[fix](fe) Upgrade gRPC and remove unused LZ4 dependencies (#67585)

### What problem does this PR solve?

Related PR: #67065

Problem Summary:

Upgrade the managed gRPC BOM from 1.65.1 to 1.75.0, matching #67065 and
replacing the `grpc-netty-shaded` version affected by CVE-2025-55163.

Exclude `org.lz4:lz4-pure-java` centrally from the managed
`odps-sdk-core` and `odps-sdk-table-api` dependencies. Neither
MaxCompute connector needs a replacement Java LZ4 dependency: the FE
uses the ODPS metadata/session APIs, and the BE uses Table API Arrow
readers/writers with ZSTD. The legacy SDK Tunnel LZ4 implementations are
outside the active Doris data path. The BE connector retains its local
Jackson exclusions.

Limit `flight-sql-jdbc-driver` to test scope. Only the FE test client
loads the JDBC driver; production code uses the retained `FlightServer`
and `FlightSqlClient` protocol libraries. The regression framework keeps
its independent JDBC driver dependency.

Add a ZSTD round-trip test through the ODPS Arrow writer/reader
factories, with the Java 17 direct-buffer access options required by the
test JVM. This verifies 1,024 rows including a null after removing LZ4,
alongside the existing isolated ODPS class-loading test.

### Release note

Upgrade gRPC to 1.75.0. Stop bundling the unused Java LZ4 dependency in
MaxCompute connectors and the test-only Flight SQL JDBC driver in the FE
runtime distribution.

### Check List (For Author)

- Test
    - [ ] Regression test
    - [x] Unit Test
    - [x] Manual test (details below)

  Validation of the final implementation in `d9613e32c86`:
- `EXTRA_FE_MODULES=maxcompute=be-java-extensions/max-compute-connector
./run-fe-ut.sh --run
'org.apache.doris.connector.maxcompute.*Test,org.apache.doris.maxcompute.*Test,!org.apache.doris.connector.maxcompute.OdpsLiveConnectivityTest'`:
146 FE and 14 BE connector tests passed, including ODPS class-loader
isolation and the new ZSTD round trip. The successful test runtime
classpaths were checked and contain no `net.jpountz.lz4` classes.
- `build.sh --fe` passed with `DISABLE_BE_JAVA_EXTENSIONS=OFF`,
`FE_MAVEN_THREADS=4`, `MVN_OPT=-Dmaven.build.cache.enabled=false`, and
`--be-extension-ignore
iceberg-metadata-scanner,hadoop-hudi-scanner,java-common,java-udf,jdbc-scanner,paimon-scanner,trino-connector-scanner,preload-extensions,hadoop-deps,java-writer`.
All 64 reactor modules passed, including Checkstyle, FE compilation and
FE/BE MaxCompute packaging. Maven wall time: 2m 31s.
- Both connector dependency trees contain no Java LZ4 artifacts. The
rebuilt FE plugin zip and BE connector jar contain no Java LZ4
jars/classes. The incremental output directory retained the previous
build's LZ4 jar; that stale artifact was removed and the runtime plugin
directory was rechecked.
- `output/fe/lib` contains `grpc-netty-shaded-1.75.0.jar`; no Flight SQL
JDBC driver jar is present under `output/fe`.
- `git diff --check` passed. Live MaxCompute connectivity, cluster
startup and regression tests were not run.
4 files changed
tree: c993d207ca6191019aa807e7888593bba4bf881a
  1. .claude/
  2. .github/
  3. .idea/
  4. be/
  5. bin/
  6. build-support/
  7. cloud/
  8. common/
  9. conf/
  10. contrib/
  11. dist/
  12. docker/
  13. docs/
  14. extension/
  15. fe/
  16. fe_plugins/
  17. fs_brokers/
  18. gensrc/
  19. hooks/
  20. pytest/
  21. regression-test/
  22. samples/
  23. task_executor_simulator/
  24. thirdparty/
  25. tools/
  26. ui/
  27. webroot/
  28. .asf.yaml
  29. .clang-format
  30. .clang-format-ignore
  31. .clang-tidy
  32. .clangd
  33. .dockerignore
  34. .editorconfig
  35. .gitattributes
  36. .gitignore
  37. .gitleaks.toml
  38. .gitmodules
  39. .licenserc.yaml
  40. .rat-excludes
  41. .shellcheckrc
  42. AGENTS.md
  43. build-for-release.sh
  44. build-plugin.sh
  45. build.sh
  46. build_profile.sh
  47. CODE_OF_CONDUCT.md
  48. CONTRIBUTING.md
  49. CONTRIBUTING_CN.md
  50. doap_Doris.rdf
  51. env.sh
  52. generated-source.sh
  53. LICENSE.txt
  54. NOTICE.txt
  55. post-build.sh
  56. README.md
  57. reset_submodule.sh
  58. run-be-ut.sh
  59. run-cloud-ut.sh
  60. run-fe-ut.sh
  61. run-fs-env-test.sh
  62. run-regression-test.sh
  63. SECURITY.md
  64. sonar-project.properties
  65. threat-model.md
README.md

🌍 Read this in other language

English • العربية • বাংলা • Deutsch • Español • فارسی • Français • हिन्दी • Bahasa Indonesia • Italiano • 日本語 • 한국어 • Polski • Português • Română • Русский • Slovenščina • ไทย • Türkçe • Українська • Tiếng Việt • 简体中文 • 繁體中文

Apache Doris

License GitHub release Slack EN doc CN doc

Official Website Quick Download


Apache Doris is an open-source, real-time analytics and search database built on MPP architecture. It provides fast SQL analytics, lakehouse query acceleration, and hybrid search across structured, text, and vector data.

Explore the official website for the latest product overview, use cases, ecosystem updates, blogs, and user stories. For version updates, see all release notes.

📈 Use Cases

Use CaseWhat it provides
Customer-Facing AnalyticsShip sub-second interactive analytics to external users.
Data WarehousingBuild one real-time warehouse across business domains.
ObservabilityAnalyze high-throughput logs, events, and metrics with SQL.
Doris for AIUse vector, text, JSON, and structured search in one SQL engine.

🚀 Core Capabilities

Apache Doris is built around three core capabilities. The website is the source of truth for detailed product descriptions and examples.

CapabilityWhat it provides
Real-Time AnalyticsStreaming ingestion, incremental transformation, and sub-second queries under high concurrency.
Lakehouse AnalyticsFast SQL analytics over open table formats such as Iceberg, Delta Lake, and Hudi.
Hybrid SearchSQL-native analytics across JSON, full-text, and vector data for AI and search workloads.

🔌 Ecosystem

Doris sits at the center of the modern data stack. It connects upstream databases, streaming systems, and lakehouse storage with downstream BI, AI, analytics, and observability tools.

For the latest ecosystem coverage, visit the official website and the connection and integration documentation.

👣 Get Started

🧱 Architecture

Apache Doris supports both compute-storage coupled and compute-storage decoupled deployments. In decoupled mode, stateless compute groups run over shared object storage, so you can scale compute on demand and isolate workloads.

Learn more in the deployment guide and deployment mode guide.

📣 Project Updates

ResourceWhat it provides
Community ReportWeekly updates on community activity, merged PRs, contributors, and feature progress.
Roadmap 2026The 2026 planning discussion for AI and hybrid search, query engine, storage, and data lake work.

🧩 Components

Doris provides connectors and tools for common data engineering workflows.

👨‍👩‍👧‍👦 Users

Apache Doris is used in production by thousands of companies worldwide across internet services, finance, retail, logistics, manufacturing, energy, telecommunications, AI, and other industries.

🙌 Contributors

Apache Doris graduated from the Apache Incubator and became an Apache Top-Level Project in June 2022. Thanks to all community contributors who help build Doris.

contrib graph

🌈 Community and Support

💬 Contact Us

🧰 Links

📜 License

Apache License, Version 2.0

Note Some licenses of the third-party dependencies are not compatible with Apache 2.0 License. So you need to disable some Doris features to comply with Apache 2.0 License. For details, refer to the thirdparty/LICENSE.txt