Skip to content

[ci-debug] DO NOT MERGE — one instrumented CI run for PR #102 diagnostics - #103

Closed
dao-jun wants to merge 36 commits into
branch-ci-debug-basefrom
ci-debug/batchread-tls
Closed

dao-jun wants to merge 36 commits into
branch-ci-debug-basefrom
ci-debug/batchread-tls

Conversation

@dao-jun

@dao-jun dao-jun commented Sep 21, 2026

Copy link
Copy Markdown
Member

Throwaway draft PR to trigger one instrumented CI run on branch-as-4.0. Purpose: capture [CI-DEBUG] log lines (client TLS engine endpoint-identification state at handshake, configureSSLHandler callers, schema-ledger metadata snapshots and delete callers) for the CI-only deterministic failures of AuthenticationTlsHostnameVerificationTest[false] / ProxyServiceTlsStarterTest.testProducer / SchemaTest.testConcurrentCreateSchemaNoOrphanLedger seen on PR #102 run 35531345414. Branch and PR will be deleted right after artifact extraction. DO NOT MERGE.

lhotari and others added 30 commits September 20, 2026 17:15
… and adding a new cache strategy based on expected read count (apache#24444)

(cherry picked from commit cf3d7d1)
…ck since it's already covered by putIfAbsent (apache#24699)

(cherry picked from commit 669ab61)
…ng the parsed instance in the broker cache (apache#24682)

(cherry picked from commit 53bbd4a)
…ad of under the wrapper write lock (apache#26463)

(cherry picked from commit ce60798)
…4.2.17 to enable the BK batch read API

Dependency enablement for apache#25280 (BK batch read): switch from the
com.ascentstream fork artifacts (bookkeeper 4.17.4.0) to Apache
org.apache.bookkeeper/org.apache.distributedlog 4.18.0, align Netty to
4.2.17 with io_uring promoted out of the incubator coordinates, raise
pulsar.client.compiler.release to 17 (BK 4.18.0 jars are Java 17
bytecode in the client dependency chain), and bump rocksdb to 9.9.3.
Carries the API-migration ripple: PulsarFlowControlHandler (netty 4.2),
EventLoopUtil, Recycler-based test adaptations, pulsar-metadata BK 4.18
ZK/underreplication API changes, offload LedgerMetadataFormat migration,
BKStateStoreProviderImpl, BookKeeperClusterTestCase loopback
advertisement, and the module pom/shading updates.

Clear the client endpoint identification algorithm in SecurityUtility's
client SslContext builders: Netty 4.2's SslContextBuilder.forClient()
defaults it to "HTTPS", which silently re-enables hostname verification
when tlsHostnameVerificationEnable=false (the per-engine HTTPS overlay
in configureSSLHandler still applies it when the flag is on). The
algorithm is final at context-build time on the OpenSSL backend, so the
default must be countered at the builder (mirrors upstream's
TlsContexts.buildNettyClientContext in PIP-478).

Extracted from the batch-read WIP (8d38f112a8 + f2b2d43759), excluding
the batch-read feature changes that arrive with apache#25280.
Co-authored-by: Lari Hotari <lhotari@apache.org>
Co-authored-by: Matteo Merli <mmerli@apache.org>
(cherry picked from commit f369915)
Co-authored-by: Matteo Merli <mmerli@apache.org>
(cherry picked from commit 1759f73)
…pache#26514)

Port of the upstream netty 4.2.17.Final -> 4.2.18.Final upgrade:
- root pom netty.version bump; netty-tcnative follows via the netty-bom
  (2.0.81.Final -> 2.0.84.Final)
- LICENSE.bin.txt (server + shell) netty/tcnative version lines realigned
  with the bundled jars
- ProxyProtocolTest.testSniProxyProtocol: use unresolvable-broker-address
  in the broker service URL so it matches the certificate SAN, as required
  by the now default-on hostname verification (same change as upstream
  PIP-478 core migration apache#26282)

Fixes the TLS handshake failures ("Connection already closed") seen with
netty 4.2.17 in ProxyServiceTlsStarterTest / ProxyProtocolTest.

(cherry picked from commit 7ddeac8e2339f3bd2b9e7c1d3694ec7c1a820bdc)
BookKeeper 4.18 jars are Java 17 bytecode (verified: class file major 61,
vs major 52 for the previous ascentstream 4.17.4.0 fork) and they are part
of the client dependency chain, so the shaded client artifacts cannot run
on Java 8/11 anymore. apache/pulsar made the same change when adopting
PIP-421 "Require Java 17 as the minimum for Pulsar Java client SDK"
(apache#24475): the SHADE_RUN matrix keeps only JDK 17+ entries.
…perties stub to the 6-arg internalAsyncMarkDelete

The apache#25796 backport (39f0def) landed both the production fix and its
test, but the test stubs the 5-arg internalAsyncMarkDelete overload:
that is the arity master's asyncMarkDelete chain reaches, while on this
branch the chain routes through the 6-arg overload (adding
propagatePersistFailure/durableFallback) that NonDurableCursorImpl
overrides. The stub therefore never intercepted the advance-path call
and the entry latch deterministically timed out, leaving the test red
since the backport landed. Stub the 6-arg overload instead; the
null-properties contract asserted by apache#25796 is unchanged.
…dentification state and schema-ledger metadata snapshots

DO NOT MERGE. Throwaway branch for one instrumented CI run to diagnose the
CI-only deterministic failures of AuthenticationTlsHostnameVerificationTest[false],
ProxyServiceTlsStarterTest.testProducer and SchemaTest.testConcurrentCreateSchemaNoOrphanLedger
on PR #102 (run 35531345414, reproduced in neither of 10+ local configurations).
Logs are prefixed [CI-DEBUG] and will be deleted with this branch.
@github-actions github-actions Bot added the PIP label Sep 21, 2026
@dao-jun
dao-jun changed the base branch from branch-as-4.0 to branch-ci-debug-base September 21, 2026 08:46
@dao-jun
dao-jun marked this pull request as ready for review September 21, 2026 08:46
@dao-jun dao-jun closed this Sep 21, 2026
@dao-jun
dao-jun deleted the ci-debug/batchread-tls branch September 21, 2026 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants