Skip to content

Conversation

periklis
Copy link
Contributor

@periklis periklis commented Oct 19, 2022

Description

Upgrade dependencies jackson-databind to 2.12.7.1 and jackson-core to 2.12.7 to address CVEs:

/cc @xperimental

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Oct 19, 2022

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: periklis

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 19, 2022
@periklis
Copy link
Contributor Author

/hold

@openshift-ci openshift-ci bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Oct 24, 2022
@periklis
Copy link
Contributor Author

Upgrading to jackson v2.12.7.1` seems to break opendistro_security plugin entirely:

java.lang.NoClassDefFoundError: com/fasterxml/jackson/core/util/JacksonFeature
	at com.fasterxml.jackson.databind.ObjectMapper.<init>(ObjectMapper.java:656) ~[?:?]
	at com.fasterxml.jackson.databind.ObjectMapper.<init>(ObjectMapper.java:558) ~[?:?]
	at com.amazon.opendistroforelasticsearch.security.DefaultObjectMapper.<clinit>(DefaultObjectMapper.java:38) ~[?:?]
	at com.amazon.opendistroforelasticsearch.security.ssl.OpenDistroSecuritySSLPlugin.<init>(OpenDistroSecuritySSLPlugin.java:198) ~[?:?]
	at com.amazon.opendistroforelasticsearch.security.OpenDistroSecurityPlugin.<init>(OpenDistroSecurityPlugin.java:231) ~[?:?]
	at jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) ~[?:?]
...

@periklis periklis force-pushed the cves-jackson-databind-v2.12.7.1 branch from 441c07b to aa5964b Compare October 27, 2022 13:00
@periklis
Copy link
Contributor Author

periklis commented Oct 27, 2022

ES requires also a bump on these deps:

 jar1: /usr/share/elasticsearch/lib/jackson-core-2.10.5.jar
jar2: /usr/share/elasticsearch/plugins/.installing-14413329575625065733/jackson-core-2.12.7.jar
	at org.elasticsearch.bootstrap.JarHell.checkClass(JarHell.java:277)
	at org.elasticsearch.bootstrap.JarHell.checkJarHell(JarHell.java:190)
	at org.elasticsearch.plugins.PluginsService.checkBundleJarHell(PluginsService.java:522)
	... 12 more 

@periklis periklis force-pushed the cves-jackson-databind-v2.12.7.1 branch 3 times, most recently from b8be5aa to 171c2bf Compare November 2, 2022 19:16
@periklis
Copy link
Contributor Author

periklis commented Nov 3, 2022

/retest

@periklis
Copy link
Contributor Author

periklis commented Nov 3, 2022

/test elastic-operator-e2e-5-2

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Nov 3, 2022

@periklis: The specified target(s) for /test were not found.
The following commands are available to trigger required jobs:

  • /test cluster-logging-operator-e2e-5-3
  • /test cluster-logging-operator-e2e-5-4
  • /test cluster-logging-operator-e2e-5-5
  • /test cluster-logging-operator-e2e-5-6
  • /test elastic-operator-e2e-5-3
  • /test elastic-operator-e2e-5-4
  • /test elastic-operator-e2e-5-5
  • /test elastic-operator-e2e-5-6
  • /test images
  • /test lint
  • /test smoke-5-3
  • /test smoke-5-4
  • /test smoke-5-5
  • /test smoke-5-6

Use /test all to run all jobs.

In response to this:

/test elastic-operator-e2e-5-2

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@periklis
Copy link
Contributor Author

periklis commented Nov 3, 2022

/retest

@periklis periklis force-pushed the cves-jackson-databind-v2.12.7.1 branch from 171c2bf to 8238df1 Compare November 3, 2022 12:53
@periklis
Copy link
Contributor Author

periklis commented Nov 3, 2022

/hold cancel

@openshift-ci openshift-ci bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Nov 3, 2022
@Red-GV
Copy link
Contributor

Red-GV commented Nov 4, 2022

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Nov 4, 2022
@Red-GV
Copy link
Contributor

Red-GV commented Nov 4, 2022

/retest

@periklis
Copy link
Contributor Author

periklis commented Nov 4, 2022

/override ci/prow/smoke-5-6

@periklis
Copy link
Contributor Author

periklis commented Nov 4, 2022

/override ci/prow/elastic-operator-e2e-5-3

@periklis
Copy link
Contributor Author

periklis commented Nov 4, 2022

/override ci/prow/cluster-logging-operator-e2e-5-3

@periklis
Copy link
Contributor Author

periklis commented Nov 4, 2022

/override ci/prow/cluster-logging-operator-e2e-5-6

@periklis
Copy link
Contributor Author

periklis commented Nov 4, 2022

/override ci/prow/elastic-operator-e2e-5-4

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Nov 4, 2022

@periklis: Overrode contexts on behalf of periklis: ci/prow/smoke-5-6

In response to this:

/override ci/prow/smoke-5-6

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Nov 4, 2022

@periklis: Overrode contexts on behalf of periklis: ci/prow/elastic-operator-e2e-5-3

In response to this:

/override ci/prow/elastic-operator-e2e-5-3

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Nov 4, 2022

@periklis: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/elastic-operator-e2e-5-2 441c07b link false /test elastic-operator-e2e-5-2
ci/prow/cluster-logging-operator-e2e-5-2 441c07b link false /test cluster-logging-operator-e2e-5-2
ci/prow/smoke-5-2 441c07b link false /test smoke-5-2

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Nov 4, 2022

@periklis: Overrode contexts on behalf of periklis: ci/prow/cluster-logging-operator-e2e-5-3

In response to this:

/override ci/prow/cluster-logging-operator-e2e-5-3

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Nov 4, 2022

@periklis: Overrode contexts on behalf of periklis: ci/prow/elastic-operator-e2e-5-4

In response to this:

/override ci/prow/elastic-operator-e2e-5-4

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Nov 4, 2022

@periklis: Overrode contexts on behalf of periklis: ci/prow/cluster-logging-operator-e2e-5-6

In response to this:

/override ci/prow/cluster-logging-operator-e2e-5-6

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-merge-robot openshift-merge-robot merged commit da674d3 into openshift:master Nov 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. midstream/Dockerfile
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants