[
https://issues.apache.org/jira/browse/HADOOP-19912?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jose Luis López updated HADOOP-19912:
-------------------------------------
Description:
The goal of this task is to move Hadoop's web servers off Jetty 9.4, which is
end of life: its releases are now rare and sponsored, and its CVEs keep coming
(HADOOP-19910, HADOOP-19915).
h3. Approach
Jetty 12 serves two servlet APIs side by side: the ee8 environment serves
{{javax.servlet}}, while ee10 and ee11 serve {{jakarta.servlet}}. This issue
moves Hadoop to Jetty 12 on ee8, so the servlet namespace, Jersey 2 and every
public signature stay as they are.
We will rollout changes to the modules preparing them for the migration to
Jetty12-ee8 (handling of the HTTP reason code, auth filters, others).
The move to the jakarta namespace (Jetty ee10, Jersey 3, JAXB 4) is a separate
decision, tracked in HADOOP-19395, which starts from here.
Jetty 12 needs Java 17, so this is for trunk. Release lines that stay on Jetty
9.4 are covered by HADOOP-19915.
h3. Tasks
* Resolve one Jetty release and one servlet API on every module classpath,
without changing the Jetty version.
* Drop jetty-util-ajax in favour of Jackson.
* Upgrade Jetty 9.4 to 12 on the ee8 environment: {{HttpServer2}}, KMS, HttpFS,
the YARN web apps, WebSocket, SLS, the services API, the shaded clients and
LICENSE-binary. Keep trunk's behaviour wherever Jetty 12 allows, and list the
rest for the release note.
* Move the YARN application catalog off Jetty 9.4, the last Jetty 9.4 in the
build, which it needs for Solr 8: retire the module, or upgrade it to Solr 10.
* Remove the JAX-RS 1.1 API ({{jsr311-api}}) from
{{hadoop-yarn-server-timelineservice-hbase-tests}}, where it duplicates JAX-RS
2.1 on the classpath.
* Upgrade Guice to 6.X, as supports both javax and jakarta namespaces.
h3. Behaviour changes
The Jetty 12 upgrade is an incompatible change. Its release note covers what
Jetty 12 changes for callers:
* no custom HTTP reason phrase; refusal messages travel in the response body
instead, and Hadoop's clients read them there;
* stricter URI parsing, adjustable with
{{hadoop.http.uri.compliance.violations}};
* TLS 1.2 renegotiation off by default, adjustable with
{{hadoop.http.ssl.renegotiation.allowed}};
* the five async HTTP metrics read 0, because Jetty 12 cannot count them;
* Jetty's own output: error-page markup, {{charset=utf-8}} and {{Vary}} on
static files, a {{Date}} header on error responses, and the default acceptor
count.
h3. Done when
* No Jetty 9.4 artifact is left on any module classpath of the trunk build.
* Every daemon serves on Jetty 12, and the full test suite passes.
* The release note lists every incompatible change.
h3. Out of scope
* The jakarta namespace, Jetty ee10/ee11, Jersey 3 and JAXB 4: HADOOP-19395.
* Jetty 9.4 security updates on release lines that cannot move to Java 17:
HADOOP-19915.
was:
The goal of this task is to move Hadoop's web servers off Jetty 9.4, which is
end of life: its releases are now rare and sponsored, and its CVEs keep coming
(HADOOP-19910, HADOOP-19915).
h3. Approach
Jetty 12 serves two servlet APIs side by side: the ee8 environment serves
{{javax.servlet}}, while ee10 and ee11 serve {{jakarta.servlet}}. This issue
moves Hadoop to Jetty 12 on ee8, so the servlet namespace, Jersey 2 and every
public signature stay as they are.
The move to the jakarta namespace (Jetty ee10, Jersey 3, JAXB 4) is a separate
decision, tracked in HADOOP-19395, which starts from here.
Jetty 12 needs Java 17, so this is for trunk. Release lines that stay on Jetty
9.4 are covered by HADOOP-19915.
h3. Tasks
* Resolve one Jetty release and one servlet API on every module classpath,
without changing the Jetty version.
* Drop jetty-util-ajax in favour of Jackson.
* Upgrade Jetty 9.4 to 12 on the ee8 environment: {{HttpServer2}}, KMS, HttpFS,
the YARN web apps, WebSocket, SLS, the services API, the shaded clients and
LICENSE-binary. Keep trunk's behaviour wherever Jetty 12 allows, and list the
rest for the release note.
* Move the YARN application catalog off Jetty 9.4, the last Jetty 9.4 in the
build, which it needs for Solr 8: retire the module, or upgrade it to Solr 10.
* Remove the JAX-RS 1.1 API ({{jsr311-api}}) from
{{hadoop-yarn-server-timelineservice-hbase-tests}}, where it duplicates JAX-RS
2.1 on the classpath.
* Upgrade Guice to 6.X, as supports both javax and jakarta namespaces.
h3. Behaviour changes
The Jetty 12 upgrade is an incompatible change. Its release note covers what
Jetty 12 changes for callers:
* no custom HTTP reason phrase; refusal messages travel in the response body
instead, and Hadoop's clients read them there;
* stricter URI parsing, adjustable with
{{hadoop.http.uri.compliance.violations}};
* TLS 1.2 renegotiation off by default, adjustable with
{{hadoop.http.ssl.renegotiation.allowed}};
* the five async HTTP metrics read 0, because Jetty 12 cannot count them;
* Jetty's own output: error-page markup, {{charset=utf-8}} and {{Vary}} on
static files, a {{Date}} header on error responses, and the default acceptor
count.
h3. Done when
* No Jetty 9.4 artifact is left on any module classpath of the trunk build.
* Every daemon serves on Jetty 12, and the full test suite passes.
* The release note lists every incompatible change.
h3. Out of scope
* The jakarta namespace, Jetty ee10/ee11, Jersey 3 and JAXB 4: HADOOP-19395.
* Jetty 9.4 security updates on release lines that cannot move to Java 17:
HADOOP-19915.
> Upgrade to Jetty 12 on the ee8 environment keeping javax.servlet
> ----------------------------------------------------------------
>
> Key: HADOOP-19912
> URL: https://issues.apache.org/jira/browse/HADOOP-19912
> Project: Hadoop Common
> Issue Type: Task
> Reporter: PJ Fanning
> Assignee: Jose Luis López
> Priority: Major
> Labels: pull-request-available
>
> The goal of this task is to move Hadoop's web servers off Jetty 9.4, which is
> end of life: its releases are now rare and sponsored, and its CVEs keep
> coming (HADOOP-19910, HADOOP-19915).
> h3. Approach
> Jetty 12 serves two servlet APIs side by side: the ee8 environment serves
> {{javax.servlet}}, while ee10 and ee11 serve {{jakarta.servlet}}. This issue
> moves Hadoop to Jetty 12 on ee8, so the servlet namespace, Jersey 2 and every
> public signature stay as they are.
> We will rollout changes to the modules preparing them for the migration to
> Jetty12-ee8 (handling of the HTTP reason code, auth filters, others).
> The move to the jakarta namespace (Jetty ee10, Jersey 3, JAXB 4) is a
> separate decision, tracked in HADOOP-19395, which starts from here.
> Jetty 12 needs Java 17, so this is for trunk. Release lines that stay on
> Jetty 9.4 are covered by HADOOP-19915.
> h3. Tasks
> * Resolve one Jetty release and one servlet API on every module classpath,
> without changing the Jetty version.
> * Drop jetty-util-ajax in favour of Jackson.
> * Upgrade Jetty 9.4 to 12 on the ee8 environment: {{HttpServer2}}, KMS,
> HttpFS, the YARN web apps, WebSocket, SLS, the services API, the shaded
> clients and LICENSE-binary. Keep trunk's behaviour wherever Jetty 12 allows,
> and list the rest for the release note.
> * Move the YARN application catalog off Jetty 9.4, the last Jetty 9.4 in the
> build, which it needs for Solr 8: retire the module, or upgrade it to Solr 10.
> * Remove the JAX-RS 1.1 API ({{jsr311-api}}) from
> {{hadoop-yarn-server-timelineservice-hbase-tests}}, where it duplicates
> JAX-RS 2.1 on the classpath.
> * Upgrade Guice to 6.X, as supports both javax and jakarta namespaces.
> h3. Behaviour changes
> The Jetty 12 upgrade is an incompatible change. Its release note covers what
> Jetty 12 changes for callers:
> * no custom HTTP reason phrase; refusal messages travel in the response body
> instead, and Hadoop's clients read them there;
> * stricter URI parsing, adjustable with
> {{hadoop.http.uri.compliance.violations}};
> * TLS 1.2 renegotiation off by default, adjustable with
> {{hadoop.http.ssl.renegotiation.allowed}};
> * the five async HTTP metrics read 0, because Jetty 12 cannot count them;
> * Jetty's own output: error-page markup, {{charset=utf-8}} and {{Vary}} on
> static files, a {{Date}} header on error responses, and the default acceptor
> count.
> h3. Done when
> * No Jetty 9.4 artifact is left on any module classpath of the trunk build.
> * Every daemon serves on Jetty 12, and the full test suite passes.
> * The release note lists every incompatible change.
> h3. Out of scope
> * The jakarta namespace, Jetty ee10/ee11, Jersey 3 and JAXB 4: HADOOP-19395.
> * Jetty 9.4 security updates on release lines that cannot move to Java 17:
> HADOOP-19915.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]