diff --git a/ORIGIN.md b/ORIGIN.md index 2f3bea3f2d72..f89c800d4aca 100644 --- a/ORIGIN.md +++ b/ORIGIN.md @@ -6,7 +6,7 @@ This repository is derived from the public [Hazelcast repository](https://github - Upstream boundary commit: `60c31e3750cbad64f5720e2e02f0a9830973193c` - PastureStack maintenance line: linear commits after that upstream boundary - Historical maintained artifact: PastureStack Maven artifact 5.7.3-pasturestack.4 (numeric Hazelcast cluster runtime 5.7.3), based on Hazelcast 5.7.0, with reviewed source and dependency security updates -- Current candidate artifact: pure numeric Maven artifact `5.7.5`, not yet built or published; product identity and provenance remain in package metadata and release evidence. Public `v5.7.4` remains immutable historical evidence. +- Current published artifact: pure numeric Maven artifact `5.7.5`, from signed tag `v5.7.5` and source `a9aea563870201462dc24f778a06279a08ed5841`; JAR SHA-256 `0f536a9c7bcd00f2369586fb6ca1606f7e45f3225e24795d10d38397051c8715`. Product identity and provenance remain in package metadata and release evidence. Public `v5.7.4` remains immutable historical evidence. The upstream Git history, copyright notices, author records, `LICENSE`, `NOTICE`, and file-level license headers are retained. PastureStack's maintenance commits do not replace or relicense upstream work, and PastureStack does not claim authorship of upstream contributions. diff --git a/README.md b/README.md index 323e4f73f4bc..eb8736395ce0 100755 --- a/README.md +++ b/README.md @@ -5,11 +5,14 @@ Earlier public Maven artifacts remain immutable historical evidence. The current public GitHub Release is -[`v5.7.4`](https://github.com/PastureStack/distributed-cache-runtime/releases/tag/v5.7.4). -This source prepares candidate -artifact `5.7.5`; it has not yet been built, scanned, or published. See -[5.7.5 candidate notes](RELEASE-NOTES-5.7.5.md) for the Jackson-only update and -pending artifact verification. Every current and future PastureStack publication +[`v5.7.5`](https://github.com/PastureStack/distributed-cache-runtime/releases/tag/v5.7.5). +It publishes the exact reviewed `hazelcast-5.7.5.jar` from source +`a9aea563870201462dc24f778a06279a08ed5841`, with SHA-256 +`0f536a9c7bcd00f2369586fb6ca1606f7e45f3225e24795d10d38397051c8715`. +See [5.7.5 release notes](RELEASE-NOTES-5.7.5.md) for its focused tests, +embedded Jackson versions and verification boundaries. The Engine consumes +this GitHub release asset; no new OCI/GHCR carrier is published by this release. +Every current and future PastureStack publication uses a pure numeric version, while product identity and provenance remain in metadata rather than the version. Generated Hazelcast cluster metadata reports numeric runtime version `5.7.3`, diff --git a/RELEASE-NOTES-5.7.5.md b/RELEASE-NOTES-5.7.5.md index 7262e91a66e2..c022598da588 100644 --- a/RELEASE-NOTES-5.7.5.md +++ b/RELEASE-NOTES-5.7.5.md @@ -1,7 +1,11 @@ -# 5.7.5 candidate: Jackson security patch +# 5.7.5: Jackson security patch -Status: source candidate only; not yet built, scanned, published, or validated -in a downstream runtime. Public `v5.7.4` remains unchanged historical evidence. +Published GitHub release: [`v5.7.5`](https://github.com/PastureStack/distributed-cache-runtime/releases/tag/v5.7.5). +Signed tag source: `a9aea563870201462dc24f778a06279a08ed5841`. +`hazelcast-5.7.5.jar` is 23,852,246 bytes with SHA-256 +`0f536a9c7bcd00f2369586fb6ca1606f7e45f3225e24795d10d38397051c8715`. +The actual published download and source-revision attachment match the +reviewed CI artifact. Public `v5.7.4` remains unchanged historical evidence. - Update the actual parent properties and imported BOMs from Jackson 2.22.2 to 2.22.3 and from Jackson 3.2.2 to 3.2.3. FasterXML lists fixes for @@ -15,7 +19,27 @@ in a downstream runtime. Public `v5.7.4` remains unchanged historical evidence. - Preserve numeric Hazelcast cluster runtime `5.7.3`, business logic, and all other dependency pins from the candidate's `origin/main` base. -The existing release gate must still build the shaded JAR, run its focused -regression suites, verify resolved Maven/SBOM and packaged metadata, and scan -the actual artifact with current vulnerability data. Source-only checks do not -prove that CVEs are absent from a built artifact or any downstream Engine JAR. +## Actual verification + +[Security gate run `36815272664`](https://github.com/PastureStack/distributed-cache-runtime/actions/runs/36815272664) +passed 510 tests across all 40 named suites, with zero failures, errors or +skipped tests. The exact retained shaded JAR was published without a +release-time rebuild. Its four embedded Jackson core/databind metadata entries +report `2.22.3` / `3.2.3`; generated cluster runtime remains `5.7.3`, and its +full source commit and abbreviated revision match the signed release source. + +The 38-project effective POM has no unresolved dependency/plugin versions. +The CycloneDX 1.6 runtime SBOM has 15 components / 16 dependency nodes and +matches all 15 Maven runtime coordinates. The original source, JAR and SBOM +Trivy 0.74.0 scans report zero Critical/High findings within their scanned +boundaries; the source secret scan reports zero findings. +[CodeQL run `36815270196`](https://github.com/PastureStack/distributed-cache-runtime/actions/runs/36815270196) +completed all four required analyses. Their exact PR-head SARIF results have +zero security-severity >=7 findings and zero unresolved result-rule metadata. + +All 19 original CI files are attached byte-for-byte. To check the original +hash manifests, place the JAR under `dist/` and the evidence files under +`evidence/`; their recorded relative paths are intentionally unchanged. +The current downstream installer consumes the GitHub asset directly. No new +OCI/GHCR carrier is published, and no downstream Engine startup, Server image, +Passkey login or complete resource/role QA is inferred from these results. diff --git a/SECURITY-MAINTENANCE.md b/SECURITY-MAINTENANCE.md index b511dd5fa0f9..0a5a7a212698 100644 --- a/SECURITY-MAINTENANCE.md +++ b/SECURITY-MAINTENANCE.md @@ -4,7 +4,7 @@ The PastureStack maintenance delta intentionally preserves the Hazelcast 5.7.0 API while updating reviewed runtime and build-time dependencies with published security fixes: -The current source prepares Maven artifact candidate `5.7.5`; it is based on upstream `5.7.0`, not an upstream Hazelcast release, and is not yet built, scanned, or published. Public `v5.7.4` remains immutable historical evidence. Hazelcast's cluster protocol parser accepts numeric product versions only, so generated runtime metadata deliberately reports `5.7.3`. The artifact version must be used by Maven coordinates, filenames, the artifact carrier, SBOM, and release evidence; the numeric runtime version must be used by cluster/member compatibility code. See [5.7.5 candidate notes](RELEASE-NOTES-5.7.5.md) for the narrow Jackson update and pending verification. +The current published Maven artifact is `5.7.5`, from signed tag `v5.7.5` and source `a9aea563870201462dc24f778a06279a08ed5841`; it is based on upstream `5.7.0`, not an upstream Hazelcast release. Public `v5.7.4` remains immutable historical evidence. Hazelcast's cluster protocol parser accepts numeric product versions only, so generated runtime metadata deliberately reports `5.7.3`. The artifact version must be used by Maven coordinates, filenames, any artifact carrier, SBOM, and release evidence; the numeric runtime version must be used by cluster/member compatibility code. See [5.7.5 release notes](RELEASE-NOTES-5.7.5.md) for the narrow Jackson update, exact artifact and validation boundaries. | Component | Upstream 5.7.0 | PastureStack maintained version | Scope | | --- | --- | --- | --- | @@ -67,8 +67,9 @@ Jetty 9 was eliminated instead of forcing an unrelated Jetty 12 server migration ## Validation Boundaries The observations below describe the prior reviewed maintenance tree. They are -not validation evidence for the unbuilt `5.7.5` candidate or a current zero-CVE -claim; candidate artifacts must pass the required release gates again. +not a current zero-CVE claim or proof that those broader integration suites +were rerun for `5.7.5`. Its exact focused CI and artifact-scoped scan results +are recorded separately in the release notes. - Temurin 25 LTS compiles the 5,863-source core module. The focused SQL, Hadoop, Avro, Protobuf, gRPC, Kafka Connect, Python, and command-line compatibility checks pass. JLine 4 selects the FFM terminal provider under WSL. The Python runtime suite passes 6/6 with Protobuf 7.36.0 and gRPC Python 1.83.0. - Kafka 4.3.1 passes real-container read/projection and write-to-topic checks against Confluent Platform 8.3.1. Spring Boot 4.1.1 with Spring Framework 7.0.9 passes all 15 module tests. The shaded tests JAR excludes dependency-owned `junit-platform.properties`, preventing a Netty test setting from silently forcing downstream suites into unsafe parallel execution. @@ -93,7 +94,7 @@ The maintained source closes the following boundaries identified by full-source - Filesystem paths originating in configuration, administrative commands, or upload metadata now pass through one physical-path boundary. Traversal segments, whitespace aliases, symbolic links, non-regular input files, unsafe child names, and unsafe output parents are rejected before any read, write, class loading, diagnostics, compatibility sampling, or job-upload operation. Legitimate existing files, directories, child JARs, and multipart uploads retain their existing behavior. - JDBC connection lifecycle handling now uses a transparent proxy with an idempotent release callback instead of a handwritten forwarding class. This removes an unrelated query sink while retaining parameterized-query behavior, standard connection semantics, and exactly-once close handling. -The standalone release gates `scripts/check-xml-parser-hardening` and `scripts/check-numeric-conversion-hardening` compile the affected production classes and exercise legitimate and malicious cases without requiring a running cache service. The canonical focused Maven suite additionally covers configuration URL, filesystem paths, uploads, JDBC URL and lifecycle behavior, phone-home, ECS metadata, multicast, serialization, XML, regular-expression complexity, and numeric bounds. The isolated class-loader integration test connects to the exact member address and cluster name it creates instead of relying on environment-dependent discovery. Potentially long-running groups have independent hard timeouts, so one failed setup cannot conceal or block later suites. The GitHub release gate requires all 38 named suites to produce a Surefire report, requires at least the verified 385-test baseline, and rejects any failure, error, skipped test, missing suite, or reduced test set. Its CodeQL evidence parser resolves rule metadata from both SARIF driver and extension components, rejects unresolved metadata, and blocks every result with a security score of 7.0 or higher. +The standalone release gates `scripts/check-xml-parser-hardening` and `scripts/check-numeric-conversion-hardening` compile the affected production classes and exercise legitimate and malicious cases without requiring a running cache service. The canonical focused Maven suite additionally covers configuration URL, filesystem paths, uploads, JDBC URL and lifecycle behavior, phone-home, ECS metadata, multicast, serialization, XML, regular-expression complexity, and numeric bounds. The isolated class-loader integration test connects to the exact member address and cluster name it creates instead of relying on environment-dependent discovery. Potentially long-running groups have independent hard timeouts, so one failed setup cannot conceal or block later suites. The GitHub release gate requires all 40 named suites, including the two direct JSON utility suites, to produce a Surefire report, requires at least the verified 385-test baseline, and rejects any failure, error, skipped test, missing suite, or reduced test set. Its CodeQL evidence parser resolves rule metadata from both SARIF driver and extension components, rejects unresolved metadata, and blocks every result with a security score of 7.0 or higher. The reviewed core JAR build invokes Maven and the pinned JDK; it does not compile the repository's C source companions or package the optional Python extension. The gate records hashes for the tracked C headers, C sources, and prebuilt native resources, then requires the native bytes embedded in the JAR to match the tracked resources exactly. It also rejects Python extension resources in the core JAR. Python 3.14.7 is pinned only for evidence validation in CI. A C compiler therefore is not a hidden input to this artifact build, and the verifier Python is not a deployed runtime component. @@ -114,6 +115,6 @@ A release is acceptable only when all of the following are true: 9. Maven Help Plugin `3.5.2` generates the complete active-reactor effective POM, and the gate rejects any active direct dependency, managed dependency, build plugin, or managed plugin without a resolved version. CycloneDX Maven Plugin `2.9.3` then generates a CycloneDX `1.6` SBOM for the actual `hazelcast` runtime module from its resolved compile/runtime dependency graph. The gate compares every required SBOM coordinate with an independently generated Maven Dependency Plugin `3.11.0` runtime tree for the same module, independently validates the SBOM with CycloneDX CLI `0.33.1`, requires unique component identities and a populated dependency graph rooted at the reviewed runtime component, and submits that complete SBOM to Trivy for a separate zero-Critical/High dependency scan. All three Maven evidence-plugin JARs and POMs are fetched from Maven Central and checked against committed SHA-256 values before and after use. The source revision, every Maven input hash, the effective POM, the runtime tree, the CycloneDX SBOM, and their validation summaries are retained together. This intentionally excludes reactor test-support modules from the deployed SBOM and replaces filesystem-only JAR inventory, which cannot reconstruct dependencies relocated into a shaded artifact. 10. The JAR contains the upstream `LICENSE` and `NOTICE` material. 11. GitHub CodeQL reports zero current-source Critical and High findings for the release commit. Historical alerts against removed workflow snapshots are documented separately and do not replace this current-source gate. -12. The GHCR artifact package is public and can be fetched anonymously by manifest digest and layer digest. +12. The published GitHub release JAR is read back over HTTPS and matches the reviewed bytes, embedded source revision and metadata. The Engine pins its release tag, asset ID and SHA-256; download gateways must not change those identities. Any separately published OCI carrier must additionally be public and read back by manifest and layer digest. `v5.7.5` publishes the GitHub assets only, not a new carrier. -The runtime image is an artifact carrier for deterministic downstream builds; it is not a standalone Hazelcast server image. +The optional runtime image is an artifact carrier for deterministic downstream builds; it is not a standalone Hazelcast server image. The current Engine installer consumes the GitHub JAR directly and does not require that optional image.