Hello team,

I support deprecating druid-handler and targeting removal in a future major 
release.

I worked on HIVE-29707 (upgrade Druid 0.17.1 --> 26.0.0) to address CVE 
exposure from the 2020-era dependency. The handler itself can be made to 
compile, but keeping it current is costly and the blast radius is wide:
1) Large API drift across storage handler, indexing, serde, and Kafka 
supervisor classes
2) hive-it-druid (~200 MB shaded jar) is pulled into unrelated qfile drivers 
(e.g. TestMiniLlapCliDriver), causing collateral test failures
3) Ongoing shading conflicts with Hive's stack (Calcite/Jackson/Guava), 
consistent with the CALCITE-6393 issues mentioned above
Combined with minimal recent development and no clear maintainer/user base, I'd 
deprecate in docs/build now and remove in the next major. I wouldn't invest in 
a full upgrade unless someone commits to long-term ownership.

Happy to share HIVE-29707 details if useful for a formal deprecation proposal.

On 2026/07/15 11:38:13 Ruben Q L wrote:
> Hello!
> 
> In the context of a WIP Calcite upgrade [1] I ran into shading issues in
> druid-handler (an ASM failure when relocating Calcite's SqlFunctions.class,
> tracked upstream in CALCITE-6393). I worked around it by dropping the
> Calcite relocation in druid-handler/pom.xml, but it prompted me to re-open
> an earlier discussion [2] about whether we should still be carrying this
> module at all.
> 
> Nothing seems to have changed since it was last raised: we're still on
> Druid 0.17.1 [3] (released in 2020), which has a number of unpatched CVEs
> [4], and there's been essentially no meaningful development in the module
> [5].
> 
> So the same questions remain open:
> - Are there any active users of druid-handler?
> - If there are users but no maintainers, should we deprecate the module
> (docs + build) and target removal in a future major release?
> - If there are neither, shall we drop it now?
> 
> Best,
> Ruben
> 
> [1] https://issues.apache.org/jira/browse/HIVE-29641
> [2] https://lists.apache.org/thread/1swonwzts4rztz0vdjhllbzmotsdx8ro
> [3]
> https://github.com/apache/hive/blob/c4791205d84201b351a8353e9eacadbc3c972c3e/pom.xml#L137
> [4] https://mvnrepository.com/artifact/org.apache.druid/druid/0.17.1
> [5]
> https://github.com/search?q=repo%3Aapache%2Fhive+druid&type=commits&s=committer-date&o=desc
> 

Reply via email to