Sitelet https://github.com/cloudfoundry/java-buildpack/pull/1462
Skip to content

Support JEP 322 JRE version strings - #1462

Draft
stokpop wants to merge 3 commits into
cloudfoundry:mainfrom
stokpop:jep322-jre-versions
Draft

stokpop wants to merge 3 commits into
cloudfoundry:mainfrom
stokpop:jep322-jre-versions

Conversation

@stokpop

@stokpop stokpop commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Java-buildpack part of #1461: support JEP 322 version strings for JRE monthly security patch releases, e.g. Liberica 21.0.12.1+1. Follow-up to #1460.

Depends on cloudfoundry/libbuildpack#214. This draft temporarily uses a replace to stokpop/libbuildpack@80c7e71. Once #214 is merged, I'll swap it for a regular libbuildpack bump and mark this ready for review.

Problem

With the current libbuildpack, a single X.Y.Z.N+B entry for a JRE in manifest.yml breaks resolution of every version of that JRE, including BP_JAVA_VERSION, JBP_CONFIG_*_JRE, the manifest default and installation (warnNewerPatch). Also, normalizeVersionPattern did not accept exact X.Y.Z.N+B pins: 21.0.12.1+1 was turned into the pattern 21.0.12.1*1.

Changes

  • src/java/jres/jre.go: replace the three exact-version regexes with one JEP 322 regex, ^\d+\.\d+\.\d+(\.\d+)*(\+\d+)?$. It accepts 17.0.13, 17.0.19+11, 21.0.12.1, 21.0.12.1+1 and 21.0.10.0.1 as exact pins. 21, 21.+ and 21.* keep resolving to the newest version.
  • go.mod / vendor: libbuildpack with JEP 322 version handling (temporary replace, see above).
  • docs/design.md: example of an exact JEP 322 pin.
  • The manifest is unchanged. Emitting the 4-part Liberica/Zulu versions is up to the buildpacks-ci watchers.

Resolution with libbuildpack#214

Request Manifest 25.0.4+9, 25.0.4.1+1, 25.0.4.1+2
25, 25.+, 25.* 25.0.4.1+2
25.0.4+9 25.0.4+9
25.0.4.1 25.0.4.1+2
25.0.4.1+1 25.0.4.1+1
25.0.4.1+3 error

Compatibility with the SapMachine 4-part versions (#1460)

  • The existing SapMachine exact 4-part pin tests pass unchanged.
  • I resolved the current manifest.yml for cflinuxfs4 and cflinuxfs5: all default versions resolve, and SapMachine 17.x, 21.x and 25.x resolve to 17.0.20.1, 21.0.12.1 and 25.0.4.1.

Tests

  • jre_test.go: added Liberica-style 25.0.4.1+N openjdk entries and a Zulu 17.0.13.1 entry, plus table tests for major/wildcard/exact/unknown-build requests and the manifest default. The existing Zulu 17.+ expectation is now 17.0.13.1.
  • Against the current libbuildpack, most GetJREVersion openjdk tests fail once the X.Y.Z.N+B fixture is present. With this PR, go vet ./... and go test ./... in src/java pass.

Accept exact X.Y.Z.N+B (and longer) JRE version pins, e.g. Liberica
monthly security patch releases such as 21.0.12.1+1, in BP_JAVA_VERSION
and JBP_CONFIG_*_JRE. Major versions and 21.+ / 21.* keep resolving to
the newest version, now including patch releases.

Use libbuildpack with JEP 322 version handling (cloudfoundry/libbuildpack#214)
so that a single X.Y.Z.N+B manifest entry no longer breaks version
resolution and installation of every version of that JRE.

Fixes cloudfoundry#1461

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Version sorting is not a valid strict ordering, and the temporary contributor-fork dependency must be replaced before merge.

1 open finding
What changed in this PR

Adds JEP 322 version support for resolving and installing monthly JRE patch releases.

Changes:

  • Supports exact multi-field JRE versions and numeric build metadata.
  • Updates libbuildpack resolution, ordering, and lifecycle warnings.
  • Adds resolution tests and documentation.
File Description
go.mod Temporarily redirects libbuildpack to the feature fork.
go.sum Adds checksums for the fork.
vendor/​modules.txt Records the vendored replacement.
vendor/​github.com/​cloudfoundry/​libbuildpack/​versions.go Implements JEP 322 parsing, matching, and ordering.
vendor/​github.com/​cloudfoundry/​libbuildpack/​installer.go Normalizes versions for patch and EOL warnings.
src/​java/​jres/​jre.go Accepts exact JEP 322 version pins.
src/​java/​jres/​jre_test.go Tests monthly-patch resolution scenarios.
docs/​design.md Documents exact JEP 322 selection.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread go.mod Outdated
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp => go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.32.0
)

replace github.com/cloudfoundry/libbuildpack => github.com/stokpop/libbuildpack v0.0.0-20261009130450-f1ccc70bd5b3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants