Skip to content

[fix][admin] Restore Pulsar 4.x compatible serialVersionUID for PackageMetadata - #26784

Merged
merlimat merged 1 commit into
apache:masterfrom
lhotari:lh-fix-packagemetadata-suid
Sep 30, 2026
Merged

merlimat merged 1 commit into
apache:masterfrom
lhotari:lh-fix-packagemetadata-suid

Conversation

@lhotari

@lhotari lhotari commented Sep 30, 2026

Copy link
Copy Markdown
Member

Motivation

In Pulsar 4.x, PackagesManagementImpl (org.apache.pulsar.packages.management.core.impl.PackagesManagementImpl) stores package metadata using Java serialization of PackageMetadata. #25570 switched the default format to JSON, but the legacy Java serialization format must still be deserializable so that package metadata written by Pulsar 4.x remains readable after an upgrade.

#25414 added serialVersionUID = 1L to PackageMetadata, which had no explicit serialVersionUID in Pulsar 4.x. Reading package metadata stored by Pulsar 4.x then fails after upgrading:

local class incompatible: stream classdesc serialVersionUID = -3557006947394568058, local class serialVersionUID = 1

Modifications

  • Set PackageMetadata.serialVersionUID to -3557006947394568058L, the default serialVersionUID computed with ObjectStreamClass.lookup from the Pulsar 4.0.13 and 4.2.4 release jars (both give the same value). The class structure hasn't changed since then. A comment explains that the value must not be changed.
  • Do the same for the Serializable data class NamespaceBundleStats (7307982611138203289L, same in 4.0.13 and 4.2.4), which [improve][build] Fix compile warnings in production code #25414 also changed to 1L.
  • The other serialVersionUID additions in [improve][build] Fix compile warnings in production code #25414 are left as they are: they are on exception classes and runtime objects, which aren't stored as serialized data.

Verifying this change

  • Make sure that the change passes the CI checks.

This change added tests and can be verified as follows:

  • Added PackageMetadataSerdeTest.testLegacyBytesWrittenByPulsar42AreReadable, which deserializes a PackageMetadata payload written by the Pulsar 4.2.4 release. It fails with the "local class incompatible" error above when serialVersionUID is 1L, and passes with this change.

Does this pull request potentially affect one of the following parts:

If the box was checked, please highlight the changes

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

…geMetadata

In Pulsar 4.x, PackagesManagementImpl
(org.apache.pulsar.packages.management.core.impl.PackagesManagementImpl)
stores package metadata using Java serialization of PackageMetadata. apache#25570
switches the default format to JSON, but the legacy Java serialization format
must still be deserializable so that package metadata written by Pulsar 4.x
remains readable after an upgrade.

apache#25414 added serialVersionUID = 1L to PackageMetadata, which had no explicit
value in Pulsar 4.x. Package metadata stored by Pulsar 4.x then fails to
deserialize after upgrading with "local class incompatible". Use the default
serialVersionUID computed from the Pulsar 4.0.13 and 4.2.4 release jars
instead, and do the same for the Serializable NamespaceBundleStats data class.

Assisted-by: Claude Code (claude-opus-5-5)
@lhotari lhotari added this to the 5.0.0 milestone Sep 30, 2026
@merlimat
merlimat merged commit 6e26b3d into apache:master Sep 30, 2026
44 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants