Skip to content

fix(docker): add jdk.net to the java-base runtime so the OpenSearch client can connect (#37722) - #37723

Merged
fabrizzio-dotCMS merged 1 commit into
mainfrom
fix-java-base-jdk-net
Sep 23, 2026
Merged

fabrizzio-dotCMS merged 1 commit into
mainfrom
fix-java-base-jdk-net

Conversation

@fabrizzio-dotCMS

Copy link
Copy Markdown
Member

Closes #37722. cc @wezell

httpcore5 5.4.3, from #37626, uses jdk.net.Sockets on every new connection. The jlinked runtime in dotcms/java-base did not include jdk.net, so in the Docker image the OpenSearch client's I/O thread dies with NoClassDefFoundError: jdk/net/Sockets and every OpenSearch request hangs, or fails with a 500 when TLS is off. Builds, unit tests and IntelliJ run on a full JDK, which is why nothing else caught it.

This adds jdk.net to the jlink --add-modules list. The module only makes the extended socket option classes available; dotCMS sets none of those options, so nothing changes beyond the client no longer crashing.

After merge, dotcms/java-base has to be republished (cicd_manual_build-java-base.yml) for product images to pick this up.

Verified locally (arm64)

Base rebuilt from this Dockerfile (35 modules, Java 25.0.4.1), product image built on it with httpcore5-5.4.3, against Elasticsearch 7.10.2 + OpenSearch 3.4.0:

  • readiness at phase 3 over TLS: 200 in ~1 s (previously hung)
  • search at phase 3: results returned, served by OpenSearch
  • full reindex at phase 3 (TLS) and phase 1 (plain HTTP): 0 errors
  • no jdk/net/Sockets / ReflectionUtils error in the log

Not verified: the CI publish of the base image, or amd64. One local product build failed once on verify-libvips.sh and passed all 59 checks on the retry; the failing run was quiet, so the cause is unknown.

🤖 Generated with Claude Code

…lient can connect (#37722)

httpcore5 5.4.3 (from #37626) uses jdk.net.Sockets on every new connection,
and the jlinked runtime in dotcms/java-base did not include jdk.net. The
OpenSearch client's I/O thread died with NoClassDefFoundError and every
request hung (or failed with a 500 when TLS was off).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@claude

claude Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @fabrizzio-dotCMS's task in 34s —— View job


Code Review

Task list

  • Read the diff (docker/java-base/Dockerfile)
  • Verify the jdk.net diagnosis (httpcore5 5.4.3 in bom)
  • Check for issues

The change adds jdk.net to the jlink --add-modules list and documents why. The diagnosis holds up against the repo:

  • bom/application/pom.xml:923-924 pins httpcore5 at 5.4.3, matching the PR's claim that chore(deps): bump six libraries with published security fixes #37626 introduced the version that references jdk.net.Sockets.
  • jdk.net is a real, standalone JDK module, so it's a valid --add-modules entry. The jlinked closure only gains the extended socket-option classes; since dotCMS sets none of those options, runtime behavior is unchanged apart from the crash going away.
  • The comment (lines 40-42) explains the "why" clearly, which is exactly what a future reader of this module list needs.

New Issues

No issues found.

Two non-blocking observations (not defects in the diff):

  • Image size: jdk.net is small; the impact on the jlinked runtime is negligible, so no concern there.
  • Rollout dependency: as the PR body notes, this only takes effect once dotcms/java-base is republished via cicd_manual_build-java-base.yml and product images rebuild on top of it — worth confirming that step happens after merge, since the code change alone won't fix running images.

The fix is correct and minimal.

· fix-java-base-jdk-net

@yolabingo yolabingo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bueno

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

OpenSearch requests hang in the Docker image: httpcore5 5.4.3 needs jdk.net, which the java-base runtime omits

2 participants