Skip to content

Conversation

@warriersruthi
Copy link

@warriersruthi warriersruthi commented Apr 26, 2022

Upgrade protobuf-java version to 3.16.1 due to security compliance issue CVE-2021-22569

Link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569

TEZ-4410

@tez-yetus
Copy link

💔 -1 overall

Vote Subsystem Runtime Comment
+0 🆗 reexec 17m 51s Docker mode activated.
_ Prechecks _
+1 💚 dupname 0m 0s No case conflicting files found.
+1 💚 @author 0m 0s The patch does not contain any @author tags.
-1 ❌ test4tests 0m 0s The patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
_ master Compile Tests _
-1 ❌ mvninstall 13m 52s root in master failed.
-1 ❌ compile 1m 37s root in master failed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.
-1 ❌ compile 1m 27s root in master failed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.
+1 💚 javadoc 2m 44s master passed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04
+1 💚 javadoc 1m 56s master passed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
_ Patch Compile Tests _
-1 ❌ mvninstall 0m 55s root in the patch failed.
-1 ❌ compile 0m 38s root in the patch failed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.
-1 ❌ javac 0m 38s root in the patch failed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.
-1 ❌ compile 0m 37s root in the patch failed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.
-1 ❌ javac 0m 37s root in the patch failed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.
+1 💚 whitespace 0m 0s The patch has no whitespace issues.
+1 💚 xml 0m 1s The patch has no ill-formed XML file.
-1 ❌ javadoc 0m 38s root in the patch failed with JDK Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.
-1 ❌ javadoc 0m 37s root in the patch failed with JDK Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.
_ Other Tests _
-1 ❌ unit 0m 55s root in the patch failed.
+1 💚 asflicense 0m 46s The patch does not generate ASF License warnings.
45m 38s
Subsystem Report/Notes
Docker ClientAPI=1.41 ServerAPI=1.41 base: https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/Dockerfile
GITHUB PR #205
Optional Tests dupname asflicense javac javadoc unit xml compile
uname Linux 23bebfa284cb 4.15.0-65-generic #74-Ubuntu SMP Tue Sep 17 17:06:04 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
Build tool maven
Personality personality/tez.sh
git revision master / 9f8d6fb
Default Java Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
Multi-JDK versions /usr/lib/jvm/java-11-openjdk-amd64:Ubuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04 /usr/lib/jvm/java-8-openjdk-amd64:Private Build-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07
mvninstall https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/branch-mvninstall-root.txt
compile https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/branch-compile-root-jdkUbuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.txt
compile https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/branch-compile-root-jdkPrivateBuild-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.txt
mvninstall https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-mvninstall-root.txt
compile https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-compile-root-jdkUbuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.txt
javac https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-compile-root-jdkUbuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.txt
compile https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-compile-root-jdkPrivateBuild-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.txt
javac https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-compile-root-jdkPrivateBuild-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.txt
javadoc https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-javadoc-root-jdkUbuntu-11.0.14.1+1-Ubuntu-0ubuntu1.20.04.txt
javadoc https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-javadoc-root-jdkPrivateBuild-1.8.0_312-8u312-b07-0ubuntu1~20.04-b07.txt
unit https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/artifact/out/patch-unit-root.txt
Test Results https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/testReport/
Max. process+thread count 99 (vs. ulimit of 5500)
modules C: . U: .
Console output https://ci-hadoop.apache.org/job/tez-multibranch/job/PR-205/1/console
versions git=2.25.1 maven=3.6.3
Powered by Apache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@guptanikhil007
Copy link
Contributor

@warriersruthi You need to regenerate proto files.
Also, please rebase and trigger a fresh build.

@warriersruthi warriersruthi deleted the sec_compliance branch May 3, 2022 05:02
@warriersruthi
Copy link
Author

I see that the Jira: TEZ-4363 is upgrading the protobuf version to 3.19.4 and I guess the vulnerability CVE-2021-22569 would be handled with this change as the problem was with version 2.5.0.
Thus closing this ticket as its duplicate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants