)]}'
{
  "log": [
    {
      "commit": "13d1bd6e69153aa14d8b7411546b57a494545ff9",
      "tree": "980d5a53e3e241a225272bac4b0c0f3094e06823",
      "parents": [
        "6e06f48e65cd4e36f93c760f1b7caa617266c197"
      ],
      "author": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Mon Sep 14 14:53:05 2026 +0200"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Mon Sep 14 14:53:05 2026 +0200"
      },
      "message": "[KYUUBI #7743] [DOC] Fix cross-references\n\n### Why are the changes needed?\nThe PR fixes cross-references and the following six documentation build warnings:\n```\n./docs/deployment/spark/aqe.md:181: WARNING: \u0027myst\u0027 cross-reference target not found: \u0027how-to-set-spark-sql-adaptive-advisorypartitionsizeinbytes\u0027 [myst.xref_missing]\n./docs/deployment/spark/aqe.md:213: WARNING: local id not found in doc \u0027configuration/settings\u0027: \u0027via-spark-defaults-conf\u0027 [myst.xref_missing]\n./docs/deployment/spark/dynamic_allocation.md:173: WARNING: local id not found in doc \u0027configuration/settings\u0027: \u0027via-spark-defaults-conf\u0027 [myst.xref_missing]\n./docs/extensions/engines/spark/jdbc-dialect.md:48: WARNING: \u0027myst\u0027 cross-reference target not found: \u0027../jdbc/kyuubi_jdbc.html\u0027 [myst.xref_missing]\n./docs/extensions/engines/spark/jdbc-dialect.md:49: WARNING: \u0027myst\u0027 cross-reference target not found: \u0027../jdbc/hive_jdbc.html\u0027 [myst.xref_missing]\n./docs/quick_start/quick_start_with_jdbc.md:22: WARNING: \u0027myst\u0027 cross-reference target not found: \u0027../client/jdbc/kyuubi_jdbc.rst\u0027 [myst.xref_missing]\n```\n\n### How was this patch tested?\nTested by building the documentation and following fixed links.\n\nBefore changes:\n```\nbuild succeeded, 12 warnings.\n```\n\nAfter changes:\n```\nbuild succeeded, 6 warnings.\n```\n\n### Was this patch assisted by generative AI tooling?\nAssisted-by: Gemini 3.1 Pro\n\nCloses #7743 from dnskr/doc-fix-cross-references.\n\nCloses #7743\n\n490900d21 [Denis Krivenko] [DOC] Fix cross-references\n\nAuthored-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "6e06f48e65cd4e36f93c760f1b7caa617266c197",
      "tree": "37903085ca7f4a5e6d2dfb5a61c999b8dbdda4c9",
      "parents": [
        "f34836befae3665c0be55dce71edfa4b15957518"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Sep 14 14:36:46 2026 +0200"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Mon Sep 14 14:36:46 2026 +0200"
      },
      "message": "[KYUUBI #7719] Bump docker/setup-qemu-action from 4.2.0 to 4.3.0\n\nBumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.2.0 to 4.3.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/docker/setup-qemu-action/releases\"\u003edocker/setup-qemu-action\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.96.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/336\"\u003edocker/setup-qemu-action#336\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/316\"\u003edocker/setup-qemu-action#316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.15 to 1.1.18 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/332\"\u003edocker/setup-qemu-action#332\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.2.0 to 4.3.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/334\"\u003edocker/setup-qemu-action#334\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/331\"\u003edocker/setup-qemu-action#331\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/317\"\u003edocker/setup-qemu-action#317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/333\"\u003edocker/setup-qemu-action#333\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/setup-qemu-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/setup-qemu-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/1f40c72289eff860ee54a304f1438e3cff362e0a\"\u003e\u003ccode\u003e1f40c72\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/336\"\u003e#336\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-to...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/932216e29e2417c3aa0bc5aec3c57089030cef2c\"\u003e\u003ccode\u003e932216e\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/a39e895360e601ae54e9ac97b8ea3b99e5f40491\"\u003e\u003ccode\u003ea39e895\u003c/code\u003e\u003c/a\u003e build(deps): bump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.96.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/a98ae9ffe777adf16ca44873bab9926427b262fa\"\u003e\u003ccode\u003ea98ae9f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/333\"\u003e#333\u003c/a\u003e from docker/dependabot/npm_and_yarn/undici-6.28.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/8ebc9d118344dda0af3e25d2a7330010dd33e951\"\u003e\u003ccode\u003e8ebc9d1\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/c41e3fcbc0d6742101e0310c3b008ac3b16a9529\"\u003e\u003ccode\u003ec41e3fc\u003c/code\u003e\u003c/a\u003e build(deps): bump undici from 6.27.0 to 6.28.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/5fc60dfac60f723a3386e73530ff8067f2848f60\"\u003e\u003ccode\u003e5fc60df\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/332\"\u003e#332\u003c/a\u003e from docker/dependabot/npm_and_yarn/brace-expansion-1...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/a26e892bb646b50218299a9b391e7a4b0322d96a\"\u003e\u003ccode\u003ea26e892\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/328\"\u003e#328\u003c/a\u003e from docker/dependabot/github_actions/actions/checkou...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/aa6d04232374700651c6e7be400e859600041423\"\u003e\u003ccode\u003eaa6d042\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/324\"\u003e#324\u003c/a\u003e from docker/dependabot/github_actions/actions/setup-n...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/d381ce5c16de15c000da8929fd1fc6e8fdef19e1\"\u003e\u003ccode\u003ed381ce5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/317\"\u003e#317\u003c/a\u003e from docker/dependabot/npm_and_yarn/sigstore-4.1.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/docker/setup-qemu-action/compare/96fe6ef7f33517b61c61be40b68a1882f3264fb8...1f40c72289eff860ee54a304f1438e3cff362e0a\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddocker/setup-qemu-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.2.0\u0026new-version\u003d4.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7719 from dependabot[bot]/dependabot/github_actions/docker/setup-qemu-action-4.3.0.\n\nCloses #7719\n\nf41696b5d [dependabot[bot]] Bump docker/setup-qemu-action from 4.2.0 to 4.3.0\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "f34836befae3665c0be55dce71edfa4b15957518",
      "tree": "4b1a06cb948d969db302346bf3f8ab24ee370e59",
      "parents": [
        "635d12e260e6e1c667531aaa155b00ddb6ab5ba2"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Sep 13 01:07:04 2026 +0900"
      },
      "committer": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Sun Sep 13 01:07:04 2026 +0900"
      },
      "message": "[KYUUBI #7735] Bump vitest from 4.1.9 to 4.1.11 in /kyuubi-server/web-ui\n\nBumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.9 to 4.1.11.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/vitest-dev/vitest/releases\"\u003evitest\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.11\u003c/h2\u003e\n\u003ch3\u003e   🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRevive global concurrency limit for test lifecycle [backport to v4]  -  by \u003ca href\u003d\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e​sheremet-va\u003c/code\u003e\u003c/a\u003e and \u003ca href\u003d\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/vitest-dev/vitest/issues/10992\"\u003evitest-dev/vitest#10992\u003c/a\u003e \u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/5146df80b\"\u003e(5146d)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eEncode iframeId in tester iframe URL [backport to v4]  -  by \u003ca href\u003d\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e​sheremet-va\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003ePduhard\u003c/strong\u003e and \u003cstrong\u003eClaude Opus 4.8\u003c/strong\u003e in \u003ca href\u003d\"https://redirect.github.com/vitest-dev/vitest/issues/10955\"\u003evitest-dev/vitest#10955\u003c/a\u003e \u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/10b2cd201\"\u003e(10b2c)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTrigger playwright/chromium gc on lower disk availability [backport to v4]  -  by \u003ca href\u003d\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenCode\u003c/strong\u003e in \u003ca href\u003d\"https://redirect.github.com/vitest-dev/vitest/issues/10951\"\u003evitest-dev/vitest#10951\u003c/a\u003e \u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/9851dbc41\"\u003e(9851d)\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emocker\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eRestrict redirect mocks to the fs allowlist [backport to v4]  -  by \u003ca href\u003d\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/vitest-dev/vitest/issues/10974\"\u003evitest-dev/vitest#10974\u003c/a\u003e \u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/fe5a11d3c\"\u003e(fe5a1)\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003e    \u003ca href\u003d\"https://github.com/vitest-dev/vitest/compare/v4.1.10...v4.1.11\"\u003eView changes on GitHub\u003c/a\u003e\u003c/h5\u003e\n\u003ch2\u003ev4.1.10\u003c/h2\u003e\n\u003ch3\u003e   🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e: Check fs access in builtin commands [backport to v4]  -  by \u003ca href\u003d\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenCode (claude-opus-4-8)\u003c/strong\u003e in \u003ca href\u003d\"https://redirect.github.com/vitest-dev/vitest/issues/10680\"\u003evitest-dev/vitest#10680\u003c/a\u003e \u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/5c18dd267\"\u003e(5c18d)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003evm\u003c/strong\u003e: Fix external module resolve error with deps optimizer query for encoded URI [backport to v4]  -  by \u003ca href\u003d\"https://github.com/SveLil\"\u003e\u003ccode\u003e​SveLil\u003c/code\u003e\u003c/a\u003e and \u003ca href\u003d\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/vitest-dev/vitest/issues/10661\"\u003evitest-dev/vitest#10661\u003c/a\u003e \u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/bae52b511\"\u003e(bae52)\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003e    \u003ca href\u003d\"https://github.com/vitest-dev/vitest/compare/v4.1.9...v4.1.10\"\u003eView changes on GitHub\u003c/a\u003e\u003c/h5\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/9bd8d464e6328c567c2dbcd8fdd977d57a9425c2\"\u003e\u003ccode\u003e9bd8d46\u003c/code\u003e\u003c/a\u003e chore: release v4.1.11 (\u003ca href\u003d\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/10995\"\u003e#10995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/9851dbc41c286a30abfb6b29cce65f3e5b7b40a1\"\u003e\u003ccode\u003e9851dbc\u003c/code\u003e\u003c/a\u003e fix(browser): trigger playwright/chromium gc on lower disk availability [back...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/db616d227b6e0cb07a94f5d1bba262ee95db7e46\"\u003e\u003ccode\u003edb616d2\u003c/code\u003e\u003c/a\u003e chore: release v4.1.10 (\u003ca href\u003d\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/10718\"\u003e#10718\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/vitest-dev/vitest/commit/bae52b5112a6fd8200101b88bf8af9685d077295\"\u003e\u003ccode\u003ebae52b5\u003c/code\u003e\u003c/a\u003e fix(vm): fix external module resolve error with deps optimizer query for enco...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href\u003d\"https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dvitest\u0026package-manager\u003dnpm_and_yarn\u0026previous-version\u003d4.1.9\u0026new-version\u003d4.1.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/apache/kyuubi/network/alerts).\n\n\u003c/details\u003e\n\nCloses #7735 from dependabot[bot]/dependabot/npm_and_yarn/kyuubi-server/web-ui/vitest-4.1.11.\n\nCloses #7735\n\ne7c674496 [dependabot[bot]] Bump vitest from 4.1.9 to 4.1.11 in /kyuubi-server/web-ui\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\n"
    },
    {
      "commit": "635d12e260e6e1c667531aaa155b00ddb6ab5ba2",
      "tree": "8e146b2264f1a34642ed1a89d17690ad47f7d2a3",
      "parents": [
        "cab165f2940f5eba67c257423de0315507ffcf33"
      ],
      "author": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Sat Sep 12 14:18:09 2026 +0900"
      },
      "committer": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Sat Sep 12 14:18:09 2026 +0900"
      },
      "message": "[KYUUBI #7714] [SPARK] Update PATH_CONFIGS and validate main-resource path\n\n### Why are the changes needed?\n\nAdd more configs into Spark `PATH_CONFIGS`. Also, add path validation for `KyuubiConf.ENGINE_SPARK_MAIN_RESOURCE`.\n\nThis can fail sessions that previously worked because of the validation.\n\n### How was this patch tested?\n\nAdded regression tests for `KyuubiConf.ENGINE_SPARK_MAIN_RESOURCE`.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: OpenCode (GLM-5.3)\n\nCloses #7714 from aajisaka/spark-path-configs.\n\nCloses #7714\n\n8b1dd038e [Akira Ajisaka] Reflect review: drop oauthTokenFile and cite DriverKubernetesCredentialsFeatureStep\n0ffb0cae6 [Akira Ajisaka] Add more configs\n2afe20acf [Akira Ajisaka] Update Spark PATH_CONFIGS\n\nAuthored-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\nSigned-off-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\n"
    },
    {
      "commit": "cab165f2940f5eba67c257423de0315507ffcf33",
      "tree": "367604b54d28a3625e32c0b836258932b61535d9",
      "parents": [
        "503aa4f17b2b353b96f0530477ff6639a88bfadd"
      ],
      "author": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Wed Sep 09 13:26:06 2026 +0300"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Wed Sep 09 13:26:06 2026 +0300"
      },
      "message": "[KYUUBI #7717] [DOC] Reformat contributing docs from RST to Markdown\n\n### Why are the changes needed?\nThe changes are needed to unify the format used for documentation, as described in the issue https://github.com/apache/kyuubi/issues/7434.\n\nThe PR also fixes broken link to `Building From Source` page: `build.html` -\u003e `building.md`.\n\nThe PR **does not** change page contents (only very minimal visual adjustments) to ensure an easier review of the migration.\nI\u0027m planning to refine the information provided on the pages and refactor them after the migration is completed.\n\n### How was this patch tested?\nTested by building the documentation and comparing the pages against the live site.\n\n### Was this patch assisted by generative AI tooling?\nAssisted-by: Qwen Coder\n\nCloses #7717 from dnskr/rst-to-md-contributing-pages.\n\nCloses #7717\n\n849ea9205 [Denis Krivenko] [DOC] Reformat contributing docs from RST to Markdown\n\nAuthored-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "503aa4f17b2b353b96f0530477ff6639a88bfadd",
      "tree": "c26fb7c2aec11fc00cdd4cf1358aaf90eeb629bd",
      "parents": [
        "c24e02a65d73a411cb08fd69b6ca279b41fd269a"
      ],
      "author": {
        "name": "nightcityblade",
        "email": "jackchen@haloailabs.com",
        "time": "Wed Sep 09 00:59:56 2026 +0900"
      },
      "committer": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Wed Sep 09 00:59:56 2026 +0900"
      },
      "message": "[KYUUBI #7676][DOCS] Recommend multi-tenant session config safeguards\n\n### Why are the changes needed?\n\nThe session configuration ignore and restrict lists are empty by default. In a\nmulti-tenant deployment, leaving both lists empty lets clients override\nsensitive session-level configuration during engine bootstrap and connection\nsetup. This adds an explicit administrator recommendation to the existing\nsecurity documentation.\n\nCloses #7676.\n\n### How was this patch tested?\n\n- `env PATH\u003d/usr/bin:/bin:/usr/sbin:/sbin dev/reformat`\n- `sphinx-build -W --keep-going -D suppress_warnings\u003dmyst.xref_missing,misc.highlighting_failure -b html docs /tmp/kyuubi-docs-build-7676-focused`\n- Confirmed the generated `security/authorization/spark/overview.html` contains\n  the recommendation.\n\nThe Sphinx suppression covers existing warnings in unrelated documentation;\nthe changed page builds without warnings.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: OpenAI Codex:GPT-5\n\nCloses #7677 from nightcityblade/kyuubi-7676-recommend-session-config.\n\nCloses #7676\n\na861a7763 [nightcityblade] docs: fix security index formatting\n95c480efd [nightcityblade] docs: separate session configuration guidance\n9bf6e91f8 [nightcityblade] docs: move session config guidance to security overview\n44994a27f [nightcityblade] [KYUUBI #7676][DOCS] Add session config baseline\nefb623931 [nightcityblade] [KYUUBI #7676][DOCS] Recommend multi-tenant session config safeguards\n\nLead-authored-by: nightcityblade \u003cjackchen@haloailabs.com\u003e\nCo-authored-by: nightcityblade \u003cnightcityblade@gmail.com\u003e\nSigned-off-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\n"
    },
    {
      "commit": "c24e02a65d73a411cb08fd69b6ca279b41fd269a",
      "tree": "104ddb8e6119866972ae5ac9b3032cfb9e2a978a",
      "parents": [
        "888bf0e0ef2c23ea5fec707ed815de239c5f6933"
      ],
      "author": {
        "name": "Shuhang Han",
        "email": "148054964+HanShuhang@users.noreply.github.com",
        "time": "Tue Sep 08 20:56:03 2026 +0800"
      },
      "committer": {
        "name": "wangzhigang",
        "email": "iamzhigangwang@gmail.com",
        "time": "Tue Sep 08 20:56:03 2026 +0800"
      },
      "message": "[KYUUBI #7645][SERVER] Fix operation state metrics transition\n\n### Why are the changes needed?\n\n`KyuubiOperation#setState` updated operation state metrics before delegating to `AbstractOperation#setState`, where the state transition is validated and the actual operation state is changed. It also did not protect the whole transition-and-metrics-update sequence with the operation lock.\n\nThis can cause inaccurate operation state metrics in two cases:\n\n1. A stale or invalid state transition may update metrics before being rejected.\n\n    For example, an operation may have already moved from `RUNNING` to `FINISHED`, while a delayed cancel/close path still tries to update it to another terminal state such as `CANCELED`. In the old implementation, the target state metric was updated before `OperationState#validateTransition` rejected the transition, so the operation remained in the original state but the metrics had already been changed.\n\n2. Concurrent state transitions for the same operation may update metrics based on the same stale old state.\n\n    For example, one thread may observe the remote query as finished and call `KyuubiOperation#setState(FINISHED)`, while another thread concurrently handles cancel/close/timeout/error and calls `KyuubiOperation#setState(CANCELED)` or another terminal state. Since the old implementation read `state` and updated metrics outside a common operation lock, both paths could observe the old state as `RUNNING` and both update the `RUNNING` metric, making `kyuubi.operation.state.ExecuteStatement.running` inaccurate.\n\nThis patch makes `KyuubiOperation#setState` execute under the operation lock, captures the old state once, delegates to `AbstractOperation#setState` first, and updates operation state metrics only after the state transition succeeds.\n\n### How was this patch tested?\n\nAdded a unit test in `KyuubiOperationSuite` to verify that a stale terminal transition does not update operation state metrics.\n```\nbuild/mvn test -pl kyuubi-server -am \\\n  -Pspark-provided -Pflink-provided -Phive-provided \\\n  -Dtest\u003dnone \\\n  -DwildcardSuites\u003dorg.apache.kyuubi.operation.KyuubiOperationSuite\n```\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: TraeCode with GPT-5\n\nCloses #7642 from HanShuhang/hsh/fix-state.\n\nCloses #7645\n\n063f24c84 [hanshuhang.lxy] [KYUUBI #7645][SERVER] Fix operation state metrics transition\n\nLead-authored-by: Shuhang Han \u003c148054964+HanShuhang@users.noreply.github.com\u003e\nCo-authored-by: hanshuhang.lxy \u003chanshuhang.lxy@bytedance.com\u003e\nSigned-off-by: wangzhigang \u003ciamzhigangwang@gmail.com\u003e\n"
    },
    {
      "commit": "888bf0e0ef2c23ea5fec707ed815de239c5f6933",
      "tree": "5909eb1d0fdecdc9b3db313121d87d1d8066f362",
      "parents": [
        "d956b252bb1869dbe9d5d45c38e25e0106dcaf93"
      ],
      "author": {
        "name": "zhigang",
        "email": "iamzhigangwang@gmail.com",
        "time": "Mon Sep 07 16:04:49 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Sep 07 16:04:49 2026 +0800"
      },
      "message": "[KYUUBI #7662][SERVER] Extend virtual thread support to server executors\n\n### Why are the changes needed?\n\nPR #7656 added virtual-thread support to the Binary frontend. This follow-up extends the same optional model to other I/O-bound Kyuubi Server executors and adds one global opt-in switch with component-level overrides.\n\nThe feature remains disabled by default. Engine-side executors are unchanged. See #7662 for the scope and benchmark results.\n\n### How was this patch tested?\n\n- Targeted configuration, thread utility, session manager, and Jetty suites on JDK 17 and JDK 21.\n- Kyuubi Common test suite on JDK 21: 295 tests passed.\n- Kyuubi Server fast package build.\n- `dev/reformat`\n- `dev/gen/gen_all_config_docs.sh`\n- `git diff --check`\n- Five-minute JDK 25 A/B benchmark with Spark 4.2 and real Spark SQL. See #7662.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: OpenAI Codex (GPT-5)\n\nCloses #7663 from wangzhigang1999/zhigang/kyuubi-7662-server-virtual-threads.\n\nCloses #7662\n\nedf125e6b [wangzhigang] [KYUUBI #7662] Cache virtual thread capability detection\n22946cb06 [wangzhigang] [KYUUBI #7662] Validate server virtual threads at startup\n39c515a97 [wangzhigang] [KYUUBI #7662] Drop virtual threads from the HTTP frontend\na2f8b515a [wangzhigang] [KYUUBI #7662] Preserve Jetty frontend thread pools\nb8481b816 [wangzhigang] [KYUUBI #7662] Address virtual thread review comments\n266035430 [wangzhigang] [KYUUBI #7662] Simplify server virtual thread configuration\nf853394d7 [wangzhigang] Expand server virtual thread support\n\nAuthored-by: zhigang \u003ciamzhigangwang@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "d956b252bb1869dbe9d5d45c38e25e0106dcaf93",
      "tree": "b282d2d2524ec8e77e0338c6a447538598f389f0",
      "parents": [
        "b090cc28eb55c0f0d47189a6952dec66c3c474bb"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Sep 06 23:26:09 2026 +0900"
      },
      "committer": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Sun Sep 06 23:26:09 2026 +0900"
      },
      "message": "[KYUUBI #7621] Bump dompurify from 3.4.11 to 3.4.13 in /kyuubi-server/web-ui\n\nBumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.11 to 3.4.13.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/cure53/DOMPurify/releases\"\u003edompurify\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDOMPurify 3.4.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with hook removal during \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href\u003d\"https://github.com/koyokr\"\u003e\u003ccode\u003e​koyokr\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with hooks potentially bypassing the clone guard, thanks \u003ca href\u003d\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with DOM clobbering via \u003ccode\u003eownerDocument\u003c/code\u003e during \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href\u003d\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where a hook would not get called for custom elements, thanks \u003ca href\u003d\"https://github.com/Rikuxx0\"\u003e\u003ccode\u003e​Rikuxx0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of hooks removing elements, \u003ca href\u003d\"https://github.com/mkrause-bee360\"\u003e\u003ccode\u003e​mkrause-bee360\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded support for a few new SVG attributes, thanks \u003ca href\u003d\"https://github.com/cbn-falias\"\u003e\u003ccode\u003e​cbn-falias\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href\u003d\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e​Develop-KIM\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of declarative partial updates\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/cure53/DOMPurify/commit/3067f774676975de12306effd6db6ad7a9a8c17f\"\u003e\u003ccode\u003e3067f77\u003c/code\u003e\u003c/a\u003e release: 3.4.13 (\u003ca href\u003d\"https://redirect.github.com/cure53/DOMPurify/issues/1562\"\u003e#1562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197\"\u003e\u003ccode\u003ea9ca1e5\u003c/code\u003e\u003c/a\u003e release: 3.4.12 (\u003ca href\u003d\"https://redirect.github.com/cure53/DOMPurify/issues/1537\"\u003e#1537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href\u003d\"https://github.com/cure53/DOMPurify/compare/3.4.11...3.4.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddompurify\u0026package-manager\u003dnpm_and_yarn\u0026previous-version\u003d3.4.11\u0026new-version\u003d3.4.13)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/apache/kyuubi/network/alerts).\n\n\u003c/details\u003e\n\nCloses #7621 from dependabot[bot]/dependabot/npm_and_yarn/kyuubi-server/web-ui/dompurify-3.4.13.\n\nCloses #7621\n\nfd3f1e14a [dependabot[bot]] Bump dompurify from 3.4.11 to 3.4.13 in /kyuubi-server/web-ui\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\n"
    },
    {
      "commit": "b090cc28eb55c0f0d47189a6952dec66c3c474bb",
      "tree": "954639042d8eb82cd1b57b234b64fe81d2356d75",
      "parents": [
        "a162cde27e43cb19f1df30ed596db743682218e1"
      ],
      "author": {
        "name": "maomaodev",
        "email": "lifumao@tencent.com",
        "time": "Fri Sep 04 21:44:45 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 21:44:45 2026 +0800"
      },
      "message": "[KYUUBI #7712] Support IPv6 `host:port` parsing in Kyuubi service discovery\n\n### Why are the changes needed?\n\nFix https://github.com/apache/kyuubi/issues/7712. Kyuubi currently cannot discover or connect to server/engine endpoints in IPv6-only clusters. Both the server side (`DiscoveryClient.parseInstanceHostPort`) and the standalone JDBC client side (`ZooKeeperHiveClientHelper`) parse a `host:port` string by naively splitting on `\":\"`. This breaks for IPv6 because IPv6 addresses themselves contain `:`.\n\nThe correct parsing behavior already exists upstream in Hive (`org.apache.hadoop.hive.common.IPStackUtils`). This patch mirrors that logic in a new lightweight `IPStackUtils` utility under `kyuubi-util`, so it can be shared between the server side and the standalone JDBC client (which only depends on `kyuubi-util`).\n\n### How was this patch tested?\n\n- Added `IPStackUtilsTest` (11 test cases) aligned with Hive\u0027s own [IPStackUtilsTest](https://github.com/apache/hive/blob/master/standalone-metastore/metastore-common/src/main/java/org/apache/hadoop/hive/common/IPStackUtils.java), covering IPv4, IPv6 with brackets, IPv6 without brackets, hostname, invalid port, missing port, missing host and port range validation.\n- Extended `DiscoveryClientSuite` with IPv6 cases (with and without brackets) and converted it from an orphan trait to a runnable class.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: DeepSeek-V4-Pro\n\nCloses #7713 from maomaodev/kyuubi-7712.\n\nCloses #7712\n\n91f9f7843 [lifumao] Support IPv6  parsing in Kyuubi service discovery\nac0c00b0b [lifumao] edit comments\n6a057ee6d [lifumao] Support IPv6 `host:port` parsing in Kyuubi service discovery\n\nAuthored-by: maomaodev \u003clifumao@tencent.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "a162cde27e43cb19f1df30ed596db743682218e1",
      "tree": "203b4c7f72b6ab09c88c89ce35f1fbb3929e0f49",
      "parents": [
        "330a6426d8126da8721bd288e7b1257193204149"
      ],
      "author": {
        "name": "Alex Cruise",
        "email": "alex@cluonflux.com",
        "time": "Fri Sep 04 17:56:54 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 17:56:54 2026 +0800"
      },
      "message": "[KYUUBI #7659][INFRA] Restore code coverage\n\n...by not overriding the test argLine!\n\nCode coverage has reported nothing since 1.8.0. Both maven-surefire-plugin and scalatest-maven-plugin default their `argLine` to the `${argLine}` property, which is resolved when the mojo runs -- late enough to see the value `jacoco:prepare-agent` publishes there. KYUUBI #4849 gave both plugins an explicit `\u003cargLine\u003e${extraJavaTestArgs}\u003c/argLine\u003e` to open JDK modules, and plugin configuration is interpolated during model building, long before the agent mojo runs. The agent option is therefore dropped and the forked test JVM runs uninstrumented:\n\n    [INFO] --- jacoco:0.8.11:prepare-agent (pre-test)  kyuubi-util-scala_2.12 ---\n    [INFO] argLine set to -javaagent:.../org.jacoco.agent-0.8.11-runtime.jar\u003d...\n    [INFO] --- jacoco:0.8.11:report (report)  kyuubi-util-scala_2.12 ---\n    [INFO] Skipping JaCoCo execution due to missing execution data file.\n\nThe build stays green and every module reports zero. KYUUBI #756 (\"Recover CODECOV\") fixed the same thing in 2021 by deleting an `argLine` element.\n\nMove the JDK options into the `argLine` property itself and drop both overrides, so the plugin defaults apply again. `prepare-agent` prepends the agent to the property\u0027s existing value rather than replacing it, so `--add-opens` survives:\n\n    argLine set to -javaagent:...\u003ddestfile\u003d... -XX:+IgnoreUnrecognizedVMOptions ...\n\nSurefire\u0027s `{argLine}` late replacement is not enough on its own here, since scalatest-maven-plugin has no equivalent and that is where most of Kyuubi\u0027s tests run.\n\nVerified locally:\n\n  - `test -Pcodecov -pl kyuubi-util-scala` (scalatest) analyzes 8 classes and writes target/jacoco.exec, where before it skipped for missing data.\n  - `test -Pcodecov -pl kyuubi-rest-client` (surefire) analyzes 63 classes.\n  - `test -pl kyuubi-util-scala` without the profile is green, argLine unchanged.\n\n### Was this patch assisted by generative AI tooling?\nYes, Claude Opus 5\n\nCloses #7661 from acruise/kyuubi-7659-codecov-argline.\n\nCloses #7659\n\n1b211e04a [Cheng Pan] [KYUUBI #7659][INFRA] Drop redundant argLine override in data-agent-engine\na9b8cd0f1 [Alex Cruise] [KYUUBI #7659][INFRA] Restore code coverage by not overriding the test argLine\n\nLead-authored-by: Alex Cruise \u003calex@cluonflux.com\u003e\nCo-authored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "330a6426d8126da8721bd288e7b1257193204149",
      "tree": "01fb9f1684a07e4b8b632848f248c0e60ee27c7f",
      "parents": [
        "e0522cd3205855f2806e2389626cdac780611aaa"
      ],
      "author": {
        "name": "Aleksandr Efimov",
        "email": "dzazheg@gmail.com",
        "time": "Fri Sep 04 17:04:35 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 17:04:35 2026 +0800"
      },
      "message": "[KYUUBI #7671][AUTHZ] Cover all injected authz rules in the excludedRules check\n\n### Why are the changes needed?\n\nCloses #7671, the follow-up wForget asked for while reviewing #7637.\n\n`AuthzConfigurationChecker` matches `org.apache.kyuubi.plugin.spark.authz.ranger` in the effective `spark.sql.optimizer.excludedRules`, which was the whole extension when the check was written. Most rules live under `org.apache.kyuubi.plugin.spark.authz.rule` now, so a rule added there is outside the denylist. This matches the extension\u0027s own package instead.\n\nIt is future-proofing rather than a fix for a live bypass, and worth saying why. `spark.sql.optimizer.excludedRules` filters optimizer batches only and Spark has no analyzer counterpart, so the resolution rules that apply masking and row filtering cannot be excluded at all. Of the four optimizer rules `RangerSparkExtension` injects, `RuleAuthorization` is in `…authz.ranger` and already covered; the other three — `RuleEliminateMarker`, `RuleEliminatePermanentViewMarker`, `RuleEliminateTypeOf` — only strip markers after the check has run, and excluding one of them breaks the query instead of lifting a check.\n\nThe change does reject configurations that are accepted today, which is why it is separate from #7637 rather than part of it.\n\n### How was this patch tested?\n\nA new case in `AuthzConfigurationCheckerSuite` covers the three `…authz.rule` rules by their `ruleName`, through both paths the checker guards: the value in effect, and the `SET` syntax.\n\n30 tests green across `AuthzConfigurationCheckerSuite`, `DataMaskingForInMemoryParquetSuite` and the row filtering suite. With the constant reverted to the ranger package the new case fails, so it tests the change rather than the code around it.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7672 from alexandrefimov/kyuubi-authz-excluded-rules-prefix.\n\nCloses #7671\n\n2df8dede5 [Aleksandr Efimov] [KYUUBI #7671][AUTHZ] Cover all injected authz rules in the excludedRules check\n\nAuthored-by: Aleksandr Efimov \u003cdzazheg@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "e0522cd3205855f2806e2389626cdac780611aaa",
      "tree": "2376886a8debb45b09f762667aec27ac00f59bd9",
      "parents": [
        "9cd300b87919e65799910244ebb666a3555be53f"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Fri Sep 04 17:00:42 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 17:00:42 2026 +0800"
      },
      "message": "[KYUUBI #7705][UTIL] Report the candidates a failed DynMethods lookup tried\n\n### Why are the changes needed?\n\nCloses #7705.\n\n`DynMethods.Builder` swallows per-candidate lookup failures and, when none matches, `build()`/`buildChecked()` threw with only the method name, e.g. `Cannot find method: apply`. Now the failure names every candidate signature it tried, each paired with its `NoSuchMethodException`/`ClassNotFoundException`:\n\n```\nCannot find method: apply\n\tMissing org.apache.spark.sql.catalyst.catalog.CatalogStorageFormat#apply(...) [java.lang.NoSuchMethodException: ...]\n\tMissing ...#apply(...) [...]\n```\n\nThis matches what `DynConstructors.Builder` already does. Entries are a list, not a name-keyed map, since two lookups can render the same name for unrelated reasons (e.g. `ClassNotFoundException` then `NoSuchMethodException`); declared-member candidates are marked so `hiddenImpl`/`impl` pairs read distinctly.\n\nTwo gaps fixed along the way:\n- A null argument class in a candidate (as `SparkUtilsHelper` passes below Spark 4.1) must count as an ordinary miss, not a throw; `DynConstructors.methodName` had the same gap.\n- #7687\u0027s `catch (RuntimeException e)` in `hiddenImpl` now records a candidate too, preserving the \"does not `opens`\" text instead of discarding it.\n\nAlso: javadoc corrections (parquet -\u003e iceberg provenance, `RuntimeError` -\u003e `RuntimeException`). `NoClassDefFoundError` handling and `DynFields` cause recording are left for follow-ups.\n\n### How was this patch tested?\n\n20 tests (19 `DynMethodsTest` + 1 `DynConstructorsTest`) cover each recording site, message layout/order, throwable pairing, suppressed order, null argument class/array on both paths, and `orNoop` with prior misses. Each was verified by mutation testing (mutate, recompile, rerun, restore). Module 65/65 green on Zulu 17.0.18; `spotless:check` passes.\n\n```\nbuild/mvn test -pl kyuubi-util -am -DwildcardSuites\u003dnone -Dtest\u003d\u0027DynMethodsTest,DynConstructorsTest\u0027\nbuild/mvn spotless:check -pl kyuubi-util\n```\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7706 from LuciferYang/kyuubi-util-dynmethods-build-diagnostics.\n\nCloses #7705\n\n93d583c60 [yangjie01] Merge remote-tracking branch \u0027origin/master\u0027 into kyuubi-util-dynmethods-build-diagnostics\n2f7e2d25e [yangjie01] Drop the upstream comparison from the class javadoc\n49589b5dd [yangjie01] Merge branch \u0027kyuubi-util-dynmethods-ctorimpl-loader\u0027 into kyuubi-util-dynmethods-build-diagnostics\nee0ee0137 [yangjie01] Drop the parquet-common state claim from the ctorImpl javadoc\n60dc388ba [yangjie01] Merge branch \u0027kyuubi-util-dynmethods-ctorimpl-loader\u0027 into kyuubi-util-dynmethods-build-diagnostics\nd1636ec4f [yangjie01] Merge remote-tracking branch \u0027origin/master\u0027 into kyuubi-util-dynmethods-ctorimpl-loader\n84efcbb55 [yangjie01] Report the candidates a failed DynMethods lookup tried\n1c1989de9 [yangjie01] [KYUUBI #7688][UTIL] Resolve ctorImpl classes through the builder\u0027s configured loader\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "9cd300b87919e65799910244ebb666a3555be53f",
      "tree": "da38dc36990b6b3c3605359400310f3fb2930027",
      "parents": [
        "1f04800014073998b296943da63bd71960a44652"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Fri Sep 04 14:05:49 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 14:05:49 2026 +0800"
      },
      "message": "[KYUUBI #7688][UTIL] Resolve ctorImpl classes through the builder\u0027s configured loader\n\n### Why are the changes needed?\n\nCloses #7688.\n\n`ctorImpl(String, ...)` built its inner `DynConstructors.Builder` without forwarding the loader configured on the outer builder, so the name resolved through the thread context loader no matter what the caller passed to `.loader(...)`. `impl(String, ...)` has always honoured it. When the context loader cannot see the class, the `ClassNotFoundException` is swallowed as a candidate miss, so the failure reads as a generic cannot-find with nothing pointing at the ignored loader.\n\nThe fix also changes when the default loader is captured: it is now the one read at builder construction, matching `impl(String, ...)`, rather than the context loader read at `ctorImpl` call time. A caller that mutates the context loader in between gets the earlier snapshot.\n\n`ctorImpl` has no caller in Kyuubi outside the new test, so this is hygiene on a retained upstream API rather than a field bug. iceberg-common removed the method in 1.7.0 (apache/iceberg#10818); dropping both overloads instead of fixing them is a maintainer call rather than mine.\n\n### How was this patch tested?\n\n`testCtorImplUsesTheConfiguredLoader` in `DynMethodsTest`, in two halves that fail in opposite directions without the fix. With the context loader blinded (a `URLClassLoader` with no URLs and a null parent) and the builder given the app loader, the lookup must succeed; reverting the fix makes `buildChecked()` throw. Swapped, the lookup must fail, which is what pins the absence of a silent fallback; reverting makes `assertThrows` see nothing.\n\n```\nbuild/mvn test -pl kyuubi-util -am -DwildcardSuites\u003dnone\nbuild/mvn spotless:check -pl kyuubi-util\n```\n\n45 of 45 green on Zulu 17.0.18, spotless clean.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7689 from LuciferYang/kyuubi-util-dynmethods-ctorimpl-loader.\n\nCloses #7688\n\nee0ee0137 [yangjie01] Drop the parquet-common state claim from the ctorImpl javadoc\nd1636ec4f [yangjie01] Merge remote-tracking branch \u0027origin/master\u0027 into kyuubi-util-dynmethods-ctorimpl-loader\n1c1989de9 [yangjie01] [KYUUBI #7688][UTIL] Resolve ctorImpl classes through the builder\u0027s configured loader\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "1f04800014073998b296943da63bd71960a44652",
      "tree": "29b74bb95737a62713e6b769d9a735fa839bd6cc",
      "parents": [
        "b9f4e6caa8bac3ca579c3aaedd62fe2cab1e6e58"
      ],
      "author": {
        "name": "Wenjun Ruan",
        "email": "wenjun@apache.org",
        "time": "Fri Sep 04 11:25:35 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 11:25:35 2026 +0800"
      },
      "message": "[KYUUBI #7632] [K8s] Clean up terminated driver pods on informer add\n\n### Why are the changes needed?\n\nAt startup, Kyuubi uses a separate one-time LIST to find and clean terminated driver pods. A pod can be missed if this LIST fails, or if it completes after the cleanup LIST observes it as running but is first reported by the informer as an ADD event. Since `onAdd` only records state and does not schedule cleanup, the pod may receive no further update and therefore remain in memory and not be deleted even when the cleanup strategy is `ALL`.\n\nThe informer already lists existing pods during initialization. Handling terminated pods in `onAdd` closes both gaps and makes the separate cleanup LIST unnecessary.\n\n### How was this patch tested?\n\nAdded `mark terminated application received from pod add event` to verify that a succeeded Spark driver pod received through ADD is registered in the terminated-application cleanup trigger. The test fails without the production change and passes with it.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nYes, using Codex: GPT-5\n\nCloses #7632 from ruanwenjun/fix-k8s-terminated-pod-on-add.\n\nCloses #7632\n\n3fab83539 [ruanwenjun] [K8s] Avoid reflection in pod add event test\nc4c3a0378 [ruanwenjun] [K8s] Handle terminated applications in Spark pod add events\n\nAuthored-by: Wenjun Ruan \u003cwenjun@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "b9f4e6caa8bac3ca579c3aaedd62fe2cab1e6e58",
      "tree": "6063e9c47609571d992bf66eef5f0cf6258cf453",
      "parents": [
        "5c8aa903b8816ef7c1fde8e92dc08822be607195"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Sep 04 11:21:17 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 11:21:17 2026 +0800"
      },
      "message": "[KYUUBI #7711] Bump actions/setup-java from 5 to 6\n\nBumps [actions/setup-java](https://github.com/actions/setup-java) from 5 to 6.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/actions/setup-java/releases\"\u003eactions/setup-java\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edist: Migrate from Zulu Discovery API to Azul Metadata API by \u003ca href\u003d\"https://github.com/jameswald\"\u003e\u003ccode\u003e​jameswald\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1010\"\u003eactions/setup-java#1010\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add .mvn/extensions.xml to Maven cache key pattern by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e with \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1041\"\u003eactions/setup-java#1041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to ESM and upgrade dependencies by \u003ca href\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e​priyagupta108\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1078\"\u003eactions/setup-java#1078\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMap Zulu x86 architecture to i686 for Azul Metadata API by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1079\"\u003eactions/setup-java#1079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRename jdkFile input to jdk-file with deprecated alias by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1083\"\u003eactions/setup-java#1083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInfer distribution from asdf .tool-versions vendor prefix by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1084\"\u003eactions/setup-java#1084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Maven compiler problem matcher for javac diagnostics by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1086\"\u003eactions/setup-java#1086\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: expose cache-primary-key output (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/597\"\u003e#597\u003c/a\u003e) by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1088\"\u003eactions/setup-java#1088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: clarify V6 ESM migration is not a user-facing breaking change by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1090\"\u003eactions/setup-java#1090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport multi-field Java versions like \u003ccode\u003e18.0.1.1\u003c/code\u003e by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1092\"\u003eactions/setup-java#1092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document seeding the Maven cache for plugin dependencies by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1094\"\u003eactions/setup-java#1094\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: clarify Maven cache paths and key hash inputs by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1096\"\u003eactions/setup-java#1096\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport pinning java-version as \u0026quot;latest\u0026quot; by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1093\"\u003eactions/setup-java#1093\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump eslint from 10.6.0 to 10.7.0 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1101\"\u003eactions/setup-java#1101\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump eslint-plugin-n from 18.2.1 to 18.2.2 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1103\"\u003eactions/setup-java#1103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump prettier from 3.9.4 to 3.9.5 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1105\"\u003eactions/setup-java#1105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump actions/checkout from 6 to 7 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1106\"\u003eactions/setup-java#1106\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump \u003ccode\u003e​types/node\u003c/code\u003e from 26.1.0 to 26.1.1 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1104\"\u003eactions/setup-java#1104\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edist: Cover Tencent Kona JDK 25 by \u003ca href\u003d\"https://github.com/johnshajiang\"\u003e\u003ccode\u003e​johnshajiang\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1108\"\u003eactions/setup-java#1108\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1102\"\u003eactions/setup-java#1102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePreserve Maven toolchains across repeated setup-java runs (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1099\"\u003e#1099\u003c/a\u003e) by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1111\"\u003eactions/setup-java#1111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edist: Support Liberica NIK (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/878\"\u003e#878\u003c/a\u003e) by \u003ca href\u003d\"https://github.com/asm0dey\"\u003e\u003ccode\u003e​asm0dey\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1112\"\u003eactions/setup-java#1112\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix template injection (zizmor alert \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/118\"\u003e#118\u003c/a\u003e) in e2e-versions.yml by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e with \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1114\"\u003eactions/setup-java#1114\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix template injection in e2e-versions.yml (zizmor alert \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/122\"\u003e#122\u003c/a\u003e) by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e with \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1120\"\u003eactions/setup-java#1120\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDisable persisted checkout credentials in e2e workflow by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e with \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1115\"\u003eactions/setup-java#1115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: Update recommended configuration for GPG signing by \u003ca href\u003d\"https://github.com/wetneb\"\u003e\u003ccode\u003e​wetneb\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/608\"\u003eactions/setup-java#608\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache Maven and Gradle wrapper distributions separately from the dependency cache by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1097\"\u003eactions/setup-java#1097\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConsolidate cache-dependency-path e2e workflow and add maven/sbt coverage by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1124\"\u003eactions/setup-java#1124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse gpg.passphraseEnvName instead of the deprecated gpg.passphrase server by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1123\"\u003eactions/setup-java#1123\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExtract repeated directory-check assertions into check-dir.sh helper by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1127\"\u003eactions/setup-java#1127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConsolidate duplicate jobs in e2e-versions workflow by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1125\"\u003eactions/setup-java#1125\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse YAML anchors to reduce boilerplate in e2e-versions workflow by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1126\"\u003eactions/setup-java#1126\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdated msft json for now by \u003ca href\u003d\"https://github.com/jmjaffe37\"\u003e\u003ccode\u003e​jmjaffe37\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1129\"\u003eactions/setup-java#1129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocument missing action inputs in README by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1130\"\u003eactions/setup-java#1130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump \u003ccode\u003e​actions/cache\u003c/code\u003e to 6.2.0 by \u003ca href\u003d\"https://github.com/philip-gai\"\u003e\u003ccode\u003e​philip-gai\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1128\"\u003eactions/setup-java#1128\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd an option to disable Java problem matchers by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1133\"\u003eactions/setup-java#1133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: update setup-java examples by \u003ca href\u003d\"https://github.com/HarithaVattikuti\"\u003e\u003ccode\u003e​HarithaVattikuti\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1131\"\u003eactions/setup-java#1131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify credential environment variable inputs by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1134\"\u003eactions/setup-java#1134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump \u003ccode\u003e​typescript-eslint/eslint-plugin\u003c/code\u003e from 8.63.0 to 8.64.0 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1135\"\u003eactions/setup-java#1135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump actions/setup-python from 6 to 7 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1143\"\u003eactions/setup-java#1143\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump fast-xml-parser from 5.9.3 to 5.10.1 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1142\"\u003eactions/setup-java#1142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump \u003ccode\u003e​typescript-eslint/parser\u003c/code\u003e from 8.64.0 to 8.65.0 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1138\"\u003eactions/setup-java#1138\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump lint-staged from 17.0.8 to 17.2.0 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1136\"\u003eactions/setup-java#1136\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1137\"\u003eactions/setup-java#1137\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): fix npm audited vulnerabilities by \u003ca href\u003d\"https://github.com/mhoffrog\"\u003e\u003ccode\u003e​mhoffrog\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1140\"\u003eactions/setup-java#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix formatting issues in README.md by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1144\"\u003eactions/setup-java#1144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemediate npm audit findings and rebuild distributions by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e with \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1145\"\u003eactions/setup-java#1145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSet GRAALVM_HOME for GraalVM distributions by \u003ca href\u003d\"https://github.com/brunoborges\"\u003e\u003ccode\u003e​brunoborges\u003c/code\u003e\u003c/a\u003e with \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-java/pull/1146\"\u003eactions/setup-java#1146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/dd06d9cba3e5552c54d9f8ea23572deb30010f7c\"\u003e\u003ccode\u003edd06d9c\u003c/code\u003e\u003c/a\u003e Prepare documentation for v6 release (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1253\"\u003e#1253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/59b3450628e54f250d3a3bfd413cd68b83bce8ed\"\u003e\u003ccode\u003e59b3450\u003c/code\u003e\u003c/a\u003e chore(deps): combine open Dependabot npm updates (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1252\"\u003e#1252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/b96213d9d21fbd1dd447987fe15dd75fce7f7726\"\u003e\u003ccode\u003eb96213d\u003c/code\u003e\u003c/a\u003e Set default signature verification for supported distributions (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1246\"\u003e#1246\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/1dbac3c9e137b6d4d280bae1ae4e9902bb4ce1b9\"\u003e\u003ccode\u003e1dbac3c\u003c/code\u003e\u003c/a\u003e docs: expose contributing guide to GitHub (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1245\"\u003e#1245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/11741d6cfaf82354eb314633583a9ce43399238b\"\u003e\u003ccode\u003e11741d6\u003c/code\u003e\u003c/a\u003e ci: constrain cache e2e job modes (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1244\"\u003e#1244\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/ff99aa1c87709f29685194226dae7d9b476c594f\"\u003e\u003ccode\u003eff99aa1\u003c/code\u003e\u003c/a\u003e Fix Oracle macOS E2E version (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1243\"\u003e#1243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/416c6d1e8ab4ffb67a533d502fd7b21f70c5d9ee\"\u003e\u003ccode\u003e416c6d1\u003c/code\u003e\u003c/a\u003e Add Red Hat Build of OpenJDK support (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1241\"\u003e#1241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/5f75b27283990add95cd9c4ceaca74d789324bf7\"\u003e\u003ccode\u003e5f75b27\u003c/code\u003e\u003c/a\u003e Add Maven dependency-resolution repositories (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1240\"\u003e#1240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/a42a52cfb590b0682db41c911da5dc7798ba620e\"\u003e\u003ccode\u003ea42a52c\u003c/code\u003e\u003c/a\u003e Add multiple Maven server credentials (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1239\"\u003e#1239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-java/commit/fb4abd7a7075173ac733c41f723ac0c47c41ad17\"\u003e\u003ccode\u003efb4abd7\u003c/code\u003e\u003c/a\u003e test: cover JDK 26 from SDKMAN (\u003ca href\u003d\"https://redirect.github.com/actions/setup-java/issues/1238\"\u003e#1238\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/actions/setup-java/compare/v5...v6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/setup-java\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d5\u0026new-version\u003d6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7711 from dependabot[bot]/dependabot/github_actions/actions/setup-java-6.\n\nCloses #7711\n\n6b13baaf2 [dependabot[bot]] Bump actions/setup-java from 5 to 6\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "5c8aa903b8816ef7c1fde8e92dc08822be607195",
      "tree": "a1ecfd3765e76d0fed3cfbb36ec4935ebccb6ee0",
      "parents": [
        "2ac0f651960dc19c109397288cdf13c99b2df568"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Sep 04 11:19:11 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 11:19:11 2026 +0800"
      },
      "message": "[KYUUBI #7665] Bump docker/setup-buildx-action from 4.2.0 to 4.3.0\n\nBumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.2.0 to 4.3.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/docker/setup-buildx-action/releases\"\u003edocker/setup-buildx-action\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.95.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/595\"\u003edocker/setup-buildx-action#595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/600\"\u003edocker/setup-buildx-action#600\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.3.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/585\"\u003edocker/setup-buildx-action#585\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/598\"\u003edocker/setup-buildx-action#598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/601\"\u003edocker/setup-buildx-action#601\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/setup-buildx-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/37fe631027851001ddb9b187196cc803df7f5f0e\"\u003e\u003ccode\u003e37fe631\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/issues/595\"\u003e#595\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-to...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/b5c4f91922681cc7c58d15ab7838986951f09d19\"\u003e\u003ccode\u003eb5c4f91\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/3e93b637c6430ba8fa896fad44d3aa6821899d63\"\u003e\u003ccode\u003e3e93b63\u003c/code\u003e\u003c/a\u003e build(deps): bump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.95.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/e527031b32c86649307d5d492506855f90470604\"\u003e\u003ccode\u003ee527031\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/issues/600\"\u003e#600\u003c/a\u003e from docker/dependabot/npm_and_yarn/brace-expansion-1...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/c68814b33cb66f1f7538e546190d410ae557a640\"\u003e\u003ccode\u003ec68814b\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/3f891b01bd5012a434f582800366972569aa1886\"\u003e\u003ccode\u003e3f891b0\u003c/code\u003e\u003c/a\u003e build(deps): bump brace-expansion from 1.1.13 to 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/787db26fcde8ddcabd49a81472318028f7113962\"\u003e\u003ccode\u003e787db26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/issues/585\"\u003e#585\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/f7793687c711790ca336bd4934f1b1bf5f778e17\"\u003e\u003ccode\u003ef779368\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/7d5e60413489a33d28077e11d71c668580cfaf8d\"\u003e\u003ccode\u003e7d5e604\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.0 to 5.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/292c2fb3837a12d3ac2d1e47bbc5c00712bad939\"\u003e\u003ccode\u003e292c2fb\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/issues/590\"\u003e#590\u003c/a\u003e from docker/dependabot/github_actions/actions/setup-n...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/docker/setup-buildx-action/compare/bb05f3f5519dd87d3ba754cc423b652a5edd6d2c...37fe631027851001ddb9b187196cc803df7f5f0e\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddocker/setup-buildx-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.2.0\u0026new-version\u003d4.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7665 from dependabot[bot]/dependabot/github_actions/docker/setup-buildx-action-4.3.0.\n\nCloses #7665\n\nc15daa839 [dependabot[bot]] Bump docker/setup-buildx-action from 4.2.0 to 4.3.0\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "2ac0f651960dc19c109397288cdf13c99b2df568",
      "tree": "7e5f5afd014b87e1ce8a5d576105c8104e81c844",
      "parents": [
        "8cafd873c11323310d306481368290780a37d5b7"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Fri Sep 04 11:17:25 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Sep 04 11:17:25 2026 +0800"
      },
      "message": "[KYUUBI #7697] Reject hiddenImpl on a DynConstructors builder without a base class\n\n### Why are the changes needed?\n\nCloses #7697.\n\n`DynConstructors.builder()` leaves `baseClass` null, and the zero-argument `hiddenImpl(Class\u003c?\u003e... types)` forwarded that field into `hiddenImpl(Class, Class...)`, which calls `targetClass.getDeclaredConstructor(types)` and catches only `SecurityException` and `NoSuchMethodException`. The null escaped as a bare NPE from inside the builder chain, with no mention of a missing base class. A builder that never named a class asking for a hidden constructor in its base class has no correct reading, so the patch rejects the call. AGENTS.md asks for a throw on unsupported usage rather than a silent skip, and `IllegalStateException` is what this file already uses when a call does not fit the receiver\u0027s state: `Ctor.bind` throws it for \"Cannot bind constructors\".\n\nA loose `Class` argument does not reach that overload: `builder().hiddenImpl(Foo.class)` binds `hiddenImpl(Class, Class...)` with `Foo` as the target. What reaches it is a call with no arguments, or one passing an explicit `Class\u003c?\u003e[]`, which is what a Scala `: _*` splat compiles to and is the shape `ReflectUtils` already uses against the `DynMethods` builder.\n\nNothing in Kyuubi reaches it either. `hiddenImpl()` has no caller outside the new tests, and the twenty-odd production sites that build without a class all continue with one of the `impl` overloads. This is hygiene on a retained upstream API, not a field failure being fixed.\n\nThere is a second option a maintainer may prefer: drop the overload, as iceberg-common did in 1.7.0 (apache/iceberg#10818) after deprecating it in 1.6.0 over the same varargs conflict. That is not free, though: a caller passing an explicit array, or a Scala splat, binds here today, so removal is a source break for them even if nothing in this repository notices. Keeping the overload means carrying this guard and its explanation indefinitely. Removing a public method from a published module is a maintainer call rather than mine; #7689 put the same choice to reviewers for `DynMethods.ctorImpl`.\n\nTwo scope notes. The guard sits below the `ctor !\u003d null` short-circuit that opens every other `impl` and `hiddenImpl` overload, so a class-less builder that already matched keeps working: `builder().impl(\"java.lang.String\").hiddenImpl()` builds before this patch and still builds after. Placed above the short-circuit it would start throwing. And the generic `Cannot find constructor for null` that a class-less builder reports when all its name-based lookups miss is untouched; `hiddenImpl()` no longer reaches it, and improving that message belongs with the `problems` diagnostics work.\n\n### How was this patch tested?\n\nTwo tests in `DynConstructorsTest`, one per half of the contract.\n\n`testHiddenImplWithoutBaseClassFailsFast` asserts that `builder().hiddenImpl()` throws `IllegalStateException` whose message says the builder has no base class. Against `origin/master`\u0027s `DynConstructors` it goes red with `Unexpected exception type thrown, expected: \u003cjava.lang.IllegalStateException\u003e but was: \u003cjava.lang.NullPointerException\u003e`, that NPE being `Cannot invoke \"java.lang.Class.getDeclaredConstructor(java.lang.Class[])\" because \"targetClass\" is null`.\n\n`testHiddenImplWithoutBaseClassIsSkippedOnceFound` builds `builder().impl(\"java.lang.String\").hiddenImpl().buildChecked()` and asserts the constructed class is `String`. It pins the guard\u0027s placement rather than restating the first test: with the null check moved above the `ctor !\u003d null` short-circuit, it fails with `IllegalStateException`.\n\n```\nbuild/mvn -o test -pl kyuubi-util -am -DwildcardSuites\u003dnone -Dtest\u003dDynConstructorsTest\nbuild/mvn -o spotless:check -pl kyuubi-util\n```\n\n6 of 6 green and spotless clean. Both revert checks above ran against a copy of the pre-fix class compiled outside the repository.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nThis patch had conflicts when merged, resolved by\nCommitter: Cheng Pan \u003cchengpan@apache.org\u003e\n\nCloses #7698 from LuciferYang/kyuubi-util-dynconstructors-hiddenimpl-nullguard.\n\nCloses #7697\n\nc64985767 [yangjie01] [KYUUBI #7697] Reject hiddenImpl on a DynConstructors builder without a base class\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "8cafd873c11323310d306481368290780a37d5b7",
      "tree": "15a221604a3bdac341ea94bc49480d1a40d9b6a9",
      "parents": [
        "5c80e74bcef6727356d2996de6f4bf792bdff1cc"
      ],
      "author": {
        "name": "maomaodev",
        "email": "lifumao@tencent.com",
        "time": "Thu Sep 03 14:47:14 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Sep 03 14:47:14 2026 +0800"
      },
      "message": "[KYUUBI #7664][DOC] Reformat and improve docs for KSHC\n\n### Why are the changes needed?\n\n1. Reformat KSHC docs from RST to Markdown, as described in the issue https://github.com/apache/kyuubi/issues/7434.\n2. Enrich the description for KSCH.\n\n### How was this patch tested?\n\nTested by building the documentation and comparing the pages against the live site:\n```\nopen https://kyuubi.readthedocs.io/en/master/connector/spark/hive.html\nopen _build/html/connector/spark/hive.html\n```\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: DeepSeek-V4-Pro\n\nCloses #7667 from maomaodev/kyuubi-7664.\n\nCloses #7664\n\n85a387162 [Cheng Pan] Update docs/connector/spark/hive.md\nc3edb02cd [Cheng Pan] Update docs/connector/spark/hive.md\nd8ded95cb [lifumao] [KYUUBI #7664][DOC] Reformat and improve docs for KSHC\nd8074cfc3 [lifumao] [KYUUBI #7664][DOC] Reformat and improve docs for KSHC\nb8dc3b759 [lifumao] [KYUUBI #7664][DOC] Reformat and improve docs for KSHC\n207436d9a [lifumao] [KYUUBI #7664][DOC] Reformat and improve docs for KSHC\n85a67d0c4 [lifumao] [KYUUBI #7664][DOC] Reformat and improve docs for KSHC\n\nLead-authored-by: maomaodev \u003clifumao@tencent.com\u003e\nCo-authored-by: Cheng Pan \u003cpan3793@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "5c80e74bcef6727356d2996de6f4bf792bdff1cc",
      "tree": "13d4bbae291f05de1cb336e881e73a2f7b1a64ea",
      "parents": [
        "ccca849416acdfab9cf4aed20d820ef701288ec5"
      ],
      "author": {
        "name": "Xuan-Bach Tran",
        "email": "tranxuanbach1@gmail.com",
        "time": "Thu Sep 03 14:45:36 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Sep 03 14:45:36 2026 +0800"
      },
      "message": "[KYUUBI #7293][KUBERNETES] Initialize in-cluster client automatically\n\n### Why are the changes needed?\n\nWhen Kyuubi Server runs inside Kubernetes without\n`kyuubi.kubernetes.client.initialize.list`, no Kubernetes client or informer is initialized\nat startup. As a result, terminated Spark driver pods can remain after their retention period\neven though cleanup is enabled.\n\nInitialize the configured namespace automatically from the in-cluster environment while\npreserving the explicit initialization list as the higher-priority configuration. Outside\nKubernetes, the existing empty-list behavior is unchanged.\n\nCloses #7293.\n\n### How was this patch tested?\n\n- `dev/gen/gen_all_config_docs.sh`\n- `dev/reformat`\n- `build/mvn test -pl kyuubi-server -am -Pspark-provided,hive-provided,flink-provided -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.engine.KubernetesApplicationOperationSuite`\n- `build/mvn scalastyle:check -pl kyuubi-common,kyuubi-server -am -Pflink-provided,hive-provided,spark-provided,spark-3.5,tpcds`\n- `helm lint charts/kyuubi`\n- `helm template review-test charts/kyuubi --show-only templates/kyuubi-role.yaml`\n\nThe focused suite covers no automatic initialization outside Kubernetes, automatic\nin-cluster initialization with non-empty Kubernetes service environment variables, and\nexplicit-list precedence. The rendered Role grants pod and service informer permissions.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: OpenAI Codex\n\nCloses #7710 from miaht94/kyuubi-7293-initialize-in-cluster-client.\n\nCloses #7293\n\n5b0348768 [Xuan Bach Tran] [KYUUBI #7293][KUBERNETES] Fix in-cluster detection calls\ncc3e48799 [Xuan Bach Tran] [KYUUBI #7293][KUBERNETES] Reuse in-cluster detection\n46f4649af [Xuan Bach Tran] [KYUUBI #7293][KUBERNETES] Clarify namespace configuration\nfacb6afad [Xuan Bach Tran] [KYUUBI #7293][KUBERNETES] Relax in-cluster detection\n5181e49a1 [Xuan Bach Tran] [KYUUBI #7293][KUBERNETES] Address in-cluster initialization review\n77cf9bce6 [Xuan Bach Tran] [KYUUBI #7293][KUBERNETES] Fix configuration line length\n6860c6dad [Xuan Bach Tran] [KYUUBI #7293][KUBERNETES] Initialize in-cluster client automatically\n\nAuthored-by: Xuan-Bach Tran \u003ctranxuanbach1@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "ccca849416acdfab9cf4aed20d820ef701288ec5",
      "tree": "8f835b329dc93dd04396ccbf3b00ed3aae9e1cc1",
      "parents": [
        "084a14f9d4c0f0a5e017753143ca96514058cba2"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "pan3793@gmail.com",
        "time": "Thu Sep 03 10:49:40 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Sep 03 10:49:40 2026 +0800"
      },
      "message": "[KYUUBI #7654] [INFRA] Improve pull request merge tool\n\n### Why are the changes needed?\n\nThis ports several useful improvements from Spark\u0027s merge tool, adapted to Kyuubi\u0027s GitHub-only workflow. It makes merges and backports safer, more traceable, and less error-prone for committers.\n\n- Suggest backport branches in descending release order, such as `branch-1.12`, then `branch-1.11`, and skip branches already picked.\n- Post a merge summary comment listing every branch and full commit link where the change landed.\n- Normalize confirmation prompts to `(y/N)`.\n- Detect already-merged PRs more robustly, including reopened PRs, merges referenced by commits, and merge footers containing linked-issue and commit-summary paragraphs.\n- Explicitly close PRs merged into non-default branches when GitHub does not auto-close them, while leaving default-branch auto-close to GitHub.\n- Validate PR numbers, yes/no answers, and backport branch names before proceeding.\n- Derive lead and co-authors from GitHub-linked commits, defaulting the lead author to the PR author.\n- Report post-merge comment and close failures without aborting remaining bookkeeping, and skip unauthenticated close requests.\n- Apply Black formatting to the merge script.\n\n### How was this patch tested?\n\n- `python3 -m py_compile dev/merge_kyuubi_pr.py`\n- `python3 -m doctest dev/merge_kyuubi_pr.py`\n- `black --check dev/merge_kyuubi_pr.py`\n- `git diff --check`\n- Verified the real merge message from PR #7116 is recognized by the referenced-event fallback.\n- Verified missing-token and simulated network-failure paths for closing and commenting.\n\n### Was this patch assisted by generative AI tooling?\n\n`Assisted-by: Codex:GLM 5.3`\n\nCloses #7654 from pan3793/merge-pr-script.\n\nCloses #7654\n\n25dcf42c2 [Cheng Pan] [INFRA] Harden post-merge GitHub calls\n4a7759977 [Cheng Pan] [INFRA] Recognize merge footers with commit summaries\nab89744f2 [Cheng Pan] [INFRA] Use GitHub data for merge authorship\nb85920c9c [Cheng Pan] [INFRA] Close branch-target pull requests explicitly\n5fdb9ed68 [Cheng Pan] [INFRA] Validate merge script inputs and branches\n922beb31e [Cheng Pan] [INFRA] Detect merged pull requests robustly\n76e7a6eb7 [Cheng Pan] [INFRA] Format merge script with Black\naacade02c [Cheng Pan] [INFRA] Post merge summaries on pull requests\nb488ca3e2 [Cheng Pan] [INFRA] Suggest next backport branch in merge script\n7911b96bd [Cheng Pan] [INFRA] Normalize merge script confirmation prompts\n\nAuthored-by: Cheng Pan \u003cpan3793@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "084a14f9d4c0f0a5e017753143ca96514058cba2",
      "tree": "32f637e12fec087bc03a2c3eb9941196c0461652",
      "parents": [
        "6ac41a4c7ea281c1a2a8bbb26b64a82a829ca9dc"
      ],
      "author": {
        "name": "Mohamed",
        "email": "81839170+moelhoussein@users.noreply.github.com",
        "time": "Wed Sep 02 19:17:53 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Wed Sep 02 19:17:53 2026 +0800"
      },
      "message": "[KYUUBI #7684][SPARK] Keep the python operation context private to the operation\n\nFixes #7684.\n\n### Why are the changes needed?\n\nPython operations of one session all run on a single pinned Py4J thread, and Spark local properties are thread local, so the per-operation context in `ExecutePython.withLocalProperties` is not private to the operation the way it is for SQL. Two problems follow from that.\n\nThe teardown clears `kyuubi.session.user` with the empty string, while `SparkOperation.withLocalProperties` clears with `null`. `AuthZUtils.getAuthzUgi` skips the property only when it is null, so an empty user reaches `UserGroupInformation.createRemoteUser` and fails with `IllegalArgumentException: Null user`. With `kyuubi.session.user.sign.enabled` it fails earlier, as `AccessControlException: Invalid user identifier []`. The empty string was already the outlier in its own method, since the same `finally` block clears the signing keys with `null` through `clearSessionUserSign`. Null is not what saves the signed path, where `verifyKyuubiSessionUser` treats null as blank and reports `Invalid user identifier [null]` just the same. There the lock is what keeps a concurrent operation from reading a cleared context.\n\n`SessionPythonWorker.runCode` takes the worker lock per call, so the 7 to 12 internal round-trips that apply and clear the context are not atomic. Another operation of the same session can set or clear these properties in between, which loses the session user and also lets one operation\u0027s `setJobGroup` tag another operation\u0027s jobs, so its `cancelJobGroup` cancels them.\n\nThis patch clears with `null` and holds the worker lock across the whole body of `withLocalProperties`, which substitutes for the isolation the SQL path gets from running each operation on its own thread. Throughput should be unaffected, because `runCode(statement)` already holds the lock for the whole execution and same-session operations are already serialized behind it. Cancellation is unaffected, because `ExecutePython.cleanup` interrupts the worker with a signal and never takes this lock.\n\n### How was this patch tested?\n\nTwo new tests in `ExecutePythonSuite`, both of which fail on master. The first runs an operation and then probes the worker thread with a bare `runCode`, which observes exactly what the teardown left behind. Master leaves `\u0027\u0027`, so it fails with `\"[\u0027\u0027]\" did not equal \"[None]\"`. The second holds an operation\u0027s context and checks that a second thread cannot reach the worker. On master it can, so it fails with `otherOperationRanCode.get() was true`.\n\nBoth tests start the python worker inside the test JVM, where its PySpark reaches this JVM\u0027s Spark classes over Py4J, so they cancel when the PySpark under `SPARK_HOME` does not match the engine\u0027s Spark. That is the case in the jobs that verify a Spark 3.5 build on a Spark 4.x binary, which carry no 3.5 PySpark to point the worker at. `PySparkTests` still covers python in those jobs, since it drives an engine from `SPARK_HOME` and both sides match there.\n\nLocal results are `ExecutePythonSuite` 2 of 2 and `PySparkTests` 7 of 8. The single failure is `executePython support timeout`, which also fails on unmodified master in the same environment (one pass in six runs on master, zero in six on this branch). It fails in the second half of that test, where `bad_code` after a timeout returns no error, which points at response handling on the worker stream after the interrupt rather than at the context.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7685 from moelhoussein/python-session-user-race.\n\nCloses #7684\n\nda9e7d9e2 [MElHoussein] [KYUUBI #7684][SPARK] Gate the python tests on the SPARK_HOME PySpark version\n1fef42e06 [MElHoussein] [KYUUBI #7684][SPARK] Add regression tests for the python operation context\ned177ee47 [MElHoussein] [KYUUBI #7684][SPARK] Clear the python operation context like SQL does\n\nLead-authored-by: Mohamed \u003c81839170+moelhoussein@users.noreply.github.com\u003e\nCo-authored-by: MElHoussein \u003cMElHoussein@geico.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "6ac41a4c7ea281c1a2a8bbb26b64a82a829ca9dc",
      "tree": "17673448b5b749b1a89a9c60041224640022e0b3",
      "parents": [
        "62d040cbf1e8909bb35035d152101c5ed5cd3281"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Wed Sep 02 18:18:50 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Wed Sep 02 18:18:50 2026 +0800"
      },
      "message": "[KYUUBI #7686][UTIL] Treat strongly-encapsulated members as candidate misses in hiddenImpl\n\n### Why are the changes needed?\n\nCloses #7686.\n\n`setAccessible` on a member of a package that is not open throws `java.lang.reflect.InaccessibleObjectException`. That happens since JDK 9 for named modules, and by default from the unnamed module since JDK 16. It is a `RuntimeException` that none of the three `hiddenImpl` builders caught, so one inaccessible candidate escaped the builder and aborted the whole lookup chain instead of falling through to the next implementation. That breaks the `hiddenImpl(...).impl(...)` pattern `ReflectUtils` uses throughout the engines, where the public-lookup fallback exists for exactly the case where the hidden lookup does not work.\n\nThe exception type does not exist on Java 8, which this module compiles against, so the catch matches it by class name and rethrows anything else unchanged.\n\n`DynFields` also records the exception with the candidate, so the `module ... does not \"opens ...\"` text that names the package to open survives into the `Cannot find field from candidates: ...` failure. Single-candidate call sites have no fallback chain to save and would otherwise be left with a bare cannot-find error that reads like a missing field; `ExecutePython`\u0027s `ProcessImpl.pid` lookup is one of them. `DynMethods.Builder` has no per-candidate structure to record into, which its javadoc now states. Aggregating diagnostics there is left to a follow-up.\n\nNeither upstream copy catches this exception either. parquet-common and iceberg-common both catch only `SecurityException` plus the `NoSuchMethod`/`NoSuchField` variant, on the releases these files were copied from and on current master, so this is a divergence Kyuubi carries deliberately and each `hiddenImpl` javadoc records it.\n\n### How was this patch tested?\n\nNew tests in all three test classes, each branching on the running JDK because the behavior is version-dependent.\n\n`testHiddenImplHandlesStronglyEncapsulatedMethods`, `testHiddenImplTreatsStronglyEncapsulatedFieldsAsMisses` and `testHiddenImplHandlesStronglyEncapsulatedConstructors`: on JDK 16+ the hidden lookup of a `java.math` member must fail as a candidate miss instead of letting the exception escape; on JDK 8 through 15 the same lookup still succeeds. `DynConstructorsTest` also asserts the `InaccessibleObjectException` is among the suppressed problems, and `DynFieldsTest` asserts the recorded candidate carries it.\n\n`testHiddenImplPropagatesUnrelatedFailures` in all three: a `RuntimeException` that is not `InaccessibleObjectException` still escapes the builder. These pass before and after the change. They are here to stop the new catch from being widened into a catch-all, not to cover the fix.\n\n`java.math` is the probe package because the surefire JVM opens `java.lang` but leaves `java.math` closed.\n\nRan on Zulu 17.0.18: `build/mvn -o test -pl kyuubi-util -am -DwildcardSuites\u003dnone` gives 39/39 green, and `build/mvn -o spotless:check -pl kyuubi-util` is clean. Reverting the `DynFields` candidate recording turns the `InaccessibleObjectException` assertion in `DynFieldsTest` red, so that assertion fails if the recording goes away. The JDK 8 leg of these tests runs in CI\u0027s `scala-test` job.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7687 from LuciferYang/kyuubi-util-reflect-hiddenimpl-inaccessible.\n\nCloses #7686\n\nb6914f152 [yangjie01] [KYUUBI #7686][UTIL] Treat strongly-encapsulated members as candidate misses in hiddenImpl\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "62d040cbf1e8909bb35035d152101c5ed5cd3281",
      "tree": "07fda5d46c826f15e2fc76dcee604b02672dfec9",
      "parents": [
        "445efc825eecfa987f9b810789174e1f9b28e75d"
      ],
      "author": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Wed Sep 02 18:16:35 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Wed Sep 02 18:16:35 2026 +0800"
      },
      "message": "[KYUUBI #7679] [DOC] Escape ampersand in LDAP group mapping example\n\n### Why are the changes needed?\nThe change is needed to fix the following warning during the documentation build process:\n```\n./docs/deployment/engine_share_level.md:156: WARNING: Lexing literal_block\n\u0027\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping\u003c/name\u003e\\n  \u003cvalue\u003eorg.apache.hadoop.security.LdapGroupsMapping\u003c/value\u003e\\n\u003c/property\u003e\\n\\n\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping.ldap.url\u003c/name\u003e\\n  \u003cvalue\u003eldap://localhost:389\u003c/value\u003e\\n\u003c/property\u003e\\n\\n\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping.ldap.base\u003c/name\u003e\\n  \u003cvalue\u003edc\u003dexample,dc\u003dcom\u003c/value\u003e\\n\u003c/property\u003e\\n\\n\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping.ldap.bind.user\u003c/name\u003e\\n  \u003cvalue\u003ecn\u003dManager,dc\u003dexample,dc\u003dcom\u003c/value\u003e\\n\u003c/property\u003e\\n\\n\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping.ldap.bind.password\u003c/name\u003e\\n  \u003cvalue\u003eexample\u003c/value\u003e\\n\u003c/property\u003e\\n\\n\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping.ldap.search.filter.user\u003c/name\u003e\\n  \u003cvalue\u003e(\u0026(objectClass\u003dposixAccount)(cn\u003d{0}))\u003c/value\u003e\\n\u003c/property\u003e\\n\\n\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping.ldap.search.filter.group\u003c/name\u003e\\n  \u003cvalue\u003e(objectClass\u003dposixGroup)\u003c/value\u003e\\n\u003c/property\u003e\\n\\n\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping.ldap.search.attr.member\u003c/name\u003e\\n  \u003cvalue\u003ememberuid\u003c/value\u003e\\n\u003c/property\u003e\\n\\n\u003cproperty\u003e\\n  \u003cname\u003ehadoop.security.group.mapping.ldap.search.attr.group.name\u003c/name\u003e\\n  \u003cvalue\u003ecn\u003c/value\u003e\\n\u003c/property\u003e\\n\u0027\n as \"xml\" resulted in an error at token: \u0027\u0026\u0027. Retrying in relaxed mode. [misc.highlighting_failure]\n```\n\nThe default `core-default.xml` uses `\u0026amp;` instead of `\u0026` character, see [here](https://github.com/apache/hadoop/blob/c48027aee9adedbcfa574647b5e06d851ca6f55b/hadoop-common-project/hadoop-common/src/main/resources/core-default.xml#L531-L532).\n\n### How was this patch tested?\nTesting by building the documentation and checking there is no warning:\n```shell\nmake clean html\n```\n\nThe `Share Level of Kyuubi Engines` page after applying the fix:\n\u003cimg width\u003d\"1272\" height\u003d\"883\" alt\u003d\"image\" src\u003d\"https://github.com/user-attachments/assets/0e269086-7dab-4a3b-abe4-e27c669e89fb\" /\u003e\n\n### Was this patch assisted by generative AI tooling?\nNo\n\nCloses #7679 from dnskr/doc-escape-ampersand-in-LDAP-group-mapping-example.\n\nCloses #7679\n\n50aec34cb [Denis Krivenko] [DOC] Escape ampersand in LDAP group mapping example\n\nAuthored-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "445efc825eecfa987f9b810789174e1f9b28e75d",
      "tree": "885da6c87e91b6df2be1bdb716c5f7c2954da6d6",
      "parents": [
        "804c00239815d3b7eece5c4c8bb8f6263063beff"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "pan3793@gmail.com",
        "time": "Wed Sep 02 17:51:27 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Wed Sep 02 17:51:27 2026 +0800"
      },
      "message": "[KYUUBI #7653] Cache reflection method lookups in Spark engine\n\n### Why are the changes needed?\nRepeated `DynMethods` lookups occur on hot paths for Hive result serialization, Spark UI rendering, and URI construction. This caches the resolved methods so reflection lookup happens once instead of on every call.\n\n### How was this patch tested?\n- `dev/reformat`\n- `build/mvn test -pl externals/kyuubi-spark-sql-engine -am -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.engine.spark.schema.RowSetSuite`\n- `build/mvn test -pl externals/kyuubi-spark-sql-engine -am -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.engine.spark.KyuubiSparkUtilSuite`\n- `build/mvn test -Pspark-4.0 -Pscala-2.13 -pl externals/kyuubi-spark-sql-engine -am -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.engine.spark.KyuubiSparkUtilSuite`\n\n### Was this patch authored or co-authored using generative AI tooling?\nYes. Assisted-by: GLM 5.3\n\nCloses #7653 from pan3793/kyuubi-rowset-bound-method.\n\nCloses #7653\n\ncc5bafc60 [Cheng Pan] Cache Spark reflection methods\nadcae0cd8 [Cheng Pan] Cache HiveResult reflection methods\n\nAuthored-by: Cheng Pan \u003cpan3793@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "804c00239815d3b7eece5c4c8bb8f6263063beff",
      "tree": "a5c44c746a5a52d54973021e9be68ac728f9bf51",
      "parents": [
        "f44fbedcbd3a75a10ea712ea8c6b70eb30361fab"
      ],
      "author": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Tue Sep 01 21:30:13 2026 +0200"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Tue Sep 01 21:30:13 2026 +0200"
      },
      "message": "[KYUUBI #7434][DOC] Reformat quick start docs from RST to Markdown\n\n### Why are the changes needed?\nThe changes are needed to unify the format used for documentation, as described in the issue https://github.com/apache/kyuubi/issues/7434.\n\nThe PR also:\n- Removes `sphinx_markdown_tables` extension to fix variable substitution in tables.\n- Fixes cross-references to `quick_start` pages.\n- Fixes `building kyuubi` link.\n\nThere is a slight difference between the configuration table representation on the `Getting Started` page and the Maven dependency declaration on the `Getting Started with Hive JDBC` page because variable substitution doesn\u0027t work inside code blocks, but it shouldn\u0027t affect user experience.\n\nThis PR **does not** change page contents to ensure an easier review of the migration.\n\n### How was this patch tested?\nTested by building the documentation and comparing the pages against the live site:\n```\nmake clean html\n\nopen https://kyuubi.readthedocs.io/en/master/quick_start/index.html\nopen _build/html/quick_start/index.html\n\nopen https://kyuubi.readthedocs.io/en/master/quick_start/quick_start.html\nopen _build/html/quick_start/quick_start.html\n\nopen https://kyuubi.readthedocs.io/en/master/quick_start/quick_start_with_jdbc.html\nopen _build/html/quick_start/quick_start_with_jdbc.html\n```\n\n### Was this patch assisted by generative AI tooling?\nAssisted-by: Qwen Coder\n\nCloses #7666 from dnskr/rst-to-md-quick-start-pages.\n\nCloses #7434\n\nde46d285e [Denis Krivenko] [DOC] Reformat quick start docs from RST to Markdown\n\nAuthored-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "f44fbedcbd3a75a10ea712ea8c6b70eb30361fab",
      "tree": "96ffc19c47349ad032f660434e4b8166e94d4717",
      "parents": [
        "8606354ed76932c3e7ebd03ffd7558051f8954a3"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Mon Aug 31 21:08:36 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 31 21:08:36 2026 +0800"
      },
      "message": "[KYUUBI #7699] Skip the argument copy in invokeChecked when the argument count already matches\n\n### Why are the changes needed?\n\nCloses #7699.\n\n`UnboundMethod.invokeChecked` copied the argument array for every fixed-arity call, including the case where `args.length` already equalled the method\u0027s parameter count. There the copy hands `Method.invoke` the same element references and, because `Arrays.copyOfRange(T[], int, int)` preserves the source array\u0027s runtime component type, the same carrier type; it is then discarded. The varargs branch has always passed the caller\u0027s array through, so this extends the same pass-through to the one case where the copy changes nothing.\n\nThis is one array allocation per call removed, and nothing more. There is no benchmark and the hotness of the path is unmeasured. The hottest in-repo caller is `RowSet.toHiveString`. It runs per column per row inside a UDF, but on the default `-Pspark-3.5` profile it passes 4 arguments to the 3-argument `HiveResult.toHiveString`, so it takes the truncating branch and gains nothing. It reaches the exact-arity branch only on Spark 4.0 and later.\n\nThe copy stays for the other two cases, and both are load-bearing. It drops extra arguments, which `HiveConnectorUtils.newStorageFormat` and `copyStorageFormat` rely on to call the 6-argument `CatalogStorageFormat.apply` with 7 arguments on Spark below 4.2; a comment above that call site states the dependency. And it null-pads a short argument list, so a caller that passes too few reaches the target with nulls rather than an exception. That is why the guard has to be `args.length \u003d\u003d argLength`. The two obvious edits each break one branch: passing through when the list is longer stops the truncation, and copying only when it is longer, which is what `DynConstructors.newInstanceChecked` does, stops the padding. Note the polarity differs between the two classes, since `DynConstructors` guards the copy while this guards the pass-through. The condition carries a comment saying so.\n\nBoth upstream copies still copy unconditionally: iceberg-common has the bare `if (argLength \u003c 0)`, and so does parquet-common. This is therefore a deliberate Kyuubi-local divergence in an already-forked file. Behaviour is preserved, so a future resync from upstream would lose the fast path and nothing else.\n\n### How was this patch tested?\n\nNothing observable changes at equal arity, so no test can distinguish this patch from its revert. For a fixed-arity method the argument array is only the reflection carrier: `Method.invoke` passes `args[i]` to the callee and never `args` itself, so the carrier\u0027s identity cannot reach user code. Any assertion written against the change would pass with it reverted, which AGENTS.md rules out.\n\nWhat the patch does add is coverage for the two branches it deliberately preserves, neither of which had any:\n\n- `testInvokeDropsExtraArgumentsForFixedArity` invokes a 2-argument method with 3 arguments and asserts the third is dropped, which is the behaviour `HiveConnectorUtils` depends on.\n- `testInvokePadsMissingArgumentsWithNull` invokes it with 1 argument and asserts the target sees a trailing null.\n\nBoth pass before and after this patch, since the old code copied unconditionally and so did both things. They are not vacuous with respect to the guard, though. Changing `\u003d\u003d` to `\u003e` makes the first fail with `IllegalArgumentException: wrong number of arguments`; changing it to `\u003c\u003d`, which is the `DynConstructors`-equivalent shape, makes the second fail the same way. Together they pin `\u003d\u003d` as the only guard that keeps both branches working.\n\nEquivalence itself was checked by running a probe against classes built before and after the change: exact arity, extra arity, short arity, a varargs callee, and a typed `String[]` carrier all produce byte-identical results. That is a regression check on one JDK. It does not prove `Method.invoke` never writes to the array, an assumption the varargs branch has made since this file was copied from parquet-common.\n\n```\nbuild/mvn -o test -pl kyuubi-util -am -DwildcardSuites\u003dnone -Dtest\u003dDynMethodsTest\nbuild/mvn -o spotless:check -pl kyuubi-util\n```\n\n11 of 11 green and spotless clean.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7700 from LuciferYang/kyuubi-util-dynmethods-invokechecked-copy.\n\nCloses #7699\n\n6265b8b1f [yangjie01] [KYUUBI #7699] Skip the argument copy in invokeChecked when the argument count already matches\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "8606354ed76932c3e7ebd03ffd7558051f8954a3",
      "tree": "b8b66aea73c39923f0f66140c88d27ae7c450881",
      "parents": [
        "41521f7b9e5c8094ef0ee05187f86a3fc308d9a3"
      ],
      "author": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Mon Aug 31 14:42:49 2026 +0200"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Mon Aug 31 14:42:49 2026 +0200"
      },
      "message": "[KYUUBI #7434][DOC] Reformat client docs from RST to Markdown\n\n### Why are the changes needed?\nThe changes are needed to unify the format used for documentation, as described in the issue https://github.com/apache/kyuubi/issues/7434.\n\nThe PR also:\n- Removes empty pages:\n   - docs/client/advanced/configurations.rst\n   - docs/client/advanced/features/engine_resources.rst\n   - docs/client/advanced/features/engine_share_level.rst\n   - docs/client/advanced/features/engine_ttl.rst\n   - docs/client/advanced/features/engine_type.rst\n   - docs/client/advanced/features/scala.rst\n   - docs/client/advanced/logging.rst\n- Simplifies `Client Commons` menu: remove `features` directory and move `Plan Only Execution Mode` page up.\n- Increases `myst_heading_anchors` to 4 to fix the following warning:\n  ```\n  ./docs/client/rest/rest_api.md:281: WARNING: \u0027myst\u0027 cross-reference target not found: \u0027kyuubioperationevent\u0027 [myst.xref_missing]\n  ```\n- Rename  `Configure Kerberos for clients to Access Kerberized Kyuubi` to `Kerberos Configuration` and remove the page from `Security / Authentication ` index page.\n- Fixed cross-references.\n\nThe PR **does not** change page contents to ensure an easier review of the migration.\n\n### How was this patch tested?\nTested by building the documentation and comparing the pages against the live site.\n\n### Was this patch assisted by generative AI tooling?\nAssisted-by: Qwen Coder\n\nCloses #7696 from dnskr/rst-to-md-client-pages.\n\nCloses #7434\n\n1a4745c78 [Denis Krivenko] [DOC] Reformat quick start docs from RST to Markdown\n575b2aa2c [Denis Krivenko] [DOC] Reformat client docs from RST to Markdown\n\nAuthored-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "41521f7b9e5c8094ef0ee05187f86a3fc308d9a3",
      "tree": "b95ebadf0f2027442add029a896687aa8ce628cd",
      "parents": [
        "a45637e93e9fdf247ad08b322aedb2807235f9f2"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Mon Aug 31 17:31:48 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 31 17:31:48 2026 +0800"
      },
      "message": "[KYUUBI #7692][TESTS] Fix testFindLocalInetAddress on loopback-only hosts\n\n### Why are the changes needed?\n\nCloses #7692.\n\n`testFindLocalInetAddress` branched on whether `InetAddress.getLocalHost()` was loopback and, in the loopback case, asserted that `findLocalInetAddress()` returns something else. The method has a third outcome the test did not account for: when the interface scan finds no address that is neither loopback nor link-local, it logs and returns the loopback address it started from. On such a host the assertion compares that address against itself and fails.\n\nThe test now branches on the outcome rather than on the starting address alone. When a replacement was scanned off an interface, it asserts the address belongs to an interface and is not link-local. Otherwise it asserts the original address came back unchanged, and when that address is loopback it also asserts no interface offered a usable one, which is what separates a correct fallback from a scan that silently returned loopback. The helper it calls only asks whether any interface address is neither loopback nor link-local; it does not repeat the selection rules.\n\nThree decisions inside the method still have no assertion behind them, and are left for a follow-up: the host-name and IPv6 scope stripping, the IPv4 preference within the chosen interface, and the reversal that decides which interface wins when several have candidates. Only the first is writable against the current API, and on a host that picks an IPv4 address it asserts nothing; the other two need a seam that lets a test supply the interface list.\n\n### How was this patch tested?\n\n```\nbuild/mvn -o test -pl kyuubi-util -am -DwildcardSuites\u003dnone -Dtest\u003dJavaUtilsTest\nbuild/mvn -o spotless:check -pl kyuubi-util\n```\n\nThat run does not reach the branch this fixes, because `getLocalHost()` resolves to a routable LAN address here. The fixed branch was exercised in a container that reproduces the failing host, where `getLocalHost()` and `findLocalInetAddress()` are both `127.0.0.1`:\n\n```\ndocker run --rm --network none --hostname loopbox --add-host loopbox:127.0.0.1 \\\n  -v ~/.m2:/root/.m2 -v $PWD:/src -w /src eclipse-temurin:17-jdk \\\n  build/mvn -o test -pl kyuubi-util -am -DwildcardSuites\u003dnone -Dtest\u003dJavaUtilsTest\n```\n\n`-o` works with no network because the mounted `~/.m2` and the already-extracted `build/apache-maven-*` in the checkout are all it needs. Master\u0027s test fails there with `expected: not equal but was: \u003cloopbox/127.0.0.1\u003e`; this one passes.\n\nFour mutations of `findLocalInetAddress` show the assertions are not vacuous. Each turns the test red, and the first three were reached by mapping the host name to `127.0.0.1` with `-Djdk.net.hosts.file`:\n\n- dropping `!addr.isLinkLocalAddress()` from the candidate filter, so the method returns a link-local address: `expected: \u003cfalse\u003e but was: \u003ctrue\u003e`\n- returning an address not bound to this host (`8.8.8.8`) instead of `strippedAddress`: `expected: not \u003cnull\u003e`\n- dropping the candidate filter entirely, so the scan returns `127.0.0.1` and the test takes the other arm: `expected: \u003cfalse\u003e but was: \u003ctrue\u003e`, from the assertion that there was nothing to find\n- replacing `if (address.isLoopbackAddress())` with `if (true)` so the scan always runs, no hosts file needed: the pass-through assertion fails because the scanned address differs from what `getLocalHost()` returned\n\nWhether any of this runs on CI depends on how `getLocalHost()` resolves on a GitHub runner, which I did not check: a routable answer means the test takes the same `assertEquals` as master, a `127.0.1.1` answer means it takes the replacement arm. The fallback path is certainly not reached there, otherwise master would be failing today.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7693 from LuciferYang/kyuubi-util-javautest-loopback-assert.\n\nCloses #7692\n\nd289319ff [yangjie01] [KYUUBI #7692][TESTS] Fix testFindLocalInetAddress on loopback-only hosts\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "a45637e93e9fdf247ad08b322aedb2807235f9f2",
      "tree": "86049bc0f3467fab2e181ce5a0169a2b5f0b6a45",
      "parents": [
        "044f8816db4a61c454c584ad4ba83bed0695f761"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "pan3793@gmail.com",
        "time": "Mon Aug 31 17:29:33 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 31 17:29:33 2026 +0800"
      },
      "message": "[KYUUBI #7657] [BUILD] Add Java 25 support and test Spark 4.2 with Java 25\n\n### Why are the changes needed?\n\nJava 25 is the current LTS (released Sep 2025, Oracle Premier Support until\nSep 2030, Extended Support until Sep 2033). Kyuubi\u0027s JVM options are still\nJava 21-era, so Kyuubi cannot run reliably on the new LTS.\n\nSpark 4.2 supports and defaults to Java 25 (SPARK-51167 (4.2.0): Build and\nRun Spark on Java 25). Aligning Kyuubi\u0027s runtime options with Spark 4.2 keeps\nthe gateway\u0027s behavior consistent with the engine it launches.\n\n### How was this patch tested?\n\nNo new tests: the change only adjusts JVM/CI configuration; the existing Spark\n4.2 CI jobs exercise it.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Codex:DeepSeek V4 Pro\n\nCloses #7657 from pan3793/java25.\n\nCloses #7657\n\n350355638 [Cheng Pan] fix style\n4bf8ab93e [Cheng Pan] skip one test on JDK 25\n52d9108e9 [Cheng Pan] Java 25\n\nAuthored-by: Cheng Pan \u003cpan3793@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "044f8816db4a61c454c584ad4ba83bed0695f761",
      "tree": "070f98d9f5c4eb5aeb062bd9921ccf9ad508b29d",
      "parents": [
        "797ba2bd43bf44dd2db94ac35e756c8d69abbce6"
      ],
      "author": {
        "name": "Zhen Wang",
        "email": "wangzhen@apache.org",
        "time": "Mon Aug 31 17:27:29 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 31 17:27:29 2026 +0800"
      },
      "message": "[KYUUBI #7674] Fix flaky PyHive SQLAlchemy insert tests\n\n### Why are the changes needed?\n\nThe Python test suite runs with multiple pytest-xdist workers. `test_insert_select` and `test_insert_values` used the same `pyhive_test_database.insert_test` table, and both tests dropped and recreated it.\n\nWhen the tests ran concurrently, one test could drop the table while the other was inserting or querying data, causing intermittent `table not found` failures.\n\nThis patch assigns a dedicated table name to each test to prevent the collision.\n\nCloses #7674.\n\n### How was this patch tested?\n\nExisting test cases.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: OpenAI Codex (GPT-5)\n\nCloses #7675 from wForget/KYUUBI-7674.\n\nCloses #7674\n\nbdebbeb71 [wforget] Use distinct tables for SQLAlchemy insert tests\n\nAuthored-by: Zhen Wang \u003cwangzhen@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "797ba2bd43bf44dd2db94ac35e756c8d69abbce6",
      "tree": "d0a084de240a329e0f8b9c9bc1d9b71c362e5719",
      "parents": [
        "6dd1d73639d1c9e334ddd984e79f33d5eb0a27ae"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Mon Aug 31 17:16:58 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 31 17:16:58 2026 +0800"
      },
      "message": "[KYUUBI #7690] Fix DynFields javadoc copied from the method variants\n\n### Why are the changes needed?\n\nCloses #7690.\n\n`DynFields` is vendored from iceberg-common and its javadoc came across with the `DynMethods` wording still in it, so a field API ends up documented in method vocabulary. `bind` said it returns a `BoundMethod`, a type this file does not contain. Six `throws` tags said \"if the method is static\" or \"if the method is not static\" for a check that reads `Modifier.isStatic` on a `Field`. Three `param fieldName` tags carried `(different from constructor)`, which separates a method from a constructor and has nothing to separate on a field.\n\nTwo of the fourteen corrections change an exception type. `build()` was documented as throwing `NoSuchFieldException` when it has no `throws` clause and raises `RuntimeException`; the `throws RuntimeException` tag in the same comment already contradicted that summary. `buildChecked(Object)` was documented as returning a `BoundMethod` and throwing `NoSuchMethodException` while its signature declares `throws NoSuchFieldException`. In both cases the documented exception is one the compiler will not let a caller catch, so the failure path the javadoc described could not be written at all.\n\nThe `UnboundField` class doc claimed \"all Exceptions wrapped by RuntimeException, or with a single Exception catch block\". `get` and `set` catch only `IllegalAccessException`, and this class has no checked-throwing accessor for the second clause to refer to; that clause describes `DynMethods.UnboundMethod.invokeChecked`. The class doc now names the one throwable that is wrapped and says the rest are not.\n\nUpstream iceberg-common carries the same wrong text, so this is not local drift that a resync would repair. Thirteen of the fourteen lines have a direct upstream counterpart and are worth sending to iceberg separately.\n\nLeft for a follow-up: the builder\u0027s `throws` tags are written unconditionally and stop holding once `defaultAlwaysNull()` is set, because the sentinel is returned instead of an exception and its `bind` override skips the static and receiver checks. Both `hiddenImpl` overloads also point `see` at `Class#getField(String)` while the code calls `getDeclaredField`. `DynMethods` has both defects too, so the two vendored copies should change together.\n\n### How was this patch tested?\n\nEvery changed line sits inside a `/** */` block, so there is no behaviour to test, and a javadoc assertion would pass with the patch reverted.\n\n`build/mvn -o test -pl kyuubi-util -am -DwildcardSuites\u003dnone` gives 33/33 green. `build/mvn -o spotless:check -pl kyuubi-util` is clean.\n\nExisting tests in `DynFieldsTest` already cover the behaviour these sentences describe: `testBuildWithoutAlwaysNullFallbackThrows` for `build()` raising `RuntimeException`, `testBindRejectsStaticField` and `testBindRejectsIncompatibleTarget` for `bind`\u0027s two conditions, and `testAlwaysNullBindsThroughEveryEntryPoint` for the sentinel path behind the deferred wording. Two of the behavioural claims have no test and were checked by reading the code: the class doc\u0027s wrapping sentence, and `asStatic`\u0027s \"if the field is not static\" path.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7691 from LuciferYang/kyuubi-util-dynfields-javadoc.\n\nCloses #7690\n\nec814231d [yangjie01] [KYUUBI #7690] Fix DynFields javadoc copied from the method variants\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "6dd1d73639d1c9e334ddd984e79f33d5eb0a27ae",
      "tree": "b30a096f4ee56d0f1d60e1d2e6032213b820d06c",
      "parents": [
        "edc32883a230bd933d40331d469f63fe18d20c1d"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Mon Aug 31 17:15:11 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 31 17:15:11 2026 +0800"
      },
      "message": "[KYUUBI #7701] Log the resolved host in the findLocalInetAddress loopback warning\n\n### Why are the changes needed?\n\nCloses #7701.\n\n`findLocalInetAddress` warns when the host name resolves to loopback and it substitutes an address taken from a network interface. The warning filled its host name and loopback slots from the substitute rather than from the address that actually resolved to loopback, so on a host with no PTR record for the substitute all three slots printed the same string: `10.0.0.5 was resolved to a loopback address: 10.0.0.5, using 10.0.0.5`. The fallback warning a few lines down already reads from the original address, so the two warnings in one method had been describing different things.\n\nNaming the wrong subject is also what sent the thread to the resolver. An address from `NetworkInterface.getInetAddresses()` carries no cached host name, so `addr.getHostName()` blocks on a lookup, and the argument is evaluated at the call site, so the lookup happens whether or not WARN is enabled. The same call measured 0.9 ms, 1.8 ms, 6.5 ms, 324 ms, 1027 ms and 3147 ms on one host at different times, every one returning the numeric form for want of a PTR record. `InetAddress.getLocalHost()` already carries its name, so the corrected slots cost nothing. This removes that one lookup and no other: callers that ask the returned address for `getCanonicalHostName()`, such as `KyuubiRestFrontendService` and `EmbeddedZookeeper`, do their own regardless of what this method returns.\n\nThe Scala code that #6499 replaced used the original address in both slots, so the Java rewrite moved the receiver. The line is unchanged on `branch-1.12`, `branch-1.11` and `branch-1.10`, so a backport is possible if maintainers want one.\n\n### How was this patch tested?\n\nNo unit test. `findLocalInetAddress` takes no arguments and reads `InetAddress.getLocalHost()` and `NetworkInterface.getNetworkInterfaces()` as statics, so a test cannot steer it into the loopback branch on an ordinary host. The returned address is identical before and after; only the log text differs, so an assertion over the return value would pass with this patch reverted. Asserting on the text would mean adding a logging backend or a static mocking library to `kyuubi-util`, whose test scope today is `junit-jupiter` alone. The missing coverage of these branches is tracked separately in #7692.\n\n```\nbuild/mvn test -pl kyuubi-util -am -DwildcardSuites\u003dnone -Dtest\u003dJavaUtilsTest\nbuild/mvn spotless:check -pl kyuubi-util\n```\n\nThe argument rendering was checked out of tree on a host that takes the branch, where `InetAddress.getLocalHost()` returns `\u003cname\u003e/127.0.0.1` and an interface carries a routable address. The old arguments render as `\u003clan-address\u003e was resolved to a loopback address: \u003clan-address\u003e, using \u003clan-address\u003e`; the new ones as `\u003cname\u003e was resolved to a loopback address: 127.0.0.1, using \u003clan-address\u003e`.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7702 from LuciferYang/kyuubi-util-javutils-loopback-warn.\n\nCloses #7701\n\nf2d7e5e6d [yangjie01] [KYUUBI #7701] Log the resolved host in the findLocalInetAddress loopback warning\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "edc32883a230bd933d40331d469f63fe18d20c1d",
      "tree": "1717387fe2f42c30250c505928564a3a2cde2042",
      "parents": [
        "f35e7df6c1197e21c6a1993eb7eff115f9dc8229"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Mon Aug 31 10:37:55 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 31 10:37:55 2026 +0800"
      },
      "message": "[KYUUBI #7694][TESTS] Assert the timestamp and random fields of generated UUIDv7 values\n\n### Why are the changes needed?\n\nCloses #7694.\n\n`UuidUtilsTest` asserted `uuid.version()` and `uuid.variant()` and nothing else. Production writes those two from the literals `0x7000L` and `0x8000000000000000L`, so they hold whatever happens to `epochMs` and whatever happens to the 74 random bits. Setting the most significant half to `0L`, shifting the timestamp by 20 instead of 16, or deleting the `SECURE_RANDOM.nextBytes(randomBytes)` call all left the old suite fully green, and after that last one every UUID sharing a timestamp is byte-identical. Time ordering and uniqueness are what #7277 wanted from v7, and they were the two things unasserted.\n\nThe test now decodes the top 48 bits and compares them with the input, brackets the no-arg overload\u0027s value between two clock readings, and asserts that the least significant half differs between two calls with the same timestamp. The two overloads move into one test each because the clock bracket has to close immediately after the no-arg call.\n\nThree coverage gaps stay open, each needing a decision rather than one more assertion.\n\nThe accepting side of the 48-bit input check has no case. The rejecting side has two, negative and `1L \u003c\u003c 48`; the largest legal value `(1L \u003c\u003c 48) - 1` is untested, so an off-by-one on the upper bound would go unnoticed. Sign-adjacent mistakes are already covered, because the existing fixture has bit 47 set.\n\nrand_a, 12 bits wide, is still unasserted. A single pair of draws would collide once in 4096 runs, so covering it properly means drawing N times and asserting at least two distinct values, which is five lines of test for 12 bits of entropy. rand_b carries the collision risk and is now pinned.\n\nSortability is unasserted, and `UUID.compareTo` is the wrong tool for asserting it. It compares each half as a signed long, and a v7 value whose timestamp has bit 47 set has a negative most significant half. The fixture used here is such a value: `0xFEDCBA987654L` is a millisecond count somewhere past the year 10000, and `generateUUIDv7(System.currentTimeMillis()).compareTo(generateUUIDv7(0xFEDCBA987654L))` returns 1, ordering the earlier timestamp above the later one. The string form and `Long.compareUnsigned` both give the right sign. An assertion has to pick one, which means first deciding which order this class promises.\n\nOne flakiness note, not a gap: the clock bracket compares against `System.currentTimeMillis()`, which is not monotonic, so an NTP step backwards between the two readings can turn it red with production untouched. Removing that dependency means making the clock injectable, which is a production change. The failure message prints all three values so this case is distinguishable from a real unit-of-time regression.\n\n### How was this patch tested?\n\n```\nbuild/mvn -o test -pl kyuubi-util -am -DwildcardSuites\u003dnone -Dtest\u003dUuidUtilsTest\nbuild/mvn -o spotless:check -pl kyuubi-util\n```\n\n4 of 4 pass. This is a test-only change, so a green run proves nothing by itself. Each new assertion was checked against a mutated `UuidUtils` compiled outside the repository, with the pre-patch suite as the control:\n\n- `long msb \u003d 0L`, timestamp never written: control green, now `timestamp 0 outside [...]` and `expected: \u003c280223976814164\u003e but was: \u003c0\u003e`\n- `epochMs \u003c\u003c 20` instead of `\u003c\u003c 16`: control green, now red on both timestamp assertions\n- no-arg overload switched to `System.currentTimeMillis() / 1000`: control green, now `timestamp 1788120386 outside [1788120386840, 1788120386853]`. This is the mutation that isolates the clock bracket\n- `SECURE_RANDOM.nextBytes(randomBytes)` deleted: control green, now `expected: not equal but was: \u003c-9223372036854775808\u003e`\n- `randLSB` forced to `0`, so rand_b is constant while rand_a still varies: control green, now red on the same assertion. This is why the assertion compares the least significant halves rather than the whole UUIDs, which the 12 bits of rand_a would satisfy on their own\n\nThe explicit-timestamp fixture `0xFEDCBA987654L` has bit 47 set, so the most significant half is negative and the unsigned `\u003e\u003e\u003e 16` decode is load-bearing; `\u003e\u003e 16` sign extends to `fffffedcba987654`.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7695 from LuciferYang/kyuubi-util-uuidtest-v7-timestamp.\n\nCloses #7694\n\n246a19444 [yangjie01] [KYUUBI #7694][TESTS] Assert the timestamp and random fields of generated UUIDv7 values\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "f35e7df6c1197e21c6a1993eb7eff115f9dc8229",
      "tree": "8ae2cde8938e69341bb7f7e5b24a02f953544e86",
      "parents": [
        "2fcd5fb5fa6c4435d701fc977f17ba3faa3e5412"
      ],
      "author": {
        "name": "littlexyw",
        "email": "shea_wong@163.com",
        "time": "Mon Aug 31 10:33:01 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 31 10:33:01 2026 +0800"
      },
      "message": "[KYUUBI #7668][SPARK] Use UUIDv7 for executor podNamePrefix to avoid same-millisecond collision\n\n### Why are the changes needed?\n\nOn Kubernetes, `SparkSQLEngine.generateExecutorPodNamePrefixForK8s` built the executor podNamePrefix as `kyuubi-\u003cuser\u003e-\u003cepoch-millis\u003e`. When two engines for the same user (same `resolvedUserName`) are launched within the same millisecond in the same namespace — e.g. a burst of short-lived engines from the same user, or two Kyuubi servers racing to launch engines for a `USER` share level — the two engines get an identical `spark.kubernetes.executor.podNamePrefix`. Their executor pod names (`\u003cprefix\u003e-exec-\u003cid\u003e`) then collide inside the namespace, and one of the two apps fails to create executors until the other releases the names.\n\nThis PR replaces the epoch-millis suffix with a UUIDv7 from the existing `UuidUtils.generateUUIDv7` helper. UUIDv7 keeps the 48-bit epoch millis in its leading bits so pod names remain roughly time-ordered when listed by name, while the trailing 74 bits of secure randomness make same-millisecond collisions essentially impossible. The oversized-user-name fallback path is switched to the same UUIDv7 for consistency.\n\n### How was this patch tested?\n\n- Added a concurrent unit test `generate executor pod name prefix should be unique for concurrent calls with the same user` in `SparkSQLEngineSuite` that fans out 1000 prefix generations across 10 threads for the same user and asserts every generated prefix is unique. Under the pre-fix epoch-millis implementation this test necessarily fails, since many calls land on the same millisecond and produce identical prefixes.\n- The existing `[KYUUBI #3385] generate executor pod name prefix with user or UUID` test still passes (sanitization, length cap, and pod-log-directory length invariants unchanged).\n\n### Was this patch assisted by generative AI tooling?\nAssisted-by: Claude Opus 4.7\n\nCloses #7669 from littlexyw/kyuubi-7668-executor-podname-uuidv7.\n\nCloses #7668\n\nb29ebc718 [littlexyw] [KYUUBI #7668][SPARK] Use UUIDv7 for executor podNamePrefix to avoid same-millisecond collision\n\nAuthored-by: littlexyw \u003cshea_wong@163.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "2fcd5fb5fa6c4435d701fc977f17ba3faa3e5412",
      "tree": "6b81c72b911433640d6f7697de63a7e43a69d35d",
      "parents": [
        "bf10595ba32c7ec008dfae117943d06a237661f6"
      ],
      "author": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Mon Aug 31 00:39:09 2026 +0900"
      },
      "committer": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Mon Aug 31 00:39:09 2026 +0900"
      },
      "message": "[KYUUBI #7678] [INFRA] Fix greetings workflow for PRs from forks\n\n### Why are the changes needed?\n\n`pull_request` action doesn\u0027t have write access to the PR. Error: https://github.com/apache/kyuubi/actions/runs/33192410137/job/98924378784\n\nUse `pull_request_target` action instead to comment to the PR.\n\nReference implementations:\n- https://github.com/apache/cloudberry/blob/4d209d23b45b146f9970f652a74a11b562091d6c/.github/workflows/greetings.yml#L29\n- https://github.com/apache/eventmesh/blob/6ec99215ca3847404ec7bf15d94f78152f2b3c60/.github/workflows/greetings.yml#L22\n\n### How was this patch tested?\n\nNot tested. The fix is available only after it\u0027s merged into main.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: OpenCode (DeepSeek V4 Flash)\n\nCloses #7678 from aajisaka/kyuubi-fix-greetings-workflow.\n\nCloses #7678\n\n05f74550e [Akira Ajisaka] Fix greetings workflow for PRs from forks\n\nAuthored-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\nSigned-off-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\n"
    },
    {
      "commit": "bf10595ba32c7ec008dfae117943d06a237661f6",
      "tree": "e6c2e92c7b9cf93966a8dbd5488b60f5bfb16c52",
      "parents": [
        "109d33a826b1cd5642c5be1e27409ea666bf8c65"
      ],
      "author": {
        "name": "wforget",
        "email": "643348094@qq.com",
        "time": "Fri Aug 28 20:18:57 2026 +0800"
      },
      "committer": {
        "name": "wforget",
        "email": "643348094@qq.com",
        "time": "Fri Aug 28 20:18:57 2026 +0800"
      },
      "message": "[KYUUBI #7644][FLINK] Prevent concurrent access to bootstrap job IDs\n\n### Why are the changes needed?\n\nCloses #7644.\n\nIn Flink YARN application mode, Kyuubi retains Flink\u0027s original application job ID list for the bootstrap job and uses a thread-safe copy for subsequent jobs. However, the list was selected based on whether the original list was empty.\n\nBecause the engine frontend could become available before bootstrap completed, the bootstrap query and a client query could both receive the original non-thread-safe `ArrayList`. Concurrent additions could then cause an `ArrayIndexOutOfBoundsException`.\n\nThis patch atomically reserves the original list for one bootstrap executor and completes bootstrap before exposing the engine frontend.\n\n### How was this patch tested?\n\nAdded `EmbeddedExecutorFactorySuite` to verify that the original Flink application job ID list is returned to only one executor and subsequent executors use the thread-safe collection.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Codex with GPT-5\n\nCloses #7646 from wForget/KYUUBI-7644.\n\nCloses #7644\n\n86bb17a78 [wforget] address comment\ndf275b0c9 [wforget] Prevent concurrent Flink job submission during bootstrap\n\nAuthored-by: wforget \u003c643348094@qq.com\u003e\nSigned-off-by: wforget \u003c643348094@qq.com\u003e\n"
    },
    {
      "commit": "109d33a826b1cd5642c5be1e27409ea666bf8c65",
      "tree": "437c71cc5e99bbea6069de9732a627817869016e",
      "parents": [
        "645b7062ca26279c7f4bb8c7bfba98468f42a5a8"
      ],
      "author": {
        "name": "Aleksandr Efimov",
        "email": "horsodilo@gmail.com",
        "time": "Fri Aug 28 20:16:08 2026 +0800"
      },
      "committer": {
        "name": "wforget",
        "email": "643348094@qq.com",
        "time": "Fri Aug 28 20:16:08 2026 +0800"
      },
      "message": "[KYUUBI #7623][AUTHZ] Check the effective value of spark.sql.optimizer.excludedRules\n\n### Why are the changes needed?\n\nCloses #7623.\n\n`AuthzConfigurationChecker` guards the exclusion by matching a `SetCommand` in the logical plan (`AuthzConfigurationChecker.scala:42-45`), so the protection covers the `SET` syntax only - which is also how the docs describe it (`docs/security/authorization/spark/overview.rst:106`, \"A set statement with key equal to ...\"). Every channel that writes the config without producing a plan keeps working: `spark.conf.set`, the Spark Connect Config RPC (`SparkConnectConfigHandler.handleSet` calls `conf.set` directly), or the key passed in a JDBC connection string. Once `RuleAuthorization` is named there, `Optimizer.batches` drops it - extension rules are not in `SparkOptimizer.nonExcludableRules` - and the rest of the session runs unauthorized.\n\nReproduced on Spark 4.0.3 with `kyuubi-spark-authz` and a Ranger plugin that denies by default: `create` denied, `SET spark.sql.optimizer.excludedRules\u003d...RuleAuthorization` rejected by the checker, the same key accepted over the Connect Config RPC, the next `create` allowed.\n\nThe documented mitigation, `kyuubi.session.conf.restrict.list` (`docs/security/authorization/spark/overview.rst:85-93`), does reject such a JDBC connection - I checked that too - but it is enforced in the server\u0027s `SessionManager`, so it does not reach a client that talks to the engine directly.\n\nThis patch reads the value in effect on every plan instead of matching the statement. Check rules are not filtered by `excludedRules`, which only applies to optimizer batches, so this check cannot be removed the same way.\n\nTwo points a reviewer may want to decide differently:\n\n- The value check matches `org.apache.kyuubi.plugin.spark.authz.ranger`, the prefix the existing `SET` case uses. The plugin also injects optimizer rules from `org.apache.kyuubi.plugin.spark.authz.rule` (`RuleEliminateMarker` and its neighbours), which neither the old nor the new check covers. I left the prefix as is rather than widen the scope here.\n- The check is fail closed for the whole session: with the exclusion already in the session conf, every plan is rejected, not just the `SET`. That is the intent, but it is a visible behaviour change for a session that set the key before this patch.\n\n### How was this patch tested?\n\nNew test in `AuthzConfigurationCheckerSuite`: the config is written through `spark.conf.set` - the same write path the Connect Config RPC takes - and the next plan is rejected, while excluding a non-authz rule (`ConstantFolding`) stays allowed.\n\n```\nbuild/mvn test -pl extensions/spark/kyuubi-spark-authz -Dtest\u003dnone \\\n    -DwildcardSuites\u003dorg.apache.kyuubi.plugin.spark.authz.rule.AuthzConfigurationCheckerSuite\n```\n\nAll three tests in the suite pass; with the new check removed from `apply`, exactly the new test fails.\n\nThe existing test needed one line: `sql(\"set spark.sql.optimizer.excludedRules\u003d...\")` applies the value to the shared session before the rule is invoked by hand, so the test now unsets it - otherwise the effective-value check rejects every later plan in that session.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-opus-5\n\nCloses #7637 from alexandrefimov/kyuubi-7623-authz-excluded-rules-value.\n\nCloses #7623\n\n2c64b3879 [Aleksandr Efimov] [KYUUBI #7623][AUTHZ] Check the effective value of spark.sql.optimizer.excludedRules\n\nAuthored-by: Aleksandr Efimov \u003chorsodilo@gmail.com\u003e\nSigned-off-by: wforget \u003c643348094@qq.com\u003e\n"
    },
    {
      "commit": "645b7062ca26279c7f4bb8c7bfba98468f42a5a8",
      "tree": "a4a10484b4cc9ed579772a0298a878635f618539",
      "parents": [
        "5f501cd9aab7f26a1ab9b785fc53916ce5fcceb3"
      ],
      "author": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Wed Aug 26 22:53:48 2026 +0200"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Wed Aug 26 22:53:48 2026 +0200"
      },
      "message": "[KYUUBI #7434][DOC] Reformat security docs from RST to Markdown\n\n### Why are the changes needed?\nThe changes are needed to unify the format used for documentation, as described in the issue https://github.com/apache/kyuubi/issues/7434.\n\nThe PR also includes the dependency updates listed in `docs/requirements.txt`.\n\nThis PR **does not** change page contents to ensure an easier review of the migration.\n\n### How was this patch tested?\nTested by building the documentation and comparing the pages against the live site:\n```\nmake clean html\n\nopen https://kyuubi.readthedocs.io/en/master/security/index.html\nopen _build/html/security/index.html\n\nopen https://kyuubi.readthedocs.io/en/master/security/authentication.html\nopen _build/html/security/authentication.html\n\nopen https://kyuubi.readthedocs.io/en/master/security/kerberos.html\nopen _build/html/security/kerberos.html\n\nopen https://kyuubi.readthedocs.io/en/master/security/authorization/index.html\nopen _build/html/security/authorization/index.html\n\nopen https://kyuubi.readthedocs.io/en/master/security/authorization/spark/index.html\nopen _build/html/security/authorization/spark/index.html\n\nopen https://kyuubi.readthedocs.io/en/master/security/authorization/spark/overview.html\nopen _build/html/security/authorization/spark/overview.html\n```\n\n### Was this patch assisted by generative AI tooling?\nAssisted-by: Qwen Coder\n\nCloses #7658 from dnskr/rst-to-md-security-pages.\n\nCloses #7434\n\n89d66c59d [Denis Krivenko] [DOC] Reformat security docs from RST to Markdown\n\nAuthored-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "5f501cd9aab7f26a1ab9b785fc53916ce5fcceb3",
      "tree": "88776606f0fdffb48e8dc1e00aeb1c38cd385d58",
      "parents": [
        "0e26b7030ad75824f80e95e05da1129fd50f361d"
      ],
      "author": {
        "name": "wangzhigang",
        "email": "iamzhigangwang@gmail.com",
        "time": "Wed Aug 26 17:29:14 2026 +0800"
      },
      "committer": {
        "name": "wangzhigang",
        "email": "iamzhigangwang@gmail.com",
        "time": "Wed Aug 26 17:29:14 2026 +0800"
      },
      "message": "[KYUUBI #7655][SERVER] Support virtual threads in the binary frontend\n\n### Why are the changes needed?\n\nVirtual threads are mature in JDK 21, which Kyuubi already supports. As an I/O-bound gateway, Kyuubi is a good fit for this execution model.\n\nThis PR makes a small first step by adding optional virtual-thread support to the server-side Thrift Binary frontend. It is disabled by default and does not affect engine frontends or other executors.\n\nThe implementation preserves the worker concurrency limit and rejection behavior while retaining compatibility with older JDKs.\n\nSee #7655 for the motivation and benchmark results.\n\n### How was this patch tested?\n\n- Targeted suites passed on JDK 11 and JDK 21.\n- `dev/reformat`\n- `git diff --check`\n- Kyuubi Server fast package build.\n- Five-minute A/B test with real Spark SQL.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: OpenAI Codex (GPT-5)\n\nCloses #7656 from wangzhigang1999/kyuubi-server-virtual-thread-frontend.\n\nCloses #7655\n\nfa33a446e [wangzhigang] [KYUUBI #7655] Regenerate configuration documentation\n55a28c1c8 [zhigang] Update kyuubi-common/src/main/scala/org/apache/kyuubi/config/KyuubiConf.scala\n221217e22 [wangzhigang] [KYUUBI #7655][SERVER] Support virtual threads in the binary frontend\n\nLead-authored-by: wangzhigang \u003ciamzhigangwang@gmail.com\u003e\nCo-authored-by: zhigang \u003ciamzhigangwang@gmail.com\u003e\nSigned-off-by: wangzhigang \u003ciamzhigangwang@gmail.com\u003e\n"
    },
    {
      "commit": "0e26b7030ad75824f80e95e05da1129fd50f361d",
      "tree": "acfe416079b88fa047e20dec6e61117d13759643",
      "parents": [
        "b3a6b45be12bd76470334ba368af210ce685ba60"
      ],
      "author": {
        "name": "maomaodev",
        "email": "lifumao@tencent.com",
        "time": "Mon Aug 24 22:08:08 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 24 22:08:08 2026 +0800"
      },
      "message": "[KYUUBI #6943][2/2] OrcScan and ParquetScan support DPP\n\n### Why are the changes needed?\n\nPart 2 of 2 to add KSHC support for dynamic partition pruning (DPP). See https://github.com/apache/kyuubi/issues/6943.\n- [x] Add DPP support in `HiveScan` for non-Parquet/ORC tables.\n- [x] Add DPP support in `ParquetScan` / `ORCScan` for Parquet/ORC tables.\n\n### How was this patch tested?\n\n#### 1. UT \u0026 TPC-DS benchmark\n- Unit tests\n- Manual test: TPC-DS benchmark (10 GB dataset, ORC and Parquet separately). Spark configuration used for the benchmark(Spark 3.5.7, Kyuubi 1.12.0-SNAPSHOT):\n```\nspark.driver.cores            1\nspark.driver.memory           4g\nspark.executor.cores          1\nspark.executor.instances      10\nspark.executor.memory         4g\nspark.master                  yarn\nspark.shuffle.service.enabled true\nspark.yarn.appMasterEnv.JAVA_HOME /usr/local/jdk-17\nspark.executorEnv.JAVA_HOME       /usr/local/jdk-17\n```\n#### 2. ORC benchmark\n\n- **Overall performance (sum of 99)**\n\n| Dimension         | Vanilla Spark | KSHC Before |    KSHC Now |\n| ----------------- | ------------: | ----------: | ----------: |\n| Total time        |     2481.85 s |   3353.43 s |   2197.26 s |\n| vs. Vanilla Spark |             — |     +35.12% |     −11.47% |\n| vs. KSHC Before   |             — |           — | **−34.48%** |\n\n- **DPP hit subset (73/99)**\n\nDPP trigger was detected by matching `runtime partition filter` in the driver logs.\n\n```\n3,4,5,6,7,8,10,11,12,13,14,15,17,18,19,20,23,25,26,27,29,30,31,32,33,\n35,36,38,40,42,43,45,46,47,48,49,50,51,52,53,54,55,56,57,58,60,61,63,\n64,65,66,67,68,69,70,71,72,74,75,77,78,79,80,81,83,85,86,87,89,91,92,\n97,98\n```\n\n| Dimension         | Vanilla Spark | KSHC Before |    KSHC Now |\n| ----------------- | ------------: | ----------: | ----------: |\n| Subset total time |     1823.48 s |   2642.11 s |   1484.39 s |\n| vs. Vanilla Spark |             — |     +44.89% |     −18.60% |\n| vs. KSHC Before   |             — |           — | **−43.82%** |\n\nOn the DPP-hit subset, KSHC Now provides a 43.82% speedup over KSHC Before, noticeably larger than the overall 34.48%, indicating the performance benefit mainly comes from queries where DPP is triggered.\n\n#### 3. Parquet benchmark\n\n- **Overall performance (sum of 99)**\n\n| Dimension         | Vanilla Spark | KSHC Before |    KSHC Now |\n| ----------------- | ------------: | ----------: | ----------: |\n| Total time        |     2325.13 s |   3363.57 s |   2152.18 s |\n| vs. Vanilla Spark |             — |     +44.66% |      −7.44% |\n| vs. KSHC Before   |             — |           — | **−36.02%** |\n\n- **DPP hit subset (73/99)**\n\nDPP trigger was detected by matching `runtime partition filter` in the driver logs.\n\n```\n3,4,5,6,7,8,10,11,12,13,14,15,17,18,19,20,23,25,26,27,29,30,31,32,33,\n35,36,38,40,42,43,45,46,47,48,49,50,51,52,53,54,55,56,57,58,60,61,63,\n64,65,66,67,68,69,70,71,72,74,75,77,78,79,80,81,83,85,86,87,89,91,92,\n97,98\n```\n\n| Dimension         | Vanilla Spark | KSHC Before |    KSHC Now |\n| ----------------- | ------------: | ----------: | ----------: |\n| Subset total time |     1619.13 s |   2487.20 s |   1369.55 s |\n| vs. Vanilla Spark |             — |     +53.61% |     −15.41% |\n| vs. KSHC Before   |             — |           — | **−44.94%** |\n\nOn the DPP-hit subset, KSHC Now provides a 44.94% speedup over KSHC Before, noticeably larger than the overall 36.02%, indicating the performance benefit mainly comes from queries where DPP is triggered.\n\n#### 4. Result correctness\n\nCompared each of the 99 result files between KSHC Now and Vanilla Spark for both ORC and Parquet. ORC: 94/99 byte-identical and 98/99 row-multiset-identical; Parquet: identical figures. The 4 row-order-only diffs (q31/q65/q71/q79) come from queries whose `ORDER BY` clause does not totally order the output. The single multiset diff (q39) is sub-ULP floating-point rounding in `stddev`-style aggregates and is also present between KSHC Before and Vanilla Spark, so it is unrelated to this PR. No correctness regression introduced.\n\n#### 5. Spark 4.0.1 benchmark\n\nThe same TPC-DS benchmark was also run against Spark 4.0.1 with KSHC. Results align with the Spark 3.5.7 numbers: KSHC matches or outperforms the native Hive path on DPP-eligible queries, and produces identical result sets. Full Spark 4.0.1 benchmark result are omitted here to keep the report compact, they can be shared on request.\n\n#### **6. Known tradeoff: native engine offload**\n\n`KyuubiParquetScan` / `KyuubiOrcScan` wrap Spark\u0027s built-in `ParquetScan` / `OrcScan` rather than subclass them, so DPP can be layered on without touching Spark internals. Native engines like Gluten and Comet identify the file format by scan class name, so KSHC-converted Parquet/ORC tables silently fall back to the JVM read path. Before this PR, KSHC-converted tables went through vanilla `ParquetScan` / `OrcScan` and were offloadable; after this PR they are not.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude Opus 4.7\n\nCloses #7476 from maomaodev/kyuubi_6943.\n\nCloses #6943\n\nb0005139f [lifumao] Fix UT\n21242e24d [lifumao] add comments\n7cc6b0508 [lifumao] Cache the Ctor in a lazy val\n007194d04 [lifumao] [KYUUBI #6943][2/2] OrcScan and ParquetScan support DPP\n\nAuthored-by: maomaodev \u003clifumao@tencent.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "b3a6b45be12bd76470334ba368af210ce685ba60",
      "tree": "75a067357d42b214447ee57c284c4d564a42744c",
      "parents": [
        "797ead5dfb2e3b14cb51ce75b20b0bf700984cf9"
      ],
      "author": {
        "name": "lifumao",
        "email": "lifumao@tencent.com",
        "time": "Mon Aug 24 19:12:15 2026 +0800"
      },
      "committer": {
        "name": "wangzhigang",
        "email": "iamzhigangwang@gmail.com",
        "time": "Mon Aug 24 19:12:15 2026 +0800"
      },
      "message": "[KYUUBI #7649] Fix compaction summarizer tokens not accumulated\n\n### Why are the changes needed?\n\nFix https://github.com/apache/kyuubi/issues/7649. `CompactionMiddleware` fires an extra summarizer LLM call when compaction triggers, but the tokens from that call (`prompt_tokens` / `completion_tokens` / `total_tokens`) are never added to the session\u0027s accumulated token totals. As a result, token accounting diverges from the LLM provider\u0027s actual billing.\n\n### How was this patch tested?\n\n```\nexport DATA_AGENT_OPENAI_API_KEY\u003d\u0027xxx\u0027\nexport DATA_AGENT_OPENAI_ENDPOINT\u003d\u0027xxx\u0027\nexport DATA_AGENT_MODEL\u003d\u0027xxx\u0027\n\n./build/mvn -pl externals/kyuubi-data-agent-engine test \\\n  -Dtest\u003dCompactionMiddlewareLiveTest \\\n  -DwildcardSuites\u003dorg.apache.kyuubi.engine.dataagent.operation.DataAgentCompactionE2ESuite \\\n  -DfailIfNoTests\u003dfalse\n```\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 4.7\n\nCloses #7650 from maomaodev/kyuubi-7649.\n\nCloses #7649\n\nb9c4f35b2 [lifumao] [KYUUBI #7649] Fix compaction summarizer tokens not accumulated\n\nAuthored-by: lifumao \u003clifumao@tencent.com\u003e\nSigned-off-by: wangzhigang \u003ciamzhigangwang@gmail.com\u003e\n"
    },
    {
      "commit": "797ead5dfb2e3b14cb51ce75b20b0bf700984cf9",
      "tree": "bf4cea0455a691196aa298bb4c5ef0da8b907905",
      "parents": [
        "7519db18e6239ac045000fff042fd9b662920a5f"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Mon Aug 24 14:28:26 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 24 14:28:26 2026 +0800"
      },
      "message": "[KYUUBI #7647] Stop truncating varargs constructor arguments in DynConstructors\n\n### Why are the changes needed?\n\nFix #7647.\n\n`Ctor.newInstanceChecked` truncated arguments to the resolved constructor\u0027s parameter count unconditionally. `Constructor.newInstance` — like `Method.invoke` — never packs loose varargs arguments (the only valid reflection form is the packed array as the last argument), so for a **varargs** constructor the truncation could never produce a correct call:\n\n- when the truncated prefix happened to type-match, trailing arguments were **silently dropped** and a wrong instance was constructed — e.g. for `Holder(String, Object...)`, `ctor.newInstance(\"one\", new Object[]{\"2a\",\"2b\"}, \"three\")` constructed `Holder(\"one\", [\"2a\",\"2b\"])` with `\"three\"` vanishing;\n- otherwise the caller got a misleading `argument type mismatch` (an artifact of the truncated call) instead of the honest `wrong number of arguments`.\n\nThe fix skips the truncation when `ctor.isVarArgs()`: varargs constructors\u0027 arguments pass through unchanged, so callers get either a working packed-array invocation or the same fail-loudly contract parquet-mr specifies upstream.\n\nThis aligns `DynConstructors` with the sibling class in the same package rather than introducing a local special case: `DynMethods.UnboundMethod` keeps `argLength` at -1 for a varargs method and so skips the identical `Arrays.copyOfRange` truncation, both in this copy and upstream, and `KyuubiSparkUtil`\u0027s `UriBuilder.build(Object...)` lookups depend on that.\n\nUpstream lineage: this class is adapted from iceberg-common (itself derived from parquet-common), and the truncation logic matches Iceberg\u0027s copy — parquet-mr\u0027s `newInstanceChecked` has never truncated (its `TestDynConstructors#testFirstImplReturned` pins extra-arguments-must-throw), while Iceberg\u0027s copy carries the identical unconditional truncation, unfixed and untested for extra/varargs arguments. This is therefore a Kyuubi-local fix, recorded on `newInstanceChecked`; it may be worth reporting upstream against Iceberg separately.\n\nScope: the fixed-arity truncation is long-standing and load-bearing — 7 in-repo sites rely on it for cross-version constructor compatibility (`TPCDSTable` across Spark versions, `HiveSessionManager` on Hive 2.3, and optional-conf provider patterns such as `EngineSecuritySecretProvider`, which binds a no-arg constructor and passes `conf` on every call) — so it is deliberately preserved. All in-repo `DynConstructors` call sites were audited: none passes loose arguments to a varargs constructor (structurally impossible to bind one without an explicit array-typed `impl` chain, of which the repo has none for constructors), so no caller\u0027s behavior changes except the intended silent-drop → loud-failure correction.\n\n### How was this patch tested?\n\nAdded `DynConstructorsTest`, the first unit tests for `DynConstructors`:\n\n- rejection of loose varargs arguments in both forms (packed-plus-extras and all-loose, asserting the honest `wrong number of arguments` message by prefix, since the JDK 18+ reflection accessor appends `: 3 expected: 2`) plus the under-arity call (reflection synthesizes no empty varargs array either);\n- the non-null-target guards of `invoke`/`invokeChecked`;\n- the packed-array happy path through all four entry points (`newInstance`, `newInstanceChecked`, `invoke`, `invokeChecked`);\n- the preserved fixed-arity truncation boundary.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude Code Opus 5\n\nCloses #7648 from LuciferYang/kyuubi-util-dynconstructors-varargs.\n\nCloses #7647\n\nbfd422ae5 [yangjie01] [KYUUBI #7647][UTIL] Match the varargs message by prefix, move the divergence note to the member\n7c2b8a80c [yangjie01] [KYUUBI #7647][UTIL] Stop truncating varargs constructor arguments in DynConstructors\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "7519db18e6239ac045000fff042fd9b662920a5f",
      "tree": "9e51b50c63eff168f999ac66f668d0df84b53668",
      "parents": [
        "f316cd38175839394b4b996b29c72614ef76bfc8"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Mon Aug 24 13:54:02 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 24 13:54:02 2026 +0800"
      },
      "message": "[KYUUBI #7651] Fix NPE binding the AlwaysNull sentinel field in DynFields\n\n### Why are the changes needed?\n\nCloses #7651.\n\n`DynFields.AlwaysNull` is a singleton with a `null` backing `Field`. It did not override `bind(Object)`, so `build(target)` / `buildChecked(target)` fell through to `UnboundField.bind`, which exempts the sentinel from the static-field check and then dereferences the null field on the next check, throwing `NullPointerException` instead of returning a field that reads `null`.\n\nThe fix mirrors `DynMethods.UnboundMethod.NOOP`, the sentinel in the sibling class, which already overrides `bind` to return a bound no-op. With that override in place the `this !\u003d AlwaysNull.INSTANCE` term in `UnboundField.bind` is unreachable, so it is narrowed to `if (isStatic())` and the sentinel case lives in one place only. `DynMethods.UnboundMethod.bind` has exactly that shape.\n\nTwo things stated so the change is not read as more than it is:\n\n- Nothing in Kyuubi calls `defaultAlwaysNull()` today, so the NPE is currently unreachable. This hardens a vendored utility rather than fixing a reported failure.\n- The sentinel is a no-op for reads and for `set(null)` only. Because `AlwaysNull` is an `UnboundField\u003cVoid\u003e`, the bridge generated for `set(Object, Void)` casts the argument to `Void`, so `BoundField.set(nonNull)` throws `ClassCastException`. That is pre-existing, reachable before this patch through `buildStatic().set(x)`, and not addressed here: making writes a true no-op would mean changing the sentinel\u0027s type parameter and its `set` contract, which is a separate concern and belongs upstream first.\n\n`kyuubi-util`\u0027s `DynFields` is copied from `iceberg-common`, which carries the same defect. It is tracked upstream as apache/iceberg#17044 and unfixed as of iceberg 1.11.0. The proposed upstream patch, apache/iceberg#17045, adds the same override but keeps the sentinel exemption in `UnboundField.bind`, so that one line stays different in this copy even after upstream lands.\n\n### How was this patch tested?\n\nNew `DynFieldsTest`, 11 cases, covering the sentinel through every entry point (`build`, `build(target)`, `buildChecked(target)`, `buildStatic`, `buildStaticChecked`, direct `bind`) and the ordinary static/instance field paths:\n\n```\nbuild/mvn test -pl kyuubi-util -am -Dtest\u003dDynFieldsTest -DwildcardSuites\u003dnone\n```\n\n```\nTests run: 11, Failures: 0, Errors: 0, Skipped: 0\n```\n\nMutation-checked that the new cases have teeth:\n\n- restoring `DynFields.java` to its state before this patch: 3 cases fail with `NullPointerException: Cannot invoke \"java.lang.reflect.Field.getDeclaringClass()\" because \"this.field\" is null`\n- removing the `AlwaysNull.toString()` override: `testAlwaysNullToStringReportsSentinelName` fails with the same NPE, and only that case\n\n`build/mvn spotless:check -pl kyuubi-util` passes.\n\n### Was this patch assisted by generative AI tooling?\n\nAssisted-by: Claude Opus 5\n\nCloses #7652 from LuciferYang/kyuubi-util-dynfields-alwaysnull-bind.\n\nCloses #7651\n\n4587501ba [yangjie01] Narrow the AlwaysNull exemption in bind and cover the sentinel\u0027s toString\nac6432ddf [yangjie01] Fix NPE binding the AlwaysNull sentinel field in DynFields\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "f316cd38175839394b4b996b29c72614ef76bfc8",
      "tree": "1e412bae2a616c38f6671206099f1525c02ec627",
      "parents": [
        "cfbbeec429db0115ce42fbaf91f13c6eb9092762"
      ],
      "author": {
        "name": "YangJie",
        "email": "yangjie01@baidu.com",
        "time": "Mon Aug 24 10:25:03 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 24 10:25:03 2026 +0800"
      },
      "message": "[KYUUBI #7640] Fix exception double-unwrap in DynMethods.UnboundMethod.invoke\n\n### Why are the changes needed?\n\nFix #7640.\n\n`UnboundMethod.invoke` unwrapped exceptions twice: `invokeChecked` already throws the real exception produced by the invoked method, but `invoke` re-threw `e.getCause()` as if `e` were still the `InvocationTargetException`. Consequences:\n\n- an exception without a cause degraded to `new RuntimeException(null)` — the type, message and stack trace of the real failure were all lost;\n- a `RuntimeException` carrying a cause was silently replaced by that cause, so `catch (IllegalStateException)` at a call site missed an `IllegalStateException` thrown by the target.\n\nThe fix re-throws `RuntimeException` as-is and wraps checked exceptions with the real exception as cause, matching the sibling `DynConstructors.Ctor.newInstance` and restoring the semantics both upstreams always had (parquet-common, unchanged since PARQUET-777; Iceberg) and that were lost during vendoring in db0047d51 ([KYUUBI #3230]).\n\nAll in-repo `.invoke`/`.invokeChecked` call sites were audited: none depends on the old behavior. Callers going through `ReflectUtils.invokeAs` keep their top-level message but now carry the real cause; direct users of the wrappers (`EmbeddedExecutorFactory`, `KyuubiSparkUtil`, `EngineTab`, `RowSet`) now see the real exception type and message.\n\n### How was this patch tested?\n\nAdded `DynMethodsTest`, the first unit tests for `org.apache.kyuubi.util.reflect`: 9 cases covering both failure modes of the old code, a causeless-`RuntimeException` identity pin (`assertSame`), a checked-exception-carrying-runtime-cause pin, the `BoundMethod`/`StaticMethod` wrappers, fixed-arity and varargs happy paths, and the `invokeChecked` contract.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: GLM-5.3\nAssisted-by: Claude Opus\n\nCloses #7641 from LuciferYang/kyuubi-util-dynmethods-invoke-unwrap.\n\nCloses #7640\n\n1ebd67d6f [yangjie01] [KYUUBI #7640][UTIL] Drop bug-history comments from DynMethodsTest\nc89486d45 [yangjie01] [KYUUBI #7640][UTIL] Fix exception double-unwrap in DynMethods.UnboundMethod.invoke\n\nAuthored-by: YangJie \u003cyangjie01@baidu.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "cfbbeec429db0115ce42fbaf91f13c6eb9092762",
      "tree": "7024267abc609c3e9a3c871b201f85ced54e4e3b",
      "parents": [
        "3bc223dbec2ace1692ba22769404c9dd329981ed"
      ],
      "author": {
        "name": "byron",
        "email": "byronwangAm@outlook.com",
        "time": "Fri Aug 21 18:28:24 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 21 18:28:24 2026 +0800"
      },
      "message": "[KYUUBI #7635][SPARK] Support Zstd compression for Arrow IPC query results\n\n### Why are the changes needed?\n\nKyuubi\u0027s Arrow result format reduces serialization/deserialization overhead, but Arrow IPC results are currently transferred without compression. For large result sets, network transfer can become a significant part of fetch latency.\n\nThis follows up on #3877 (related issue #3865). Spark 4.1 introduced the upstream Arrow compression configurations (`SPARK-54134`), so this PR follows Spark\u0027s configuration and Arrow IPC compression semantics instead of introducing a Kyuubi-specific protocol.\n\nThe main changes are:\n\n- Support `none` (default) and `zstd` for Arrow IPC query results, including ZSTD compression-level configuration.\n- Preserve compression when Arrow batches are sliced, e.g. when `LIMIT` crosses a batch boundary.\n- Decode compressed batches in the JDBC client using standard Arrow IPC compression metadata.\n- Keep `arrow-compression` optional on the Spark engine side. The default `none` path requires no additional dependency; when zstd is enabled, Kyuubi checks the required Arrow compression capability at runtime and reports a clear error if it is unavailable.\n- Update `kyuubi-hive-jdbc-shaded` to include/relocate `arrow-compression`, while excluding `zstd-jni` and declaring it optional.\n- Exclude `commons-compress`, since LZ4 is not supported.\n\nFor Spark runtimes that do not provide a compatible `arrow-compression` implementation, users enabling zstd need to add one to the Spark classpath. The default `none` behavior remains unchanged.\n\nA cluster benchmark with Kyuubi 1.13.0-SNAPSHOT + Spark 3.5.9 showed 78.8%-81.8% fewer Arrow IPC bytes, with fetch time reduced from 19.3s to 7.5s in the 8-column case and from 205.8s to 94.1s in the 34-column case.\n\n### How was this patch tested?\n\nAdded/updated coverage for:\n\n- ZSTD compression/decompression and compression-level behavior.\n- Compressed batch slicing across `LIMIT` boundaries.\n- Full JDBC client \u003c\u003d\u003e Kyuubi server \u003c\u003d\u003e Spark engine ZSTD round trip.\n- The default `none` path with no `arrow-compression` on the engine classpath.\n- Runtime capability checking when zstd is enabled without the required dependency.\n- Session-level `none -\u003e zstd -\u003e none` switching within the same engine.\n- Unsupported LZ4 configuration.\n\nTargeted engine tests and `KyuubiOperationPerUserSuite` pass on JDK 17 / Spark 3.5.8. The shaded artifacts were also checked to verify the intended `arrow-compression` / `zstd-jni` packaging.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: DeepSeek Harness:deepseek-v4-pro\n\nCloses #7636 from byronwang123/kyuubi-7635-arrow-ipc-compression.\n\nCloses #7635\n\n8911c395f [byronwang] [KYUUBI #7635][SPARK][TEST] Make session-level zstd test independent of the engine classpath\n34e8ac6f3 [byronwang] [KYUUBI #7635][SPARK][FOLLOWUP] Prefix Arrow compression helper with Kyuubi\n347e38aab [byronwang] [KYUUBI #7635][SPARK][FOLLOWUP] Detect arrow-compression capability at runtime before using zstd\nc761a93ac [byronwang] [KYUUBI #7635][SPARK][FOLLOWUP] Make arrow-compression optional on the engine side and exclude zstd-jni from the shaded client\n024f3c685 [byronwang] [KYUUBI #7635][SPARK][FOLLOWUP] Drop commons-compress from the arrow-compression dependency chain\nc9afd969a [byronwang] [KYUUBI #7635][SPARK][FOLLOWUP] Make LIMIT slice tests deterministic and fail fast on unsupported codec\ned8339839 [byronwang] [KYUUBI #7635][SPARK] Reject lz4 codec and drop reflective Dataset#toArrowBatchRdd\nc041d1cd6 [byronwang] [KYUUBI #7635][SPARK] Bundle relocated arrow-compression into the engine jar\n0dddffe64 [byronwang] [KYUUBI #7635][SPARK] Support Arrow IPC compression for query results (zstd)\n\nAuthored-by: byron \u003cbyronwangAm@outlook.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "3bc223dbec2ace1692ba22769404c9dd329981ed",
      "tree": "81e101baeea15518c034598e2073ab50b38b10dc",
      "parents": [
        "f1e7fc5749226214ddad821a4fa6ffb837846074"
      ],
      "author": {
        "name": "zanarelli",
        "email": "zanarelli.dev@gmail.com",
        "time": "Fri Aug 21 16:20:27 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 21 16:20:27 2026 +0800"
      },
      "message": "[KYUUBI #7639] Give kyuubi.server.redaction.regex a default so REDACTED redacts on a stock install\n\nFollow-up from a private report I sent to securityapache.org (forwarded to the Kyuubi PMC, cc Yikf pan3793 turboFei). aajisaka reviewed the original patch (which made the REST session-conf response fail closed on an unset regex) and flagged it as a breaking change for the conf-map shape, and suggested the master-branch fix should instead give the redaction regex a real default. This PR is that.\n\n### Why are the changes needed?\n\n`kyuubi.server.conf.retrieveMode` defaults to `REDACTED` since 1.12.0, but the regex it depends on (`kyuubi.server.redaction.regex`) has no default (`createOptional`, no `createWithDefault`). `ApiUtils.buildConf`\u0027s `REDACTED` case hands that `None` straight to `Utils.redact`, whose `None` branch returns the conf map untouched. So `GET /api/v1/sessions` and `GET /api/v1/sessions/{handle}` return session conf — including `spark.password`-style keys — unredacted on a stock install, even though the retrieve mode is `REDACTED`.\n\n`SessionsResourceSuite` masked this: its shared `conf` sets `kyuubi.server.redaction.regex` to `(?i)password` explicitly (line 45), so no existing test exercises the stock-default path.\n\n### Fix\n\nGive `kyuubi.server.redaction.regex` a default of `\"(?i)secret|password|token|access[.]key\"` — the same fallback pattern `SparkSQLEngine` already uses for `spark.redaction.regex` (`SparkSQLEngine.scala:275`), so this isn\u0027t a new convention. `REDACTED` now actually redacts by default instead of silently behaving like `ORIGINAL`. As a side effect, `Utils.redactCommandLineArgs` (which shares the same config entry for redacting spawned command-line args) gets the same improvement.\n\nAlso updated `SERVER_CONF_RETRIEVE_MODE`\u0027s doc to reflect that the redaction pattern now has a default.\n\n### How was this patch tested?\n\n- Added `SessionsResourceSuite`: \"get /sessions redacts spark confs by default with no explicit redaction regex\" — explicitly unsets the redaction pattern (`withNoExplicitRedactionPattern`) and asserts a `spark.password` value comes back redacted, not raw.\n- Verified fail-before/pass-after locally: with the config default reverted, the new test fails with the raw secret value present in the response (`\"shouldNeverLeak\" equaled \"shouldNeverLeak\"`); with the default applied, it passes.\n- `build/mvn test -pl kyuubi-server -am -DwildcardSuites\u003dorg.apache.kyuubi.server.api.v1.SessionsResourceSuite`: 9/9 relevant tests pass (3 unrelated tests in this suite — `submit operation and get operation handle`, `fix kyuubi session leak caused by engine stop`, `list all type operations under session` — fail identically on unmodified `master` in this environment; confirmed pre-existing/environmental, not related to this change).\n- `dev/reformat` run; diff scoped back down to the 4 files this PR touches (the initial pass also reformatted unrelated pre-existing drift across `kyuubi-hive-beeline`/`kyuubi-hive-jdbc`, reverted before committing).\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude Sonnet 5\n\nCloses #7639 from zanarellidev/fix/redact-session-conf-when-no-redaction-pattern.\n\nCloses #7639\n\ne01fbd846 [zanarelli] [KYUUBI #7639][DOCS] Stop emphasizing the redaction-regex default in .doc(), regen config docs\n6ce22bd65 [zanarelli] Give kyuubi.server.redaction.regex a default so REDACTED redacts on a stock install\n\nAuthored-by: zanarelli \u003czanarelli.dev@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "f1e7fc5749226214ddad821a4fa6ffb837846074",
      "tree": "8b68f872693d386243e9de7c64fa5b033fb8b567",
      "parents": [
        "6218835119f032fcad4866b046e2649ba62462a5"
      ],
      "author": {
        "name": "Shuhang Han",
        "email": "148054964+HanShuhang@users.noreply.github.com",
        "time": "Fri Aug 21 16:18:59 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 21 16:18:59 2026 +0800"
      },
      "message": "[KYUUBI #7643] [TESTS] Fix closed operation metric assertion\n\n### Why are the changes needed?\n\n`KyuubiOperationPerUserSuite` used `finishedMetric` as the baseline for `closedCount`; this patch fixes it to use `closedMetric`.\n\n### How was this patch tested?\n\n```\nbuild/mvn test -pl kyuubi-server -am  \\\n             -Dtest\u003dnone \\\n             -DwildcardSuites\u003dorg.apache.kyuubi.operation.KyuubiOperationPerUserSuite\n```\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nNo\n\nCloses #7643 from HanShuhang/hsh/fix-ut.\n\nCloses #7643\n\n71c4c80b7 [hanshuhang.lxy] [KYUUBI][TESTS] Fix closed operation metric assertion\n\nLead-authored-by: Shuhang Han \u003c148054964+HanShuhang@users.noreply.github.com\u003e\nCo-authored-by: hanshuhang.lxy \u003chanshuhang.lxy@bytedance.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "6218835119f032fcad4866b046e2649ba62462a5",
      "tree": "c4b11d3c08ae6638290d77d1f37cc24a8f0b6a5e",
      "parents": [
        "ddcc31c9738f802813ec3d2f12996a1f64ed50a2"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 21 15:15:04 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 21 15:15:04 2026 +0800"
      },
      "message": "[KYUUBI #7638] Minor improvement of PR template\n\n### Why are the changes needed?\n\nSmall words tune, please review the inline change.\n\n### How was this patch tested?\n\nReview.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nNo.\n\nCloses #7638 from pan3793/pr-tmpl.\n\nCloses #7638\n\n6ec8ceebd [Cheng Pan] Minor improvement of PR template\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "ddcc31c9738f802813ec3d2f12996a1f64ed50a2",
      "tree": "899afdf325cc84c395ce9931f0eb5bb9de59250f",
      "parents": [
        "ad817afd4d31e06d1a32abd16dc8d2e981289d4c"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 17 11:29:07 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Aug 17 11:29:07 2026 +0800"
      },
      "message": "[KYUUBI #7633] Drop support for Flink 1.17, 1.18 and 1.19\n\n### Why are the changes needed?\n\nFlink 1.17, 1.18 and 1.19 are EOL and were deprecated earlier (KYUUBI #7199, KYUUBI #7285),\nwith their building support already removed. Kyuubi 1.13 drops the remaining support, making\nFlink 1.20 the minimum. Flink 2.0 is EOL, so it is marked deprecated.\n\n### What changes are proposed?\n\n- Remove the flink-1.17/flink-1.18/flink-1.19 Maven profiles and their deprecation warning\n- Drop Flink 1.17/1.18/1.19 from the CI matrix\n- Clean up stale adaptation code that only existed for Flink \u003c 1.20, including the\n  FlinkResultSet reflection shim, the 4-arg DefaultContext.load branch, and \u003e\u003d \"1.17\" test guards\n- Remove the obsolete kyuubi.engine.flink.doAs.generateTokenFile workaround, superseded by\n  FLINK-35525 (1.20.0)\n- Deprecate Flink 2.0 at engine startup\n- Update docs to record the removal and deprecation\n\n### How was this patch tested?\n\nCross-version tested: engine compiled with Flink 1.20, run against a Flink 2.3.0 distribution;\nFlinkOperationSuite and FlinkOperationSuiteOnYarn passed 12/12.\n\nCI coverage: the flink-it matrix keeps Flink 1.20 (JDK 8) plus Flink 2.0/2.1/2.2/2.3\nbinary verification (JDK 17). Spotless and Scalastyle pass.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: DeepSeek V4 Pro\n\nCloses #7633 from pan3793/kyuubi-drop-flink-1-17-1-18-1-19.\n\nCloses #7633\n\n76c03d987 [Cheng Pan] Remove obsolete kyuubi.engine.flink.doAs.generateTokenFile\na33970f57 [Cheng Pan] Drop support for Flink 1.17, 1.18 and 1.19\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "ad817afd4d31e06d1a32abd16dc8d2e981289d4c",
      "tree": "17b9f943e54e6003810ed6ce914333ba83d2fa91",
      "parents": [
        "3df4e50ce54127f38d8efd1f1b19018df345e577"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 14 13:25:19 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 14 13:25:19 2026 +0800"
      },
      "message": "[KYUUBI #7631] Drop support for Spark 3.3 and 3.4\n\n### Why are the changes needed?\n\nSpark 3.3 and 3.4 are EOL and were deprecated in KYUUBI #7285. Kyuubi 1.13 drops support for them, and Spark 3.5 becomes the minimum supported version.\n\n### What changes are proposed?\n\n- Remove the spark-3.3/spark-3.4 Maven profiles and the kyuubi-extension-spark-3-3/kyuubi-extension-spark-3-4 modules\n- Drop Spark 3.3/3.4 from CI matrices, snapshot publishing, release scripts, and codecov\n- Remove compatibility shims that only existed for Spark \u003c 3.5, including reflections, version gates, and Python 2/pre-3.8 code\n- Update docs to record the removal\n\n### How was this patch tested?\n\nThe patch also updates CI itself; after the change, GHA covers:\n\n- default job: Spark 3.5 (Scala 2.12, JDK 17) and Spark 4.0/4.1/4.2 (Scala 2.13, JDK 21)\n- binary verification: the engine built with Spark 3.5 runs against Spark 4.0.3/4.1.2/4.2.0 distributions\n- connector cross-version tests: connectors compiled with Spark 3.5 run against Spark 4.0/4.1/4.2 runtimes\n- scala-test: Spark 3.5 on JDK 8 with Scala 2.13\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: DeepSeek V4 Pro\n\nCloses #7631 from pan3793/kyuubi-drop-spark-3-3-3-4.\n\nCloses #7631\n\nec36d52d5 [Cheng Pan] Update snapshot publish matrix to Spark 3.5 and 4.x\nf2e6f01ee [Cheng Pan] Drop Python 3.11 from Python Client CI matrix\n13a476940 [Cheng Pan] Drop support for Spark 3.3 and 3.4\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "3df4e50ce54127f38d8efd1f1b19018df345e577",
      "tree": "2049f3563e94148ed0e3b5a87ac75359a0fce34c",
      "parents": [
        "0e1c4a38c5c83ffdc6a4ecce194d78c38249b4ee"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 14 01:24:14 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Aug 14 01:24:14 2026 +0800"
      },
      "message": "[KYUUBI #6995] Support Flink 2.0, 2.1, 2.2 and 2.3\n\n### Why are the changes needed?\n\nCloses #6995.\n\nExtend the Flink SQL engine to support Flink 2.0, 2.1, 2.2 and 2.3, while keeping the existing\n1.17 to 1.20 support. The engine keeps shipping a single jar that runs against all supported\nFlink versions, so the version differences are bridged by reflection rather than by per-version\nsource trees.\n\nFlink 2.x changes that the engine has to adapt to:\n\n- FLINK-14068 (2.0.0) removed `org.apache.flink.api.common.time.Time` in favor of `Duration`,\n  which is a parameter of `EmbeddedJobClient`\u0027s constructor.\n- FLINK-33212 (2.0.0) added a `Configuration` parameter to `EmbeddedExecutor`\u0027s constructor.\n- FLINK-38974 (2.3.0) split `EmbeddedExecutorFactory`\u0027s and `EmbeddedExecutor`\u0027s job ids into the\n  application, suspended and terminal ones, and made the dispatcher reject jobs that carry no\n  registered application id. Flink resolves the factory constructor at compile time, so Kyuubi\u0027s\n  copy of `EmbeddedExecutorFactory` declares both constructors and stamps the application id\n  captured from the bootstrap job on every submitted `StreamGraph`, which enables application\n  mode on Flink 2.3.\n- FLINK-35625 and FLINK-36310 (2.0.0) merged `flink run-application` into `flink run` and removed\n  the former, so `FlinkProcessBuilder` picks the action by the version detected from the\n  `flink-dist` jar under `$FLINK_HOME/lib`.\n- FLINK-36760 (2.0.0) removed `CliOptionsParser#checkFilePath`, which is now inlined into\n  `FlinkEngineUtils`. Note that `DefaultContext#load` needs no adaption, its dependency list\n  changed from `List\u003cURL\u003e` to `List\u003cURI\u003e` but both erase to the same descriptor, and Flink still\n  reads the elements as `URL` in `SessionContext#create`.\n- `Configuration#getString(ConfigOption)` was removed, `Configuration#get(ConfigOption)` is used\n  instead, which exists in all supported versions.\n\nFlink 2.x requires Java 11 or higher and is compiled with Java 11 target, so the `flink-2.x`\nprofiles raise `enforcer.maxJdkVersion` to 11, and the Flink 2.x CI jobs run on Java 17.\n\n### How was this patch tested?\n\nNew UTs cover the Flink version detection and the application mode command selection in\n`FlinkProcessBuilderSuite`.\n\n`FlinkOperationSuite` asserts the result of `ENCODE` by version, since FLINK-38062 (2.2.0)\ncorrected its return type from `BINARY` to `VARBINARY`, before that the result was silently\ntruncated to the first byte.\n\n`externals/kyuubi-flink-sql-engine` tests were run against each Flink binary distribution, with\n`FLINK_HOME` pinned to the matching distribution:\n\n| Flink | Result |\n| --- | --- |\n| 1.20.5 | 111 passed |\n| 2.0.2 | 111 passed |\n| 2.1.3 | 111 passed |\n| 2.2.1 | 111 passed |\n| 2.3.0 | 111 passed |\n\n`FlinkOperationOnYarnSuite` covers application mode on Flink 2.3, and the cross-version job\ncompiles the engine against Flink 1.20 and runs it on the Flink 2.3 distribution.\n\nThe GA `flink-it` matrix now always compiles against the default Flink version and varies only\nthe runtime distribution, covering 1.17, 1.18, 1.19 on Java 8 and 2.0, 2.1, 2.2, 2.3 on Java 17.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude Opus 5, Codex\n\nCloses #7628 from pan3793/kyuubi-flink-2.\n\nCloses #6995\n\n9b53c59fc [Cheng Pan] [KYUUBI #6995][FLINK] Support Flink 2.3 application mode\n8d711e294 [Cheng Pan] Cancel Flink IT application mode suite per test on Flink 2.3\n7fbe4ec1c [Cheng Pan] Skip Flink IT application mode suite on Flink 2.3\ne7166614f [Cheng Pan] Fix Flink IT compile against Flink 2.x\na0056ce26 [Cheng Pan] [KYUUBI #6995][FLINK] Support Flink 2.0, 2.1, 2.2 and 2.3\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "0e1c4a38c5c83ffdc6a4ecce194d78c38249b4ee",
      "tree": "6568cc161e7401482e7f98421f552c62a920022b",
      "parents": [
        "032c379bb643615682ab280fc88143647077ca64"
      ],
      "author": {
        "name": "wforget",
        "email": "643348094@qq.com",
        "time": "Thu Aug 13 21:44:05 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Aug 13 21:44:05 2026 +0800"
      },
      "message": "[KYUUBI #7613][BUILD] Use spark 3.5 to build the extra scala 2.12 engine for spark 4.x\n\n### Why are the changes needed?\n\n`build/dist` packages Spark SQL engine artifacts for both Scala 2.12 and Scala 2.13.\n\nWhen Spark 4.x and Scala 2.13 profiles are specified, the extra engine build switches the Scala profile to 2.12 but retains the Spark 4.x profile. Since Spark 4.x artifacts are unavailable for Scala 2.12, Maven dependency resolution fails.\n\nThe distribution should continue shipping both engine variants so that it can support Spark 4.x while retaining compatibility with Spark 3.5 LTS. This patch replaces the Spark 4.x or `spark-master` profile with `spark-3.5` when building the extra Scala 2.12 engine.\n\nCloses #7613.\n\n### How was this patch tested?\n\nbuild successful using the command `./build/dist --tgz --spark-provided --flink-provided --hive-provided -Pspark-4.2,scala-2.13`.\n\n```\n+ FILTERED_ARGS\u003d()\n+ EXTRA_SCALA_212_SPARK_PROFILE\u003dspark-3.5\n+ for arg in \u0027\"$\"\u0027\n+ FILTERED_ARG\u003d-Pspark-4.2,scala-2.13\n+ [[ -Pspark-4.2,scala-2.13 \u003d\u003d *scala-2.12* ]]\n+ [[ -Pspark-4.2,scala-2.13 \u003d\u003d *scala-2.13* ]]\n+ FILTERED_ARG\u003d-Pspark-4.2,scala-2.12\n+ [[ 2.13 \u003d\u003d \\2\\.\\1\\3 ]]\n+ [[ 4.2.0 \u003d\u003d 4.* ]]\n+ [[ -Pspark-4.2,scala-2.12 \u003d~ spark-4\\.[0-9]+ ]]\n+ FILTERED_ARG\u003d-Pspark-3.5,scala-2.12\n+ [[ -Pspark-3.5,scala-2.12 \u003d~ spark-4\\.[0-9]+ ]]\n+ FILTERED_ARG\u003d-Pspark-3.5,scala-2.12\n+ FILTERED_ARGS+\u003d(\"$FILTERED_ARG\")\n+ \u0027[\u0027 2.13 \u003d 2.12 \u0027]\u0027\n+ EXTRA_SPARK_ENGINE_BUILD_COMMAND\u003d(\"$MVN\" install $MVN_DIST_OPT ${FILTERED_ARGS[]} -pl :kyuubi-spark-sql-engine_2.12 -am)\n+ echo -e \u0027$ /Users/wforget/work/git/kyuubi/build/mvn\u0027 install -DskipTests -Dmaven.source.skip -Pspark-provided -Pflink-provided -Phive-provided -Pspark-3.5,scala-2.12 -pl :kyuubi-spark-sql-engine_2.12 \u0027-am\\n\u0027\n$ /Users/wforget/work/git/kyuubi/build/mvn install -DskipTests -Dmaven.source.skip -Pspark-provided -Pflink-provided -Phive-provided -Pspark-3.5,scala-2.12 -pl :kyuubi-spark-sql-engine_2.12 -am\n\n+ /Users/wforget/work/git/kyuubi/build/mvn install -DskipTests -Dmaven.source.skip -Pspark-provided -Pflink-provided -Phive-provided -Pspark-3.5,scala-2.12 -pl :kyuubi-spark-sql-engine_2.12 -am\nUsing `mvn` from path: /Users/wforget/work/git/kyuubi/build/apache-maven-3.9.14/bin/mvn\n```\n\n\u003cimg width\u003d\"873\" height\u003d\"116\" alt\u003d\"image\" src\u003d\"https://github.com/user-attachments/assets/6c6f9059-475f-45f2-af1f-bb450a2c460d\" /\u003e\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Codex:GPT-5.6\n\nCloses #7614 from wForget/KYUUBI-7613.\n\nCloses #7613\n\nb146eb43b [wforget] Build Spark engines for both Scala versions\n0d8c8f810 [wforget] Build extra Spark engine only for supported Spark versions\n\nAuthored-by: wforget \u003c643348094@qq.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "032c379bb643615682ab280fc88143647077ca64",
      "tree": "87b96253bb4e4756e85ad8853c7a8c943aac3b93",
      "parents": [
        "4b8a225c00caf49f6d21ad8a8988fb362da6495b"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Aug 13 14:11:48 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Aug 13 14:11:48 2026 +0800"
      },
      "message": "[KYUUBI #7627] [KSHC] Fix connector compatibility with Spark 4.2\n\n### _Why are the changes needed?_\n\nThe `spark-4.2` Maven profile is already supported, but the connectors compiled against Spark 3.5 fail with `NoSuchMethodError` at runtime against Spark 4.2, because Spark 4.2 changed several case classes:\n\n- SPARK-55645 added `serdeName` to `CatalogStorageFormat`\n- SPARK-50675 added `collation` to `CatalogTable`\n- SPARK-52729 added `multipartIdentifier` to `CatalogTable`\n- SPARK-54870 added `collation` to `CharType`/`VarcharType`\n\nDispatch the affected constructors/copies through the `Dyn*` reflection helpers so the connector jar stays binary-compatible across Spark 3.5, 4.0, 4.1 and 4.2, and add Spark 4.2 to the connector cross-version test matrix to guard it.\n\n### _How was this patch tested?_\n\nCross-version test matrix, compiled against Spark 3.5 and run against Spark 3.3/3.4 (Scala 2.12) and 3.5/4.0/4.1/4.2 (Scala 2.13) - all pass.\n\n### _Was this patch authored or co-authored using generative AI tooling?_\n\nAssisted-by: DeepSeek V4 Pro\n\nCloses #7627 from pan3793/spark-connector-test.\n\nCloses #7627\n\n1c168d360 [Cheng Pan] [KSHC] Support Spark 4.2 in the connector cross version test\n0cd340c59 [Cheng Pan] [INFRA] Add Spark 4.2 to spark connector cross version test\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "4b8a225c00caf49f6d21ad8a8988fb362da6495b",
      "tree": "ab959378c681391d29e0f0879d30552359fa498a",
      "parents": [
        "aa870b63bdf5d801652fffc6906eb1e850ef2061"
      ],
      "author": {
        "name": "Kaifei Yi",
        "email": "yikaifei@apache.org",
        "time": "Wed Aug 12 23:15:07 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Wed Aug 12 23:15:07 2026 +0800"
      },
      "message": "[KYUUBI #6403][KSHC] Fix write into partitioned table with non-last partition column\n\n### Why are the changes needed?\n\nFixes [#6403](https://github.com/apache/kyuubi/issues/6403).\n\nWriting a partitioned Hive table via the Kyuubi Spark Hive connector fails when the partition column is **not the last column** of the schema, e.g. `df.write.partitionBy(\"mid_col\").saveAsTable(...)`.\n\nThere are two root causes:\n\n1. `HiveWrite` split data/partition columns **positionally** with `take`/`takeRight`, assuming partition columns are always trailing. When a partition column is in the middle, columns are mis-classified and the metastore rejects the written partition spec:\n   ```\n   Table$ValidationFailureSemanticException: Partition spec {favorite_color\u003d, favorite_numbers\u003d2} contains non-partition columns\n   ```\n2. The Hive metastore reorders partition columns to the end of the schema, but the CTAS query output keeps the original column order. Spark\u0027s `ResolveOutputRelation` resolves output columns **by position**, so a non-last partition column is mis-cast onto a trailing data column (`INCOMPATIBLE_DATA_FOR_TABLE.CANNOT_SAFELY_CAST`).\n\nThis fixes both:\n- `HiveWrite` now splits data/partition columns **by name** against `table.partitionColumnNames` (also for the write `dataSchema` derivation).\n- `HiveTableCatalog.createTable` preserves the requested schema order on the returned table, so the subsequent CTAS write resolves output columns against the original order.\n\nAffects 1.8.1 and current `master`.\n\n### How was this patch tested?\n\nAdded a regression test in `HiveQuerySuite` that writes a table whose partition column is in the middle of the schema, using **mixed column types** (`String`/`String`/`Int`) so the schema-order bug is genuinely exercised (an all-`String` case would not surface the cast failure).\n\nVerified locally with `-Pspark-3.5`:\n- `HiveQuerySuite`: 21 tests passed (incl. the new case)\n- `HiveCatalogSuite`: 24 tests passed\n- `dev/reformat` (Spotless + Scalastyle) passed\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-opus-4-8\n\nCloses #7622 from yikf/kyuubi-6403-non-last-partition-column.\n\nCloses #6403\n\n08a5c53bc [Kaifei Yi] Fix write into partitioned table with non-last partition column\n\nAuthored-by: Kaifei Yi \u003cyikaifei@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "aa870b63bdf5d801652fffc6906eb1e850ef2061",
      "tree": "abcf459929f34b5545e4564cb8272ee120fa7e93",
      "parents": [
        "6607767fd4f91effa3f4b5f9e665147c2c6a6b9e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Aug 11 15:08:14 2026 +0200"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Tue Aug 11 15:08:14 2026 +0200"
      },
      "message": "[KYUUBI #7611] Bump actions/stale from 10 to 11\n\nBumps [actions/stale](https://github.com/actions/stale) from 10 to 11.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/actions/stale/releases\"\u003eactions/stale\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev11.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancement\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate to ESM and update dependencies by \u003ca href\u003d\"https://github-grid.enterprise.slack.com/team/U08CVLQ4JKE\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1350\"\u003eactions/stale#1350\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency Update\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eOverride brace-expansion to 5.0.8 to address 24 high-severity dependency vulnerabilities by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1351\"\u003eactions/stale#1351\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/stale/compare/v10...v11.0.0\"\u003ehttps://github.com/actions/stale/compare/v10...v11.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eBug Fix\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eonly-issue-types\u003c/code\u003e validation  by \u003ca href\u003d\"https://github.com/trueberryless\"\u003e\u003ccode\u003e​trueberryless\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1338\"\u003eactions/stale#1338\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency Updates\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump undici to 6.27.0 via override, clean up stale license files, and version to 10.4.0. by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1342\"\u003eactions/stale#1342\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/trueberryless\"\u003e\u003ccode\u003e​trueberryless\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1338\"\u003eactions/stale#1338\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/stale/compare/v10.3.0...v10.4.0\"\u003ehttps://github.com/actions/stale/compare/v10.3.0...v10.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eBug Fix\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnhancement: ignore stale labeling events by \u003ca href\u003d\"https://github.com/shamoon\"\u003e\u003ccode\u003e​shamoon\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1311\"\u003eactions/stale#1311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency Updates\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade dependencies (\u003ccode\u003e​actions/core\u003c/code\u003e, \u003ccode\u003e​octokit/plugin-retry\u003c/code\u003e, \u003ca href\u003d\"https://github.com/typescript-eslint\"\u003e\u003ccode\u003e​typescript-eslint\u003c/code\u003e\u003c/a\u003e) by \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1335\"\u003eactions/stale#1335\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/shamoon\"\u003e\u003ccode\u003e​shamoon\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1311\"\u003eactions/stale#1311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/stale/compare/v10...v10.3.0\"\u003ehttps://github.com/actions/stale/compare/v10...v10.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eBug Fix\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix checking state cache (fix \u003ca href\u003d\"https://redirect.github.com/actions/stale/issues/1136\"\u003e#1136\u003c/a\u003e) and switch to Octokit helper methods by \u003ca href\u003d\"https://github.com/itchyny\"\u003e\u003ccode\u003e​itchyny\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1152\"\u003eactions/stale#1152\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency Updates\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade js-yaml from  4.1.0 to 4.1.1 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1304\"\u003eactions/stale#1304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade lodash from 4.17.21 to 4.17.23 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1313\"\u003eactions/stale#1313\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade actions/cache from 4.0.3 to 5.0.2 and actions/github from 5.1.1 to 7.0.0  by \u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1312\"\u003eactions/stale#1312\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/itchyny\"\u003e\u003ccode\u003e​itchyny\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1152\"\u003eactions/stale#1152\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/stale/compare/v10...v10.2.0\"\u003ehttps://github.com/actions/stale/compare/v10...v10.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/actions/stale/blob/main/CHANGELOG.md\"\u003eactions/stale\u0027s changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch1\u003e[10.1.0]\u003c/h1\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd only-issue-types option to filter issues by type by \u003ca href\u003d\"https://github.com/Bibo-Joshi\"\u003e\u003ccode\u003e​Bibo-Joshi\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1255\"\u003eactions/stale#1255\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e[10.0.0]\u003c/h1\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch2\u003eBreaking Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to node 24 by \u003ca href\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1279\"\u003eactions/stale#1279\u003c/a\u003e\nMake sure your runner is on version v2.327.1 or later to ensure compatibility with this release. \u003ca href\u003d\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003eRelease Notes\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eEnhancement\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIntroducing sort-by option by \u003ca href\u003d\"https://github.com/suyashgaonkar\"\u003e\u003ccode\u003e​suyashgaonkar\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1254\"\u003eactions/stale#1254\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependency Upgrades\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade actions/publish-immutable-action from 0.0.3 to 0.0.4 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1186\"\u003eactions/stale#1186\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade undici from 5.28.4 to 5.28.5 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1201\"\u003eactions/stale#1201\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e​action/cache\u003c/code\u003e from 4.0.0 to 4.0.2 by \u003ca href\u003d\"https://github.com/aparnajyothi-y\"\u003e\u003ccode\u003e​aparnajyothi-y\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1226\"\u003eactions/stale#1226\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e​action/cache\u003c/code\u003e from 4.0.2 to 4.0.3 by \u003ca href\u003d\"https://github.com/suyashgaonkar\"\u003e\u003ccode\u003e​suyashgaonkar\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1233\"\u003eactions/stale#1233\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade undici from 5.28.5 to 5.29.0 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1251\"\u003eactions/stale#1251\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade form-data to bring in fix for critical vulnerability by \u003ca href\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1277\"\u003eactions/stale#1277\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChangelog update for recent releases by \u003ca href\u003d\"https://github.com/suyashgaonkar\"\u003e\u003ccode\u003e​suyashgaonkar\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1224\"\u003eactions/stale#1224\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePermissions update in Readme by \u003ca href\u003d\"https://github.com/ghadimir\"\u003e\u003ccode\u003e​ghadimir\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1248\"\u003eactions/stale#1248\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e[9.1.0]\u003c/h1\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDocumentation update by \u003ca href\u003d\"https://github.com/Marukome0743\"\u003e\u003ccode\u003e​Marukome0743\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1116\"\u003eactions/stale#1116\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd workflow file for publishing releases to immutable action package by \u003ca href\u003d\"https://github.com/Jcambass\"\u003e\u003ccode\u003e​Jcambass\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1179\"\u003eactions/stale#1179\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate undici from 5.28.2 to 5.28.4 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1150\"\u003eactions/stale#1150\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate actions/checkout from 3 to 4 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1091\"\u003eactions/stale#1091\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate actions/publish-action from 0.2.2 to 0.3.0 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1147\"\u003eactions/stale#1147\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate ts-jest from 29.1.1 to 29.2.5 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1175\"\u003eactions/stale#1175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate \u003ccode\u003e​actions/core\u003c/code\u003e from 1.10.1 to 1.11.1 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1191\"\u003eactions/stale#1191\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate \u003ccode\u003e​types/jest\u003c/code\u003e from 29.5.11 to 29.5.14 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1193\"\u003eactions/stale#1193\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate \u003ccode\u003e​actions/cache\u003c/code\u003e from 3.2.2 to 4.0.0 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/stale/pull/1194\"\u003eactions/stale#1194\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e[9.0.0]\u003c/h1\u003e\n\u003ch2\u003eBreaking Changes\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAction is now stateful: If the action ends because of \u003ca href\u003d\"https://github.com/actions/stale#operations-per-run\"\u003eoperations-per-run\u003c/a\u003e then the next run will start from the first unprocessed issue skipping the issues processed during the previous run(s). The state is reset when all the issues are processed. This should be considered for scheduling workflow runs.\u003c/li\u003e\n\u003cli\u003eVersion 9 of this action updated the runtime to Node.js 20. All scripts are now run with Node.js 20 instead of Node.js 16 and are affected by any breaking changes between Node.js 16 and 20.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/stale/commit/4391f3da665fdf50b6810c1a66712fb9ba21aa93\"\u003e\u003ccode\u003e4391f3d\u003c/code\u003e\u003c/a\u003e Fix 24 high severity vulnerabilities by overriding brace-expansion to 5.0.8 (...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/stale/commit/eaf9131fae5eafd0c31a64ebe3a2e183266fec48\"\u003e\u003ccode\u003eeaf9131\u003c/code\u003e\u003c/a\u003e refactor: update imports to use ES module syntax and improve test structure (...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href\u003d\"https://github.com/actions/stale/compare/v10...v11\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/stale\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d10\u0026new-version\u003d11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7611 from dependabot[bot]/dependabot/github_actions/actions/stale-11.\n\nCloses #7611\n\n56d67e347 [dependabot[bot]] Bump actions/stale from 10 to 11\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "6607767fd4f91effa3f4b5f9e665147c2c6a6b9e",
      "tree": "29483b854c5914b8018500ba6e59731f0bbecba5",
      "parents": [
        "6c0098ff298f4a48e4d3acb04eb43361723ecf4f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Aug 11 15:14:06 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Aug 11 15:14:06 2026 +0800"
      },
      "message": "[KYUUBI #7612] Bump docker/login-action from 4.5.1 to 4.6.0\n\nBumps [docker/login-action](https://github.com/docker/login-action) from 4.5.1 to 4.6.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/docker/login-action/releases\"\u003edocker/login-action\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/docker/login-action/compare/abd2ef45e78c5afb21d64d4ca52ee8550d9572c7...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddocker/login-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.5.1\u0026new-version\u003d4.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7612 from dependabot[bot]/dependabot/github_actions/docker/login-action-4.6.0.\n\nCloses #7612\n\naf27da84b [dependabot[bot]] Bump docker/login-action from 4.5.1 to 4.6.0\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "6c0098ff298f4a48e4d3acb04eb43361723ecf4f",
      "tree": "b1e215072f3dad39e76f863e705c8e6d3cfd63a8",
      "parents": [
        "d71d6d88e2363b98b69093c681de4e8629ff2e0a"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Aug 11 15:12:16 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Aug 11 15:12:16 2026 +0800"
      },
      "message": "[KYUUBI #7617] Enable arrow-based query metrics test for Spark 4.1+\n\n### Why are the changes needed?\n\nit was disabled due to SPARK-54749, has been fixed in Spark 4.1.1\n\n### How was this patch tested?\n\nPass GHA.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nNo.\n\nCloses #7617 from pan3793/enable-test.\n\nCloses #7617\n\ne7c7417c0 [Cheng Pan] Enable arrow-based query metrics test for Spark 4.1+\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "d71d6d88e2363b98b69093c681de4e8629ff2e0a",
      "tree": "d047b587407a368c50dbe6911dde89edfc241f65",
      "parents": [
        "ccddf8e56cf3bfce0fed300069e3bd610a902191"
      ],
      "author": {
        "name": "wforget",
        "email": "643348094@qq.com",
        "time": "Tue Aug 11 15:11:12 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Aug 11 15:11:12 2026 +0800"
      },
      "message": "[KYUUBI #7618] Pack spark extension jar into the kyuubi distribution for spark 4.x\n\n### Why are the changes needed?\n\nPack the spark extension jar into the kyuubi distribution for spark 4.x\n\ncloses #7618\n\n### How was this patch tested?\n\n\u003cimg width\u003d\"900\" height\u003d\"492\" alt\u003d\"image\" src\u003d\"https://github.com/user-attachments/assets/35dcc060-8f33-4545-9b7e-6ea8d25e91aa\" /\u003e\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nNo\n\nCloses #7619 from wForget/KYUUBI-7618.\n\nCloses #7618\n\nf3a72e028 [wforget] [KYUUBI #7618] Add spark 4.x and remove spark 3.2 extension versions\n\nAuthored-by: wforget \u003c643348094@qq.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "ccddf8e56cf3bfce0fed300069e3bd610a902191",
      "tree": "7e2feb2624b11d43f849cee8352ef60c8cdf0e75",
      "parents": [
        "a5bb52a0fbf30aa676e0d24753da2a24dbcb6556"
      ],
      "author": {
        "name": "Bowen Liang",
        "email": "liang.bowen.123@qq.com",
        "time": "Thu Aug 06 21:08:23 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Aug 06 21:08:23 2026 +0800"
      },
      "message": "[KYUUBI #7601] [Web] Bump Node.js to v24 LTS and pnpm to v11\n\n### Why are the changes needed?\n\nStay on a supported LTS line and pick up the latest pnpm stable. Node v22 has moved to Maintenance LTS (security fixes only, EOL 2027-04-30); v24 is the current Active LTS and is supported until 2028-04-30. pnpm v12 is still beta, so the latest v11 stable is the right target.\n\n| Tool    | Before   | After            | Released   |\n| ------- | -------- | ---------------- | ---------- |\n| Node.js | v22.23.1 | **v24.11.1** (Active LTS) | 2025-11-11 |\n| pnpm    | v9.11.0  | **v11.18.0**     | 2026-07-29 |\n\nMigration notes:\n\n- pnpm v11 no longer reads the `pnpm` field in `package.json`; moved the security overrides to a new `kyuubi-server/web-ui/pnpm-workspace.yaml`.\n- pnpm v11\u0027s `strictDepBuilds` defaults to true; explicitly allow `parcel/watcher` and `vue-demi` via `allowBuilds` since Vite\u0027s toolchain depends on their install/postinstall scripts.\n- `engines.node` simplified to `\u003e\u003d24.0.0`.\n\n### How was this patch tested?\n\n- Local `pnpm install` against the updated toolchain succeeded with no resolution drift (lockfile content byte-identical to v9.11.0).\n- `pnpm run build` and `pnpm run lint` pass locally.\n- GitHub `web-ui` and `style` workflows both read `node.version` / `pnpm.version` from `pom.xml` and will exercise the new versions end-to-end.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nYes. Assisted-by: OpenCode with MiniMax-M3\n\nCloses #7601 from bowenliang123/kyuubi-bump-node-pnpm.\n\nCloses #7601\n\n0a8c1090c [Bowen Liang] [INFRA] Bump Node.js to v24 LTS and pnpm to v11\n\nAuthored-by: Bowen Liang \u003cliang.bowen.123@qq.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "a5bb52a0fbf30aa676e0d24753da2a24dbcb6556",
      "tree": "7fd0c124a90d91e1f36f188acbebdcaab6a1e371",
      "parents": [
        "0e77fd4a5fcd2cd39af00e74fda52de53cf4e6e0"
      ],
      "author": {
        "name": "nujjwal",
        "email": "nujjwal@cisco.com",
        "time": "Thu Aug 06 21:02:16 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Aug 06 21:02:16 2026 +0800"
      },
      "message": "[KYUUBI #7360] Fix flaky PyHive test connection\n\n### Why are the changes needed?\n\nFixes #7360.\n\n`python/pyhive/tests/test_hive.py::TestHive::test_description` can fail intermittently while opening the Hive connection with `TTransportException: TSocket read 0 bytes`.\n\nThis patch makes the test connection helper retry transient `TTransportException`s before failing, which makes the PyHive integration tests more tolerant of short HiveServer2 startup or connection timing issues.\n\n### How was this patch tested?\n\nAdded a unit test that simulates a transient `TTransportException` from `hive.connect` and verifies that `TestHive.connect()` retries and succeeds on the next attempt.\n\nTested with:\n\n```bash\npython -m pytest python/pyhive/tests/test_hive.py::TestHive::test_connect_retries_transient_transport_failure -q\n\nResult:\n1 passed in 1.07s\n\nCloses #7595 from NikhilUjjwal7/fix-pyhive-test-description-flaky.\n\nCloses #7360\n\n5c4a3f5ac [Cheng Pan] Retry connection-refused in PyHive test connect helper\n46186ca1c [nujjwal] Address PyHive retry review comment\nbde81c3ca [nujjwal] Fix flaky PyHive test connection\n\nLead-authored-by: nujjwal \u003cnujjwal@cisco.com\u003e\nCo-authored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "0e77fd4a5fcd2cd39af00e74fda52de53cf4e6e0",
      "tree": "2863ed68290e1039bc31c64ea9baae02c935e742",
      "parents": [
        "7a70a3cbb964c329766e090e18a297f4bbb20dc9"
      ],
      "author": {
        "name": "lifumao",
        "email": "lifumao@tencent.com",
        "time": "Thu Aug 06 20:51:01 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Aug 06 20:51:01 2026 +0800"
      },
      "message": "[KYUUBI #7608][AUTHZ] Include commons-collections into authz\n\n### Why are the changes needed?\n\nFix https://github.com/apache/kyuubi/issues/7608. kyuubi-spark-authz fails during plugin initialization on Spark 4.1+\n```\njava.lang.NoClassDefFoundError: org/apache/commons/collections/CollectionUtils\n  at org.apache.ranger.authorization.hadoop.config.RangerPluginConfig.setSuperUsersGroups(RangerPluginConfig.java:239)\n  at org.apache.ranger.plugin.service.RangerBasePlugin.setSuperUsersAndGroups(RangerBasePlugin.java:263)\n  at org.apache.ranger.plugin.service.RangerBasePlugin.\u003cinit\u003e(RangerBasePlugin.java:112)\n  at org.apache.kyuubi.plugin.spark.authz.ranger.SparkRangerAdminPlugin$.\u003cinit\u003e(SparkRangerAdminPlugin.scala:30)\n  at org.apache.kyuubi.plugin.spark.authz.ranger.RangerSparkExtension.\u003cinit\u003e(RangerSparkExtension.scala:44)\n```\nRanger\u0027s `RangerPluginConfig` uses `org.apache.commons.collections.CollectionUtils` (commons-collections 3.x) but declares that dependency with provided scope. Spark 3.x ships commons-collections-3.2.2.jar in $SPARK_HOME/jars/, but Spark 4.1+ only ships commons-collections4, and Hadoop 3.4.2+ removed the 3.x transitive dependency via [HADOOP-15760](https://issues.apache.org/jira/browse/HADOOP-15760).\n\n### How was this patch tested?\n\n```\n$ build/mvn dependency:tree -pl :kyuubi-spark-authz_2.13 -am -Pspark-4.1 -Pscala-2.13 -Dincludes\u003dcommons-collections:commons-collections\n\n[INFO] org.apache.kyuubi:kyuubi-spark-authz_2.13:jar:1.13.0-SNAPSHOT\n[INFO] \\- commons-collections:commons-collections:jar:3.2.2:compile\n\n$ build/mvn clean package -DskipTests -pl :kyuubi-spark-authz-shaded_2.13 -am -Pspark-4.1 -Pscala-2.13\n$ jar tf extensions/spark/kyuubi-spark-authz-shaded/target/kyuubi-spark-authz-shaded_2.13-1.13.0-SNAPSHOT.jar | grep org/apache/commons/collections/CollectionUtils\n\norg/apache/kyuubi/shade/org/apache/commons/collections/CollectionUtils.class\n```\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-opus-4-7\n\nCloses #7610 from maomaodev/kyuubi-7608.\n\nCloses #7608\n\n476db54a4 [lifumao] relocation commons-collections\nc85165428 [lifumao] [KYUUBI-7608][AUTHZ] Include commons-collections into authz\n\nAuthored-by: lifumao \u003clifumao@tencent.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "7a70a3cbb964c329766e090e18a297f4bbb20dc9",
      "tree": "ed8af315e3f02d51d98dbcb9f1b2d713c713a24d",
      "parents": [
        "5a254674ab14ca37598865e9b048aabcaa73ce49"
      ],
      "author": {
        "name": "lifumao",
        "email": "lifumao@tencent.com",
        "time": "Wed Aug 05 02:30:29 2026 +0800"
      },
      "committer": {
        "name": "Bowen Liang",
        "email": "liang.bowen.123@qq.com",
        "time": "Wed Aug 05 02:30:29 2026 +0800"
      },
      "message": "[KYUUBI #6718][AUTHZ] Support {OWNER} variable for Hudi update/delete/merge\n\n### Why are the changes needed?\n\nFix https://github.com/apache/kyuubi/issues/6718.\n\nHudi `UPDATE` / `DELETE` / `MERGE INTO` commands are handled by `HudiDataSourceV2RelationTableExtractor` and `HudiMergeIntoTargetTableExtractor` in `table_command_spec.json`. Previously, both extractors delegated the `SubqueryAlias(identifier, _)` case to `StringTableExtractor`, which only parses `database.table` from a string and always leaves `Table.owner` as `None`.\n\nAs a result, `AccessResource#setOwnerUser` is never called for these commands, so Ranger cannot resolve the `{OWNER}` variable, and a policy like `{OWNER}` -\u003e `ALL on database/table/column` never matches — even when the user running the statement is exactly the table\u0027s creator/owner.\n\n### How was this patch tested?\n\nAdded UT.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-opus-4-7\n\nCloses #7606 from maomaodev/kyuubi_6718.\n\nCloses #6718\n\n6555756f5 [lifumao] [KYUUBI #6718][AUTHZ] Fix hudi table owner can not update/delete/merge tables they have created\n\nAuthored-by: lifumao \u003clifumao@tencent.com\u003e\nSigned-off-by: Bowen Liang \u003cliang.bowen.123@qq.com\u003e\n"
    },
    {
      "commit": "5a254674ab14ca37598865e9b048aabcaa73ce49",
      "tree": "8ce574b881372f182922ca68a254e04ce1a15070",
      "parents": [
        "1feaa1d7a2bb9987c1db3ffc027bf77da89e52c7"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 01:22:30 2026 +0200"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Sat Aug 01 01:22:30 2026 +0200"
      },
      "message": "[KYUUBI #7604] Bump docker/login-action from 4.4.0 to 4.5.1\n\nBumps [docker/login-action](https://github.com/docker/login-action) from 4.4.0 to 4.5.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/docker/login-action/releases\"\u003edocker/login-action\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/abd2ef45e78c5afb21d64d4ca52ee8550d9572c7\"\u003e\u003ccode\u003eabd2ef4\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1055\"\u003e#1055\u003c/a\u003e from crazy-max/test-registry-auth-oidc\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/d49d3a9839fef51322fa44989a44fdc43fccfc22\"\u003e\u003ccode\u003ed49d3a9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1054\"\u003e#1054\u003c/a\u003e from crazy-max/oidc-missing-dhi\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/b58b17c30b4db92a4ed049b213cae512b12e460b\"\u003e\u003ccode\u003eb58b17c\u003c/code\u003e\u003c/a\u003e test: cover Docker Hub OIDC with registry-auth\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/be646c21cec26cea303e29290d5f6ba6fde8e606\"\u003e\u003ccode\u003ebe646c2\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/d77c059cb9956cedaa427dc022d89f39acba678f\"\u003e\u003ccode\u003ed77c059\u003c/code\u003e\u003c/a\u003e support dhi.io as Docker Hub OIDC registry\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/06fb636fac595d6fb4b28a5dfcb21a6f5091859c\"\u003e\u003ccode\u003e06fb636\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1037\"\u003e#1037\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/a8bc9539118a762b0e5788b53a50907977cc1b8d\"\u003e\u003ccode\u003ea8bc953\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/f54b9019bf5074f6e3480a3ac4b834f5f4b90aab\"\u003e\u003ccode\u003ef54b901\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/77f18f6713512f90ac35aaf21db0d3710f1b85a6\"\u003e\u003ccode\u003e77f18f6\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1049\"\u003e#1049\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/ec0bf287fb1e2e051c56b2f6e6a3eed487b9fe52\"\u003e\u003ccode\u003eec0bf28\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1050\"\u003e#1050\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/docker/login-action/compare/af1e73f918a031802d376d3c8bbc3fe56130a9b0...abd2ef45e78c5afb21d64d4ca52ee8550d9572c7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddocker/login-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.4.0\u0026new-version\u003d4.5.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7604 from dependabot[bot]/dependabot/github_actions/docker/login-action-4.5.1.\n\nCloses #7604\n\n49013d343 [dependabot[bot]] Bump docker/login-action from 4.4.0 to 4.5.1\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "1feaa1d7a2bb9987c1db3ffc027bf77da89e52c7",
      "tree": "55ee483d13a9cf4c801101a05395c20ead7010ad",
      "parents": [
        "d627103f0e3a4f45f060593eac22c53d8fede1d5"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 01:20:49 2026 +0200"
      },
      "committer": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Sat Aug 01 01:20:49 2026 +0200"
      },
      "message": "[KYUUBI #7602] Bump actions/setup-python from 6 to 7\n\nBumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/actions/setup-python/releases\"\u003eactions/setup-python\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate to ESM and upgrade dependencies by \u003ca href\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e​priyagupta108\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1330\"\u003eactions/setup-python#1330\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin SHA commits and update docs with latest versions by \u003ca href\u003d\"https://github.com/HarithaVattikuti\"\u003e\u003ccode\u003e​HarithaVattikuti\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1338\"\u003eactions/setup-python#1338\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove the pip-install input by \u003ca href\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1336\"\u003eactions/setup-python#1336\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fix\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix to Classify stderr warning messages as warnings instead of errors in annotations by \u003ca href\u003d\"https://github.com/lmvysakh\"\u003e\u003ccode\u003e​lmvysakh\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1335\"\u003eactions/setup-python#1335\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate and retry manifest fetch to prevent silent failures by \u003ca href\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e​priyagupta108\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1332\"\u003eactions/setup-python#1332\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency Upgrade\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump certifi from 2020.6.20 to 2024.7.4 in /\u003cstrong\u003etests\u003c/strong\u003e/data by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1328\"\u003eactions/setup-python#1328\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove EOL Python versions and Bumps numpy text fixture by \u003ca href\u003d\"https://github.com/priya-kinthali\"\u003e\u003ccode\u003e​priya-kinthali\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1333\"\u003eactions/setup-python#1333\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e​actions/cache\u003c/code\u003e to 6.2.0 by \u003ca href\u003d\"https://github.com/philip-gai\"\u003e\u003ccode\u003e​philip-gai\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1337\"\u003eactions/setup-python#1337\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/lmvysakh\"\u003e\u003ccode\u003e​lmvysakh\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1335\"\u003eactions/setup-python#1335\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/philip-gai\"\u003e\u003ccode\u003e​philip-gai\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1337\"\u003eactions/setup-python#1337\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/setup-python/compare/v6...v7.0.0\"\u003ehttps://github.com/actions/setup-python/compare/v6...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.3.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancement\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd RHEL support and include Linux distro in cache keys by \u003ca href\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e​priyagupta108\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1323\"\u003eactions/setup-python#1323\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix pip cache error handling on Windows by \u003ca href\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e​priyagupta108\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1040\"\u003eactions/setup-python#1040\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency update\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade minimatch from 3.1.2 to 3.1.5 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1281\"\u003eactions/setup-python#1281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade actions dependencies by \u003ca href\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e​gowridurgad\u003c/code\u003e\u003c/a\u003e with \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1303\"\u003eactions/setup-python#1303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e​actions/cache\u003c/code\u003e to 5.1.0, log cache write denied by \u003ca href\u003d\"https://github.com/jasongin\"\u003e\u003ccode\u003e​jasongin\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1324\"\u003eactions/setup-python#1324\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade dependency versions and test workflow configuration by \u003ca href\u003d\"https://github.com/HarithaVattikuti\"\u003e\u003ccode\u003e​HarithaVattikuti\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1322\"\u003eactions/setup-python#1322\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate advanced-usage.md by \u003ca href\u003d\"https://github.com/Dunky-Z\"\u003e\u003ccode\u003e​Dunky-Z\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/811\"\u003eactions/setup-python#811\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e​gowridurgad\u003c/code\u003e\u003c/a\u003e with \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1303\"\u003eactions/setup-python#1303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/jasongin\"\u003e\u003ccode\u003e​jasongin\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1324\"\u003eactions/setup-python#1324\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/Dunky-Z\"\u003e\u003ccode\u003e​Dunky-Z\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/811\"\u003eactions/setup-python#811\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/setup-python/compare/v6.2.0...v6.3.0\"\u003ehttps://github.com/actions/setup-python/compare/v6.2.0...v6.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.2.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eDependency Upgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade dependencies to Node 24 compatible versions by \u003ca href\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/pull/1259\"\u003eactions/setup-python#1259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-python/commit/5fda3b95a4ea91299a34e894583c3862153e4b97\"\u003e\u003ccode\u003e5fda3b9\u003c/code\u003e\u003c/a\u003e Pin SHA commits and update docs with latest versions (\u003ca href\u003d\"https://redirect.github.com/actions/setup-python/issues/1338\"\u003e#1338\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-python/commit/4ab7e95f05e168b4356aebde89dd84f59c283d8e\"\u003e\u003ccode\u003e4ab7e95\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/actions/setup-python/issues/1337\"\u003e#1337\u003c/a\u003e from actions/philip-gai/bump-actions-cache-6-2-0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-python/commit/0f3a009f475dbea83c0371cd85d099690fee8c5c\"\u003e\u003ccode\u003e0f3a009\u003c/code\u003e\u003c/a\u003e Remove the pip-install input (\u003ca href\u003d\"https://redirect.github.com/actions/setup-python/issues/1336\"\u003e#1336\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-python/commit/f8cf4291c8b8e273ddd26e569454615c7315d932\"\u003e\u003ccode\u003ef8cf429\u003c/code\u003e\u003c/a\u003e Migrate to ESM and upgrade dependencies (\u003ca href\u003d\"https://redirect.github.com/actions/setup-python/issues/1330\"\u003e#1330\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-python/commit/54baeea5b34417d10a7479663a23cca53ea209b5\"\u003e\u003ccode\u003e54baeea\u003c/code\u003e\u003c/a\u003e Validate and retry manifest fetch to prevent silent failures (\u003ca href\u003d\"https://redirect.github.com/actions/setup-python/issues/1332\"\u003e#1332\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-python/commit/c7092773a316760f4ecfe498e4af668a4dafeac5\"\u003e\u003ccode\u003ec709277\u003c/code\u003e\u003c/a\u003e Annotation code fix (\u003ca href\u003d\"https://redirect.github.com/actions/setup-python/issues/1335\"\u003e#1335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-python/commit/6849080452e69b330395e8a6d23cf90f56d76a1a\"\u003e\u003ccode\u003e6849080\u003c/code\u003e\u003c/a\u003e remove EOL Python versions and Bumps numpy text fixture (\u003ca href\u003d\"https://redirect.github.com/actions/setup-python/issues/1333\"\u003e#1333\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-python/commit/0903b469fbf4441aadfe4f4b249dc5b1fba3a73e\"\u003e\u003ccode\u003e0903b46\u003c/code\u003e\u003c/a\u003e Bump certifi from 2020.6.20 to 2024.7.4 in /\u003cstrong\u003etests\u003c/strong\u003e/data (\u003ca href\u003d\"https://redirect.github.com/actions/setup-python/issues/1328\"\u003e#1328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href\u003d\"https://github.com/actions/setup-python/compare/v6...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/setup-python\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d6\u0026new-version\u003d7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7602 from dependabot[bot]/dependabot/github_actions/actions/setup-python-7.\n\nCloses #7602\n\nf6ca7f5e2 [dependabot[bot]] Bump actions/setup-python from 6 to 7\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\n"
    },
    {
      "commit": "d627103f0e3a4f45f060593eac22c53d8fede1d5",
      "tree": "748b05413878a90a3da6c3dc7caa827c8cd2da73",
      "parents": [
        "a8f82a02d8e4e28ee3cf61f8cf8ce6e952eda2f3"
      ],
      "author": {
        "name": "bowenliang123",
        "email": "liang.bowen.123@qq.com",
        "time": "Thu Jul 30 14:25:48 2026 +0800"
      },
      "committer": {
        "name": "bowenliang123",
        "email": "liang.bowen.123@qq.com",
        "time": "Thu Jul 30 14:25:48 2026 +0800"
      },
      "message": "[KYUUBI #7584] Update dev/dependencyList for postgresql 42.7.12\n\n### Why are the changes needed?\n\n[PR #7584](https://github.com/apache/kyuubi/pull/7584) bumped `org.postgresql:postgresql` from 42.7.11 to 42.7.12 (security: [CVE-2026-54291](https://nvd.nist.gov/vuln/detail/CVE-2026-54291)) but updated only `pom.xml`. It did not regenerate `dev/dependencyList` via `build/dependency.sh --replace`, so the two are now out of sync and the **Dependencies CI check fails on `master`**:\n\n```\nDependency List Changed Detected:\n- postgresql/42.7.11//postgresql-42.7.11.jar\n+ postgresql/42.7.12//postgresql-42.7.12.jar\n```\n\nThis PR brings `dev/dependencyList` back in line with the pom so CI is green again.\n\n### How was this patch tested?\n\n- [x] Verified the only diff is the postgresql entry expected by the pom bump in #7584\n- [x] `git diff` against the version produced by `build/dependency.sh` shows no further drift\n\n`build/dependency.sh` requires downloading Spark/Flink/Hive engines and running a full `mvn install` to verify locally; CI will exercise it on the PR branch.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nYes.\nAssisted-by: OpenCode with MiniMax-M3\n\nCloses #7605 from bowenliang123/kyuubi-7584-update-dependency-list.\n\nCloses #7584\n\n387af5171 [bowenliang123] [KYUUBI #7584][INFRA] Update dev/dependencyList for postgresql 42.7.12\n\nAuthored-by: bowenliang123 \u003cliang.bowen.123@qq.com\u003e\nSigned-off-by: bowenliang123 \u003cliang.bowen.123@qq.com\u003e\n"
    },
    {
      "commit": "a8f82a02d8e4e28ee3cf61f8cf8ce6e952eda2f3",
      "tree": "e344f21e308e7c15cddf92c7062f35a0f023e9f1",
      "parents": [
        "48b22ea28437bf5063b3403e677011eab010adc9"
      ],
      "author": {
        "name": "Bowen Liang",
        "email": "liang.bowen.123@qq.com",
        "time": "Wed Jul 29 22:48:18 2026 +0800"
      },
      "committer": {
        "name": "Bowen Liang",
        "email": "liang.bowen.123@qq.com",
        "time": "Wed Jul 29 22:48:18 2026 +0800"
      },
      "message": "[KYUUBI #7597][INFRA] Fix labeler.yml YAML parsing error under actions/labeler v7\n\nCloses #7597\n\n### Why are the changes needed?\n\n`actions/labelerv7` fails to parse `.github/labeler.yml` and aborts the workflow before applying any labels:\n\n```\nRun actions/labelerv7\nThe configuration file (path: .github/labeler.yml) was not found locally, fetching via the api\nError: YAMLException: deficient indentation (24:7)\n\n 21 | \"kind:build\":\n 22 |   - changed-files:\n 23 |     - any-glob-to-any-file: [\n 24 |       \u0027.dockerignore\u0027,\n------------^\n 25 |       \u0027.rat-excludes\u0027,\n 26 |       \u0027.scalafmt\u0027,\n```\n\nEvery `any-glob-to-any-file: [ ... ]` / `all-globs-to-any-file: [ ... ]` block fails with the same error, so the job bails out and no `kind:*` / `module:*` labels are applied to PRs. Triage has been silently broken since the v7 bump in #7583.\n\n**Root cause.** The file uses YAML flow-style sequences (`[ ... ]`) split across multiple lines, with continuation lines indented at 6 spaces while the opening `[` sits at column 27. YAML 1.2 (and `js-yaml4`, which `actions/labelerv7` depends on) requires flow-sequence continuation lines to be indented at least one column past the line containing the opening bracket — hence `deficient indentation`.\n\nThe format was introduced in #5874 (commit `7e96dc7bc9`, 2023-12-19) when the action was bumped from v4 to v5. v5/v6 bundled an older `js-yaml` that did not strictly enforce the indentation rule, which is why the bug stayed latent for ~2 years.\n\n### What does this PR do?\n\nRewrite every `any-glob-to-any-file: [ ... ]` and `all-globs-to-any-file: [ ... ]` block in `.github/labeler.yml` as a standard YAML block-style sequence. Same 22 labels, same glob sets — no semantic change. The file now parses cleanly under strict YAML 1.2 and is forward-compatible with future `actions/labeler` releases.\n\nAlso dropped:\n- the trailing whitespace on line 48 of the old file (under the `kind:deploy` block)\n- the inconsistent 6-space indent under `module:spark`, which was the only block at odds with the rest of the file\n\n### How was this patch tested?\n\n1. Parsed the rewritten file with `python3 -c \"import yaml; yaml.safe_load(open(\u0027.github/labeler.yml\u0027))\"` — succeeds.\n2. Cross-checked label keys and glob counts against the pre-change file: 22 labels preserved, identical glob counts per label.\n3. Spotless does not process YAML files (see `pom.xml` — only `java`, `scala`, `pom`, `python`, `markdown` are in scope), so no format step is required for this change.\n\nEnd-to-end verification will happen on the next PR opened against `apache/master` that runs the `Pull Request Labeler` workflow.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: OpenCode with MiniMax-M3\n\nCloses #7598 from bowenliang123/kyuubi-7597-fix-labeler-yaml-indentation.\n\nCloses #7597\n\n33ab1ef9c [Bowen Liang] [KYUUBI #7597][INFRA] Fix labeler.yml YAML parsing error under actions/labeler v7\n\nAuthored-by: Bowen Liang \u003cliang.bowen.123@qq.com\u003e\nSigned-off-by: Bowen Liang \u003cliang.bowen.123@qq.com\u003e\n"
    },
    {
      "commit": "48b22ea28437bf5063b3403e677011eab010adc9",
      "tree": "04e0c1d63bed4b2e8a9082ee8cb3d8cbb44d802f",
      "parents": [
        "25d43f16d4a9187478e43590623de359b7d87a1d"
      ],
      "author": {
        "name": "attilapiros",
        "email": "piros.attila.zsolt@gmail.com",
        "time": "Tue Jul 28 21:00:36 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 28 21:00:36 2026 +0800"
      },
      "message": "[KYUUBI #7589][AUTHZ] Rejecting RESET on the restricted configs parameters\n\n### Why are the changes needed?\n\nThe `AuthzConfigurationChecker` only validates setting configuration parameters to explicit values (`SET \u003ckey\u003e\u003d\u003cvalue\u003e`). It currently fails to check actions that restore default values or remove configurations entirely, such as `RESET \u003ckey\u003e` or `RESET` (which reset all the config parameters).\n\nFor more details, see the: https://spark.apache.org/docs/latest/sql-ref-syntax-aux-conf-mgmt-reset.html\n\n### How was this patch tested?\n\nA unit test was extended.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nYes.\n\nAssisted-by: Claude:claude-sonnet\n\nCloses #7591 from attilapiros/reset_support.\n\nCloses #7589\n\nb1a9dbab5 [attilapiros] [KYUUBI #7589][AUTHZ] Rejecting RESET on the restricted configs parameters\n\nAuthored-by: attilapiros \u003cpiros.attila.zsolt@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "25d43f16d4a9187478e43590623de359b7d87a1d",
      "tree": "e2864c63afdb418cbe8a7b8af5d666141e00e558",
      "parents": [
        "2ffc9978218fba6d590422844dbc4492865f542e"
      ],
      "author": {
        "name": "attilapiros",
        "email": "piros.attila.zsolt@gmail.com",
        "time": "Tue Jul 28 20:58:58 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 28 20:58:58 2026 +0800"
      },
      "message": "[KYUUBI #7585] Queries with \u0027TRANSFORM ... USING \u003cshell-script\u003e\u0027 must be rejected\n\n### Why are the changes needed?\n\nThis PR adds a configurable plan-node deny list to kyuubi-spark-authz. The first (and currently only) entry blocks `ScriptTransformation` — the Spark SQL `TRANSFORM ... USING \u003cscript\u003e` feature — which would otherwise let any SQL user execute arbitrary shell commands on Spark executors, bypassing all Ranger data-access controls.\n\n### How was this patch tested?\n\nAdded a new unit test suite `NodeDenyListCheckerSuite`:\n\n```\nDiscovery starting.\nDiscovery completed in 134 milliseconds.\nRun starting. Expected test count is: 3\nNodeDenyListCheckerSuite:\n- plain SELECT is allowed\n- TRANSFORM ... USING is rejected\n- TRANSFORM ... USING inside a subquery is rejected\nRun completed in 4 seconds, 858 milliseconds.\nTotal number of tests run: 3\nSuites: completed 2, aborted 0\nTests: succeeded 3, failed 0, canceled 0, ignored 0, pending 0\n```\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nYes.\n\nAssisted-by: Claude:claude-sonnet\n\nCloses #7586 from attilapiros/master.\n\nCloses #7585\n\n1929982a2 [attilapiros] [KYUUBI #7585] Queries with \u0027TRANSFORM ... USING \u003cshell-script\u003e\u0027 must be rejected\n\nAuthored-by: attilapiros \u003cpiros.attila.zsolt@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "2ffc9978218fba6d590422844dbc4492865f542e",
      "tree": "3f24475062c4d5e58a3a4368471fbb621b91ecdf",
      "parents": [
        "c98d6fffbd5986827091d79c67f628a222950fd3"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 28 20:56:41 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 28 20:56:41 2026 +0800"
      },
      "message": "[KYUUBI #7584] Bump org.postgresql:postgresql from 42.7.11 to 42.7.12\n\nBumps [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) from 42.7.11 to 42.7.12.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/pgjdbc/pgjdbc/releases\"\u003eorg.postgresql:postgresql\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev42.7.12: security\u003c/h2\u003e\n\u003ch3\u003eSilent channel-binding authentication downgrade (CVE-2026-54291)\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003echannelBinding\u003drequire\u003c/code\u003e connections can be silently downgraded from SCRAM-SHA-256-PLUS (with channel binding) to plain SCRAM-SHA-256 (without it), losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection triggers the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash. Examples are Ed25519, Ed448, and post-quantum algorithms.\u003c/p\u003e\n\u003cp\u003eTwo issues combine in releases 42.7.4 through 42.7.11:\u003c/p\u003e\n\u003cp\u003eThe bundled \u003ccode\u003ecom.ongres.scram:scram-client\u003c/code\u003e (3.1 or 3.2) returns an empty byte array instead of failing when it cannot derive the binding hash for such a certificate. This is the library issue tracked as \u003ca href\u003d\"https://github.com/ongres/scram/security/advisories/GHSA-p9jg-fcr6-3mhf\"\u003eGHSA-p9jg-fcr6-3mhf\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003epgJDBC does not enforce channelBinding\u003drequire where it matters. ScramAuthenticator checks only that the server advertised a -PLUS mechanism; it neither rejects the empty binding nor checks that the negotiated mechanism uses channel binding. The connection therefore downgrades silently.\u003c/p\u003e\n\u003cp\u003eOnly connections that set channelBinding\u003drequire are affected. Under the default prefer policy, and under allow or disable, falling back to plain SCRAM is the documented behaviour.\u003c/p\u003e\n\u003cp\u003eReleases before 42.7.4 are unaffected, because they do not support channel binding.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md\"\u003eorg.postgresql:postgresql\u0027s changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[42.7.12] (2026-06-29)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix: Enforce SCRAM channel-binding policy and prevent silent downgrade.\nUnder \u003ccode\u003echannelBinding\u003drequire\u003c/code\u003e, the driver silently downgraded from \u003ccode\u003eSCRAM-SHA-256-PLUS\u003c/code\u003e (with channel binding) to plain \u003ccode\u003eSCRAM-SHA-256\u003c/code\u003e (without it) when the server presented a certificate whose signature algorithm has no \u003ccode\u003etls-server-end-point\u003c/code\u003e channel-binding hash (e.g. Ed25519, Ed448, or post-quantum algorithms). An attacker who can intercept the TLS connection could exploit this to strip channel-binding protection.\nThe fix enforces channel binding in the driver\u0027s own code: it now fails the connection when no binding data can be extracted, and verifies the negotiated mechanism uses channel binding (\u003ccode\u003e-PLUS\u003c/code\u003e) when \u003ccode\u003erequire\u003c/code\u003e is set.\nOnly connections that set \u003ccode\u003echannelBinding\u003drequire\u003c/code\u003e are affected. The default \u003ccode\u003eprefer\u003c/code\u003e policy and releases before 42.7.4 (which introduced channel-binding support) are unaffected.\nSee the \u003ca href\u003d\"https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-j92g-9f8w-j867\"\u003eSecurity Advisory\u003c/a\u003e for more detail.\nThe following \u003ca href\u003d\"https://nvd.nist.gov/vuln/detail/CVE-2026-54291\"\u003eCVE-2026-54291\u003c/a\u003e has been issued.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/pgjdbc/pgjdbc/commit/77df98e4e66c12936ded3478a0954f6f580bad99\"\u003e\u003ccode\u003e77df98e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/pgjdbc/pgjdbc/commit/68c53a435291fea8be40eb1d9c550311743d326d\"\u003e\u003ccode\u003e68c53a4\u003c/code\u003e\u003c/a\u003e chore: bump version to 42.7.12\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href\u003d\"https://github.com/pgjdbc/pgjdbc/compare/REL42.7.11...REL42.7.12\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dorg.postgresql:postgresql\u0026package-manager\u003dmaven\u0026previous-version\u003d42.7.11\u0026new-version\u003d42.7.12)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/apache/kyuubi/network/alerts).\n\n\u003c/details\u003e\n\nCloses #7584 from dependabot[bot]/dependabot/maven/org.postgresql-postgresql-42.7.12.\n\nCloses #7584\n\n2c3d43d7d [dependabot[bot]] Bump org.postgresql:postgresql from 42.7.11 to 42.7.12\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "c98d6fffbd5986827091d79c67f628a222950fd3",
      "tree": "72c9dc359c8321c34e7f6f3f72196a74d6ff5518",
      "parents": [
        "397e9213403c1b0472cdf7f395d3cfe2a9564ae6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 28 20:54:18 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 28 20:54:18 2026 +0800"
      },
      "message": "[KYUUBI #7583] Bump actions/labeler from 6 to 7\n\nBumps [actions/labeler](https://github.com/actions/labeler) from 6 to 7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/actions/labeler/releases\"\u003eactions/labeler\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancements:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate to ESM and update dependencies by \u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/949\"\u003eactions/labeler#949\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/labeler/compare/v6...v7.0.0\"\u003ehttps://github.com/actions/labeler/compare/v6...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.2.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eBug Fix\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove PR number validation and warning messages in input handling by \u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/939\"\u003eactions/labeler#939\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency Updates\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump js-yaml to 4.2.0, apply npm audit fix, and add undici override  by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/943\"\u003eactions/labeler#943\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​typescript-eslint/eslint-plugin\u003c/code\u003e from 8.59.1 to 8.61.1 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/942\"\u003eactions/labeler#942\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/labeler/compare/v6.1.0...v6.2.0\"\u003ehttps://github.com/actions/labeler/compare/v6.1.0...v6.2.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.1.0\u003c/h2\u003e\n\u003ch2\u003eEnhancements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd changed-files-labels-limit and max-files-changed configuration options to cap the number of labels added by \u003ca href\u003d\"https://github.com/bluca\"\u003e\u003ccode\u003e​bluca\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/923\"\u003eactions/labeler#923\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove Labeler Action documentation and permission error handling by \u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/897\"\u003eactions/labeler#897\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePreserve manually added labels during workflow runs and refine label synchronization logic by \u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/917\"\u003eactions/labeler#917\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependency Updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade brace-expansion from 1.1.11 to 1.1.12 and document breaking changes in v6 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/877\"\u003eactions/labeler#877\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade minimatch from 10.0.1 to 10.2.3 by \u003ca href\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/926\"\u003eactions/labeler#926\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade dependencies (\u003ccode\u003e​actions/core\u003c/code\u003e, \u003ccode\u003e​actions/github\u003c/code\u003e, js-yaml, minimatch, \u003ca href\u003d\"https://github.com/typescript-eslint\"\u003e\u003ccode\u003e​typescript-eslint\u003c/code\u003e\u003c/a\u003e) by \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/934\"\u003eactions/labeler#934\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/897\"\u003eactions/labeler#897\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/bluca\"\u003e\u003ccode\u003e​bluca\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/923\"\u003eactions/labeler#923\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/934\"\u003eactions/labeler#934\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/labeler/compare/v6...v6.1.0\"\u003ehttps://github.com/actions/labeler/compare/v6...v6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade publish-action from 0.2.2 to 0.4.0 by \u003ca href\u003d\"https://github.com/aparnajyothi-y\"\u003e\u003ccode\u003e​aparnajyothi-y\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/901\"\u003eactions/labeler#901\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/aparnajyothi-y\"\u003e\u003ccode\u003e​aparnajyothi-y\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/labeler/pull/901\"\u003eactions/labeler#901\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/labeler/compare/v6.0.0...v6.0.1\"\u003ehttps://github.com/actions/labeler/compare/v6.0.0...v6.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/labeler/commit/bf12e9b00b37c5c0ca2b87b79b2daf7891dbda13\"\u003e\u003ccode\u003ebf12e9b\u003c/code\u003e\u003c/a\u003e feat: migrate to ESM and update dependencies (\u003ca href\u003d\"https://redirect.github.com/actions/labeler/issues/949\"\u003e#949\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href\u003d\"https://github.com/actions/labeler/compare/v6...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/labeler\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d6\u0026new-version\u003d7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7583 from dependabot[bot]/dependabot/github_actions/actions/labeler-7.\n\nCloses #7583\n\n0ba0feee5 [dependabot[bot]] Bump actions/labeler from 6 to 7\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "397e9213403c1b0472cdf7f395d3cfe2a9564ae6",
      "tree": "6318a4e99b0077c114ef63b0393f3d79f4f8fb6c",
      "parents": [
        "ac66880b6184b6cf288b648a259468125d52fdc7"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 28 20:52:22 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 28 20:52:22 2026 +0800"
      },
      "message": "[KYUUBI #7582] Bump actions/setup-node from 6 to 7\n\nBumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/actions/setup-node/releases\"\u003eactions/setup-node\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancements:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd cache-primary-key and cache-matched-key as outputs by \u003ca href\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1577\"\u003eactions/setup-node#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to ESM and upgrade dependencies by \u003ca href\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1574\"\u003eactions/setup-node#1574\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove dummy NODE_AUTH_TOKEN export by \u003ca href\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1558\"\u003eactions/setup-node#1558\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOnly use \u003ccode\u003emirrorToken\u003c/code\u003e in \u003ccode\u003egetManifest\u003c/code\u003e if it\u0027s provided by \u003ca href\u003d\"https://github.com/deiga\"\u003e\u003ccode\u003e​deiga\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1548\"\u003eactions/setup-node#1548\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation updates:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd documentation for publishing to npm with Trusted Publisher (OIDC) by \u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1536\"\u003eactions/setup-node#1536\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: Update restore-only cache documentation by \u003ca href\u003d\"https://github.com/priya-kinthali\"\u003e\u003ccode\u003e​priya-kinthali\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1550\"\u003eactions/setup-node#1550\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: Update caching recommendations to mitigate cache poisoning risks by \u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1567\"\u003eactions/setup-node#1567\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency update:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e​actions/cache\u003c/code\u003e to 5.1.0, log cache write denied by \u003ca href\u003d\"https://github.com/jasongin\"\u003e\u003ccode\u003e​jasongin\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1569\"\u003eactions/setup-node#1569\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/chiranjib-swain\"\u003e\u003ccode\u003e​chiranjib-swain\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1536\"\u003eactions/setup-node#1536\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/deiga\"\u003e\u003ccode\u003e​deiga\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1548\"\u003eactions/setup-node#1548\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/jasongin\"\u003e\u003ccode\u003e​jasongin\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1569\"\u003eactions/setup-node#1569\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/setup-node/compare/v6...v7.0.0\"\u003ehttps://github.com/actions/setup-node/compare/v6...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.5.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e​actions/cache\u003c/code\u003e to 5.1.0 and add security overrides for undici and fast-xml-parser by \u003ca href\u003d\"https://github.com/HarithaVattikuti\"\u003e\u003ccode\u003e​HarithaVattikuti\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1579\"\u003eactions/setup-node#1579\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0\"\u003ehttps://github.com/actions/setup-node/compare/v6.4.0...v6.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eDependency updates:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ca href\u003d\"https://github.com/actions\"\u003e\u003ccode\u003e​actions\u003c/code\u003e\u003c/a\u003e dependencies by \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Node.js versions in versions.yml and bump package to v6.4.0  by \u003ca href\u003d\"https://github.com/priya-kinthali\"\u003e\u003ccode\u003e​priya-kinthali\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1533\"\u003eactions/setup-node#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e​Copilot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/actions/setup-node/compare/v6...v6.4.0\"\u003ehttps://github.com/actions/setup-node/compare/v6...v6.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.3.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancements:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport parsing \u003ccode\u003edevEngines\u003c/code\u003e field by \u003ca href\u003d\"https://github.com/susnux\"\u003e\u003ccode\u003e​susnux\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/pull/1283\"\u003eactions/setup-node#1283\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/820762786026740c76f36085b0efc47a31fe5020\"\u003e\u003ccode\u003e8207627\u003c/code\u003e\u003c/a\u003e Migrate to ESM and upgrade dependencies (\u003ca href\u003d\"https://redirect.github.com/actions/setup-node/issues/1574\"\u003e#1574\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/04be95cf3511ea51ebf9f224ddfb99cc7ab87cd4\"\u003e\u003ccode\u003e04be95c\u003c/code\u003e\u003c/a\u003e Add cache-primary-key and cache-matched-key as outputs (\u003ca href\u003d\"https://redirect.github.com/actions/setup-node/issues/1577\"\u003e#1577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/7c2c68d20d402ed6a201ada70a81341941093140\"\u003e\u003ccode\u003e7c2c68d\u003c/code\u003e\u003c/a\u003e docs: Update caching recommendations to mitigate cache poisoning risks (\u003ca href\u003d\"https://redirect.github.com/actions/setup-node/issues/1567\"\u003e#1567\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/6a61c0375d66246de94630495909f12cf8dac84d\"\u003e\u003ccode\u003e6a61c03\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/actions/setup-node/issues/1569\"\u003e#1569\u003c/a\u003e from jasongin/update-actions-cache-5.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/30eb73b41ded577900c1ebf968ef95cdf8f7434f\"\u003e\u003ccode\u003e30eb73b\u003c/code\u003e\u003c/a\u003e Resolve high-severity audit issues\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/4e1a87a501d0302f99e30e2748568adcb388d09f\"\u003e\u003ccode\u003e4e1a87a\u003c/code\u003e\u003c/a\u003e Update dist\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/360237f0c01778d0c17291f75c56d6feae4f7574\"\u003e\u003ccode\u003e360237f\u003c/code\u003e\u003c/a\u003e Strict equality\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/4f8aac5beb2f0854bc79651567a18c67eb0b9de3\"\u003e\u003ccode\u003e4f8aac5\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e​actions/cache\u003c/code\u003e to 5.1.0, log cache write denied\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/f4a67bbeca970f103397d3d2b9462cf787cd2980\"\u003e\u003ccode\u003ef4a67bb\u003c/code\u003e\u003c/a\u003e Only use \u003ccode\u003emirrorToken\u003c/code\u003e in \u003ccode\u003egetManifest\u003c/code\u003e if it\u0027s provided (\u003ca href\u003d\"https://redirect.github.com/actions/setup-node/issues/1548\"\u003e#1548\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/actions/setup-node/commit/0355742c943ddb13ca8a6b700f824231caa91e75\"\u003e\u003ccode\u003e0355742\u003c/code\u003e\u003c/a\u003e Remove dummy NODE_AUTH_TOKEN export (\u003ca href\u003d\"https://redirect.github.com/actions/setup-node/issues/1558\"\u003e#1558\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/actions/setup-node/compare/v6...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/setup-node\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d6\u0026new-version\u003d7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7582 from dependabot[bot]/dependabot/github_actions/actions/setup-node-7.\n\nCloses #7582\n\nf015ecd84 [dependabot[bot]] Bump actions/setup-node from 6 to 7\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "ac66880b6184b6cf288b648a259468125d52fdc7",
      "tree": "6782ee49dad5a8a41754ef9e3d89e643172658d7",
      "parents": [
        "614c8d4c0bc00e1967a19cf4d8213a066cb00608"
      ],
      "author": {
        "name": "Xiduo You",
        "email": "ulyssesyou@apache.org",
        "time": "Tue Jul 28 11:28:10 2026 +0800"
      },
      "committer": {
        "name": "Xiduo You",
        "email": "ulyssesyou@apache.org",
        "time": "Tue Jul 28 11:28:10 2026 +0800"
      },
      "message": "[KYUUBI #7587] [SPARK] Infer cast-wrapped join keys in InferRebalanceAndSortOrders\n\n### Why are the changes needed?\n\nTwo fixes to `InferRebalanceAndSortOrders` (applied across the Spark 3.5, 4.0, 4.1 and 4.2 extension modules):\n\n1. **Support cast-wrapped join keys.** When join key columns have mismatched types (e.g. via a `UNION ALL` branch that widens `int` to `bigint`), the analyzer inserts a cast on the join key such as `cast(genre_tag_id as bigint)`. The outer projection\u0027s alias map is keyed by the unary-peeled attribute, so the full cast expression never matched and the key was silently dropped by the `outputSet` filter — only the un-cast keys survived, weakening the inferred rebalance/sort. This adds `mapThroughAlias`, which retries the alias lookup with the unary-peeled key (symmetric with how `getAliasMap` builds its keys), so a cast-wrapped key maps back to its aliased output attribute. `Cast` is also treated as cheap in `isCheap` for keys that survive without being aliased away.\n\n2. **Gate the cheap-column check by `maxColumns`.** `INFER_REBALANCE_AND_SORT_ORDERS_MAX_COLUMNS` is now threaded into `infer` and the truncation is applied *before* the cheap-column check, so only the first `maxColumns` inferred columns need to be cheap (previously an expensive key beyond the limit could discard the whole inference).\n\n### How was this patch tested?\n\nAdded unit tests in `RebalanceBeforeWritingSuite` for each affected module:\n- cast-wrapped join key resolves to its aliased output attribute,\n- a `Cast` over a cheap column is treated as cheap,\n- `maxColumns` gates the cheap-column check.\n\nVerified locally with:\n- Spark 3.5: `build/mvn -Pspark-3.5 test -pl extensions/spark/kyuubi-extension-spark-3-5 -am -DwildcardSuites\u003dorg.apache.spark.sql.RebalanceBeforeWritingSuite`\n- Spark 4.0 / 4.1 / 4.2 (JDK 17, `-Pscala-2.13`): same suite per module.\n\nAll suites pass; `dev/reformat` applied.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-opus-4-8\n\nCloses #7587 from ulysses-you/ne-infer-cast-wrapped-join-keys.\n\nCloses #7587\n\n3999f3a68 [Xiduo You] [SPARK] Infer cast-wrapped join keys in InferRebalanceAndSortOrders\n\nAuthored-by: Xiduo You \u003culyssesyou@apache.org\u003e\nSigned-off-by: Xiduo You \u003culyssesyou@apache.org\u003e\n"
    },
    {
      "commit": "614c8d4c0bc00e1967a19cf4d8213a066cb00608",
      "tree": "b210fcc31b92abfe96e24c27f5d32cd27ecb63a6",
      "parents": [
        "8db1a4902a731e92da9253a263afcfd18158c3a4"
      ],
      "author": {
        "name": "Xiduo You",
        "email": "ulyssesyou@apache.org",
        "time": "Thu Jul 23 12:50:39 2026 +0800"
      },
      "committer": {
        "name": "Xiduo You",
        "email": "ulyssesyou@apache.org",
        "time": "Thu Jul 23 12:50:39 2026 +0800"
      },
      "message": "[KYUUBI #7581] [SPARK] Use the larger advisory partition size when both configs are set\n\n### Why are the changes needed?\n\nWhen both `spark.sql.adaptive.rebalancePartitionsAdvisoryPartitionSizeInBytes`\nand `spark.sql.finalStage.adaptive.advisoryPartitionSizeInBytes` are set,\n`KyuubiSQLConf.getAdvisoryPartitionSize` previously let the rebalance config\nunconditionally take precedence. This could pick a smaller advisory partition\nsize than the finalStage config even when the finalStage value is larger.\n\nThis changes the resolution so the larger of the two values is used when both\nare set, which better reflects the intent of both knobs. The doc for the\nrebalance config is updated accordingly. The change is applied to the\nspark-3.5, 4.0 and 4.1 extension modules.\n\n### How was this patch tested?\n\nUpdated `RebalanceBeforeWritingSuite` in all three modules to cover:\n- both set, rebalance larger -\u003e rebalance wins\n- both set, finalStage larger -\u003e finalStage wins\n- both set to the same value\n\nRan the suite locally:\n\n```\nbuild/mvn test -pl extensions/spark/kyuubi-extension-spark-3-5 -am -Pspark-3.5 \\\n  -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.spark.sql.RebalanceBeforeWritingSuite   # 14 passed\nbuild/mvn test -pl extensions/spark/kyuubi-extension-spark-4-0 -am -Pspark-4.0 -Pscala-2.13 \\\n  -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.spark.sql.RebalanceBeforeWritingSuite   # 12 passed\nbuild/mvn test -pl extensions/spark/kyuubi-extension-spark-4-1 -am -Pspark-4.1 -Pscala-2.13 \\\n  -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.spark.sql.RebalanceBeforeWritingSuite   # 12 passed\n```\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nYes.\n\nAssisted-by: Claude Opus 4.8\n\nCloses #7581 from ulysses-you/advisory-partition-size-max.\n\nCloses #7581\n\n1923b5ae6 [Xiduo You] [SPARK] Apply the larger advisory partition size change to the 4.2 module\ncd113c726 [Xiduo You] [SPARK] Use the larger advisory partition size when both configs are set\n\nAuthored-by: Xiduo You \u003culyssesyou@apache.org\u003e\nSigned-off-by: Xiduo You \u003culyssesyou@apache.org\u003e\n"
    },
    {
      "commit": "8db1a4902a731e92da9253a263afcfd18158c3a4",
      "tree": "1a297429c067cc6bb4dde946c9ccaee054b45725",
      "parents": [
        "14322e8a4a05cafc6abfd1813ff23ee9c3c09091"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 21 17:46:10 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 21 17:46:10 2026 +0800"
      },
      "message": "[KYUUBI #7579] [INFRA] Reduce snapshot Docker image publish schedule to every 5 days\n\n### Why are the changes needed?\n\nThe `Publish Snapshot Docker Image` workflow runs daily and writes a large\nmulti-arch build cache via `type\u003dgha`. Because a repo shares a limited GitHub\nActions cache quota with LRU eviction, this daily snapshot cache occupies a big\nchunk of the quota and pushes out other workflows\u0027 caches, causing them to be\nevicted and re-downloaded more often.\n\nReducing the cadence to every 5 days (`0 0 */5 * *`) keeps the master-snapshot\nimage fresh enough while relieving cache-quota pressure on other workflows.\n\n### How was this patch tested?\n\nCI scheduling change only; no functional code change.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-opus-4-8\n\nCloses #7579 from pan3793/reduce-snapshot-docker-cron.\n\nCloses #7579\n\n76cbecfd9 [Cheng Pan] [INFRA] Reduce snapshot Docker image publish schedule to every 5 days\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "14322e8a4a05cafc6abfd1813ff23ee9c3c09091",
      "tree": "4fc80621b17b8eaeedb27e75dc7c24f4a482e6de",
      "parents": [
        "ab47c672113a0761751332912508bcf484109e21"
      ],
      "author": {
        "name": "hutiefang",
        "email": "hutiefang@qq.com",
        "time": "Tue Jul 21 11:16:10 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 21 13:49:12 2026 +0800"
      },
      "message": "[KYUUBI #2470][AUTHZ] Add Ranger performance tracing to rule authorization\n\n### Why are the changes needed?\n\nCloses #2470.\n\n`RuleAuthorization.checkPrivileges` currently has no Ranger performance trace around privilege-request construction and evaluation. This adds the established `sparkauth.request` tracer around the complete authorization path and logs it from `finally`, so both successful checks and exceptions finish the timing record without changing authorization results.\n\n### How was this patch tested?\n\n- `JAVA_HOME\u003d$(/usr/libexec/java_home -v 17) ./dev/reformat`\n- `JAVA_HOME\u003d$(/usr/libexec/java_home -v 17) ./build/mvn -pl extensions/spark/kyuubi-spark-authz -am -DwildcardSuites\u003dorg.apache.kyuubi.plugin.spark.authz.ranger.InMemoryCatalogRangerSparkExtensionSuite -DskipITs test`\n  - 16 tests passed, including a new assertion that captures the performance trace on both successful and denied authorization paths.\n- `git diff --check`\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: OpenAI Codex with GPT-5\n\nCloses #7555 from hutiefang76/codex/kyuubi-2470-ranger-perf-tracer.\n\nCloses #2470\n\n35aa3ecd9 [Cheng Pan] restore\n1f4dffcbb [Cheng Pan] DataSourceV2RelationTableExtractorSuite extends KyuubiFunSuite\nd2ac06ffe [Cheng Pan] fix PaimonCatalogRangerSparkExtensionSuite\nd4c6f6854 [Cheng Pan] flip assume and super.beforeEach()\na0379aa74 [Cheng Pan] codestyle\n8333cc478 [Cheng Pan] codestyle\n356a24d43 [Cheng Pan] restore test hierarchy\nce04403e7 [hutiefang] [KYUUBI #2470][AUTHZ] Add Ranger performance tracing to rule authorization\n\nLead-authored-by: hutiefang \u003chutiefang@qq.com\u003e\nCo-authored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "ab47c672113a0761751332912508bcf484109e21",
      "tree": "7eba2c490e0476b952815e5acf3f63d2b4e0313d",
      "parents": [
        "f67edd6f9ea8177b7eb6c648bf196d44938d0c26"
      ],
      "author": {
        "name": "Jiwon Park",
        "email": "jpark92@outlook.kr",
        "time": "Tue Jul 21 07:49:59 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 21 07:49:59 2026 +0800"
      },
      "message": "[KYUUBI #7230][AUTHZ] Support skipping privilege check for DataSourceV2Relation without catalog and identifier\n\n### Why are the changes needed?\n\nDSv2 `TableProvider`s that do not implement `SupportsCatalogOptions` (the MongoDB connector, the ClickHouse native connector, etc.), when used directly via `format(...).load()` / `.save()`, produce a `DataSourceV2Relation` with neither `catalog` nor `identifier` — Spark\u0027s non-catalog fallback in `DataSourceV2Utils.loadV2Source` / `DataFrameWriter` passes `(None, None)`, and the read-side fallback carries Spark\u0027s own TODO note that \"Non-catalog paths for DSV2 are currently not well defined\".\n\nFor such relations `DataSourceV2RelationTableExtractor` falls back to `table.name()`, which is connector-defined and usually synthetic (e.g. `MongoTable()`). The resulting Ranger resource has no `database` element, and a resource missing a parent level of the `database → table → column` hierarchy matches no policy at all — not even `database\u003d* / table\u003d*` (`RangerDefaultPolicyResourceMatcher.isHierarchyValidForResources`, Ranger 2.6.0). So the current behavior is an unconditional deny that operators cannot lift with any policy, reported in #7230. Meanwhile the v1 path is already skipped: a `LogicalRelation` without `catalogTable` produces no privilege object.\n\nThis PR adds an operator-level opt-out, default `false` so default behavior is unchanged:\n\n- `spark.kyuubi.authz.skip.catalogless.v2.relation.enabled` (default `false`): when enabled, the extractor returns `None` for a `DataSourceV2Relation` whose catalog and identifier are both empty, restoring parity with the v1 path.\n- The key is added to `AuthzConfigurationChecker`\u0027s built-in restricted list (like `spark.sql.runSQLOnFiles`), so end users cannot flip it with `SET`. Operators should also consider listing it in `kyuubi.session.conf.restrict.list`.\n\nNote: whether skipping is safe is deployment-specific — fine when credentials for the external system are supplied per query by the end user, risky when the shared Spark principal holds ambient credentials. Hence opt-in rather than unconditional. Skipped relations produce no Ranger audit events.\n\n### How was this patch tested?\n\n- New `DataSourceV2RelationTableExtractorSuite`:\n  - default behavior preserved: the synthetic `table.name()` is still extracted verbatim when the conf is off;\n  - the relation is skipped when the conf is enabled;\n  - relations carrying an identifier are unaffected even with the conf enabled (the database fallback from #6544 still applies).\n- Extended `AuthzConfigurationCheckerSuite`: `SET` on the new key throws `AccessControlException`.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude Opus 4.8\n\nCloses #7557 from j1wonpark/fix/authz-skip-catalogless-v2relation.\n\nCloses #7230\n\n35693a4ab [Jiwon Park] [KYUUBI #7230][AUTHZ] Support skipping privilege check for DataSourceV2Relation without catalog and identifier\n\nAuthored-by: Jiwon Park \u003cjpark92@outlook.kr\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "f67edd6f9ea8177b7eb6c648bf196d44938d0c26",
      "tree": "35534dbe312e5eb3055fdf89b31aea8179c2de98",
      "parents": [
        "78d2107ebe648574fd253996245129af8ab6b582"
      ],
      "author": {
        "name": "Jiwon Park",
        "email": "jpark92@outlook.kr",
        "time": "Mon Jul 20 14:23:02 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Jul 20 14:23:02 2026 +0800"
      },
      "message": "[KYUUBI #7576][AUTHZ] Fix data masking failure on a UNION-ALL view over a masked view\n\n### Why are the changes needed?\n\nClose #7576.\n\nReading a permanent view that UNION-ALLs a masked permanent view fails with `MISSING_ATTRIBUTES`, while reading the masked view directly works (#3581).\n\nBoth branches expand the masked view with identical output exprIds. After `RuleApplyDataMaskingStage0` marks both branches, `DeduplicateRelations` re-instances one branch, so that branch\u0027s `exprToMaskers()` ends up keyed on ids now owned by the other branch. `RuleApplyDataMaskingStage1` merges all marker maps into one `Map` (duplicate keys silently last-wins) and substitutes unconditionally, rewiring the outer view\u0027s schema compensation Project — above the Union — to attributes the Union never outputs. See #7576 for the full analysis.\n\nThis change scopes the Stage1 substitution: rewrite the children first, keep only the maskers the rewritten children actually expose (matched by exprId, since `SubqueryAlias` may requalify outputs), and merge the per-marker maps after that filtering. When a child is not resolved yet (a type-changing masker leaves Union branches incompatible until type coercion runs, and `Union.output` fails on them), the previous unfiltered substitution is kept. Branch-local substitution keeps working; the cross-branch leak is blocked at the Union boundary.\n\n### How was this patch tested?\n\nTwo tests added to `DataMaskingTestBase` (run by all data masking suites): a reproduction that failed with `MISSING_ATTRIBUTES` before this fix, and a control proving the same view shape resolves fine without a masking policy. A view-level type-preserving MASK policy is added to the fixture, since a type-changing mask dies earlier with `CANNOT_UP_CAST` and would hide the bug.\n\n```\nbuild/mvn test -pl extensions/spark/kyuubi-spark-authz -Dtest\u003dnone \\\n  -DwildcardSuites\u003dorg.apache.kyuubi.plugin.spark.authz.ranger.datamasking.DataMaskingForHiveParquetSuite\n```\n\nAll five data masking suites pass, and the full kyuubi-spark-authz module is green (662 succeeded / 0 failed / 42 pre-existing skips).\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-fable-5\n\nCloses #7577 from j1wonpark/fix/authz-datamasking-nested-view.\n\nCloses #7576\n\n96f6b8312 [Jiwon Park] [KYUUBI #7576][AUTHZ] Define the nested-view mask policy in PolicyJsonFileGenerator\n555a51901 [Jiwon Park] [KYUUBI #7576][AUTHZ] Fix data masking failure on a UNION-ALL view over a masked view\nb8d353611 [Jiwon Park] [KYUUBI #7576][AUTHZ] control: unmasked UNION-ALL view resolves — masking is the cause\n050f00b74 [Jiwon Park] [KYUUBI #7576][AUTHZ] repro: data masking breaks on UNION-ALL view nested over a masked view\n\nAuthored-by: Jiwon Park \u003cjpark92@outlook.kr\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "78d2107ebe648574fd253996245129af8ab6b582",
      "tree": "91120760c6167efe3dbbe7f8ce2584fccd86e5a9",
      "parents": [
        "5fc51faf9ac7c6fc63d5ab3461ae69ba327abf1d"
      ],
      "author": {
        "name": "Denis Krivenko",
        "email": "dnskrv88@gmail.com",
        "time": "Mon Jul 20 13:53:56 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Jul 20 13:53:56 2026 +0800"
      },
      "message": "[KYUUBI #7578] [K8S][HELM] Update default Kyuubi version to 1.12.0\n\n### Why are the changes needed?\nDefault Kyuubi version used in the Helm chart should be aligned with the latest release version.\n\n### How was this patch tested?\nRender the chart templates to ensure `1.12.0` version is used.\n```shell\nhelm template kyuubi charts/kyuubi\n```\nOutput (reduced)\n```yaml\n# Source: kyuubi/templates/kyuubi-statefulset.yaml\napiVersion: apps/v1\nkind: StatefulSet\nmetadata:\n  name: kyuubi\n  labels:\n    ...\n    app.kubernetes.io/version: \"1.12.0\"\nspec:\n  template:\n    ...\n    spec:\n      serviceAccountName: kyuubi\n      containers:\n        - name: kyuubi-server\n          image: \"apache/kyuubi:1.12.0\"\n          imagePullPolicy: IfNotPresent\n          ...\n```\n\n### Was this patch authored or co-authored using generative AI tooling?\nNo\n\nCloses #7578 from dnskr/helm-default-kyuubi-version-1.12.0.\n\nCloses #7578\n\n2737d8185 [Denis Krivenko] [K8S][HELM] Update default Kyuubi version to 1.12.0\n\nAuthored-by: Denis Krivenko \u003cdnskrv88@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "5fc51faf9ac7c6fc63d5ab3461ae69ba327abf1d",
      "tree": "ffb21b7eea945e34c7335178c035b66a1202911b",
      "parents": [
        "7066271318b2a1d81e4a3e7b7c89f622b14107ad"
      ],
      "author": {
        "name": "Hiroki Egawa",
        "email": "hiegawa@lycorp.co.jp",
        "time": "Mon Jul 20 13:47:18 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Jul 20 13:47:18 2026 +0800"
      },
      "message": "[KYUUBI #7387] Replace serverOnly with audience and immutable on ConfigEntry\n\nThis implementation is based on the following suggestion.\n- https://github.com/apache/kyuubi/pull/7451#issuecomment-4587409731\n\n### Why are the changes needed?\n\n`ConfigEntry.serverOnly` conflated two concerns, \"don\u0027t send to engines\" and \"users can\u0027t override\", by stripping entries from the config in `getUserDefaults()`.\nThis caused `kyuubi.server.redaction.regex` to be removed from the session config before `ProcBuilder.toString` could use it for redacting sensitive values in engine command lines (#7387).\n\nAdditionally, `conf.getAll` sends all configs to every engine regardless of engine type, causing Flink-specific configs to be sent to Spark, Trino configs to Hive, etc.\n\nSplitting these concepts into audience and immutable provides the following benefits:\n- Server-side code to always see all config values (fixing redaction — Closes #7387)\n- Engine process builders to receive only audience-appropriate configs via `getEngineConf`\n\n---\n\n[redactCommandLineArgs](https://github.com/apache/kyuubi/blob/7066271318b2a1d81e4a3e7b7c89f622b14107ad/kyuubi-common/src/main/scala/org/apache/kyuubi/Utils.scala#L329-L348) previously only redacted `key\u003dvalue` arguments that followed a `--conf` marker.\nSince arguments like `-Dsome.secret\u003dvalue` are not preceded by `--conf`, they were not redacted even when matching `SERVER_SECRET_REDACTION_PATTERN`.\nThe `--conf` guard is removed so that all arguments containing `\u003d` are subject to redaction.\n\n### How was this patch tested?\n\nUnit tests.\n\n```shell\n$ ./build/mvn test -pl kyuubi-server -am -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.operation.KyuubiServerInfoProviderSuite\n$ ./build/mvn test -pl kyuubi-common -am -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.config,org.apache.kyuubi.session.SessionManagerValidationSuite\n$ ./build/mvn test -pl kyuubi-server -am -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.engine.dataagent.DataAgentProcessBuilderSuite,org.apache.kyuubi.engine.flink.FlinkProcessBuilderSuite,org.apache.kyuubi.engine.trino.TrinoProcessBuilderSuite,org.apache.kyuubi.engine.jdbc.JdbcYarnModeProcessBuilderSuite,org.apache.kyuubi.engine.jdbc.JdbcProcessBuilderSuite,org.apache.kyuubi.engine.hive.HiveProcessBuilderSuite,org.apache.kyuubi.engine.hive.HiveYarnModeProcessBuilderSuite,org.apache.kyuubi.engine.spark.SparkBatchProcessBuilderSuite,org.apache.kyuubi.engine.spark.SparkProcessBuilderSuite\n```\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-opus-4-6\n\nCloses #7451 from LamiumAmplexicaule/fix-redaction.\n\nCloses #7387\n\nb6ba20873 [Hiroki Egawa] Address review comments on `AGENTS.md` configuration section\ncbf70e153 [Hiroki Egawa] Set `audience(SERVER)` on `SERVER_INFO_PROVIDER`\n1099ba78b [Hiroki Egawa] Forward unregistered non-kyuubi configs to all engines for backward compatibility\n4bd82cf64 [Hiroki Egawa] Verify all `KyuubiReservedKeys` constants are in `reservedKeys`\n59f09d984 [Hiroki Egawa] Fix stale doc on `SERVER_ONLY_PREFIXES`\n9aec39313 [Hiroki Egawa] Set `audience(ANY)` on frontend thrift configs shared with engines\nf06bf5ffc [Hiroki Egawa] Replace serverOnly with audience and immutable on ConfigEntry\n\nAuthored-by: Hiroki Egawa \u003chiegawa@lycorp.co.jp\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "7066271318b2a1d81e4a3e7b7c89f622b14107ad",
      "tree": "f0080334fb1c3d083a538c388eb7666223a510e0",
      "parents": [
        "dcc0f2f6939440bf81dd17ded92f4b70020d66f5"
      ],
      "author": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Fri Jul 17 22:33:07 2026 +0900"
      },
      "committer": {
        "name": "Akira Ajisaka",
        "email": "aajisaka@apache.org",
        "time": "Fri Jul 17 22:33:07 2026 +0900"
      },
      "message": "[KYUUBI #7575] Improve access path validation\n\n### Why are the changes needed?\n\nNormalize config keys before access path validation\n\n### How was this patch tested?\n\nAdded unit tests\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted by: GPT-5.5\n\nCloses #7575 from aajisaka/fix-spark-access-path.\n\nCloses #7575\n\n9c1b47268 [Akira Ajisaka] Improve access path validation\n\nAuthored-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\nSigned-off-by: Akira Ajisaka \u003caajisaka@apache.org\u003e\n"
    },
    {
      "commit": "dcc0f2f6939440bf81dd17ded92f4b70020d66f5",
      "tree": "df92fcfb5f38e049aed7c74ef8b8e58cd68cec6e",
      "parents": [
        "91bb98d66c8d4ef5849de0a57fe0386380671f24"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Jul 16 23:28:34 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Jul 16 23:28:34 2026 +0800"
      },
      "message": "[RELEASE] Bump 1.13.0-SNAPSHOT\n"
    },
    {
      "commit": "91bb98d66c8d4ef5849de0a57fe0386380671f24",
      "tree": "68aae7a77affc0e076ffa0ce973ca6160057fb9b",
      "parents": [
        "9afb1d88927c9d3d3c6d25edd940bd5f0f75530e"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Jul 16 23:25:32 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Jul 16 23:25:32 2026 +0800"
      },
      "message": "[KYUUBI #7570] Support Spark 4.2\n\n### Why are the changes needed?\n\nSpark 4.2.0 is released. This adds the `spark-4.2` profile and the `kyuubi-extension-spark-4-2` module, enabling Kyuubi to run on Spark 4.2.\n\n### What changes are proposed?\n\n- Add `spark-4.2` Maven profile with the `kyuubi-extension-spark-4-2` module. Lakehouse engines (Delta/Hudi/Paimon/Iceberg) fall back to 4.1 artifacts until native 4.2 support lands.\n- Adapt the engine UI and servlet adapter for Spark 4.2\u0027s Jetty 12 (ee10) / Servlet 6.0 upgrade.\n- Re-fork `KyuubiEnsureRequirements` and update `MaxScanStrategy` for Spark 4.2 physical plan API changes.\n- Add spark-4.2 CI matrix entries (`normal` + `verify-on-spark-4.2-binary`).\n\n### How was this patch tested?\n\nPass GHA.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: GLM 5.2\n\nCloses #7570 from pan3793/spark-4.2.\n\nCloses #7570\n\ncbc1dd22e [Cheng Pan] Fix stale spark-4.1 references in kyuubi-extension-spark-4-2\nedbdcbd19 [Cheng Pan] nit: style\n7eb2fec4e [Cheng Pan] Apply suggestions from code review\n562a43bb4 [Cheng Pan] Support Spark 4.2 CatalogTable constructor in HiveTableCatalog\n871db157f [Cheng Pan] Rename test helpers to avoid Spark 4.2 QueryTestBase conflicts\nf4c865d01 [Cheng Pan] Unwrap InvocationTargetException in setCurrentNamespace reflective call\nbc4174c18 [Cheng Pan] Fix setCurrentNamespace reflective call for Array[String] varargs\n750d5114a [Cheng Pan] Add spark-4.2 extension to release script\neaf4a5da9 [Cheng Pan] Sync kyuubi-extension-spark-4-2 pom.xml with 4-1 sibling\n20a405148 [Cheng Pan] Access CatalogManager reflectively for Spark 4.2 cross-version compat\nbe7c99412 [Cheng Pan] Reference SPARK JIRA tickets in Spark 4.x comments\ndfd3c1eef [Cheng Pan] Remove redundant ANSI disable in authz SparkSessionProvider\n9d0408307 [Cheng Pan] Accept DAGScheduler.cleanupQueryJobs NPE in engine crash test\n77f82e40b [Cheng Pan] Use Spark CurrentUserContext for session_user on Spark 4.0+\ne68244c95 [Cheng Pan] update docs\n71ea1e264 [Cheng Pan] Support Spark 4.2\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "9afb1d88927c9d3d3c6d25edd940bd5f0f75530e",
      "tree": "2a4aab196274f5cc8db44a4118a562d0211853f5",
      "parents": [
        "4bd78d8d562554ca7364cbcb2112a18ccddfbdd9"
      ],
      "author": {
        "name": "ruanwenjun",
        "email": "wenjun@apache.org",
        "time": "Thu Jul 16 13:10:51 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Jul 16 13:10:51 2026 +0800"
      },
      "message": "[KYUUBI #7509] [SERVER] Add engine startup time metric\n\n### Why are the changes needed?\n\nKyuubi already exposes operation execution time metrics, but there is no server-side metric for how long a new engine takes to become available. This patch adds an engine startup time histogram so operators can observe successful engine startup latency, including waiting for startup permits, launching the engine, cluster scheduling, engine initialization, and discovery by the Kyuubi server.\n\n### How was this patch tested?\n\n- `git diff --check`\n- `build/mvn spotless:apply -pl kyuubi-metrics,kyuubi-server -DskipTests`\n- `build/mvn test -pl kyuubi-server -am -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.engine.EngineRefWithZookeeperSuite`\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: OpenAI Codex (GPT-5)\n\nCloses #7509 from ruanwenjun/kyuubi-engine-startup-time.\n\nCloses #7509\n\n6de83b863 [Cheng Pan] fmt\n34bf12be8 [ruanwenjun] Make engine startup metric test robust\n5472ca9cd [ruanwenjun] [SERVER] Add engine startup time metric\n\nLead-authored-by: ruanwenjun \u003cwenjun@apache.org\u003e\nCo-authored-by: Cheng Pan \u003cpan3793@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "4bd78d8d562554ca7364cbcb2112a18ccddfbdd9",
      "tree": "baebbfaacff6303216edc1d1d9c249a18c64979b",
      "parents": [
        "794ebc520027032ea5694ea5196cb8c58ff94e60"
      ],
      "author": {
        "name": "wangzhigang",
        "email": "iamzhigangwang@gmail.com",
        "time": "Thu Jul 16 13:09:25 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Jul 16 13:09:25 2026 +0800"
      },
      "message": "[KYUUBI #7567] [SERVER] Improve Engine UI proxy 403 response\n\n### Why are the changes needed?\n\nThe Engine UI proxy currently falls back to Jetty\u0027s generic 403 page when proxying is disabled, the target host is not allowlisted, or the URL is invalid. The page does not tell users which Kyuubi settings need to be changed.\n\nThis patch keeps the existing 403 status and host validation, but returns an actionable Kyuubi-styled page that shows the target engine and the relevant proxy and host allowlist settings.\n\n### How was this patch tested?\n\n- `dev/reformat`\n- `build/mvn -pl kyuubi-server -am -Pspark-provided,hive-provided,flink-provided scalastyle:check`\n- `build/mvn test -pl kyuubi-server -am -rf :kyuubi-server_2.12 -Pspark-provided,hive-provided,flink-provided -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.kyuubi.server.api.EngineUIProxyServletSuite`\n- Compared the previous and updated 403 responses through real Jetty servlets in a browser.\n\n### Visual comparison\n\nBefore:\n\n![Jetty default 403 response](https://raw.githubusercontent.com/wangzhigang1999/kyuubi/zhigang/pr-7567-assets/pr-assets/7567/before.png)\n\nAfter:\n\n![Actionable Kyuubi Engine UI 403 response](https://raw.githubusercontent.com/wangzhigang1999/kyuubi/zhigang/pr-7567-assets/pr-assets/7567/after.png)\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Codex with GPT-5\n\nCloses #7567 from wangzhigang1999/zhigang/engine-ui-403-page.\n\nCloses #7567\n\nebe253f55 [wangzhigang] [KYUUBI] Improve Engine UI proxy 403 response\n\nAuthored-by: wangzhigang \u003ciamzhigangwang@gmail.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "794ebc520027032ea5694ea5196cb8c58ff94e60",
      "tree": "5524c01deb6800e7f71daf6e51a180a958685a76",
      "parents": [
        "8fe59c57b5668eba5db9579c0752919b61866bfb"
      ],
      "author": {
        "name": "lifumao",
        "email": "lifumao@tencent.com",
        "time": "Thu Jul 16 13:07:55 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Jul 16 13:07:55 2026 +0800"
      },
      "message": "[KYUUBI #7574] Fix typo in kyuubi-extension-spark-jdbc-dialect pom.xml\n\n### Why are the changes needed?\n\nFixed https://github.com/apache/kyuubi/issues/7574. There is a typo in extensions/spark/kyuubi-extension-spark-jdbc-dialect/pom.xml:\n```\n\u003coutputDirectory\u003etarget/scala-${scala.binary.verison}/classes\u003c/outputDirectory\u003e\n\u003ctestOutputDirectory\u003etarget/scala-${scala.binary.verison}/test-classes\u003c/testOutputDirectory\u003e\n```\nThe property name `scala.binary.verison` is misspelled (should be `scala.binary.version`). Because Maven cannot resolve the misspelled property, the placeholder is not substituted, and the build outputs are written to a directory literally named target/scala-${scala.binary.verison}/ instead of the expected target/scala-2.12/ or target/scala-2.13/.\n\n### How was this patch tested?\n\nPass GHA.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nNo\n\nCloses #7573 from maomaodev/kyuubi_build.\n\nCloses #7574\n\na31d7acf5 [lifumao] Fix typo in kyuubi-extension-spark-jdbc-dialect pom.xml\n\nAuthored-by: lifumao \u003clifumao@tencent.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "8fe59c57b5668eba5db9579c0752919b61866bfb",
      "tree": "e8bf21926d373042db7f1dfd7a65c89eeb082b23",
      "parents": [
        "6a68db38e6bcedf0dda91dc3d9344b61ae93c2f2"
      ],
      "author": {
        "name": "Jiwon Park",
        "email": "jpark92@outlook.kr",
        "time": "Thu Jul 16 13:05:50 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Thu Jul 16 13:05:50 2026 +0800"
      },
      "message": "[KYUUBI #7568][AUTHZ] Eliminate TypeOfPlaceHolder across the whole plan\n\n### Why are the changes needed?\n\nFixes #7568.\n\n`RuleApplyTypeOfMarker` marks every `TypeOf` in the whole plan (`transformAllExpressions`), but since #5997 `RuleEliminateTypeOf` reverts them with `transformExpressionsUp`, which only visits the root node\u0027s expressions. A `TypeOfPlaceHolder` below the root — under `Sort`, `Union`, `Aggregate`, or a subquery — survives into execution and fails with `CLASS_NOT_OVERRIDE_EXPECTED_METHOD`, since it implements `doGenCode` but no `eval`.\n\nThis change uses `transformAllExpressions` on the eliminating side as well, so both rules cover the same scope in a single pass.\n\nAffects 1.9.0 onwards, including master.\n\n### How was this patch tested?\n\nAdded a test to `RangerSparkExtensionSuite` covering the root shapes the existing `Project`-root-only test misses: `Sort`, `Union`, `Aggregate`, and a subquery. It fails on master and passes with this change. Full `extensions/spark/kyuubi-spark-authz` suite: 657 passed, 0 failed.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude:claude-opus-4-8\n\nCloses #7569 from j1wonpark/fix/authz-eliminate-typeof-whole-plan.\n\nCloses #7568\n\n38464f17f [Jiwon Park] Sort collected rows in the UNION ALL case to avoid order dependency while keeping Union as the root node\n9ffea2de0 [Jiwon Park] [KYUUBI #7568][AUTHZ] Eliminate TypeOfPlaceHolder across the whole plan\n\nAuthored-by: Jiwon Park \u003cjpark92@outlook.kr\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "6a68db38e6bcedf0dda91dc3d9344b61ae93c2f2",
      "tree": "fc6366528e263f69875d2eba8ac6a4c63c173796",
      "parents": [
        "99bed388587c57c4d181d8833974db6668669548"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Wed Jul 15 14:04:54 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Wed Jul 15 14:04:54 2026 +0800"
      },
      "message": "[KYUUBI #7571] [INFRA] Redirect build/mvn fallback message to stderr to avoid corrupting captures\n\n### Why are the changes needed?\n\nFor example, the Spark version was wrongly captured as `Falling back to archive.apache.org to download Maven`\n\nhttps://github.com/apache/kyuubi/actions/runs/29387027103/job/87262361668?pr\u003d7570\n\n### How was this patch tested?\n\nMerge then monitor CI.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nNo.\n\nCloses #7571 from pan3793/mvn-echo.\n\nCloses #7571\n\n83b48e1fd [Cheng Pan] [INFRA] Redirect build/mvn fallback message to stderr to avoid corrupting captures\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "99bed388587c57c4d181d8833974db6668669548",
      "tree": "e3939624c10bdf7ead614f03fd5e7dd7f1f880c2",
      "parents": [
        "445a906c2b41a04cbf512d01b5c6f02583821a7e"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 14 13:52:17 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 14 13:52:17 2026 +0800"
      },
      "message": "[KYUUBI #7564] [INFRA] Bump GHA workflows to latest action versions\n\n### Why are the changes needed?\n\nTo keep our CI on the latest GitHub Actions versions, per the [apache/infrastructure-actions allowlist](https://github.com/apache/infrastructure-actions/blob/main/actions.yml).\n\n- For the GitHub-maintained actions (`actions/*`, `github/*`) and allowlisted `*` actions, the allowlist permits any version, so this PR tracks the latest **major** version tags (`vN`) rather than specific patches.\n- For hash-pinned allowlisted third-party actions, the convention is to pin to the allowlisted commit hash with a `# vX.Y.Z` comment. The Docker actions used here were already at the latest allowlisted hashes, so they are unchanged.\n\nChanges (patch tag -\u003e latest major):\n\n- `actions/checkout`      `v7.0.0`  -\u003e `v7`\n- `actions/setup-java`    `v5.4.0`  -\u003e `v5`\n- `actions/setup-python`  `v6.3.0`  -\u003e `v6`\n- `actions/cache`         `v6.1.0`  -\u003e `v6`  (and `v4` -\u003e `v6` in `.github/actions/setup-maven/action.yaml`)\n- `actions/stale`         `v10.3.0` -\u003e `v10`\n\n### How was this patch tested?\n\nYAML-only change; no unit tests apply. Verified by:\n\n- Cross-checked each action\u0027s target against the ASF allowlist and the latest release tag on GitHub.\n- Ran `./dev/reformat` (no source changes; Spotless does not manage YAML).\n- The `ASF Allowlist Check` workflow in this repo enforces the allowlist on this PR.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: codemaker with glm-5.2\n\nCloses #7564 from pan3793/gha-bump-actions.\n\nCloses #7564\n\nd5a81d7f8 [Cheng Pan] [INFRA] Bump GHA workflows to latest action versions\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "445a906c2b41a04cbf512d01b5c6f02583821a7e",
      "tree": "992320a236f783239be1f55d1170afd59136b8d6",
      "parents": [
        "00ba4e65d2fe30ce09620a20ebef8ff2e99e6ac8"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 14 10:21:52 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Tue Jul 14 10:21:52 2026 +0800"
      },
      "message": "[KYUUBI #7561] [INFRA] Cache CI engine archives per URL with a reusable action\n\n### Why are the changes needed?\n\nThe old `cache-engine-archives` cache is one blob under a constant key, so bumping any\nengine invalidates all of them. This provisions engines explicitly instead:\n\n- New reusable action `.github/actions/download-archive` downloads a tarball and caches it\n  with `actions/cache` **keyed by the URL** (atomic download), so each engine caches\n  independently and stable versions restore instantly.\n- `.github/scripts/resolve-engine-archive-urls.sh` derives each URL from the Maven\n  properties (honoring the build\u0027s profiles/`-D` overrides); `expose-engine-homes.sh`\n  publishes `SPARK_HOME`/`HIVE_HOME`/`FLINK_HOME` from `/opt`.\n- Every `master.yml` job now resolves → downloads → exposes only the engines it needs, and\n  the build runs with `-P{spark,flink,hive}-provided`. The now-orphaned\n  `cache-engine-archives` action is removed.\n- Flink test helpers now honor `FLINK_HOME` first (fallback to the download dir for local\n  runs), matching Spark/Hive.\n- Spark extension modules gain a `spark-home-from-archive` profile, auto-activated only when\n  `SPARK_HOME` is unset, so the Standalone-cluster tests use the downloaded archive locally\n  but a provided `SPARK_HOME` is no longer overridden.\n- The `hive-it` avatica/CALCITE-1224 hack is now a single `zip -d`.\n\n### How was this patch tested?\n\nRun by this PR\u0027s CI.\n\nLocally checked: URL resolution across all matrix cases (Scala 2.13, Spark/Flink/Hive\nversion overrides, CDH6 empty-query), `*_HOME` resolution, the `closer.lua` redirect for\n`curl -fSL`, the `zip -d` patch on a mock jar, and the extension `SPARK_HOME` profile via\nthe effective POM (inherits the env when set, falls back to the archive otherwise).\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: Claude Opus 4.8\n\nCloses #7561 from pan3793/gha-dl.\n\nCloses #7561\n\n1f9ad04dc [Cheng Pan] [INFRA] Restore SPARK_SCALA_VERSION for Spark extension local-cluster tests\n20a94b22f [Cheng Pan] [INFRA] Bump actions/cache to v6 in download-archive action\na5c4208f0 [Cheng Pan] fix spark extension standalone tests\n0010f4e4c [Cheng Pan] [INFRA] Remove orphaned cache-engine-archives action\nda90a49d2 [Cheng Pan] nit\n13948d3d3 [Cheng Pan] [INFRA] Cache CI engine archives per URL with a reusable action\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "00ba4e65d2fe30ce09620a20ebef8ff2e99e6ac8",
      "tree": "1a8707e55c52299beb31147bc61dde83ff99a53a",
      "parents": [
        "0783f075d7d05b7da0faaaa29282711640242bab"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Jul 13 17:42:26 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Mon Jul 13 17:42:26 2026 +0800"
      },
      "message": "[KYUUBI #7562] [INFRA] Remove gluten integration test module\n\n### Why are the changes needed?\n\nThis removes the kyuubi-gluten-it module, the gluten-it Maven profile, the CI workflow, and the GlutenSuiteMixin test utility.\n\nGluten IT is not maintained well, let\u0027s just remove it.\n\n### How was this patch tested?\n\nPass GHA.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: GLM 5.2\n\nCloses #7562 from pan3793/remove-gluten-it.\n\nCloses #7562\n\n45918d4c7 [Cheng Pan] [INFRA] Remove gluten integration test module\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "0783f075d7d05b7da0faaaa29282711640242bab",
      "tree": "1d394cb1f2e2b0017fb1043ce293b9fdfdb8349b",
      "parents": [
        "84d74d9d9980ea2ac1fa9d9892d3235595534d11"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 23:05:17 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 23:05:17 2026 +0800"
      },
      "message": "[KYUUBI #7554] Bump Log4j 2.26.1\n\n### Why are the changes needed?\n\nLog4j 2.26.1 Release notes (released 02 Jul 2026, patch on 2.26.0):\n\nhttps://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1\n\nNotable fixes in 2.26.1:\n- `RollingFileAppender` `createOnDemand` deferral;\n- non-finite number handling in MapMessage→JSON;\n- MSGID/SD-ID encoding in StructuredDataMessage→XML;\n- stack-trace rendering for exceptions with colliding `equals()`/`hashCode()`;\n- resource leaks in `ConfigurationSource` on failed URL config load;\n- `KafkaAppender` spurious error after successful retry;\n- plus improved `LinkageError` logging around LMAX Disruptor.\n\n### How was this patch tested?\n\nGHA.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: GLM 5.2\n\nCloses #7554 from pan3793/bump-log4j-2.26.1.\n\nCloses #7554\n\nb12910f65 [Cheng Pan] [KYUUBI] Bump Log4j 2.26.1\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "84d74d9d9980ea2ac1fa9d9892d3235595534d11",
      "tree": "7e4d42da8079cb2a069231047dfb970e0b236cbe",
      "parents": [
        "e532738a29322280f902268d8c97731183995178"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 23:04:16 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 23:04:16 2026 +0800"
      },
      "message": "[KYUUBI #7553] Bump Flink 1.20.5\n\n### Why are the changes needed?\n\nAs title.\n\n### How was this patch tested?\n\nPass GHA.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: GLM 5.2\n\nCloses #7553 from pan3793/bump-flink-1.20.5.\n\nCloses #7553\n\nd15dce68f [Cheng Pan] [KYUUBI] Bump Flink 1.20.5\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "e532738a29322280f902268d8c97731183995178",
      "tree": "4e8c7b98c9d40593f7a9971fa7c60b854f8bff25",
      "parents": [
        "0c6f752754e600b4eb1f715c5b1dee05c22825f4"
      ],
      "author": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 23:03:35 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 23:03:35 2026 +0800"
      },
      "message": "[KYUUBI #7552] Authz supports Spark 4.0 and 4.1\n\n### Why are the changes needed?\n\n`kyuubi-spark-authz` does not support Spark 4.0/4.1. Several Spark 4.0+ changes break authorization, row-filtering, and data masking. This PR fixes all known issues and enables CI for Spark 4.0/4.1.\n\n### What changes are proposed?\n\n**Authz fixes:**\n- `AlterColumns` spec for SPARK-43995 (`AlterColumn`→`AlterColumns` rename in Spark 4.0)\n- Unwrap `CommandResult` to authorize CALL procedures (Spark 4.0 eager execution)\n- Match `ShowNamespacesCommand` for SHOW DATABASES row-filtering (Spark 4.1 nodeName change)\n- Clear leaked `KYUUBI_AUTHZ_TAG` from cached catalog nodes (Spark 4.0 `LogicalRelation` reuse)\n\n**Test adaptations:**\n- Disable ANSI mode in data masking tests (SPARK-44444 enables ANSI by default; `AnsiStringPromotionTypeCoercion` casts masked strings to bigint → `CAST_INVALID_INPUT`)\n- `HoodieCatalogTableTableExtractor` fallback for Hudi 1.2.0 `DeleteHoodieTableCommand.dft`→`query` rename\n- Paimon suite: `isSupportedVersion \u003d isScalaV212 || isSparkV40OrGreater`, alter non-PK column, handle `LocalDateTime`\n\n**Dependency upgrades:**\n- Delta 4.3.1 with Spark-version-specific artifacts (`delta-spark_4.0_2.13` / `delta-spark_4.1_2.13`)\n- Hudi 1.1.1 (Spark 3.x, Java 8) / 1.2.0 (Spark 4.x)\n- Paimon 1.4.2 for Spark 4.0; keep 0.8.2 for Spark 3.x (1.4.x has known Spark 3.3 issues)\n- Enable Iceberg, Delta, Hudi tests for Spark 4.0/4.1, Paimon for Spark 4.0\n\n### How was this patch tested?\n\nAll existing authz tests pass across Spark 3.3/3.4/3.5 (Scala 2.12) and Spark 4.0/4.1 (Scala 2.13).\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: codemaker with glm-5.2\n\nCloses #7552 from pan3793/authz-spark-4.1-v2.\n\nCloses #7552\n\nc4f990276 [Cheng Pan] style\n5c5df395b [Cheng Pan] mv to injectPostHocResolutionRule\n76b41b98d [Cheng Pan] Update authz README for Supported Apache Spark Versions\n76e6873f5 [Cheng Pan] mention hudi 1.1 is the latest version that support Java 8\n0530e9d64 [Cheng Pan] [AUTHZ] Fix Paimon Changing Column Type test to use real type change\nf10efc7b6 [Cheng Pan] fix\n7d2e9bd04 [Cheng Pan] tune paimon and hudi version\n94f0343ef [Cheng Pan] enable authz ci for spark 4.0 and 4.1\n411a2220b [Cheng Pan] [AUTHZ] Bump Paimon 1.4.2 and enable Paimon tests for Spark 4.0\n38cd0df01 [Cheng Pan] [AUTHZ] Bump Hudi 1.2.0 and enable Hudi tests for Spark 4.0/4.1\n7bd778496 [Cheng Pan] enable delta lake tests for spark 4.1\n28198f944 [Cheng Pan] Bump Delta Lake 4.3.0\nb13cee1e3 [Cheng Pan] enable iceberg test for spark 4.1\n8ea58653f [Cheng Pan] [AUTHZ] Adapt tests for Spark 4.0 behavior changes\n939da7e4d [Cheng Pan] [AUTHZ] Clear leaked authz tags to fix permanent-view column deny on Spark 4.0\nb3e0232bb [Cheng Pan] [AUTHZ] Fix SHOW DATABASES row-filtering on Spark 4.1\ndb1932197 [Cheng Pan] [AUTHZ] Authorize CALL procedures on Spark 4.0 via CommandResult unwrap\nf7bccd7a0 [Cheng Pan] [AUTHZ] Add AlterColumns spec for Spark 4.0 ALTER COLUMN rename\n\nAuthored-by: Cheng Pan \u003cchengpan@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "0c6f752754e600b4eb1f715c5b1dee05c22825f4",
      "tree": "4d0007d10208650d8767b1821a345612fec9828e",
      "parents": [
        "4b740c509def9252139d60472f6e3e28b99701f7"
      ],
      "author": {
        "name": "Xiduo You",
        "email": "ulyssesyou@apache.org",
        "time": "Fri Jul 10 16:42:13 2026 +0800"
      },
      "committer": {
        "name": "Xiduo You",
        "email": "ulyssesyou@apache.org",
        "time": "Fri Jul 10 16:42:13 2026 +0800"
      },
      "message": "[KYUUBI #7551] [Spark] Optimize InferRebalanceAndSortOrders to support skip non-cheap keys and local sort\n\n### Why are the changes needed?\n\nThe `InferRebalanceAndSortOrders` optimization infers rebalance partitioning\nand sort columns from the original query (e.g. join keys) to improve the\ncompression ratio before writing. In practice this can regress performance in\ntwo cases:\n\n1. **Expensive inferred columns.** When the inferred rebalance/sort keys are\n   non-trivial expressions, evaluating them during the extra shuffle and local\n   sort adds CPU cost that can outweigh the compression benefit.\n2. **Unwanted local sort.** Some workloads only want the file-layout benefit\n   from rebalance and do not want the additional local `Sort` before writing.\n\nThis PR makes the inference tunable so users can opt out of expensive-column\ninference and skip the sort while keeping the rebalance.\n\nTwo new configs are added (default behavior is unchanged except that inference\nnow restricts to cheap columns by default):\n\n| Config | Default | Description |\n|---|---|---|\n| `spark.sql.optimizer.inferRebalanceAndSortOrdersWithCheapColumns.enabled` | `true` | Only infer rebalance/sort columns when all inferred columns are cheap expressions (attributes, foldable values, or field extractions over cheap expressions). |\n| `spark.sql.optimizer.skipInferRebalanceAndSortOrders.enabled` | `false` | Only infer the rebalance partition columns and skip inferring the sort orders. |\n\nBoth configs only take effect when\n`spark.sql.optimizer.inferRebalanceAndSortOrders.enabled` is `true`.\n\nImplementation notes:\n\n- `InferRebalanceAndSortOrders.infer` gains an `onlyInferWithCheapColumns`\n  parameter. A new `isCheap` helper classifies an expression as cheap when it is\n  an `Attribute` / `OuterReference` / `BoundReference`, foldable, or an `Alias` /\n  `ExtractValue` whose children are all cheap. When the flag is set and any\n  inferred column is not cheap, inference returns `None` and the rule falls back\n  to a plain rebalance.\n- `RebalanceBeforeWritingBase.buildRebalance` reads the two new configs and\n  skips the local `Sort` when `skipInferRebalanceAndSortOrders.enabled` is on.\n- The change is applied consistently across the Spark `4.1`, `4.0`, and `3.5`\n  extension modules, and the rule docs table is updated.\n\n### How was this patch tested?\n\n- Added `Skip inferring sort orders` — end-to-end check that enabling\n  `skipInferRebalanceAndSortOrders.enabled` drops the inferred local `Sort`\n  while keeping the `RebalancePartitions`.\n- Added `Infer rebalance and sort orders only with cheap columns` — unit-level\n  check on `InferRebalanceAndSortOrders.infer`: expensive join keys\n  (`col1 + 1`) are not inferred when the cheap-column restriction is on and are\n  inferred when it is off; cheap attribute keys are inferred regardless.\n- Tests added to the `RebalanceBeforeWritingSuite` of all three modules.\n\nRan locally (all green):\n\n```\nbuild/mvn -Pspark-4.1 -Pscala-2.13 test -pl extensions/spark/kyuubi-extension-spark-4-1 -am\n  -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.spark.sql.RebalanceBeforeWritingSuite   # 12/12\nbuild/mvn -Pspark-4.0 -Pscala-2.13 test -pl extensions/spark/kyuubi-extension-spark-4-0 -am\n  -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.spark.sql.RebalanceBeforeWritingSuite   # 12/12\nbuild/mvn -Pspark-3.5 test -pl extensions/spark/kyuubi-extension-spark-3-5 -am\n  -Dtest\u003dnone -DwildcardSuites\u003dorg.apache.spark.sql.RebalanceBeforeWritingSuite   # 14/14\n```\n\n`dev/reformat` run; no style changes required.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nYes.\n\nAssisted-by: Claude Opus 4.8\n\nCloses #7551 from ulysses-you/infer.\n\nCloses #7551\n\n0b6003bef [Xiduo You] comment\n54320bcdd [Xiduo You] Optimize InferRebalanceAndSortOrders to support skip non-cheap keys and local sort\n\nAuthored-by: Xiduo You \u003culyssesyou@apache.org\u003e\nSigned-off-by: Xiduo You \u003culyssesyou@apache.org\u003e\n"
    },
    {
      "commit": "4b740c509def9252139d60472f6e3e28b99701f7",
      "tree": "06f92ba91c86d4e6a002700362fa0bc63a0f06b4",
      "parents": [
        "32b06b78950501cf36f39c2b289b5b4a4e1c3876"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 10 15:28:57 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 15:28:57 2026 +0800"
      },
      "message": "[KYUUBI #7548] Bump docker/setup-buildx-action from 4.1.0 to 4.2.0\n\n[//]: # (dependabot-start)\n⚠️  **Dependabot is rebasing this PR** ⚠️\n\nRebasing might not happen immediately, so don\u0027t worry if this takes some time.\n\nNote: if you make any changes to this PR yourself, they will take precedence over the rebase.\n\n---\n\n[//]: # (dependabot-end)\n\nBumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.1.0 to 4.2.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/docker/setup-buildx-action/releases\"\u003edocker/setup-buildx-action\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/572\"\u003edocker/setup-buildx-action#572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/551\"\u003edocker/setup-buildx-action#551\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/557\"\u003edocker/setup-buildx-action#557\u003c/a\u003e \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/580\"\u003edocker/setup-buildx-action#580\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/573\"\u003edocker/setup-buildx-action#573\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/576\"\u003edocker/setup-buildx-action#576\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/562\"\u003edocker/setup-buildx-action#562\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/577\"\u003edocker/setup-buildx-action#577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/556\"\u003edocker/setup-buildx-action#556\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.25.0 to 6.27.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/570\"\u003edocker/setup-buildx-action#570\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/pull/569\"\u003edocker/setup-buildx-action#569\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/setup-buildx-action/compare/v4.1.0...v4.2.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v4.1.0...v4.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/bb05f3f5519dd87d3ba754cc423b652a5edd6d2c\"\u003e\u003ccode\u003ebb05f3f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/issues/580\"\u003e#580\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-to...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/321c814cb51fbe4af8eca00249525cc0973ea66f\"\u003e\u003ccode\u003e321c814\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/b9a36ef79ba42cfc611885a1e8c388fbf8b8cb3f\"\u003e\u003ccode\u003eb9a36ef\u003c/code\u003e\u003c/a\u003e build(deps): bump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.91.0 to 0.92.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/ebeab241289497cd564ac98b3cfc9e64607bb276\"\u003e\u003ccode\u003eebeab24\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/issues/570\"\u003e#570\u003c/a\u003e from docker/dependabot/npm_and_yarn/undici-6.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/5c7b8ae78cec97a3215d4d86679b1d072eaa80cb\"\u003e\u003ccode\u003e5c7b8ae\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/037e618cd98e95e81525b15ff0e9c96f507e6a0e\"\u003e\u003ccode\u003e037e618\u003c/code\u003e\u003c/a\u003e build(deps): bump undici from 6.25.0 to 6.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/66080e5802281ec2e72b7f3108915643e702db85\"\u003e\u003ccode\u003e66080e5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/issues/577\"\u003e#577\u003c/a\u003e from docker/dependabot/npm_and_yarn/sigstore-4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/409aef0aa3f48f0a742e7dec4e0e04ab19afe93c\"\u003e\u003ccode\u003e409aef0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-buildx-action/issues/562\"\u003e#562\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-4.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/49c6e42949280fa0d70fb327633591be54efbfb6\"\u003e\u003ccode\u003e49c6e42\u003c/code\u003e\u003c/a\u003e build(deps): bump sigstore from 4.1.0 to 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-buildx-action/commit/2211273e8121ecf9ecb7d6c7c0fcd55526d530c7\"\u003e\u003ccode\u003e2211273\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/docker/setup-buildx-action/compare/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5...bb05f3f5519dd87d3ba754cc423b652a5edd6d2c\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddocker/setup-buildx-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.1.0\u0026new-version\u003d4.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7548 from dependabot[bot]/dependabot/github_actions/docker/setup-buildx-action-4.2.0.\n\nCloses #7548\n\n217a88e1f [dependabot[bot]] Bump docker/setup-buildx-action from 4.1.0 to 4.2.0\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "32b06b78950501cf36f39c2b289b5b4a4e1c3876",
      "tree": "a5132da8edc58581c52a71a41394392a9ce420da",
      "parents": [
        "8a144c96dd70c78daa311947aac23fd8df6e736a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 10 15:27:51 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 15:27:51 2026 +0800"
      },
      "message": "[KYUUBI #7547] Bump docker/build-push-action from 7.2.0 to 7.3.0\n\nBumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.2.0 to 7.3.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a\"\u003e\u003ccode\u003e53b7df9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/issues/1572\"\u003e#1572\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/154298c1ca89be1c0e019084f0611ddca621aafc\"\u003e\u003ccode\u003e154298c\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/cb1238b9c9eb453d106b4e4142a5bd9cde710040\"\u003e\u003ccode\u003ecb1238b\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.91.0 to 0.92.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/24f845d5cbe75d2d350a984fd0e18cb7a3f29c1c\"\u003e\u003ccode\u003e24f845d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/issues/1566\"\u003e#1566\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-4.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/9c6973007b52c322651c38915d5e8824cea95c50\"\u003e\u003ccode\u003e9c69730\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/bc3a3a5f72a6dca16c2c2468d1dfc55ee66d2193\"\u003e\u003ccode\u003ebc3a3a5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/issues/1574\"\u003e#1574\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/a82c504a2387bb8bedc50072f9c554ae2a7dab5d\"\u003e\u003ccode\u003ea82c504\u003c/code\u003e\u003c/a\u003e chore(deps): Bump js-yaml from 4.1.1 to 4.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/0285a75190c039d6dac52b7711abcef3f5d8f6f6\"\u003e\u003ccode\u003e0285a75\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/issues/1573\"\u003e#1573\u003c/a\u003e from docker/dependabot/github_actions/actions/cache-...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/c6ad2a3f9644680619de938b97c8a10a87b2a88d\"\u003e\u003ccode\u003ec6ad2a3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/issues/1575\"\u003e#1575\u003c/a\u003e from docker/dependabot/github_actions/actions/checko...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/build-push-action/commit/d37484fb9737c5442a257e2f0ae5a8d756ed7d92\"\u003e\u003ccode\u003ed37484f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/build-push-action/issues/1564\"\u003e#1564\u003c/a\u003e from docker/dependabot/npm_and_yarn/undici-6.27.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/docker/build-push-action/compare/f9f3042f7e2789586610d6e8b85c8f03e5195baf...53b7df96c91f9c12dcc8a07bcb9ccacbed38856a\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddocker/build-push-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d7.2.0\u0026new-version\u003d7.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7547 from dependabot[bot]/dependabot/github_actions/docker/build-push-action-7.3.0.\n\nCloses #7547\n\ndd51be3a2 [dependabot[bot]] Bump docker/build-push-action from 7.2.0 to 7.3.0\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "8a144c96dd70c78daa311947aac23fd8df6e736a",
      "tree": "fdd8f7dfa19dbb4f13f88c9ca3defa0899995746",
      "parents": [
        "f6fbbd58e2a661f51d4192578b59767ff49681ca"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 10 15:26:47 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 15:26:47 2026 +0800"
      },
      "message": "[KYUUBI #7546] Bump docker/setup-qemu-action from 4.1.0 to 4.2.0\n\nBumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.1.0 to 4.2.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/docker/setup-qemu-action/releases\"\u003edocker/setup-qemu-action\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/311\"\u003edocker/setup-qemu-action#311\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/295\"\u003edocker/setup-qemu-action#295\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.91.0 to 0.92.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/315\"\u003edocker/setup-qemu-action#315\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/312\"\u003edocker/setup-qemu-action#312\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.2.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/310\"\u003edocker/setup-qemu-action#310\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.6 to 0.2.7 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/304\"\u003edocker/setup-qemu-action#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.26.0 to 6.27.0 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/308\"\u003edocker/setup-qemu-action#308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/pull/307\"\u003edocker/setup-qemu-action#307\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/setup-qemu-action/compare/v4.1.0...v4.2.0\"\u003ehttps://github.com/docker/setup-qemu-action/compare/v4.1.0...v4.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/96fe6ef7f33517b61c61be40b68a1882f3264fb8\"\u003e\u003ccode\u003e96fe6ef\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/315\"\u003e#315\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-to...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/31f08d3fc9186dbe4b4550696f2e32e9aa7f9465\"\u003e\u003ccode\u003e31f08d3\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/4e7017a474d2cf3912bb0437f7fafec6d5fb6c52\"\u003e\u003ccode\u003e4e7017a\u003c/code\u003e\u003c/a\u003e build(deps): bump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.91.0 to 0.92.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/0eca235293ca1939b58c082f69bdc981ccce8c94\"\u003e\u003ccode\u003e0eca235\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/314\"\u003e#314\u003c/a\u003e from crazy-max/fix-yarn-preapprove-actions-toolkit\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/ea66a4130b037e7961e14a0e5b155836e797cced\"\u003e\u003ccode\u003eea66a41\u003c/code\u003e\u003c/a\u003e chore: allow actions-toolkit to bypass yarn age gate\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/451542b03ae7946b7082a398b11c8c315a0e4e80\"\u003e\u003ccode\u003e451542b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/308\"\u003e#308\u003c/a\u003e from docker/dependabot/npm_and_yarn/undici-6.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/532ae0057542ec2102e2d19e9feccf85f1f69013\"\u003e\u003ccode\u003e532ae00\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/b6f5af659afad3f9931b782668dee4595ae7e841\"\u003e\u003ccode\u003eb6f5af6\u003c/code\u003e\u003c/a\u003e build(deps): bump undici from 6.26.0 to 6.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/cf96b86294b57480ac6d330bd177fca87eac95bc\"\u003e\u003ccode\u003ecf96b86\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/setup-qemu-action/issues/304\"\u003e#304\u003c/a\u003e from docker/dependabot/npm_and_yarn/tmp-0.2.7\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/setup-qemu-action/commit/f0ba643f78dc96bc931fb83e5dadc39628e10047\"\u003e\u003ccode\u003ef0ba643\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/docker/setup-qemu-action/compare/06116385d9baf250c9f4dcb4858b16962ea869c3...96fe6ef7f33517b61c61be40b68a1882f3264fb8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddocker/setup-qemu-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.1.0\u0026new-version\u003d4.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7546 from dependabot[bot]/dependabot/github_actions/docker/setup-qemu-action-4.2.0.\n\nCloses #7546\n\n321ea5a60 [dependabot[bot]] Bump docker/setup-qemu-action from 4.1.0 to 4.2.0\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "f6fbbd58e2a661f51d4192578b59767ff49681ca",
      "tree": "c29b9cd3af04fb76f10eb94c3602b6250f129763",
      "parents": [
        "5a763c3f0da71fe5812cfdd7faa4de78bc7ae9d1"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 10 15:25:32 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 15:25:32 2026 +0800"
      },
      "message": "[KYUUBI #7545] Bump docker/login-action from 4.2.0 to 4.4.0\n\nBumps [docker/login-action](https://github.com/docker/login-action) from 4.2.0 to 4.4.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/docker/login-action/releases\"\u003edocker/login-action\u0027s releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href\u003d\"https://github.com/crazy-max\"\u003e\u003ccode\u003e​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href\u003d\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href\u003d\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/af1e73f918a031802d376d3c8bbc3fe56130a9b0\"\u003e\u003ccode\u003eaf1e73f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1034\"\u003e#1034\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/da722bde43bacb027adfc67d42dbaa4c0f9e550b\"\u003e\u003ccode\u003eda722bd\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/2916ad60bd5cb72f07aa54c69fdcc61749c09b7a\"\u003e\u003ccode\u003e2916ad6\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/ca0a662f786e4cfddce972005bd68f3dafc3a903\"\u003e\u003ccode\u003eca0a662\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1035\"\u003e#1035\u003c/a\u003e from crazy-max/fix-registry-auth-empty-mask\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/c455755a579833bf0d2e4e54e3beb413ef10cc80\"\u003e\u003ccode\u003ec455755\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/48351901f89581a7c12870c787d3f06d1f498438\"\u003e\u003ccode\u003e4835190\u003c/code\u003e\u003c/a\u003e skip empty registry-auth secret mask\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/992421c6e6806a7f6df609d1bfff374f9eca3004\"\u003e\u003ccode\u003e992421c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1033\"\u003e#1033\u003c/a\u003e from docker/dependabot/github_actions/docker/bake-ac...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/b249b43765525dd7951068267a34cf63f22ab4f0\"\u003e\u003ccode\u003eb249b43\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/docker/login-action/issues/1032\"\u003e#1032\u003c/a\u003e from docker/dependabot/github_actions/docker/bake-ac...\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/1b67977736863551a88ff218642a2d7628b10520\"\u003e\u003ccode\u003e1b67977\u003c/code\u003e\u003c/a\u003e build(deps): bump docker/bake-action from 7.2.0 to 7.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/docker/login-action/commit/9d49d6a3234c78daa10c3c12183ef7b6caa8e69e\"\u003e\u003ccode\u003e9d49d6a\u003c/code\u003e\u003c/a\u003e build(deps): bump docker/bake-action/subaction/matrix\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...af1e73f918a031802d376d3c8bbc3fe56130a9b0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003ddocker/login-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.2.0\u0026new-version\u003d4.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `dependabot rebase` will rebase this PR\n- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\n\nCloses #7545 from dependabot[bot]/dependabot/github_actions/docker/login-action-4.4.0.\n\nCloses #7545\n\n8dded6e86 [dependabot[bot]] Bump docker/login-action from 4.2.0 to 4.4.0\n\nAuthored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    },
    {
      "commit": "5a763c3f0da71fe5812cfdd7faa4de78bc7ae9d1",
      "tree": "09202c6166ce65fc012e525eb080f48934376010",
      "parents": [
        "fe81544f64a495e4092933a487e96e8f8936b49a"
      ],
      "author": {
        "name": "ruanwenjun",
        "email": "wenjun@apache.org",
        "time": "Fri Jul 10 15:24:20 2026 +0800"
      },
      "committer": {
        "name": "Cheng Pan",
        "email": "chengpan@apache.org",
        "time": "Fri Jul 10 15:24:20 2026 +0800"
      },
      "message": "[KYUUBI #7527] [JDBC] Respect interrupt while waiting for engine launch\n\n### Why are the changes needed?\n\nJDBC clients can block inside `KyuubiConnection` construction while waiting for engine launch. If the caller cancels that connection attempt with `Thread.interrupt()`, the wait loop previously kept polling and the caller still had no returned `Connection` object to close.\n\nThis patch makes the launch wait path honor interruption by converting it to a typed JDBC exception, `KyuubiInterruptedException`. The interrupt status is intentionally consumed before the exception reaches the caller, and comments explain that the caller receives the typed exception while the current thread is not interrupted.\n\nThe patch also keeps `SQLException` subclasses intact when `KyuubiDataSource` creates a connection, so callers can distinguish the interrupted launch path.\n\n### How was this patch tested?\n\n- `./build/mvn -pl kyuubi-hive-jdbc -am spotless:apply`\n- `./build/mvn -pl kyuubi-hive-jdbc -am -Dtest\u003dKyuubiConnectionTest,KyuubiStatementTest,TestJdbcDriver,TestKyuubiPreparedStatement,UtilsTest,ZooKeeperHiveClientHelperTest -DwildcardSuites\u003dnone test`\n- `git diff --check`\n\nAlso attempted `dev/reformat`, but the full repo reformat is blocked in this local environment because Spotless expects `black 22.3.0` while the installed executable is `black 25.1.0`.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nAssisted-by: OpenAI Codex: GPT-5\n\nCloses #7527 from ruanwenjun/kyuubi-jdbc-interrupt-launch.\n\nCloses #7527\n\n6ff3e96ef [ruanwenjun] [JDBC] Use error SQLState for launch cancellation\n6795917ac [ruanwenjun] [JDBC] Reuse ExceptionUtils for interrupt cause checks\n5db1bad5d [ruanwenjun] [JDBC] Narrow launch interrupt cleanup handling\nb471c4653 [ruanwenjun] [JDBC] Simplify launch interrupt handling\n5f6a573b9 [ruanwenjun] [JDBC] Respect interrupt while waiting for engine launch\n\nAuthored-by: ruanwenjun \u003cwenjun@apache.org\u003e\nSigned-off-by: Cheng Pan \u003cchengpan@apache.org\u003e\n"
    }
  ],
  "next": "fe81544f64a495e4092933a487e96e8f8936b49a"
}
