Repository navigation
client: exclude jdk15on BouncyCastle artifacts from the shaded jar - #14353
weizhouapache wants to merge 3 commits into
Conversation
The client shade config only excluded the jdk18on BouncyCastle artifacts, which are shipped as separate jars in the management server lib folder. If a stale or transitive dependency pulls in bcprov/bcpkix/bctls-jdk15on, the old classes are bundled into the fat jar and can shadow bcprov-jdk18on depending on the classpath order of lib/*, failing with NoSuchFieldError (e.g. xmss_SHAKE128_512ph) when the root CA module starts.
|
I faced the issue below on ubuntu 24/26 Quick workaround on the management server: put the BouncyCastle jars first in CLASSPATH in The issue has been reported by @RosiKyu in the comment #14033 (comment) This issue happens rarely, I did not face it before, but faced it 3 times yesterday. (related to #12794 ) |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #14353 +/- ##
============================================
- Coverage 19.91% 19.91% -0.01%
+ Complexity 20200 20199 -1
============================================
Files 6373 6373
Lines 577230 577230
Branches 70696 70696
============================================
- Hits 114958 114953 -5
- Misses 449703 449711 +8
+ Partials 12569 12566 -3
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
@blueorangutan package |
|
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
There was a problem hiding this comment.
🟢 Approval recommended
The reviewed shading configuration change addresses the artifact conflict with no unresolved issues.
0 open findings
What changed in this PR
Updates the client shaded JAR configuration to prevent legacy BouncyCastle JDK15 artifacts from shadowing JDK18 artifacts.
Changes:
- Excludes
bcprov,bcpkix,bctls, andbcutilJDK15 artifacts from shading.
| File | Description |
|---|---|
client/pom.xml |
Adds BouncyCastle JDK15 artifact exclusions. |
🧠 Review effort: Lite
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19466 |
|
@blueorangutan test ubuntu24 kvm-ubuntu24 |
|
Vishesh has found this is caused by netris-java-sdk update. good finding! |
|
@blueorangutan test ubuntu24 kvm-ubuntu24 |
|
@weizhouapache a [SL] Trillian-Jenkins test job (ubuntu24 mgmt + kvm-ubuntu24) has been kicked to run smoke tests |
|
[SF] Trillian Build Failed (tid-17098) |
|
this PR does not fix the issue and |
…d jar" This reverts commit e1f9011.
The netris-java-sdk 1.0.0 artifact was republished without a version bump and now declares bcprov-jdk15on and bctls-jdk15on 1.70. These were shaded into the management server jar next to the bcprov/bcpkix/bctls-jdk18on 1.83 jars in lib/, and the old classes could shadow the new ones depending on the classpath order, failing with NoSuchFieldError (xmss_SHAKE128_512ph) when the root CA module starts. The SDK still gets BouncyCastle (BouncyCastleProvider and BouncyCastleJsseProvider) from the managed jdk18on 1.83 artifacts.
|
@blueorangutan package |
|
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19470 |
|
@blueorangutan test ubuntu24 kvm-ubuntu24 |
|
@weizhouapache a [SL] Trillian-Jenkins test job (ubuntu24 mgmt + kvm-ubuntu24) has been kicked to run smoke tests |
|
[SF] Trillian Build Failed (tid-17100) |
|
this PR is not required when bump the netris-java-sdk to 1.1.0 closing |
|
[SF] Trillian Build Failed (tid-17102) |
|
Hi @weizhouapache @vishesh92 please check #14365 |
Description
The client shade config only excluded the jdk18on BouncyCastle artifacts, which are shipped as separate jars in the management server lib folder. If a stale or transitive dependency pulls in bcprov/bcpkix/bctls-jdk15on, the old classes are bundled into the fat jar and can shadow bcprov-jdk18on depending on the classpath order of lib/*, failing with NoSuchFieldError (e.g. xmss_SHAKE128_512ph) when the root CA module starts.
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Bug Severity
Screenshots (if appropriate):
How Has This Been Tested?
How did you try to break this feature and the system with this change?