Skip to content

Saxenapranav/abfs apachehttpclient yetus#18

Merged
saxenapranav merged 9 commits intosaxenapranav/abfs-apachehttpclientfrom
saxenapranav/abfs-apachehttpclient-yetus
Jun 10, 2024
Merged

Saxenapranav/abfs apachehttpclient yetus#18
saxenapranav merged 9 commits intosaxenapranav/abfs-apachehttpclientfrom
saxenapranav/abfs-apachehttpclient-yetus

Conversation

@saxenapranav
Copy link
Copy Markdown
Owner

Description of PR

How was this patch tested?

For code changes:

  • Does the title or this PR starts with the corresponding JIRA issue id (e.g. 'HADOOP-17799. Your PR title ...')?
  • Object storage: have the integration tests been executed and the endpoint declared according to the connector-specific documentation?
  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0?
  • If applicable, have you updated the LICENSE, LICENSE-binary, NOTICE-binary files?

yzhang559 and others added 9 commits June 3, 2024 09:10
…tionFileAttributes when bucket not encrypted with sse-kms (apache#6859)

Follow up of HADOOP-19190
This stop gh-pages deployments from increasing the size of the git repository on every run

Contributed by Cheng Pan
Addresses

* CVE-2024-29857 - Importing an EC certificate with specially crafted F2m parameters can cause high CPU usage during parameter evaluation.
* CVE-2024-30171 - Possible timing based leakage in RSA based handshakes due to exception processing eliminated.
* CVE-2024-30172 - Crafted signature and public key can be used to trigger an infinite loop in the Ed25519 verification code.
* CVE-2024-301XX - When endpoint identification is enabled and an SSL socket is not created with an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address. 

Contributed by PJ Fanning
* parameterize the test run rather than do it from within the test suite.
* log what the committer factory is up to (and improve its logging)
* close all filesystems, then create the test filesystem with cache enabled.

The cache is critical, we want the fs from cache to be used when querying
filesystem properties, rather than one created from the committer jobconf,
which will have the same options as the task committer, so not actually
validate the override logic.

Contributed by Steve Loughran
…5. (apache#6664)" (apache#6875)

This reverts commit 88ad7db.
Signed-off-by: Shilun Fan <slfan1989@apache.org>
@saxenapranav saxenapranav merged commit 8637673 into saxenapranav/abfs-apachehttpclient Jun 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants