Re: 3.9.2 is our latest stable version, or 3.8.4?

2024-05-14 Thread Andor Molnar
We have stable and current version pointers. Current points to 3.9.2 while stable points to 3.8.4 now. As soon as we release 3.10 and EoL 3.7.x, the pointers can we moved. Andor On Wed, 2024-05-15 at 08:13 +0800, tison wrote: > Hi, > > Our download page [1] states that 3.8.4 is our latest

[ANNOUNCE] New ZooKeeper PMC member: Damien Diederen

2024-04-16 Thread Andor Molnar
I am happy to announce that Damien Diederen has been invited to join the Apache ZooKeeper PMC and he accepted. Damien is doing great work for our community. Please join me in congratulating with him Congrats Damien ! If you want to know more about the ASF works and what is a PMC you can read

[ANNOUNCE] New ZooKeeper PMC member: Zili Chen

2024-04-16 Thread Andor Molnar
I am happy to announce that Zili Chen (tison) has been invited to join the Apache ZooKeeper PMC and he accepted. Zili is doing great work for our community. Please join me in congratulating with him Congrats Mate ! If you want to know more about the ASF works and what is a PMC you can read

Re: Proposal for Updating the Wiki Page and JIRA Ticket (ZOOKEEPER-4805)

2024-03-27 Thread Andor Molnar
Thanks Villo. Now the below wiki page should have all the updated information related to the recent improvements that Villo made on the merge script. It should be capable of merging PRs via GitHub API, use Jira via access token, no need to expose passwords anymore, etc. The script should be the

Re: Backport to active branches by default

2024-03-20 Thread Andor Molnar
branch? The > whole idea is that that's the "stable" release while the mainline is > the > most current... > > Regards, > > Patrick > > On Wed, Mar 20, 2024 at 12:54 PM Andor Molnar > wrote: > > > Hi ZK committers, > > > > I've com

Backport to active branches by default

2024-03-20 Thread Andor Molnar
Hi ZK committers, I've come across recently that patch authors keep asking me to backport their patches to active branches, because it was only submitted to the master branch. I think we should get into the habit of submitting every accepted PRs to all active branches (today it's branch-3.8 and

Re: CVE-2024-23944: Apache ZooKeeper: Information disclosure in persistent watcher handling

2024-03-14 Thread Andor Molnar
elease notes of 3.9.2 and 3.8.4, but the status > is > still OPEN and there is no PR link there. > > https://issues.apache.org/jira/browse/ZOOKEEPER-4799 > > We are in 3.7.2 and may need to patch it ourselves. > > Best, > > Li > > > > On Thu, Mar 14,

CVE-2024-23944: Apache ZooKeeper: Information disclosure in persistent watcher handling

2024-03-14 Thread Andor Molnar
Severity: critical Affected versions: - Apache ZooKeeper 3.9.0 through 3.9.1 - Apache ZooKeeper 3.8.0 through 3.8.3 - Apache ZooKeeper 3.6.0 through 3.7.2 Description: Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to

Re: [ANNOUNCE] Apache ZooKeeper 3.8.4

2024-03-06 Thread Andor Molnar
Nice job Damien. Thanks! On Tue, 2024-03-05 at 23:00 +0100, Damien Diederen wrote: > The Apache ZooKeeper team is proud to announce Apache ZooKeeper > version 3.8.4 > > ZooKeeper is a high-performance coordination service for distributed > applications. It exposes common services - such as

Re: [VOTE] Apache ZooKeeper release 3.8.4 candidate 0

2024-02-28 Thread Andor Molnar
+1 (binding) - verified checksum and gpg signature of the artifacts - full build was successful - unit tests passed - checkstyle and spotbugs passed - apache-rat passed - owasp (CVE check) passed - smoke tests (basic commands, watchers, etc.) passed Andor On Mon, 2024-02-12 at 23:35 +0100,

Re: [VOTE] Apache ZooKeeper release 3.9.2 candidate 0

2024-02-28 Thread Andor Molnar
+1 (binding) - verified checksum and gpg signature of the artifacts - full build was successful - unit tests passed - checkstyle and spotbugs passed - apache-rat passed - owasp (CVE check) passed Andor On Mon, 2024-02-12 at 22:37 +0100, Damien Diederen wrote: > Greetings, all! > > > This is

Re: Lack of support for TLS-only ZK cluster

2024-02-22 Thread Andor Molnar
gt; > > > > > > Reviewed. > > Thanks > > > > Enrico > > > > > > > Regards, > > > Abhilash Kishore > > > > > > > > > On Tue, 13 Feb 2024 at 02:28, Andor Molnar > > wrote: > > >

Re: Lack of support for TLS-only ZK cluster

2024-02-13 Thread Andor Molnar
ler > and > cleaner solution. > > I'll work on the changes and will try to keep it backwards > compatible. > > Regards, > Abhilash Kishore > > > On Fri, 5 Jan 2024 at 09:00, Andor Molnar wrote: > > > Hi Abhilash, > > > > Thanks for looki

[jira] [Created] (ZOOKEEPER-4806) Commits have to be refreshed after merging

2024-02-09 Thread Andor Molnar (Jira)
Andor Molnar created ZOOKEEPER-4806: --- Summary: Commits have to be refreshed after merging Key: ZOOKEEPER-4806 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4806 Project: ZooKeeper

[jira] [Created] (ZOOKEEPER-4805) Update cwiki page with latest changes

2024-02-09 Thread Andor Molnar (Jira)
Andor Molnar created ZOOKEEPER-4805: --- Summary: Update cwiki page with latest changes Key: ZOOKEEPER-4805 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4805 Project: ZooKeeper Issue

[ANNOUNCE] Apache ZooKeeper 3.7 End-of-Life 2nd Feb, 2024

2024-02-01 Thread Andor Molnar
The Apache ZooKeeper community would like to make the official announcement of 3.7 release line End-of-Life. It will be effective on 2nd of February, 2024 00:01 AM (PDT). From that day forward the 3.7 version of Apache ZooKeeper won’t be supported by the community which means we won't - accept

Re: Moving 3.7 to End-of-Life

2024-01-31 Thread Andor Molnar
tests [1]. I'm open to inputs about which ZK > versions should new Curator versions maintain compatibility. > > Best, > tison. > > [1] https://github.com/apache/curator/pull/496 > > Andor Molnar 于2024年1月31日周三 16:57写道: > > Hi all, > > > > W

Re: Moving 3.7 to End-of-Life

2024-01-31 Thread Andor Molnar
immediately? Thoughts? Andor On Mon, 2024-01-29 at 10:30 +0100, Andor Molnar wrote: > Thanks guys. > > Sounds like we have 3 binding +1 votes. > > Andor > > > > On Sat, 2024-01-27 at 09:29 +0100, Enrico Olivelli wrote: > > Il Sab 27 Gen 2024, 0

Re: Moving 3.7 to End-of-Life

2024-01-29 Thread Andor Molnar
> > > > +1 to mark 3.7 release line as EOL > > Enrico > > > > > Regards, > > > > Patrick > > > > On Fri, Jan 26, 2024 at 7:33 AM Andor Molnar > > wrote: > > > > > Hi zk community, > > > >

Moving 3.7 to End-of-Life

2024-01-26 Thread Andor Molnar
Hi zk community, According to our Releases [1] page ZooKeeper 3.8.2 became the first stable version of 3.8.x line on 3 Aug, 2023 (when 3.9.0 was released). The previous stable version "in approximately half a year will be announced as End-of-Life". 6 months will pass on 3 Feb, 2024, so we should

Re: Lack of support for TLS-only ZK cluster

2024-01-05 Thread Andor Molnar
Hi Abhilash, Thanks for looking into this issue. I wouldn't complicate things by trying to get reconfig parameters aligned and mixed with clientPort/secureClientPort. Since the documentation says these options are already deprecated I suggest to upgrade Reconfig config line to support secure

Re: [DISCUSS] OpenTelemetry for Zookeeper?

2024-01-02 Thread Andor Molnar
. That could be hard to do. > > This doesn't mean it shouldn't be done, just that if it is done, > these are > some things to consider to try to avoid potential problems down the > line. > > On Tue, Jan 2, 2024, 10:57 Andor Molnar wrote: > > > Hi all, > > > &

[DISCUSS] OpenTelemetry for Zookeeper?

2024-01-02 Thread Andor Molnar
Hi all, Inspired by the following CURATOR ticket I started to think about what needs to be done for ZooKeeper to support OpenTelemetry. CURATOR-695 Open Telemetry Tracing Driver [1] Unfortunately we don't have such generic tracing driver, even ZooTrace class looks unusable for this use case,

New merge script with GH api

2023-12-01 Thread Andor Molnar
Hi folks, We've just submitted https://issues.apache.org/jira/browse/ZOOKEEPER-4756 to all active branches. It's about an improvement for the merge script to use GH api for merging PRs instead of manually pushing and leaving the PR is "closed" state. The PR itself has been merged with the new

ZOOKEEPER-2053 Zookeeper scripts should honor ZOOKEEPER_HOME

2023-11-27 Thread Andor Molnar
Hi ZK folks, I have an relative old PR still open to address ZOOKEEPER-2053 Shall we commit it? https://github.com/apache/zookeeper/pull/2037 Thanks, Andor

CVE-2023-44981: Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication

2023-10-11 Thread Andor Molnar
Severity: critical Affected versions: - Apache ZooKeeper 3.9.0 - Apache ZooKeeper 3.8.0 through 3.8.2 - Apache ZooKeeper 3.7.0 through 3.7.1 - Apache ZooKeeper before 3.7.0 Description: Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer

[ANNOUNCE] Apache ZooKeeper 3.7.2

2023-10-09 Thread Andor Molnar
The Apache ZooKeeper team is proud to announce Apache ZooKeeper version 3.7.2 ZooKeeper is a high-performance coordination service for distributed applications. It exposes common services - such as naming, configuration management, synchronization, and group services - in a simple interface so

[ANNOUNCE] Apache ZooKeeper 3.8.3

2023-10-09 Thread Andor Molnar
The Apache ZooKeeper team is proud to announce Apache ZooKeeper version 3.8.3 ZooKeeper is a high-performance coordination service for distributed applications. It exposes common services - such as naming, configuration management, synchronization, and group services - in a simple interface so

[ANNOUNCE] Apache ZooKeeper 3.9.1

2023-10-09 Thread Andor Molnar
The Apache ZooKeeper team is proud to announce Apache ZooKeeper version 3.9.1 ZooKeeper is a high-performance coordination service for distributed applications. It exposes common services - such as naming, configuration management, synchronization, and group services - in a simple interface so

[RESULT] [VOTE] Apache ZooKeeper release 3.7.2 candidate 0

2023-10-09 Thread Andor Molnar
I'm happy to announce that we have unanimously approved this release. There are 4 approving votes, 3 of which are binding: - Damien Diederen (non-binding) - Mate Szalay-Beko (binding) - Patrick Hunt (binding) - Andor Molnar (binding) There are no disapproving votes. I will promote

[RESULT] [VOTE] Apache ZooKeeper release 3.8.3 candidate 0

2023-10-09 Thread Andor Molnar
I'm happy to announce that we have unanimously approved this release. There are 4 approving votes, 3 of which are binding: - Damien Diederen (non-binding) - Mate Szalay-Beko (binding) - Patrick Hunt (binding) - Andor Molnar (binding) There are no disapproving votes. I will promote

[RESULT] [VOTE] Apache ZooKeeper release 3.9.1 candidate 0

2023-10-09 Thread Andor Molnar
I'm happy to announce that we have unanimously approved this release. There are 5 approving votes, 4 of which are binding: - Enrico Olivelli (binding) - Damien Diederen (non-binding) - Mate Szalay-Beko (binding) - Patrick Hunt (binding) - Andor Molnar (binding) There are no disapproving

Re: [VOTE] Apache ZooKeeper release 3.8.3 candidate 0

2023-10-09 Thread Andor Molnar
rds, Andor On Thu, 2023-10-05 at 12:50 +0200, Andor Molnar wrote: > Hi, > > This is a release candidate for 3.8.3. > > This is a bugfix release for the 3.8 release line. Includes important > dependency upgrades to address CVEs. > > The full release notes is available at

Re: [VOTE] Apache ZooKeeper release 3.7.2 candidate 0

2023-10-09 Thread Andor Molnar
-build/job/branch-3.7.2/ - created 3-node SSL ensemble and ran a few smoke tests - release notes looks fine, but history lacks the notes of 3.7.0 - I'll make a note in the release guide - verified CLI commands Regards, Andor On Fri, 2023-10-06 at 12:04 +0200, Andor Molnar wrote: >

[VOTE] Apache ZooKeeper release 3.7.2 candidate 0

2023-10-06 Thread Andor Molnar
Hi ZK folks, This is a release candidate for 3.7.2. This is a bugfix release for the 3.7 release line. Includes important bugfixes and dependency upgrades to address CVEs. The full release notes is available at: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310801=12351732

[jira] [Created] (ZOOKEEPER-4756) Merge script should use GitHub api to merge pull requests

2023-10-06 Thread Andor Molnar (Jira)
Andor Molnar created ZOOKEEPER-4756: --- Summary: Merge script should use GitHub api to merge pull requests Key: ZOOKEEPER-4756 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4756 Project

[VOTE] Apache ZooKeeper release 3.8.3 candidate 0

2023-10-05 Thread Andor Molnar
Hi, This is a release candidate for 3.8.3. This is a bugfix release for the 3.8 release line. Includes important dependency upgrades to address CVEs. The full release notes is available at: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310801=12353400 *** Please download,

Re: [VOTE] Apache ZooKeeper release 3.9.1 candidate 0

2023-10-04 Thread Andor Molnar
commit id is not replaced by Maven. [zk: andor-5560-ubuntu:2183(CONNECTED) 5] version ZooKeeper CLI version: 3.9.1-${mvngit.commit.id}, built on 2023-10-04 15:03 UTC Andor On Wed, 2023-10-04 at 14:28 +0200, Andor Molnar wrote: > Hi team, > > This is a release candidate for 3.9.1. > >

[VOTE] Apache ZooKeeper release 3.9.1 candidate 0

2023-10-04 Thread Andor Molnar
Hi team, This is a release candidate for 3.9.1. This is a bugfix release for the 3.9 release line. Includes important dependency upgrades to address CVEs. The full release notes is available at: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310801=12353480 *** Please

[ANNOUNCE] Apache ZooKeeper 3.9.0

2023-08-04 Thread Andor Molnar
The Apache ZooKeeper team is proud to announce Apache ZooKeeper version 3.9.0 ZooKeeper is a high-performance coordination service for distributed applications. It exposes common services - such as naming, configuration management, synchronization, and group services - in a simple interface so

Re: [VOTE] Apache ZooKeeper release 3.9.0 candidate 1

2023-07-31 Thread Andor Molnar
run > > > the owasp > > > checker, and start various ensemble sizes manually w/o issue. > > > lgtm. > > > > > > Patrick > > > > > > On Wed, Jul 19, 2023 at 2:20 AM Andor Molnar > > > wrote: > > > > > > > This

[VOTE] Apache ZooKeeper release 3.9.0 candidate 1

2023-07-19 Thread Andor Molnar
This is release candidate for ZooKeeper 3.9.0. It is a major release and it introduces a lot of new features, most notably: - Admin server API for taking snapshot and stream out the data - Communicate the Zxid that triggered a WatchEvent to fire - TLS - dynamic loading for client trust/key store

Re: [VOTE] Apache ZooKeeper release 3.9.0 candidate 0

2023-07-18 Thread Andor Molnar
9.0 > - rolling upgrade from 3.6.4 to 3.9.0 > - rolling upgrade from 3.7.1 to 3.9.0 > - rolling upgrade from 3.8.2 to 3.9.0 > - compared generated release notes ( > https://dist.apache.org/repos/dist/dev/zookeeper/zookeeper-3.9.0-candidate-0/website/releasenot

Re: [VOTE] Apache ZooKeeper release 3.9.0 candidate 0

2023-07-18 Thread Andor Molnar
s/dist/dev/zookeeper/zookeeper-3.9.0-candidate-0/website/releasenotes.html > ) with Jira ( > https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310801=12351304 > ) > > > Best regards, > Máté > > On Mon, Jul 17, 2023 at 3:11 PM Andor Molnar &g

[jira] [Created] (ZOOKEEPER-4721) Upgrade OWASP Dependency Check to 8.3.1

2023-07-18 Thread Andor Molnar (Jira)
Andor Molnar created ZOOKEEPER-4721: --- Summary: Upgrade OWASP Dependency Check to 8.3.1 Key: ZOOKEEPER-4721 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4721 Project: ZooKeeper

Re: [VOTE] Apache ZooKeeper release 3.8.2 candidate 0

2023-07-18 Thread Andor Molnar
e the release procedure. > > Thanks to everyone who contributed to this release! > > Best Regards, > Máté > > On Mon, Jul 17, 2023 at 4:08 PM Andor Molnar > wrote: > > > +1 (binding) > > > > - verified checksum and gpg signature of the artifacts > &g

Re: [VOTE] Apache ZooKeeper release 3.8.2 candidate 0

2023-07-17 Thread Andor Molnar
+1 (binding) - verified checksum and gpg signature of the artifacts - I built the source code (incl. the C-client, using -Pfull-build) on Ubuntu 20.04 using OpenJDK 8u302, maven 3.6.3 and GCC version 9.4.0 - all the unit tests passed (both Java and C-client) - I also built the code using Oracle

[VOTE] Apache ZooKeeper release 3.9.0 candidate 0

2023-07-17 Thread Andor Molnar
Hi team, This is a release candidate for 3.9.0. It is a major release and it introduces a lot of new features, most notably: - Admin server API for taking snapshot and stream out the data - Communicate the Zxid that triggered a WatchEvent to fire - TLS - dynamic loading for client trust/key

Re: ZOOKEEPER-4714 and ZOOKEEPER-4715

2023-07-17 Thread Andor Molnar
ZOOKEEPER-4714 is merged now. No more blockers, I'll cut the release. Andor On Fri, 2023-07-14 at 16:46 +0200, Andor Molnar wrote: > In my understanding > > ZOOKEEPER-4714 <-- depends on <-- ZOOKEEPER-4715 > > which is already submitted to the master branch. Addition

Re: ZOOKEEPER-4714 and ZOOKEEPER-4715

2023-07-14 Thread Andor Molnar
at 11:49 +0300, Andor Molnar wrote: > Hi Yan Zhao, > > I noticed you opened these 2 new tickets against the 3.9.0 fix > version > which is next release of ZooKepeer I'm just about to cut this week > from > the master branch. > > Do you think these tickets are blockers of 3.9.0? > > Regards, > Andor > > >

Re: ZooKeeper release 3.9.0

2023-07-07 Thread Andor Molnar
a/browse/ZOOKEEPER-4718 > * https://issues.apache.org/jira/browse/ZOOKEEPER-4715 > > Best, > tison. > > > Andor Molnar 于2023年7月1日周六 21:41写道: > > > I'm fine with that. Thanks Damien. > > > > Andor > > > > > > > > On Wed, 2023

ZOOKEEPER-4714 and ZOOKEEPER-4715

2023-07-05 Thread Andor Molnar
Hi Yan Zhao, I noticed you opened these 2 new tickets against the 3.9.0 fix version which is next release of ZooKepeer I'm just about to cut this week from the master branch. Do you think these tickets are blockers of 3.9.0? Regards, Andor

Re: Netty CVE-2023-34462 (SniHandler)

2023-07-02 Thread Andor Molnar
Hi Colin, Thanks for the heads-up. We just committed the upgrade of Netty on master and branch-3.8: https://github.com/apache/zookeeper/pull/2019 That means the new Netty version can be expected in 3.9.0 and 3.8.2 versions of ZooKeeper soon. I think we should backport it to branch-3.7 too,

Re: ZooKeeper release 3.9.0

2023-07-01 Thread Andor Molnar
I'm fine with that. Thanks Damien. Andor On Wed, 2023-06-21 at 14:53 +0200, Damien Diederen wrote: > Hi Andor, Máté, All, > > > There're 64 open tickets which has fixVersion = 3.9.0 > > I'll remove the fixVersion from all of them except the ones that we > > marked as release blockers. > […] >

zk-merge-pr.py

2023-06-16 Thread Andor Molnar
Hi all, The greatest advantage of our merge script is the ability of backporting to other branches. The greatest disadvantage of our merge script is it closes the pull request (red color) instead of "merging" (purple color). We could replace the current pure git approach of merging the main

Re: ZooKeeper release 3.9.0

2023-06-16 Thread Andor Molnar
Submitted. (was a great opportunity to verify the new Merge button restrictions) Thanks, Andor On Fri, 2023-06-16 at 16:27 +0200, Andor Molnar wrote: > Looks like Michael and Flavio have already reviewed and approved it, > so > let's merge it then. > > Andor > > &g

Re: ZooKeeper release 3.9.0

2023-06-16 Thread Andor Molnar
at > > https://lists.apache.org/thread/ww4v1r733whcds64jg5wt7ozclbjhdr0 . > > > > Looking forward to your feedback! > > I would like to commit that patch, but unfortunately there is an open > discussion and we need some reviewers to formally approve it. > > That sai

Re: Current master branch is broker

2023-06-16 Thread Andor Molnar
Fix submitted. On Fri, 2023-06-16 at 14:07 +0200, Andor Molnar wrote: > Yeah, sorry, I've submitted the patch which broke the build. My first > thought was to revert immediately and let the contributor to fix it, > but Kezhu already opened a PR with the fix. > > Once the build

Re: Current master branch is broker

2023-06-16 Thread Andor Molnar
Yeah, sorry, I've submitted the patch which broke the build. My first thought was to revert immediately and let the contributor to fix it, but Kezhu already opened a PR with the fix. Once the build is greeen, I'm submitting it with the title: ZOOKEEPER-4655: [ADDENDUM] fix build error Thanks

[jira] [Created] (ZOOKEEPER-4705) Restrict GitHub merge butten to allow squash commit only

2023-06-15 Thread Andor Molnar (Jira)
Andor Molnar created ZOOKEEPER-4705: --- Summary: Restrict GitHub merge butten to allow squash commit only Key: ZOOKEEPER-4705 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4705 Project

Re: Netty native libraries in ZooKeeper

2023-06-15 Thread Andor Molnar
; > Il Gio 15 Giu 2023, 19:49 Andor Molnar ha scritto: > > > Interesting that with only the BOM included and the dependencies > > without the classifier, Netty doesn't load the native epoll > > selector, > > but loads the native SSL library. > > > >

Re: Netty native libraries in ZooKeeper

2023-06-15 Thread Andor Molnar
be6ea262c202660d684fb7/pom.xml#L647 > https://github.com/apache/pulsar/blob/d7f355881b2b1eebf2be6ea262c202660d684fb7/pulsar-common/pom.xml#L146 > > This way Maven should bundle all the native libraries for all the > supported platforms > > > > Enrico > > Il giorno

Re: FIPS: removing ZKTrustManager

2023-06-15 Thread Andor Molnar
023 alle ore 13:43 Andor Molnar > ha scritto: > > PR has been created with the proposed resolution: > > > > https://github.com/apache/zookeeper/pull/2008 > > Committed to master and branch-3.8 > > Thank you > Enrico > > > Please review. > > &g

ZooKeeper release 3.9.0

2023-06-15 Thread Andor Molnar
Hi folks, There're 64 open tickets which has fixVersion = 3.9.0 I'll remove the fixVersion from all of them except the ones that we marked as release blockers. Currently: - ZOOKEEPER-4393 Problem to connect to zookeeper in FIPS mode - ZOOKEEPER-4622 Add Netty-TcNative OpenSSL Support -

Netty native libraries in ZooKeeper

2023-06-15 Thread Andor Molnar
Hi, I've come across the following when working on the support of native SSL libraries. Currently ZooKeeper supports loading the native epoll- based event loop of Netty, but a build profile which would download the required dependencies is not shipped with our product. This is perfectly okay

Re: Volounteers for releases ?

2023-06-14 Thread Andor Molnar
Created a patch for this: https://github.com/apache/zookeeper/pull/2009 Andor On Tue, 2023-06-13 at 10:57 +0200, Andor Molnar wrote: > Awesome. Thanks Enrico! > > I owe you an apology: found an important TLS ticket which is another > low hanging fruit: > > https://issu

Re: FIPS: removing ZKTrustManager

2023-06-14 Thread Andor Molnar
PR has been created with the proposed resolution: https://github.com/apache/zookeeper/pull/2008 Please review. Thanks, Andor On Sat, 2023-06-10 at 11:25 +0200, Andor Molnar wrote: > "we use this method dozens of other places in the code" > > Checked. Mostly logging an

Re: Volounteers for releases ?

2023-06-14 Thread Andor Molnar
ocus on 3.8.2 instead? > > > > what do you think? > > > > Let's focus on 3.8.2. > Users on 3.7 can easily migrate to 3.8 > > > Thanks > > Enrico > > > > > > Mate > > > > On Tue, Jun 13, 2023 at 10:58 AM Andor Molna

Re: Volounteers for releases ?

2023-06-13 Thread Andor Molnar
cale: en_US, platform encoding: UTF-8 > OS name: "linux", version: "4.15.0-206-generic", arch: "amd64", > family: "unix" > > https://ci-hadoop.apache.org/view/ZooKeeper/job/ZooKeeper-Java-EA/113/ > > Enrico > > Il giorno l

Re: Volounteers for releases ?

2023-06-12 Thread Andor Molnar
Sure. I've just noticed that the patch has been outstanding for a year now, small and ready to be submitted. Andor On Mon, 2023-06-12 at 14:29 +0200, Enrico Olivelli wrote: > Il giorno lun 12 giu 2023 alle ore 11:13 Andor Molnar > ha scritto: > > I came across the graceful termi

Re: Volounteers for releases ?

2023-06-12 Thread Andor Molnar
at 08:49 +0200, Enrico Olivelli wrote: > Il giorno lun 12 giu 2023 alle ore 08:19 Andor Molnar > ha scritto: > > Hi Kezhu, > > > > Sure, I'll take a look at the open PRs before cutting 3.9.0 from > > master. Let's mark these tickets release blockers as you suggest

Re: Volounteers for releases ?

2023-06-12 Thread Andor Molnar
hread! > > [1]: https://issues.apache.org/jira/browse/ZOOKEEPER-4471 > [2]: https://issues.apache.org/jira/browse/ZOOKEEPER-4472 > [3]: https://lists.apache.org/thread/m7gxcffsnjy2lm8g52nssfxb6t800o3r > > > Best, > Kezhu Wang > > > > Best, > Kezhu Wa

Re: FIPS: removing ZKTrustManager

2023-06-10 Thread Andor Molnar
"we use this method dozens of other places in the code" Checked. Mostly logging and output formatting like 4lws, etc. On Sat, 2023-06-10 at 11:18 +0200, Andor Molnar wrote: > First, I've created a pull request for ZOOKEEPER-3860: > > https://github.com/apache/

Re: FIPS: removing ZKTrustManager

2023-06-10 Thread Andor Molnar
> term it > is good not to use a custom trust manager, but rely on the standard > one. > > Máté > > > On Fri, Jun 9, 2023 at 2:08 PM Enrico Olivelli > wrote: > > > Il giorno ven 9 giu 2023 alle ore 14:07 Andor Molnar > > ha scritto: > > > I'd like t

Re: FIPS: removing ZKTrustManager

2023-06-09 Thread Andor Molnar
it > > is good not to use a custom trust manager, but rely on the standard > > one. > > > > Máté > > > > > > On Fri, Jun 9, 2023 at 2:08 PM Enrico Olivelli > > > > wrote: > > > > > Il giorno ven 9 giu 2023 alle ore 14:07

Re: FIPS: removing ZKTrustManager

2023-06-09 Thread Andor Molnar
rote: > I think that switching to > sslParameters.setEndpointIdentificationAlgorithm("HTTPS"); is a good > option. > The less tweaks we have about Security code the better. > > > It would be great to see this in 3.9.0. > > Enrico > > Il giorno ven 9 giu 2023 alle

FIPS: removing ZKTrustManager

2023-06-09 Thread Andor Molnar
Hi zk folks, Problem(s) == One problem that we're having with a custom Trust Manager in ZK is that FIPS doesn't allow that: https://issues.apache.org/jira/browse/ZOOKEEPER-4393 In FIPS mode the only allowed TrustManager in the JDK is X509TrustManagerImpl which is the default

Re: Volounteers for releases ?

2023-06-09 Thread Andor Molnar
Hi Enrico, I can take the master cut next week, but let me put together an email about a TLS topic first. I'd like to propose a fix to resolve the problem of FIPS (custome trust manager in ZK) and reverse DNS lookups. I'd like to include it in 3.9.0 and 3.8.2. Andor p.s. Whoever is making a

Re: [jira] [Created] (ZOOKEEPER-4696) Update for Zookeeper latest version

2023-05-26 Thread Andor Molnar
, Andor Molnar wrote: > Hi Ben, > > Let me check this. > I triggered an owasp check build on Apache CI: > https://ci-hadoop.apache.org/view/ZooKeeper/job/zookeeper-multi-branch-owasp/job/branch-3.8.1/7/ > > Btw, Enrico, we're still having both 3.8.0 and 3.8.1 releases on the &

Re: [jira] [Created] (ZOOKEEPER-4696) Update for Zookeeper latest version

2023-05-26 Thread Andor Molnar
Hi Ben, Let me check this. I triggered an owasp check build on Apache CI: https://ci-hadoop.apache.org/view/ZooKeeper/job/zookeeper-multi-branch-owasp/job/branch-3.8.1/7/ Btw, Enrico, we're still having both 3.8.0 and 3.8.1 releases on the web page as separate release lines. Would you mind if I

[jira] [Created] (ZOOKEEPER-4683) CVE-2022-45688

2023-03-22 Thread Andor Molnar (Jira)
Andor Molnar created ZOOKEEPER-4683: --- Summary: CVE-2022-45688 Key: ZOOKEEPER-4683 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4683 Project: ZooKeeper Issue Type: Bug

Re: [ANNOUNCE] Apache ZooKeeper 3.8.1 released

2023-02-23 Thread Andor Molnar
Hi Enrico, Thanks for the release, nice work. Looks like 3.8.0 downloads and documentation have been kept on the website. Is that intentional? Regards, Andor On Mon, 2023-01-30 at 08:55 +0100, Enrico Olivelli wrote: > The Apache ZooKeeper team is proud to announce Apache ZooKeeper > version

Re: CI and Pull request validation - too many CI servers ?

2022-09-30 Thread Andor Molnar
People was excited to try out new technologies. :) ASF Jenkins is the "official" one, if we can say that. Andor On Thu, 2022-09-29 at 15:38 +0200, Enrico Olivelli wrote: > Hello ZooKeepers, > Currently we are testing our PRs using: > - GitHub actions > - Travis > - ASF Jenkins > > Honestly I

New releases page: endoflife.date

2022-07-27 Thread Andor Molnar
Hi ZK folks, I'm lettig you know that I've added ZooKeeper to this page: https://endoflife.date/zookeeper It's pretty neat to track releases there. We don't need to manually update it, because it monitors the tags on GitHub mirror page, so it should be all automatic. Hope you like it. Andor

Re: [VOTE] Apache ZooKeeper release 3.5.10 candidate 1

2022-06-01 Thread Andor Molnar
+1 (binding) - verified signatures, checksums, - opened some web pages, - rat, spotbugs, checkstyle clean, - build successful with unit tests on Ubuntu 22.04, - verified local 3-node cluster w/ and w/o SSL, - logging looks good, TRACE logging works. Thanks, Andor On Sun, 2022-05-29 at 19:08

Re: [ANNOUNCE] new ZooKeeper PMC member: Mate Szalay-Beko

2022-03-28 Thread Andor Molnar
Congratulations Mate! Well deserved! Andor > On 2022. Mar 28., at 8:42, Enrico Olivelli wrote: > > I am happy to announce that Mate Szalay-Beko has been invited to join > the Apache ZooKeeper PMC and he accepted. > > Mate is doing great work for our community. > > Please join me in

[ANNOUNCE] Apache ZooKeeper 3.5 End-of-Life 1st June, 2022

2022-03-03 Thread Andor Molnar
Hi, The Apache ZooKeeper community would like to make the official announcement of 3.5 release line End-of-Life. It will be effective on 1st of June, 2022 00:01 AM (PDT). From that day forward the 3.5 version of Apache ZooKeeper won’t be supported by the community which means we won’t - accept

Re: [VOTE] Apache ZooKeeper release 3.8.0 candidate 1

2022-03-03 Thread Andor Molnar
+1 (binding) - checksum / signatures verified - compiled the full build on Mac, - unit test run on Java 11 - I had a few tests which was constantly failing on my Mac, but given that CI already passed all tests and others reported the same, I take it as passed,

Re: Moving 3.5 to EOL

2022-03-02 Thread Andor Molnar
3.7.0) with > large clusters in production? Are we confident saying 3.7 is stable? > (on the other hand, if we don't do the announcement, most likely people > won't start to migrate to 3.7) > > Mate > > On Wed, Feb 16, 2022 at 1:33 PM Enrico Olivelli wrote: > >> A

Re: Moving 3.5 to EOL

2022-02-16 Thread Andor Molnar
ase. We also >> use this to provide users with information about supported upgrade paths so >> users can upgrade from LTM to LTM, skipping over non-LTM releases, or they >> can stay on the latest (whether or not it is LTM). >> >> For ZooKeeper, I would suggest: &

Re: Moving 3.5 to EOL

2022-02-11 Thread Andor Molnar
., at 20:28, Patrick Hunt wrote: > > On Wed, Feb 9, 2022 at 3:07 AM Andor Molnar wrote: > >> Hi Pat, >> >> Yeah, I asked for a more specific suggestion from you. If we avoid using >> the LTS in ZooKeeper releases and stay with the stable/latest labels, how

Re: [VOTE] Apache ZooKeeper release 3.8.0 candidate 0

2022-02-10 Thread Andor Molnar
I agree with Pat. Though adding exclusions doesn’t make any difference in the quality of our code, but a build is a build. It’s either green or red (not green). No excuse. Andor > On 2022. Feb 10., at 16:51, Patrick Hunt wrote: > > On Thu, Feb 10, 2022 at 12:22 AM Enrico Olivelli > wrote:

Re: Moving 3.5 to EOL

2022-02-09 Thread Andor Molnar
in maintenance. What should we do with it to reduce the maintenance cost? Andor > On 2022. Feb 4., at 17:58, Patrick Hunt wrote: > > On Fri, Feb 4, 2022 at 8:19 AM Andor Molnar wrote: > >> More specifically? >> > > Are you asking me? :-) "LTS" literall

Re: Moving 3.5 to EOL

2022-02-04 Thread Andor Molnar
think it would be less confusing to stay with the > stable/latest labels we have had in the past and plan ahead a bit in terms > of giving notice when releases will be removed from support. > > Patrick > > On Tue, Feb 1, 2022 at 3:12 AM Andor Molnar wrote: > >> Hi Andre

Re: Moving 3.5 to EOL

2022-02-01 Thread Andor Molnar
Hi Andrew, I think that wasn’t a general plan from the community at that time, just my opinion based on how long 3.4 was the stable release of ZooKeeper (4 years). Since then the release schedule has become much faster and to be honest I’m not participating in it. As mentioned 3.6 and 3.7

Re: Cutting 3.8.0 release

2022-01-31 Thread Andor Molnar
What’s the reason for cutting a new minor release? The logback migration? 3.7 only has a single patch release so far: 3.7.0 Isn’t that too early? Andor > On 2022. Jan 28., at 16:28, Enrico Olivelli wrote: > > Sure. > > Il giorno ven 28 gen 2022 alle ore 14:19 Szalay-Bekő Máté > ha

Logback phase #2

2022-01-28 Thread Andor Molnar
Hi folks, I’ve created the second and hopefully final patch for the Logback migration covering the rest of maven projects. Please review. https://github.com/apache/zookeeper/pull/1807 Regards, Andor

[jira] [Created] (ZOOKEEPER-4461) Migrate zookeeper-contrib and -recipes projects.

2022-01-28 Thread Andor Molnar (Jira)
Andor Molnar created ZOOKEEPER-4461: --- Summary: Migrate zookeeper-contrib and -recipes projects. Key: ZOOKEEPER-4461 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4461 Project: ZooKeeper

Re: Logback

2022-01-20 Thread Andor Molnar
> specifically tested this on your branch and confirmed it works.) > > Chris Nauroth > > > On Wed, Jan 19, 2022 at 1:46 PM Andor Molnar wrote: > >> I’m done with all the changes that I wanted to include in the first >> logback patch. >> Most of Chris’ feedba

Re: Logback

2022-01-19 Thread Andor Molnar
ires Java 1.6 or later. Since it's still receiving >>> patches, and it's not alpha, that's probably the best version to use. >>> Currently, it seems to be at 1.2.9. >>> >>> On Tue, Jan 18, 2022 at 2:25 PM Andor Molnar wrote: >>> >>>> I agree with yo

  1   2   3   4   5   6   7   8   9   10   >