You are viewing a plain text version of this content. The canonical link for it is here.
Posted to common-issues@hadoop.apache.org by "Ayush Saxena (Jira)" <ji...@apache.org> on 2020/03/03 15:34:00 UTC
[jira] [Commented] (HADOOP-16210) Update guava to 27.0-jre in
hadoop-project trunk
[ https://issues.apache.org/jira/browse/HADOOP-16210?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17050314#comment-17050314 ]
Ayush Saxena commented on HADOOP-16210:
---------------------------------------
bq. It looks like guava added single parameter optimizations which breaks compatibility with VAR_ARGS. So, even though it shows source compatibility it is going to throw a runtime error due to binary incompatibility.
Marked imcompatible, I too observed the same issue, If we get this in the client needs to be updated, else it gives me the same error at runtime.
I am not sure, does the compatibility guidelines allow this for 3.3.0? If not IMHO we should discuss a way to come over or try reverting this!!!
> Update guava to 27.0-jre in hadoop-project trunk
> ------------------------------------------------
>
> Key: HADOOP-16210
> URL: https://issues.apache.org/jira/browse/HADOOP-16210
> Project: Hadoop Common
> Issue Type: Sub-task
> Affects Versions: 3.3.0
> Reporter: Gabor Bota
> Assignee: Gabor Bota
> Priority: Critical
> Labels: imcompatible
> Fix For: 3.3.0
>
> Attachments: HADOOP-16210.001.patch, HADOOP-16210.002.findbugsfix.wip.patch, HADOOP-16210.002.patch, HADOOP-16210.003.patch
>
>
> com.google.guava:guava should be upgraded to 27.0-jre due to new CVE's found CVE-2018-10237.
> This is a sub-task for trunk from HADOOP-15960 to track issues with that particular branch.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: common-issues-unsubscribe@hadoop.apache.org
For additional commands, e-mail: common-issues-help@hadoop.apache.org