I'm happy to announce that we have unanimously approved this release. There are 5 approving votes, 5 of which are binding:
- Patrick Hunt (binding) - Szalay-Beko Mate (binding) - Andor Molnar (binding) - tison (binding) - Flavio Junqueira (binding) There are no disapproving votes. I will promote the artifacts and complete the release procedure. Thanks to every one who contributed to this great release ! Andor > On Sep 14, 2026, at 02:59, Flavio Junqueira <[email protected]> > wrote: > > +1 > > Thanks, Andor. > > Verified: > > * SHA-512 checksums for both source and binary tarballs. > * GPG signatures on both tarballs and on the staged Maven artifacts > (jar, pom, sources) — all good, signed with > 3F7A1D16FA4217B1DC75E1C9FFE35B7F15DFA1BA, which is in the project > KEYS file. > * The source tarball matches the release-3.8.7-0 tag. The only > difference is that .gitattributes and .gitignore are not included in > the tarball (1402 files vs 1404 in the tag); everything present is > identical. Note this differs from 3.9.6, whose tarball does include > those two files — harmless, but the two branches' source assemblies > are inconsistent if anyone cares to align them. > * The zookeeper-3.8.7.jar in the Maven staging repo is byte-identical > (same SHA-256) to the one in the binary tarball. > * The running server reports version 3.8.7-9085db92..., matching the > tag commit. > * branch-3.8 contains only "Prepared 3.8.8-SNAPSHOT" after the tag, so > nothing was left out of the candidate. > * The set of bundled jars and per-jar LICENSE files in the binary > tarball is identical to released 3.8.6. > * Release notes are complete and consistent: all 12 issues with > fixVersion 3.8.7 map to commits in the tag, the staged website matches > JIRA, and the reverted logback change (ZOOKEEPER-5057) is correctly > absent. I also checked the 3.9.6 fixes that are not in 3.8.7 > (ZOOKEEPER-5043, 5044, 5045, 5049, 5052, 4912) — all are scoped to > 3.10.0 and 3.9.6 in JIRA, so those omissions look deliberate. > * Built from source on JDK 11. Test suite: 3036 tests, 1 failure, > 1 error, 4 skipped — see below, none attributable to the candidate. > * Standalone smoke test from the binary tarball: CRUD, four-letter > words and AdminServer all fine. ACL enforcement verified in both > directions — an unauthenticated read of a digest-restricted znode is > denied, and the same read succeeds after addauth. > * Three-node ensemble: quorum formed, writes on a follower replicated to > all members, killed the leader and re-election succeeded, data > survived, writes continued on a 2/3 quorum, and the restarted member > rejoined and caught up on data written while it was down. No > unexpected errors in the server logs. > * zkCli works on JDK 8, 11 and 21. > > Tested on macOS (arm64). > > On the three test problems, none of which I think are release blockers: > > 1. ClientSSLTest.testClientServerSSL_negative[2] (fipsEnabled=false) > fails reproducibly for me, but released 3.8.6 fails the identical > test, same parameterisation, same line on the same machine, so it is > pre-existing rather than a 3.8.7 regression. The cause is > environmental: this host's name resolves to 127.0.0.1, which is in > the test certificate's iPAddress SAN, so with FIPS off ZKTrustManager > matches on the resolved address and the connection the test expects to > fail actually succeeds. With FIPS on, the JDK checks the hostname > string and correctly rejects. The test implicitly assumes the local > hostname does not resolve to loopback, which is not true everywhere. > Might be worth a JIRA to make it robust. > > 2. SaslAuthTest.testDisconnectNotCreatingLoginThread timed out under > parallel forks but passes in isolation. > > 3. QuorumZxidSyncTest had its surefire fork die under load. It is > untouched by this release and passes consistently on its own. I saw > the same thing on the 3.9.6 candidate. > > -Flavio > >> On 11 Sep 2026, at 22:27, Andor Molnár <[email protected]> wrote: >> >> +1 (binding) >> >> - verified checksum and gpg signature of the artifacts >> - built source code with JDK 8, 11, 17 >> - all the java unit tests passed for me >> - all the C-client tests passed too >> - checkstyle and spotbugs passed >> - apache-rat passed >> - 3-node quorum with standard smoke tests works fine (w/ and w/o TLS) >> - zk-smoketest.py passed >> - zk-latencies.py passed >> >> Andor >> >> >> >>> On Sep 3, 2026, at 13:14, Andor Molnár <[email protected]> wrote: >>> >>> Hi, >>> >>> This is a release candidate for 3.8.7 >>> >>> This is a minor release with bug- and security fixes. >>> >>> The full release notes is available at: >>> >>> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310801&version=12356710 >>> >>> *** Please download, test and vote by September 11th 2026, 23:59 UTC+0. *** >>> >>> Source files: >>> https://dist.apache.org/repos/dist/dev/zookeeper/zookeeper-3.8.7-candidate-0/ >>> >>> Maven staging repo: >>> https://repository.apache.org/content/repositories/orgapachezookeeper-1116/ >>> >>> The release candidate tag in git to be voted upon: release-3.8.7-0 >>> https://github.com/apache/zookeeper/tree/release-3.8.7-0 >>> >>> ZooKeeper's KEYS file containing PGP keys we use to sign the release: >>> https://www.apache.org/dist/zookeeper/KEYS >>> >>> The staging version of the website is: >>> https://dist.apache.org/repos/dist/dev/zookeeper/zookeeper-3.8.7-candidate-0/website/index.html >>> >>> >>> Should we release this candidate? >>> >>> Andor >>> >>> >> >
