Repository navigation
[improve][misc] Upgrade Jetty to 12.1.12 - #26302
Merged
Merged
Conversation
Keep Pulsar on the latest Jetty 12.1.x patch release. Release notes: https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.12 Jetty 12.1.12 pulls in ASM 9.10.1 (from 9.10) transitively via jetty-annotations, so the OW2 ASM entries in the server LICENSE are updated as well.
dao-jun
approved these changes
Aug 10, 2026
….1.12 # Conflicts: # gradle/libs.versions.toml
…rRoutingTest FunctionWorkerRoutingTest called rewriteTarget() on an AdminProxyHandler that was never initialized as a servlet. That happened to work until Jetty 12.1.12, where AbstractProxyServlet.validateDestination() was rewritten to filter hosts through a single IncludeExclude and now always dereferences the logger that init() assigns, instead of only doing so when a whitelist or blacklist entry matched. The test therefore failed with a NullPointerException on _log. In production the servlet is registered through a ServletHolder in ProxyServiceStarter, so the container calls init() and the logger is set; only the test bypassed initialization. Initialize the servlet in the test the same way and destroy it afterwards, so the real validateDestination() path stays covered.
lhotari
added a commit
that referenced
this pull request
Aug 10, 2026
(cherry picked from commit 403aae6)
lhotari
added a commit
that referenced
this pull request
Aug 10, 2026
(cherry picked from commit 403aae6)
nodece
pushed a commit
to ascentstream/pulsar
that referenced
this pull request
Aug 28, 2026
(cherry picked from commit 403aae6)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Keep Pulsar on the latest Jetty 12.1.x patch release. Jetty 12.1.12 release notes: https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.12
Regarding security fixes: no published Jetty security advisory lists 12.1.12 as its patched version. The most recent Jetty CVEs (CVE-2026-10050 and CVE-2026-10051) were already addressed in 12.1.10, which Pulsar upgraded to previously.
12.1.12 does contain a number of correctness fixes in areas that Pulsar exercises directly — the reverse proxy in
pulsar-proxy(AdminProxyHandler extends ProxyServletfromjetty-ee10-proxy), the WebSocket endpoints inpulsar-websocket, and theForwardedRequestCustomizerthat the broker, proxy, WebSocket proxy and function worker all install for original-client-IP resolution:Proxy response headers (
jetty-ee10-proxyAbstractProxyServlet, used byAdminProxyHandler):onServerResponseHeadersnow usessetHeader()instead ofaddHeader(), so a header already present on the proxy response (e.g. set by a servlet filter) is replaced rather than duplicatedServerandDateheaders were set twice when proxyingWebSocket:
RFC6455Handshakerand the WebSocket parserHTTP:
ForwardedRequestCustomizerno longer falls back to the connection port when the forwarded host carries no port; it uses the protocol default insteadsetHeader("Content-Length", N)is now treated likesetContentLengthLong(N), which removes an extra empty HTTP/2DATAframe and a second flushIncludeExcludeis now consistently case-insensitive (relevant to theCompressionHandlermime-type matching behindGzipHandlerUtil)etc/jetty-http-config.xml, so it does not affect Pulsar's embedded JettyModifications
Bump
jettyfrom 12.1.11 to 12.1.12 ingradle/libs.versions.tomlUpdate the Jetty artifact versions in
distribution/server/src/assemble/LICENSE.bin.txtanddistribution/shell/src/assemble/LICENSE.bin.txtUpdate the OW2 ASM entries in
distribution/server/src/assemble/LICENSE.bin.txtfrom 9.10 to 9.10.1: Jetty 12.1.12'sjetty-annotations/jetty-ee10-annotationsbring in the newer ASM transitively. Verified with./gradlew :distribution:pulsar-server-distribution:dependencyInsight --configuration distLib --dependency org.ow2.asm:asm.Initialize the
AdminProxyHandlerservlet inFunctionWorkerRoutingTest. The test calledrewriteTarget()on a handler that was never initialized as a servlet. That worked until 12.1.12, where mime-type filtering by IncludeExclude should always be case-insensitive jetty/jetty.project#15496's companion change rewroteAbstractProxyServlet.validateDestination()to filter hosts through a singleIncludeExclude; it now always dereferences the logger assigned byinit(), whereas before it only did so when a whitelist/blacklist entry matched. The test consequently failed with an NPE on_log.This is a test-only gap, not a production regression:
ProxyServiceStarterregisters the handler through aServletHolder, so the container callsinit()and the logger is set. The test now initializes the servlet the same way and destroys it afterwards, which keeps the realvalidateDestination()path covered rather than working around it.Verifying this change
This change is already covered by existing tests. Besides the full CI run, the following Jetty-facing tests were run locally against 12.1.12 and pass:
pulsar-proxy: the full module test suite (164 tests)pulsar-broker:org.apache.pulsar.broker.web.*(includingWebServiceTestandWebServiceOriginalClientIPTest, which covers theForwardedRequestCustomizerpath)pulsar-websocket: the full module test suiteGzipHandlerUtilTestandPulsarAdminGzipTest./gradlew checkBinaryLicenseand./gradlew sanityCheckalso pass.Does this pull request potentially affect one of the following parts:
If the box was checked, please highlight the changes