[SPARK-35305][BUILD] Upgrade Zookeeper to 3.7.0#32572
[SPARK-35305][BUILD] Upgrade Zookeeper to 3.7.0#32572zhulipeng wants to merge 2 commits intoapache:masterfrom zhulipeng:SPARK-35305
Conversation
|
Can one of the admins verify this patch? |
wangyum
left a comment
There was a problem hiding this comment.
Please update the dependencies:
./dev/test-dependencies.sh --replace-manifest|
Does this present any compatibility concerns with Hadoop 3.2? |
|
Are those CVE applicable to Zookeeper Client , @lipzhu ? |
Found https://issues.apache.org/jira/browse/ZOOKEEPER-4278 https://issues.apache.org/jira/browse/ZOOKEEPER-4272 |
There was a problem hiding this comment.
Thanks for the pointers. I checked those Zookeeper JIRA issues and CVEs.
- https://issues.apache.org/jira/browse/ZOOKEEPER-4278
- https://issues.apache.org/jira/browse/ZOOKEEPER-4272
- CVE-2021-21295 (requires 4.1.60)
- CVE-2021-21290 (requires 4.1.59)
- CVE-2021-21409 (requires 4.1.61)
Apache Spark is using netty-all 4.1.63.Final. Isn't it enough?
|
Yes, you are right, the list CVE were resolved by |
|
Thank you for closing, @lipzhu . |
### What changes were proposed in this pull request? Upgrade ZooKeeper to 3.6.3 ### Why are the changes needed? ZooKeeper 3.6.3 contains many bugfixes, such as a thread leak issue described in ZOOKEEPER-3706. FYI, https://zookeeper.apache.org/doc/r3.6.3/releasenotes.html - Why is 3.6.3 but not higher? - #37507 - #32572 ### Does this PR introduce _any_ user-facing change? no ### How was this patch tested? existing tests and dependency check Closes #38733 from yaooqinn/SPARK-41211. Authored-by: Kent Yao <yao@apache.org> Signed-off-by: Kent Yao <yao@apache.org>
### What changes were proposed in this pull request? Upgrade ZooKeeper to 3.6.3 ### Why are the changes needed? ZooKeeper 3.6.3 contains many bugfixes, such as a thread leak issue described in ZOOKEEPER-3706. FYI, https://zookeeper.apache.org/doc/r3.6.3/releasenotes.html - Why is 3.6.3 but not higher? - apache#37507 - apache#32572 ### Does this PR introduce _any_ user-facing change? no ### How was this patch tested? existing tests and dependency check Closes apache#38733 from yaooqinn/SPARK-41211. Authored-by: Kent Yao <yao@apache.org> Signed-off-by: Kent Yao <yao@apache.org>
### What changes were proposed in this pull request? Upgrade ZooKeeper to 3.6.3 ### Why are the changes needed? ZooKeeper 3.6.3 contains many bugfixes, such as a thread leak issue described in ZOOKEEPER-3706. FYI, https://zookeeper.apache.org/doc/r3.6.3/releasenotes.html - Why is 3.6.3 but not higher? - apache#37507 - apache#32572 ### Does this PR introduce _any_ user-facing change? no ### How was this patch tested? existing tests and dependency check Closes apache#38733 from yaooqinn/SPARK-41211. Authored-by: Kent Yao <yao@apache.org> Signed-off-by: Kent Yao <yao@apache.org>
### What changes were proposed in this pull request? Upgrade ZooKeeper to 3.6.3 ### Why are the changes needed? ZooKeeper 3.6.3 contains many bugfixes, such as a thread leak issue described in ZOOKEEPER-3706. FYI, https://zookeeper.apache.org/doc/r3.6.3/releasenotes.html - Why is 3.6.3 but not higher? - apache#37507 - apache#32572 ### Does this PR introduce _any_ user-facing change? no ### How was this patch tested? existing tests and dependency check Closes apache#38733 from yaooqinn/SPARK-41211. Authored-by: Kent Yao <yao@apache.org> Signed-off-by: Kent Yao <yao@apache.org>
What changes were proposed in this pull request?
Upgrade zookeeper to 3.7.0.
Why are the changes needed?
Upgrade ZooKeeper to 3.7.0 to fix the vulnerabilities.
List of CVE's:
CVE-2021-21295
CVE-2021-21290
CVE-2021-21409
Does this PR introduce any user-facing change?
No.
How was this patch tested?
Exists UT.