Skip to content

Upgrade protobuf-java version to 3.16.1 - #205

Closed
warriersruthi wants to merge 1 commit into
apache:masterfrom
warriersruthi:sec_compliance
Closed

Upgrade protobuf-java version to 3.16.1#205
warriersruthi wants to merge 1 commit into
apache:masterfrom
warriersruthi:sec_compliance

Conversation

@warriersruthi

@warriersruthiwarriersruthi commented Apr 26, 2022

Copy link
Copy Markdown

Upgrade protobuf-java version to 3.16.1 due to security compliance issue CVE-2021-22569

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569

TEZ-4410

@tez-yetus

Copy link
Copy Markdown

💔 -1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec17m 51sDocker mode activated.
_ Prechecks _
+1 💚dupname0m 0sNo case conflicting files found.
+1 💚@author0m 0sThe patch does not contain any @author tags.
-1 ❌test4tests0m 0sThe patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
-1 ❌mvninstall13m 52sroot in master failed.
-1 ❌compile1m 37sroot in master failed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.
-1 ❌compile1m 27sroot in master failed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.
+1 💚javadoc2m 44smaster passed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04
+1 💚javadoc1m 56smaster passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
_ Patch Compile Tests _
-1 ❌mvninstall0m 55sroot in the patch failed.
-1 ❌compile0m 38sroot in the patch failed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.
-1 ❌javac0m 38sroot in the patch failed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.
-1 ❌compile0m 37sroot in the patch failed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.
-1 ❌javac0m 37sroot in the patch failed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.
+1 💚whitespace0m 0sThe patch has no whitespace issues.
+1 💚xml0m 1sThe patch has no ill-formed XML file.
-1 ❌javadoc0m 38sroot in the patch failed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.
-1 ❌javadoc0m 37sroot in the patch failed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.
_ Other Tests _
-1 ❌unit0m 55sroot in the patch failed.
+1 💚asflicense0m 46sThe patch does not generate ASF License warnings.
45m 38s
SubsystemReport/Notes
DockerClientAPI=1.41 ServerAPI=1.41 base: https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/Dockerfile
GITHUB PR#205
Optional Testsdupname asflicense javac javadoc unit xml compile
unameLinux 23bebfa284cb 4.15.0-65-generic #74-Ubuntu SMP Tue Sep 17 17:06:04 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
Personalitypersonality/tez.sh
git revisionmaster / 9f8d6fb
Default JavaPrivate Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
Multi-JDK versions/usr/lib/jvm/java-11-openjdk-amd64:Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04 /usr/lib/jvm/java-8-openjdk-amd64:Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
mvninstallhttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/branch-mvninstall-root.txt
compilehttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/branch-compile-root-jdkUbuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.txt
compilehttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/branch-compile-root-jdkPrivateBuild-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.txt
mvninstallhttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-mvninstall-root.txt
compilehttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-compile-root-jdkUbuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.txt
javachttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-compile-root-jdkUbuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.txt
compilehttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-compile-root-jdkPrivateBuild-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.txt
javachttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-compile-root-jdkPrivateBuild-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.txt
javadochttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-javadoc-root-jdkUbuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.txt
javadochttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-javadoc-root-jdkPrivateBuild-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.txt
unithttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-unit-root.txt
Test Resultshttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/testReport/
Max. process+thread count99 (vs. ulimit of 5500)
modulesC: . U: .
Console outputhttps://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/console
versionsgit=2.25.1 maven=3.6.3
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@guptanikhil007

Copy link
Copy Markdown
Contributor

@warriersruthi You need to regenerate proto files.
Also, please rebase and trigger a fresh build.

@warriersruthi
warriersruthi deleted the sec_compliance branch May 3, 2022 05:02
@warriersruthi

Copy link
Copy Markdown
Author

I see that the Jira: TEZ-4363 is upgrading the protobuf version to 3.19.4 and I guess the vulnerability CVE-2021-22569 would be handled with this change as the problem was with version 2.5.0.
Thus closing this ticket as its duplicate.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@warriersruthi@tez-yetus@guptanikhil007