Skip to content

HBASE-29126 Bump netty4 to 4.1.119.Final - #130

Merged
NihalJain merged 2 commits into
apache:masterfrom
revathy023:patch-1
Mar 19, 2025
Merged

HBASE-29126 Bump netty4 to 4.1.119.Final#130
NihalJain merged 2 commits into
apache:masterfrom
revathy023:patch-1

Conversation

@revathy023

Copy link
Copy Markdown
Contributor

Uplifting the netty version in order to resolve few high CVE vulnerability(CVE-2025-24970)

Uplifting the netty version in order to resolve few high CVE vulnerability(CVE-2025-24970)
@Apache-HBase

Copy link
Copy Markdown

🎊 +1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec0m 58sDocker mode activated.
_ Prechecks _
+1 💚dupname0m 0sNo case conflicting files found.
+1 💚@author0m 0sThe patch does not contain any @author tags.
-0 ⚠️test4tests0m 0sThe patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
+1 💚mvninstall0m 48smaster passed
+1 💚compile0m 12smaster passed
+1 💚javadoc0m 6smaster passed
_ Patch Compile Tests _
+1 💚mvninstall0m 34sthe patch passed
+1 💚compile0m 12sthe patch passed
+1 💚javac0m 12sthe patch passed
+1 💚whitespace0m 0sThe patch has no whitespace issues.
+1 💚xml0m 1sThe patch has no ill-formed XML file.
+1 💚javadoc0m 6sthe patch passed
_ Other Tests _
+1 💚unit0m 32sroot in the patch passed.
+1 💚asflicense0m 6sThe patch does not generate ASF License warnings.
3m 45s
SubsystemReport/Notes
DockerClientAPI=1.43 ServerAPI=1.43 base: https://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/1/artifact/yetus-precommit-check/output/Dockerfile
GITHUB PR#130
Optional Testsdupname asflicense javac javadoc unit xml compile
unameLinux 1367190efaa3 5.4.0-1103-aws #111~18.04.1-Ubuntu SMP Tue May 23 20:04:10 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
git revisionmaster / 8eaa9c0
Default JavaTemurin-1.8.0_442-b06
Test Resultshttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/1/testReport/
Max. process+thread count405 (vs. ulimit of 1000)
modulesC: . U: .
Console outputhttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/1/console
versionsgit=2.43.0 maven=3.9.9
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@revathy023

Copy link
Copy Markdown
ContributorAuthor

No New testcases are specifically added for this patch,as it is a version uplift to resolve CVEs

@karthik-j

Copy link
Copy Markdown

Can we update this to use newer release netty-4.1.119.Final?

@NihalJain

Copy link
Copy Markdown
Contributor

Hi @revathy023 thank you for submitting a fix. Welcome to the project.
There is an existing issue to fix this, please assign HBASE-29126 to yourself or let me know your jira id if this is your first PR in hbase?

@NihalJain

Copy link
Copy Markdown
Contributor

Can we update this to use newer release netty-4.1.119.Final?

Agreed!

@NihalJainNihalJain changed the title Uplift the netty.version to 4.1.118.FinalHBASE-29126 Bump netty4 to 4.1.119.FinalMar 11, 2025
@Apache-HBase

Copy link
Copy Markdown

💔 -1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec0m 33sDocker mode activated.
_ Prechecks _
+1 💚dupname0m 0sNo case conflicting files found.
+1 💚@author0m 0sThe patch does not contain any @author tags.
-0 ⚠️test4tests0m 0sThe patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
-1 ❌mvninstall0m 18sroot in master failed.
-1 ❌compile0m 17sroot in master failed.
-1 ❌javadoc0m 18sroot in master failed.
_ Patch Compile Tests _
-1 ❌mvninstall0m 17sroot in the patch failed.
-1 ❌compile0m 18sroot in the patch failed.
-1 ❌javac0m 18sroot in the patch failed.
+1 💚whitespace0m 0sThe patch has no whitespace issues.
+1 💚xml0m 1sThe patch has no ill-formed XML file.
-1 ❌javadoc0m 17sroot in the patch failed.
_ Other Tests _
-1 ❌unit0m 17sroot in the patch failed.
+0 🆗asflicense0m 18sASF License check generated no output?
3m 15s
SubsystemReport/Notes
DockerClientAPI=1.43 ServerAPI=1.43 base: https://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/Dockerfile
GITHUB PR#130
Optional Testsdupname asflicense javac javadoc unit xml compile
unameLinux 55682f241afd 5.4.0-1103-aws #111~18.04.1-Ubuntu SMP Tue May 23 20:04:10 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
git revisionmaster / 8eaa9c0
Default JavaTemurin-1.8.0_442-b06
mvninstallhttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/branch-mvninstall-root.txt
compilehttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/branch-compile-root.txt
javadochttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/branch-javadoc-root.txt
mvninstallhttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/patch-mvninstall-root.txt
compilehttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/patch-compile-root.txt
javachttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/patch-compile-root.txt
javadochttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/patch-javadoc-root.txt
unithttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/artifact/yetus-precommit-check/output/patch-unit-root.txt
Test Resultshttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/testReport/
Max. process+thread count9 (vs. ulimit of 1000)
modulesC: . U: .
Console outputhttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/2/console
versionsgit=2.43.0 maven=3.9.9
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@revathy023

revathy023 commented Mar 12, 2025

Copy link
Copy Markdown
ContributorAuthor

hey @NihalJain I did uplift the version to 4.1.119.Final, but looks like the build is not successful as per the previous robot comment, kindly lemme know if there is anything to be done from my end..thanks

@NihalJain

Copy link
Copy Markdown
Contributor

hey @NihalJain I did uplift the version to 4.1.119.Final, but looks like the build is not successful as per the previous robot comment, kindly lemme know if there is anything to be done from my end..thanks

let me re-trigger

@NihalJain

Copy link
Copy Markdown
Contributor

hey @NihalJain I did uplift the version to 4.1.119.Final, but looks like the build is not successful as per the previous robot comment, kindly lemme know if there is anything to be done from my end..thanks

let me re-trigger

Retriggered job: https://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/3/console

@Apache-HBase

Copy link
Copy Markdown

🎊 +1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec0m 59sDocker mode activated.
_ Prechecks _
+1 💚dupname0m 0sNo case conflicting files found.
+1 💚@author0m 0sThe patch does not contain any @author tags.
-0 ⚠️test4tests0m 0sThe patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
+1 💚mvninstall0m 48smaster passed
+1 💚compile0m 11smaster passed
+1 💚javadoc0m 7smaster passed
_ Patch Compile Tests _
+1 💚mvninstall0m 34sthe patch passed
+1 💚compile0m 12sthe patch passed
+1 💚javac0m 12sthe patch passed
+1 💚whitespace0m 0sThe patch has no whitespace issues.
+1 💚xml0m 0sThe patch has no ill-formed XML file.
+1 💚javadoc0m 5sthe patch passed
_ Other Tests _
+1 💚unit0m 33sroot in the patch passed.
+1 💚asflicense0m 7sThe patch does not generate ASF License warnings.
3m 48s
SubsystemReport/Notes
DockerClientAPI=1.43 ServerAPI=1.43 base: https://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/3/artifact/yetus-precommit-check/output/Dockerfile
GITHUB PR#130
Optional Testsdupname asflicense javac javadoc unit xml compile
unameLinux d7faa755e1c6 5.4.0-1103-aws #111~18.04.1-Ubuntu SMP Tue May 23 20:04:10 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
git revisionmaster / 8eaa9c0
Default JavaTemurin-1.8.0_442-b06
Test Resultshttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/3/testReport/
Max. process+thread count383 (vs. ulimit of 1000)
modulesC: . U: .
Console outputhttps://ci-hbase.apache.org/job/HBase-Thirdparty-PreCommit/job/PR-130/3/console
versionsgit=2.43.0 maven=3.9.9
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@revathy023

Copy link
Copy Markdown
ContributorAuthor

Thanks @NihalJain for retriggering the job... Could u guide me further on the next steps to be followed inorder to merge this PR and mark it closed. This is my first PR in the hbase space... Thanks in advance.

@NihalJain

NihalJain commented Mar 18, 2025

Copy link
Copy Markdown
Contributor

Thanks @NihalJain for retriggering the job... Could u guide me further on the next steps to be followed inorder to merge this PR and mark it closed. This is my first PR in the hbase space... Thanks in advance.

The PR LGTM, I will merge this in a while and close the ticket. Ideally we would want to have same change in main hbase repo as well but I think it is fine and we can do that once next third party release happens.

This is my first PR in the hbase space...

And thanks again for making your first contribution..

@revathy023

Copy link
Copy Markdown
ContributorAuthor

Thanks @NihalJain for the approval... sure..dat sounds great..kindly go ahead and merge this PR as per the necessity... Thanks again

@NihalJain
NihalJain merged commit 5bb7b54 into apache:masterMar 19, 2025
@karthik-j

Copy link
Copy Markdown

we can do that once next third party release happens.

Hi @NihalJain, how should we request a hbase-thirdparty release? Readme indicates it has to be done via hbase project scripts, do you know how I can request the release there, as I don't have privileges to initiate a release candidate.

@NihalJain

NihalJain commented Apr 5, 2025

Copy link
Copy Markdown
Contributor

we can do that once next third party release happens.

Hi @NihalJain, how should we request a hbase-thirdparty release? Readme indicates it has to be done via hbase project scripts, do you know how I can request the release there, as I don't have privileges to initiate a release candidate.

Hi @karthik-j, we had our last release of 2.6 branch in feb end. Refer https://github.com/apache/hbase/releases/tag/rel%2F2.6.2

If you want a new release for an urgent or critical bug fix you may drop a mail to dev@hbase.apache.org and check with team on tentative dates for next release.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@revathy023@Apache-HBase@karthik-j@NihalJain