DanielLeens commented on PR #11545:
URL: https://github.com/apache/seatunnel/pull/11545#issuecomment-6036036253

   @SEZ9, two corrections to my comment from 08:02Z, and what I pushed since. 
Everything below is against head `74ac922d6`.
   
   **Correction 1 (F2) - that comment was wrong.** I wrote that no runtime 
detection or log line was added for the Kerberos reload. That is false. 
`KuduUtil` (the `catch (IllegalAccessException e)` block at lines 159-166) and 
`PaimonSecurityContext` (lines 144-151) both log an ERROR that names the 
missing `--add-exports=java.security.jgss/sun.security.krb5=ALL-UNNAMED` flag 
when the JVM denies the reflective call; other refresh failures keep their 
WARN. It landed in `1b1da9e86` and was not "deferred". What really is missing 
is a startup check for a preserved `config/` directory that lacks the flags: 
the launcher re-injection covers that case, and no separate check exists. The 
PR description now says so.
   
   **Correction 2 (line ranges).** The launcher blocks are `seatunnel.sh` lines 
112-136 and `seatunnel-cluster.sh` lines 157-181 (Java version check, then the 
loop that appends each module flag only if it is not already present). The 
`pom.xml` lines I gave (186, 798, 830) were right.
   
   **Pushed (`d1794e8fb..74ac922d6`):**
   - `e936b6dcc` drops the jgss `--add-exports` from `JAVA_TOOL_OPTIONS` in 
`codeql.yaml` (heap and Maven flags kept), `publish-docker.yaml` and 
`upgrade_compatibility.yml`, as you suggested. The commit message states that 
the `publish-docker.yaml` removal is unverified, since it only runs on a 
release tag. No workflow sets that export any more.
   - `45a14d047` points the `backend.yml` unit-test comment at #12655, so the 
repeated flags are not removed before `connector-lance` is fixed.
   - A merge of `dev` (no conflicts, no `pom.xml` in the diff).
   - PR description: added the #12655 link, the F2 behaviour above, and a line 
that the six-flag list is not proven minimal (only `java.net` has a captured 
failing trace).
   
   **CI evidence, scoped:** attempt 2 of run 37331927562 (head `d1794e8fb`) 
finished `87 success, 9 skipped` across all 96 jobs, so the four jobs I re-ran 
passed and none failed twice. That run does not cover these three new commits, 
which only touch workflows and comments plus the `dev` merge. A fork run for 
`74ac922d6` should start from the push; I have not seen its result.
   
   Still open from your list: F3 minimality and the F4/F7 questions about 
starting 2.3.13 on JDK 17 or without the export. I have not tested either (the 
workflow runs it on JDK 11).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to