[fix](fe) Upgrade gRPC and remove unused LZ4 dependencies (#67585)
### What problem does this PR solve?
Related PR: #67065
Problem Summary:
Upgrade the managed gRPC BOM from 1.65.1 to 1.75.0, matching #67065 and
replacing the `grpc-netty-shaded` version affected by CVE-2025-55163.
Exclude `org.lz4:lz4-pure-java` centrally from the managed
`odps-sdk-core` and `odps-sdk-table-api` dependencies. Neither
MaxCompute connector needs a replacement Java LZ4 dependency: the FE
uses the ODPS metadata/session APIs, and the BE uses Table API Arrow
readers/writers with ZSTD. The legacy SDK Tunnel LZ4 implementations are
outside the active Doris data path. The BE connector retains its local
Jackson exclusions.
Limit `flight-sql-jdbc-driver` to test scope. Only the FE test client
loads the JDBC driver; production code uses the retained `FlightServer`
and `FlightSqlClient` protocol libraries. The regression framework keeps
its independent JDBC driver dependency.
Add a ZSTD round-trip test through the ODPS Arrow writer/reader
factories, with the Java 17 direct-buffer access options required by the
test JVM. This verifies 1,024 rows including a null after removing LZ4,
alongside the existing isolated ODPS class-loading test.
### Release note
Upgrade gRPC to 1.75.0. Stop bundling the unused Java LZ4 dependency in
MaxCompute connectors and the test-only Flight SQL JDBC driver in the FE
runtime distribution.
### Check List (For Author)
- Test
- [ ] Regression test
- [x] Unit Test
- [x] Manual test (details below)
Validation of the final implementation in `d9613e32c86`:
- `EXTRA_FE_MODULES=maxcompute=be-java-extensions/max-compute-connector
./run-fe-ut.sh --run
'org.apache.doris.connector.maxcompute.*Test,org.apache.doris.maxcompute.*Test,!org.apache.doris.connector.maxcompute.OdpsLiveConnectivityTest'`:
146 FE and 14 BE connector tests passed, including ODPS class-loader
isolation and the new ZSTD round trip. The successful test runtime
classpaths were checked and contain no `net.jpountz.lz4` classes.
- `build.sh --fe` passed with `DISABLE_BE_JAVA_EXTENSIONS=OFF`,
`FE_MAVEN_THREADS=4`, `MVN_OPT=-Dmaven.build.cache.enabled=false`, and
`--be-extension-ignore
iceberg-metadata-scanner,hadoop-hudi-scanner,java-common,java-udf,jdbc-scanner,paimon-scanner,trino-connector-scanner,preload-extensions,hadoop-deps,java-writer`.
All 64 reactor modules passed, including Checkstyle, FE compilation and
FE/BE MaxCompute packaging. Maven wall time: 2m 31s.
- Both connector dependency trees contain no Java LZ4 artifacts. The
rebuilt FE plugin zip and BE connector jar contain no Java LZ4
jars/classes. The incremental output directory retained the previous
build's LZ4 jar; that stale artifact was removed and the runtime plugin
directory was rechecked.
- `output/fe/lib` contains `grpc-netty-shaded-1.75.0.jar`; no Flight SQL
JDBC driver jar is present under `output/fe`.
- `git diff --check` passed. Live MaxCompute connectivity, cluster
startup and regression tests were not run.English • العربية • বাংলা • Deutsch • Español • فارسی • Français • हिन्दी • Bahasa Indonesia • Italiano • 日本語 • 한국어 • Polski • Português • Română • Русский • Slovenščina • ไทย • Türkçe • Українська • Tiếng Việt • 简体中文 • 繁體中文
Apache Doris is an open-source, real-time analytics and search database built on MPP architecture. It provides fast SQL analytics, lakehouse query acceleration, and hybrid search across structured, text, and vector data.
Explore the official website for the latest product overview, use cases, ecosystem updates, blogs, and user stories. For version updates, see all release notes.
| Use Case | What it provides |
|---|---|
| Customer-Facing Analytics | Ship sub-second interactive analytics to external users. |
| Data Warehousing | Build one real-time warehouse across business domains. |
| Observability | Analyze high-throughput logs, events, and metrics with SQL. |
| Doris for AI | Use vector, text, JSON, and structured search in one SQL engine. |
Apache Doris is built around three core capabilities. The website is the source of truth for detailed product descriptions and examples.
| Capability | What it provides |
|---|---|
| Real-Time Analytics | Streaming ingestion, incremental transformation, and sub-second queries under high concurrency. |
| Lakehouse Analytics | Fast SQL analytics over open table formats such as Iceberg, Delta Lake, and Hudi. |
| Hybrid Search | SQL-native analytics across JSON, full-text, and vector data for AI and search workloads. |
Doris sits at the center of the modern data stack. It connects upstream databases, streaming systems, and lakehouse storage with downstream BI, AI, analytics, and observability tools.
For the latest ecosystem coverage, visit the official website and the connection and integration documentation.
Apache Doris supports both compute-storage coupled and compute-storage decoupled deployments. In decoupled mode, stateless compute groups run over shared object storage, so you can scale compute on demand and isolate workloads.
Learn more in the deployment guide and deployment mode guide.
| Resource | What it provides |
|---|---|
| Community Report | Weekly updates on community activity, merged PRs, contributors, and feature progress. |
| Roadmap 2026 | The 2026 planning discussion for AI and hybrid search, query engine, storage, and data lake work. |
Doris provides connectors and tools for common data engineering workflows.
Apache Doris is used in production by thousands of companies worldwide across internet services, finance, retail, logistics, manufacturing, energy, telecommunications, AI, and other industries.
Apache Doris graduated from the Apache Incubator and became an Apache Top-Level Project in June 2022. Thanks to all community contributors who help build Doris.
Note Some licenses of the third-party dependencies are not compatible with Apache 2.0 License. So you need to disable some Doris features to comply with Apache 2.0 License. For details, refer to the
thirdparty/LICENSE.txt