4 passed
-1 ❌ mvnsite 3m 51s /branch-mvnsite-root.txt root in branch-3.3.4 failed.
+1 💚 javadoc 5m 48s branch-3.3.4 passed
+0 🆗 spotbugs 0m 21s branch/hadoop-project no spotbugs output file (spotbugsXml.xml)
-1 ❌ spotbugs 0m 16s /branch-spotbugs-hadoop-yarn-project_hadoop-yarn_hadoop-yarn-applications_hadoop-yarn-applications-catalog_hadoop-yarn-applications-catalog-webapp.txt hadoop-yarn-applications-catalog-webapp in branch-3.3.4 failed.
+0 🆗 spotbugs 0m 15s branch/hadoop-client-modules/hadoop-client-runtime no spotbugs output file (spotbugsXml.xml)
-1 ❌ spotbugs 16m 33s /branch-spotbugs-root.txt root in branch-3.3.4 failed.
+1 💚 shadedclient 12m 53s branch has no errors when building and testing our client artifacts.
_ Patch Compile Tests _
+0 🆗 mvndep 1m 44s Maven dependency ordering for patch
-1 ❌ mvninstall 0m 42s /patch-mvninstall-hadoop-common-project_hadoop-common.txt hadoop-common in the patch failed.
-1 ❌ mvninstall 0m 19s /patch-mvninstall-hadoop-common-project_hadoop-registry.txt hadoop-registry in the patch failed.
-1 ❌ mvninstall 0m 28s /patch-mvninstall-hadoop-mapreduce-project_hadoop-mapreduce-client_hadoop-mapreduce-client-core.txt hadoop-mapreduce-client-core in the patch failed.
-1 ❌ mvninstall 0m 40s /patch-mvninstall-hadoop-yarn-project_hadoop-yarn_hadoop-yarn-applications_hadoop-yarn-applications-catalog_hadoop-yarn-applications-catalog-webapp.txt hadoop-yarn-applications-catalog-webapp in the patch failed.
-1 ❌ mvninstall 0m 19s /patch-mvninstall-hadoop-tools_hadoop-rumen.txt hadoop-rumen in the patch failed.
-1 ❌ mvninstall 2m 5s /patch-mvninstall-hadoop-client-modules_hadoop-client-runtime.txt hadoop-client-runtime in the patch failed.
-1 ❌ mvninstall 0m 24s /patch-mvninstall-root.txt root in the patch failed.
+1 💚 compile 11m 53s the patch passed
-1 ❌ javac 11m 53s /results-compile-javac-root.txt root generated 229 new + 1738 unchanged - 2 fixed = 1967 total (was 1740)
-1 ❌ blanks 0m 0s /blanks-tabs.txt The patch 8 line(s) with tabs.
-0 ⚠️ checkstyle 1m 37s /results-checkstyle-root.txt root: The patch generated 10 new + 469 unchanged - 2 fixed = 479 total (was 471)
+1 💚 mvnsite 19m 25s the patch passed
+1 💚 xml 0m 4s The patch has no ill-formed XML file.
+1 💚 javadoc 5m 13s the patch passed
+0 🆗 spotbugs 0m 15s hadoop-project has no data from spotbugs
-1 ❌ spotbugs 0m 41s /new-spotbugs-hadoop-common-project_hadoop-registry.html hadoop-common-project/hadoop-registry generated 1 new + 0 unchanged - 0 fixed = 1 total (was 0)
-1 ❌ spotbugs 1m 0s /new-spotbugs-hadoop-mapreduce-project_hadoop-mapreduce-client_hadoop-mapreduce-client-core.html hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-core generated 1 new + 0 unchanged - 0 fixed = 1 total (was 0)
+0 🆗 spotbugs 0m 16s hadoop-client-modules/hadoop-client-runtime has no data from spotbugs
-1 ❌ shadedclient 21m 39s patch has errors when building and testing our client artifacts.
_ Other Tests _
-1 ❌ unit 8m 27s /patch-unit-root.txt root in the patch failed.
+1 💚 asflicense 0m 41s The patch does not generate ASF License warnings.
166m 36s
Reason Tests
SpotBugs module:hadoop-common-project/hadoop-registry
Dead store to ftxn in org.apache.hadoop.registry.server.services.MicroZookeeperService.serviceStart() At MicroZookeeperService.java:org.apache.hadoop.registry.server.services.MicroZookeeperService.serviceStart() At MicroZookeeperService.java:[line 231]
SpotBugs module:hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-core
A known null value is checked to see if it is an instance of org.apache.avro.util.Utf8 in org.apache.hadoop.mapreduce.jobhistory.JobSubmitted.customDecode(ResolvingDecoder) At JobSubmitted.java:checked to see if it is an instance of org.apache.avro.util.Utf8 in org.apache.hadoop.mapreduce.jobhistory.JobSubmitted.customDecode(ResolvingDecoder) At JobSubmitted.java:[line 1246]
Failed junit tests hadoop.security.authentication.util.TestZKSignerSecretProvider
Subsystem Report/Notes
Docker ClientAPI=1.55 ServerAPI=1.55 base: https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8710/2/artifact/out/Dockerfile
GITHUB PR #8710
Optional Tests dupname asflicense compile javac javadoc mvninstall mvnsite unit shadedclient codespell xml spotbugs checkstyle
uname Linux 1bb191336856 5.15.0-190-generic #200-Ubuntu SMP Fri Aug 7 15:06:04 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux
Build tool maven
Personality dev-support/bin/hadoop.sh
git revision branch-3.3.4 / 93bba46
Default Java Private Build-1.8.0_362-8u372-gaus1-0ubuntu118.04-b09
Test Results https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8710/2/testReport/
Max. process+thread count 538 (vs. ulimit of 5500)
modules C: hadoop-project hadoop-common-project/hadoop-common hadoop-common-project/hadoop-registry hadoop-mapreduce-project/hadoop-mapreduce-client/hadoop-mapreduce-client-core hadoop-yarn-project/hadoop-yarn/hadoop-yarn-applications/hadoop-yarn-applications-catalog/hadoop-yarn-applications-catalog-webapp hadoop-tools/hadoop-rumen hadoop-client-modules/hadoop-client-runtime . U: .
Console output https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8710/2/console
versions git=2.17.1 maven=3.6.0 spotbugs=4.2.2
Powered by Apache Yetus 0.14.0-SNAPSHOT https://yetus.apache.org

This message was automatically generated.

@pan3793

pan3793 commented Sep 4, 2026

Copy link
Copy Markdown
Member

do such a thing in your forked version, upstream does not accept changes after a version is officially released.

@pan3793 pan3793 closed this Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants