Skip to content

[fix][build] Upgrade Conscrypt to 2.6.3 - #26660

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:lh-fix-upgrade-conscrypt-2.6.3
Sep 20, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:lh-fix-upgrade-conscrypt-2.6.3

Conversation

@lhotari

@lhotari lhotari commented Sep 19, 2026

Copy link
Copy Markdown
Member

Motivation

Conscrypt 2.6.2 was built with a BoringSSL revision that removed X25519Kyber768Draft00 while Conscrypt still configured that group, causing TLS handshakes to fail with Error parsing groups (upstream issue #1530).

The 2.6.3 release notes state that it uses the same Conscrypt source as 2.6.2, rebuilt with BoringSSL 0.20260616.0 to address that regression.

Related: #26659. This upgrade has not been confirmed to resolve the native finalizer crash reported there.

Modifications

  • Upgrade conscrypt-openjdk-uber from 2.6.2 to 2.6.3 in the shared version catalog.
  • Update the server and shell distribution license inventories to match the bundled JAR version.

Verifying this change

  • ./gradlew help quickCheck checkBinaryLicense --configuration-cache
  • ./gradlew assemble --configuration-cache
  • ./gradlew :pulsar-broker:assemble :pulsar-broker:test --tests org.apache.pulsar.broker.admin.AdminApiTlsAuthTest -PtestRetryCount=0 --configuration-cache — 20 tests passed, no skips or retries.

Validated locally on macOS with Corretto 25. These checks do not establish that the Linux CI crash in #26659 is resolved.

  • Make sure that the change passes the CI checks.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

@nodece
nodece merged commit 911b475 into apache:master Sep 20, 2026
43 checks passed
lhotari added a commit that referenced this pull request Sep 23, 2026
lhotari added a commit that referenced this pull request Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants