Skip to content

libxml2 package under contrib directory is upgraded to 2.9.13#35034

Merged
KochetovNicolai merged 2 commits intoClickHouse:masterfrom
ClibMouse:libxml_upgrade
Mar 24, 2022
Merged

libxml2 package under contrib directory is upgraded to 2.9.13#35034
KochetovNicolai merged 2 commits intoClickHouse:masterfrom
ClibMouse:libxml_upgrade

Conversation

@varadarajkumar
Copy link
Copy Markdown
Contributor

@varadarajkumar varadarajkumar commented Mar 4, 2022

Changelog category (leave one):

  • Not for changelog (changelog entry is not required)

Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):
to fix vulnerabilities reported by white source.

CVE-2017-9049
CVE-2020-24977
CVE-2018-9251
CVE-2021-3537
CVE-2019-19956
CVE-2018-14567
CVE-2018-9466
CVE-2018-9466
CVE-2020-3846
CVE-2021-3541
CVE-2018-14404
CVE-2018-9466
CVE-2021-3518
CVE-2022-23308
CVE-2018-9466
CVE-2019-20388
CVE-2021-3516
CVE-2018-9466
CVE-2021-3517
CVE-2018-9466

Information about CI checks: https://clickhouse.tech/docs/en/development/continuous-integration/

@robot-clickhouse robot-clickhouse added the pr-not-for-changelog This PR should not be mentioned in the changelog label Mar 4, 2022
@varadarajkumar varadarajkumar changed the title libxml2 package is upgraded to 2.9.13 libxml2 package under contrib directory is upgraded to 2.9.13 Mar 4, 2022
@alexey-milovidov alexey-milovidov added the can be tested Allows running workflows for external contributors label Mar 5, 2022
@alexey-milovidov alexey-milovidov self-assigned this Mar 5, 2022
@varadarajkumar
Copy link
Copy Markdown
Contributor Author

varadarajkumar commented Mar 8, 2022

@alexey-milovidov, Is it normal that two stress test cases are failing due to broken pipe error. and these are not related the current changes pushed.

@alexey-milovidov
Copy link
Copy Markdown
Member

alexey-milovidov commented Mar 14, 2022

No, it is not normal. Even if they are unrelated they require investigation and fixing.
And this has hundred times higher priority than upgrading libxml2.

@alexey-milovidov
Copy link
Copy Markdown
Member

@KochetovNicolai The issue introduced here: #34219

@varadarajkumar
Copy link
Copy Markdown
Contributor Author

varadarajkumar commented Mar 18, 2022

@KochetovNicolai with the PR (#35305) still few checks are failing. Will it be better to check which version is failing from 2.9.8 to 2.9.13 incremental fashion

@alexey-milovidov
Copy link
Copy Markdown
Member

@Mergifyio update

@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Mar 18, 2022

update

❌ Pull request can't be updated with latest base branch changes

Details

Mergify needs the author permission to update the base branch of the pull request.
DevTeamBK needs to authorize modification on its head branch.
err-code: 37B9F

@alexey-milovidov
Copy link
Copy Markdown
Member

@Mergifyio update

@alexey-milovidov
Copy link
Copy Markdown
Member

Yes, with the presence of this error, merging is impossible.
Let's check if it was fixed in master...

@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Mar 20, 2022

update

❌ Pull request can't be updated with latest base branch changes

Details

Mergify needs the author permission to update the base branch of the pull request.
DevTeamBK needs to authorize modification on its head branch.
err-code: FE994

@alexey-milovidov
Copy link
Copy Markdown
Member

@varadarajkumar Please update this PR to master.

@alexey-milovidov alexey-milovidov marked this pull request as draft March 21, 2022 02:37
@varadarajkumar
Copy link
Copy Markdown
Contributor Author

@alexey-milovidov, Can you suggest what to do next ?

@alexey-milovidov
Copy link
Copy Markdown
Member

alexey-milovidov commented Mar 24, 2022

We need to wait while master will become green, then refresh this PR and then merge.
This PR has very low importance for us (almost zero), because we only use libxml2 to parse configs.

It is still good to merge, because it makes sense to intregrate Whitesource to our CI.

@alexey-milovidov
Copy link
Copy Markdown
Member

No action needed from your side.

@alexey-milovidov alexey-milovidov marked this pull request as ready for review March 24, 2022 14:41
@KochetovNicolai
Copy link
Copy Markdown
Member

Backward compatibility check, Stateless tests (thread, actions) were flacky.

Stateless tests (memory, actions) looks like a real race, but it does not look related to the PR.

@KochetovNicolai KochetovNicolai merged commit 9282f3f into ClickHouse:master Mar 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

can be tested Allows running workflows for external contributors pr-not-for-changelog This PR should not be mentioned in the changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants