Skip to content

chore(deps): upgrade grpc, jackson, logback, commons and drop joda-time - #6950

Open
halibobo1205 wants to merge 5 commits into
tronprotocol:developfrom
halibobo1205:feature/upgrade_dependencies
Open

chore(deps): upgrade grpc, jackson, logback, commons and drop joda-time#6950
halibobo1205 wants to merge 5 commits into
tronprotocol:developfrom
halibobo1205:feature/upgrade_dependencies

Conversation

@halibobo1205

@halibobo1205 halibobo1205 commented Sep 4, 2026

Copy link
Copy Markdown
Collaborator

What does this PR do?

Upgrade dependencies and remove obsolete dependencies and compatibility code:

Dependency From To
io.grpc:grpc-* 1.83.0 1.83.1
com.fasterxml.jackson.core:jackson-databind 2.18.6 2.18.10
ch.qos.logback:logback-classic 1.2.13 1.3.16
org.slf4j:slf4j-api / jcl-over-slf4j / jul-to-slf4j 1.7.36 2.0.17
org.apache.commons:commons-lang3 3.4 3.20.0
org.apache.commons:commons-collections4 4.1 4.6.0
org.apache.commons:commons-math 2.2 Removed
joda-time:joda-time 2.3 Removed

Along with these changes:

  • Remove the temporary gRPC stream-limit shim and restore the directNettyServerBuilder.maxConcurrentCallsPerConnection(...) call.
  • Replace Joda-Time with java.time, introducing Time.getIsoTimeString for log formatting and migrating date arithmetic in tests.
  • Update the bundled Toolkit Logback configuration.

Why are these changes required?

gRPC 1.83.1 enforces the concurrent-stream limit at handler startup, before the client acknowledges SETTINGS. This covers the behavior previously supplied by the local shim. See the gRPC 1.83.1 release notes.

Logback 1.3.16 preserves the x86_64 build's JDK 8 requirement while incorporating fixes absent from 1.2.13, including the CVE-2025-11226 backport and removal of JaninoEventEvaluator. Logback 1.3 uses the SLF4J 2.0 provider model, so SLF4J is upgraded alongside it. See Logback's maintenance status and runtime requirements, the 1.3.16 release notes, and the 1.3.15 security backports.

commons-math has no direct source references, and the existing Joda-Time usages can be replaced with JDK APIs.

This PR has been tested by:

  • 56 targeted tests passed .
  • CI green.

Compatibility notes and migration requirements

The bundled default logging configurations have been verified. Users supplying a custom --log-config should review the following changes and migrate affected configurations before upgrading.

  1. Include paths that depend only on XML-defined properties require migration.

    In the example below, when includedir is defined only in the XML and no system property, environment variable, or fallback value supplies it, Logback 1.3.16 fails to resolve the include path:

    <property name="includedir" value="/etc/tron/logging"/>
    <include file="${includedir}/appenders.xml"/>

    Under these conditions, the path resolves to includedir_IS_UNDEFINED/appenders.xml, relative to the process working directory. Logback 1.2.13 resolves the same configuration correctly. In 1.3.16, doConfigure returns without throwing, so this failure does not raise TronError(LOG_LOAD). If the failed include supplies all of the application's logging destinations, application logs are discarded. Independently configured destinations can remain operational.

    The failure is reported to the console: LogService calls StatusPrinter.printInCaseOfErrorsOrWarnings, which prints WARN in ch.qos.logback.core.joran.action.IncludeAction - Failed to open [.../includedir_IS_UNDEFINED/appenders.xml] to the console at startup.

    Verified workarounds are to use a literal absolute include path, or to supply the property through a JVM argument such as -Dincludedir=/etc/tron/logging. Upstream documented a fix in 1.5.5; the 1.3.16 artifact used here still exhibits this behavior. See the Logback 1.5.5 release notes.

  2. Janino-based expression evaluators must be migrated.

    The removal of JaninoEventEvaluator was backported in Logback 1.3.15 to address CVE-2024-12798, so it applies to this upgrade to 1.3.16. See the Logback 1.3.15 release notes. An EvaluatorFilter using the implicit evaluator syntax <evaluator><expression>…</expression></evaluator> behaves differently depending on whether Janino is present on the classpath:

    • Without Janino on the classpath, the tested expression configuration throws NoClassDefFoundError: org/codehaus/janino/ScriptEvaluator on 1.2.13. This Error bypasses LogService's catch (Exception) and aborts startup. On 1.3.16, configuration processing instead returns normally with the filter inactive. The project does not declare Janino as a dependency.
    • On a deployment that adds Janino itself, the filter worked on 1.2.13 and is now inert on 1.3.16, so messages the filter previously denied will be logged. Such deployments must migrate the filtering logic to an explicit EventEvaluator implementation.

    The bundled default configuration does not use this feature. See the evaluator migration instructions.

  3. JMX-based logging management is no longer available.

    The entire ch.qos.logback.classic.jmx package was removed in 1.3.x, so <jmxConfigurator/> is now reported as an unknown property and ignored, where 1.2.13 loaded it silently.

  4. The legacy shutdown hook name still works, with a warning.

    DelayingShutdownHook was renamed to DefaultShutdownHook. Logback 1.3.16 still accepts the old name through a compatibility mapping and warns before instantiating the new class, so existing operator configurations keep working. This PR does not rely on that mapping: the bundled Toolkit configuration has been migrated to DefaultShutdownHook.

  5. Log files may exceed the configured size threshold.

    SizeAndTimeBasedRollingPolicy checks file size less frequently. Under sustained heavy logging, individual files may temporarily exceed maxFileSize. Time-based rollover and maxHistory / totalSizeCap cleanup are unaffected.

  6. Invalid appender classes may affect other logging destinations.

    A custom configuration referencing a missing or uninstantiable appender class produces console errors and may also prevent other appender references from being attached.

  7. Reflections scan diagnostics are no longer emitted.

    SLF4J 2.x removes org.slf4j.impl.StaticLoggerBinder, which Reflections 0.9.11 probes to determine whether logging is available. Its own diagnostic logging is therefore disabled. Scanning remains functional, all of its logging sites are null-guarded, and actuator registration failures still surface through TronError(ACTUATOR_REGISTER).

Timestamp formatting

Ordinary UTC timestamp output has been verified against the previous implementation. Non-UTC output may use different offsets because the JDK and the older Joda-Time release contain different time-zone databases, while still representing the same instant.

1. bump grpcVersion to 1.83.1 to pick up the upstream fix for
   grpc/grpc-java#12930 (PR grpc/grpc-java#12942), which enforces
   connection.remote().maxActiveStreams(maxStreams) at handler startup
2. drop GrpcNettyMaxConcurrentStreamsLimiter, the local protocol-negotiator
   shim that applied the same limit while 1.83.0 left the remote endpoint
   unbounded until the client acknowledged SETTINGS
bump jackson-databind from 2.18.6 to 2.18.10 to pick up cumulative fixes from the 2.18.x line
1. bump logback-classic from 1.2.13 to 1.3.16 and slf4j-api,
   jcl-over-slf4j, jul-to-slf4j from 1.7.36 to 2.0.17; logback 1.3
   requires the slf4j 2.0 provider model, and 1.3.16 is the last 1.3.x
   release and the ceiling for the x86_64 JDK 8 build, since 1.5.x
   requires JDK 11
2. rename DelayingShutdownHook to DefaultShutdownHook in the toolkit
   logback.xml; logback 1.3 removed the old class and only auto-maps
   the legacy name with a startup warning
3. drop the CONSOLE appender from the toolkit logback.xml; no logger
   ever referenced it, so it never emitted output on 1.2 either, and
   logback 1.3 now flags it with an unreferenced-appender warning
4. accept one known 1.3.x behavior change: SizeAndTimeBasedRollingPolicy
   now throttles its maxFileSize comparison to once per 60s
   (SimpleInvocationGate) instead of the adaptive ~100-800ms gate of
   1.2.13, so under sustained heavy logging a file can overshoot the
   500MB cap by up to 60s of writes before the %i rollover fires;
   time-based rollover and totalSizeCap/maxHistory cleanup are ungated
   and unaffected
5. note for operators running a custom --log-config file: well-formed
   1.2-era configs using standard elements keep working unchanged
   (jmxConfigurator degrades to an ignored-property warning, the legacy
   shutdown hook name is auto-mapped), and malformed XML still fails
   fast via TronError(LOG_LOAD) exactly as on 1.2; however, a config
   that references an uninstantiable class (e.g. a custom appender
   missing from the classpath) now aborts the whole appender-ref phase
   instead of losing just that one appender, so the node starts with no
   log output while the ERROR statuses are printed to stdout by
   LogService
1. bump commons-lang3 from 3.4 to 3.20.0; the runtime classpath already
   resolved 3.18.0 through libp2p 2.2.9's transitive requirement, so
   align the declaration with what actually ships and move past the
   CVE-2025-48924 range that the nominal 3.4 still sits in
2. bump commons-collections4 from 4.1 to 4.6.0
3. remove commons-math 2.2; no source file imports
   org.apache.commons.math and nothing else in the dependency graph
   requests it
1. drop the joda-time 2.3 dependency.
2. replace the six new DateTime(millis) log-formatting call sites in
   DynamicPropertiesStore, DposTask and DposService with a new
   Time.getIsoTimeString helper backed by java.time; its formatter
   (yyyy-MM-dd'T'HH:mm:ss.SSSXXX in the system zone) reproduces joda's
   DateTime.toString() output byte for byte where the JDK and joda 2.3
   time-zone databases agree (UTC nodes are unaffected); zones whose
   rules changed after joda's 2013-era tzdb, e.g. Europe/Moscow, now
   render the corrected offset for the same instant.
3. replace DateTime.now() day arithmetic in four test classes with the
   java.time equivalent, ZonedDateTime.now().minusDays(n)/plusDays(n)
   .toInstant().toEpochMilli(), keeping joda's calendar semantics
   one-to-one, and map plain DateTime.now().getMillis() to
   System.currentTimeMillis()
@halibobo1205 halibobo1205 added this to the GreatVoyage-v4.8.3 milestone Sep 4, 2026
@halibobo1205 halibobo1205 added the topic:dependency dependency upgrade label Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

topic:dependency dependency upgrade

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant