-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Coordinated Vert.x 4.5.11 upgrades #44515
Conversation
61dbf69
to
a28b5af
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
Should we "undraft" it to run the full CI?
I just want to have a look at eclipse-vertx/vert.x#5387 |
@mkouba could you help @jponge with eclipse-vertx/vert.x#5387? We may also need to check Quarkus HTTP (Jakarta WebSocket) |
That being said the old API is still there but deprecated, so that might be another PR (at least @mkouba is aware that there's a change here) |
Looks like we have some failures, we'll see with the summary report what's to be investigated |
The issues are SSL-related, see
and:
|
This comment has been minimized.
This comment has been minimized.
AFAIK we don't use the old API at all. Basically, the endpoint handler does not attempt to perform the upgrade if an |
FTR the
CC @radcortez @gsmet |
I'm a bit worried about the SSL IT issues. It can come from a change in Netty (we know that that code changed) or the PR from Franz changing the allocator when using SSL (the PR should have been super defensive, but never know) |
|
@mkouba I've tried running
I'm not sure this relates to the changes in this PR, it might be a different issue IMHO. |
Edit: it failed also with 17 |
/cc @franz1981 |
It was passing the tests on Vertx, which by default was still using the default approach, so...it should be fine(tm). I can take an additional look If you're blocked @jponge ? |
IF we can be sure if comes from that, we would need to revert it and wait for another Vert.x release. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Some Test failures are related.
Yes it is. I'd need to rewrite those tests when I find some time. |
Trying to reproduce it on my machine. |
Let's the new run on 17, and then I will need to edit the commits because it's not clean |
Strange. I did change that very recently in #44079, which was merged yesterday, but the CI was green. I've just checked out the PR and run it locally, and it also passes. Let me try to investigate it further. |
This comment has been minimized.
This comment has been minimized.
(let me redo my commits) |
388dc53
to
ae60d76
Compare
Here's a single commit 🚀 |
- Bump to Netty 4.1.115.Final and fix SSL-related substitutions due to internal Netty breaking changes - Bump to Vert.x 4.5.11 - Bump Mutiny Vert.x bindings 3.16.0 - Re-aligned the Vert.x versions across Quarkus modules Fixes CVE-2024-47535 with Netty 4.1.115.Final
ae60d76
to
9fd8dcb
Compare
@cescoffier pending another CI run completes, do you still want to hold on? |
Let's wait for that run to complete. |
Status for workflow
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We are good to go. I would wait a bit before backporting
(even if it will need backport)
Will this be applied also in the LTS version? |
That's what the But as Clement said, we need some bake time to ensure it doesn't cause any problems |
As I said in my last comment - yes, we want to backport it, but not immediately. There are some changes in Netty that need longer testing. |
Yep, i Will send the PRs (or delegate) next week |
…oud-jsonlogging!25) This MR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [io.quarkus:quarkus-extension-processor](https://github.com/quarkusio/quarkus) | | minor | `3.16.3` -> `3.17.0` | | [io.quarkus:quarkus-extension-maven-plugin](https://github.com/quarkusio/quarkus) | build | minor | `3.16.3` -> `3.17.0` | | [io.quarkus:quarkus-bom](https://github.com/quarkusio/quarkus) | import | minor | `3.16.3` -> `3.17.0` | | [io.quarkus:quarkus-maven-plugin](https://github.com/quarkusio/quarkus) | build | minor | `3.16.3` -> `3.17.0` | | [org.jboss.logmanager:jboss-logmanager](https://jboss.org) ([source](https://github.com/jboss-logging/jboss-logmanager)) | optional | minor | `3.0.6.Final` -> `3.1.0.Final` | --- ### Release Notes <details> <summary>quarkusio/quarkus</summary> ### [`v3.17.0`](quarkusio/quarkus@3.16.4...3.17.0) [Compare Source](quarkusio/quarkus@3.16.4...3.17.0) ### [`v3.16.4`](https://github.com/quarkusio/quarkus/releases/tag/3.16.4) [Compare Source](quarkusio/quarkus@3.16.3...3.16.4) ##### Complete changelog - [#​37040](quarkusio/quarkus#37040) - The flyway extension generates Kubernetes resources as if quarkus.flyway.enabled was a runtime property - [#​42446](quarkusio/quarkus#42446) - Add explanation/concept for extension maturity model - [#​44367](quarkusio/quarkus#44367) - Gradle 3.16 fails with missing required property `additionalForcedProperties` - [#​44399](quarkusio/quarkus#44399) - Declaring explicitly the build service in the QuarkusBuildTask - [#​44433](quarkusio/quarkus#44433) - Reflection free serializers ArrayIndexOutOfBoundsException - [#​44438](quarkusio/quarkus#44438) - Gradle `buildForkOptions` no longer used since quarkus 3.16.1 - [#​44457](quarkusio/quarkus#44457) - Support for short and uncommon field names like set, get, and is - [#​44468](quarkusio/quarkus#44468) - Use `QUARKUS_FLYWAY_ACTIVE` instead of `QUARKUS_FLYWAY_ENABLED` env in Kubernetes resources - [#​44472](quarkusio/quarkus#44472) - Kotlin native Jackson serialization regression: EmptyList & EmptyMap missing - [#​44480](quarkusio/quarkus#44480) - Fix nullpointer on null code websockets-next - [#​44493](quarkusio/quarkus#44493) - Using BuildForkOptions in QuarkusBuildTask - [#​44494](quarkusio/quarkus#44494) - Register Kotlin's empty list and map for reflection - [#​44505](quarkusio/quarkus#44505) - Log in smallrye-jwt and oauth2 extensions when no bearer access token is available - [#​44507](quarkusio/quarkus#44507) - Fixed Timestamp not being set for otel log signals - [#​44509](quarkusio/quarkus#44509) - Updates to Infinispan 15.0.11.Final - [#​44515](quarkusio/quarkus#44515) - Coordinated Vert.x 4.5.11 upgrades - [#​44531](quarkusio/quarkus#44531) - Correct image file name to resolve broken image - [#​44537](quarkusio/quarkus#44537) - Update smallrye-jwt to 4.6.1 - [#​44545](quarkusio/quarkus#44545) - Wrong index of ParameterizedType argument of Map when register type to be generated in JacksonCodeGenerator - [#​44571](quarkusio/quarkus#44571) - Update `CacheJsonRPCService.java` reference - [#​44574](quarkusio/quarkus#44574) - Grammar corrections for en-us </details> <details> <summary>jboss-logging/jboss-logmanager</summary> ### [`v3.1.0.Final`](https://github.com/jboss-logging/jboss-logmanager/releases/tag/v3.1.0.Final): 3.1.0.Final [Compare Source](jboss-logging/jboss-logmanager@3.0.6.Final...v3.1.0.Final) #### What's Changed - \[LOGMGR-345] Ensure logger FQCN is correct for system logger by [@​dmlloyd](https://github.com/dmlloyd) in jboss-logging/jboss-logmanager#457 - Migrate tests to keep the log files that were created. Put the log fi… by [@​jamezp](https://github.com/jamezp) in jboss-logging/jboss-logmanager#459 - Bump org.junit:junit-bom from 5.10.1 to 5.10.2 by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#461 - \[LOGMGR-346] Bump org.jboss.modules:jboss-modules from 2.1.2.Final to 2.1.3.Final by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#462 - \[LOGMGR-347] Do not use deprecated SmallRye Common OS `Process` by [@​dmlloyd](https://github.com/dmlloyd) in jboss-logging/jboss-logmanager#464 - \[LOGMGR-349] Bump org.eclipse.parsson:parsson from 1.1.5 to 1.1.6 by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#466 - \[LOGMGR-351] Fix periodic file rotation by week, month, year. by [@​alex-pumpkin](https://github.com/alex-pumpkin) in jboss-logging/jboss-logmanager#468 - Bump org.jboss.modules:jboss-modules from 2.1.3.Final to 2.1.5.Final by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#467 - \[LOGMGR-350] Avoid TCCL when configuring the log manager by [@​dmlloyd](https://github.com/dmlloyd) in jboss-logging/jboss-logmanager#469 - \[LOGMGR-351] Remove the deprecated per-deployment logging options. by [@​jamezp](https://github.com/jamezp) in jboss-logging/jboss-logmanager#471 - Bump org.junit:junit-bom from 5.10.2 to 5.10.3 by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#478 - Bump org.jboss.byteman:byteman-bmunit5 from 4.0.22 to 4.0.23 by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#476 - Bump org.junit:junit-bom from 5.10.3 to 5.11.2 by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#488 - Bump org.junit:junit-bom from 5.11.2 to 5.11.3 by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#490 - \[LOGMGR-354] Avoid expensive JLine setup on JDK 23+ by [@​dmlloyd](https://github.com/dmlloyd) in jboss-logging/jboss-logmanager#491 - Save head encoding on sanitized String(s) by [@​franz1981](https://github.com/franz1981) in jboss-logging/jboss-logmanager#492 - Use `NO_FORMAT` when using parameterless log methods by [@​dmlloyd](https://github.com/dmlloyd) in jboss-logging/jboss-logmanager#493 - Switch to formal module descriptor by [@​dmlloyd](https://github.com/dmlloyd) in jboss-logging/jboss-logmanager#494 - Module descriptor updates by [@​dmlloyd](https://github.com/dmlloyd) in jboss-logging/jboss-logmanager#496 - Bump org.jboss.modules:jboss-modules from 2.1.5.Final to 2.1.6.Final by [@​dependabot](https://github.com/dependabot) in jboss-logging/jboss-logmanager#495 - Add smart service provider method by [@​dmlloyd](https://github.com/dmlloyd) in jboss-logging/jboss-logmanager#497 #### New Contributors - [@​alex-pumpkin](https://github.com/alex-pumpkin) made their first contribution in jboss-logging/jboss-logmanager#468 - [@​franz1981](https://github.com/franz1981) made their first contribution in jboss-logging/jboss-logmanager#492 **Full Changelog**: jboss-logging/jboss-logmanager@3.0.4.Final...v3.1.0.Final </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever MR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This MR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC4yNC4wIiwidXBkYXRlZEluVmVyIjoiMzQuMjQuMCJ9-->
Upgrades to:
Fixes CVE-2024-47535 with Netty 4.1.115.Final