Skip to content

Maintenance execution plan: ordered batches and backlog review (2026-09-25) #169

Description

@jmanico

Reviewed the complete open inventory on 2026-09-25 (America/Los_Angeles): 30 issues and 1 PR, against main at bd249f5. Read all issue bodies and discussion comments, reviewed the open PR diff/checks, compared recent merged/closed work, and rechecked relevant repository settings and Central availability. This tracker records the execution order; it does not implement or release the batches.

How to work this queue

Use the numbered milestones in order, with the dependencies below controlling merge order. Work that is independent and ready may proceed while external access or a preceding decision is blocked. priority: P0/P1/P2/P3 indicates urgency, area:* ownership, and triage:* disposition. security-review marks sensitive acceptance criteria, not a vulnerability classification. Keep batches reviewable; a batch need not be one giant PR.

Order Batch and items Execution rule
00 #111, #112 Correct consumer guidance now; finish exact signed 1.4.1 Central delivery when namespace access permits. Independent vault/access checks need actual evidence.
01 #100, #130 Align ESAPI URL/context semantics and deprecation guidance together, preserving supported encoder contexts.
02 #102, #109, #97, #119, #108 Pin/guard first, add scanning and updates, preserve complete CI gates, then enforce settings that depend on them. Independent settings hardening can start now.
03 #137, #131 / PR #168, #120, #93 Derive real OSGi API floors, finish XML 1.1 adapter review, test the final TLD surface through JSP engines, then decide/modernize the browser fixture.
04 #123, #96, #104, #122, #95, #103, #124, #125, #110 Normalize and decide site scope; coordinate toolchain/release changes; measure reproducibility and quality. Re-run final byte comparison after byte-affecting changes. Historical key records can proceed independently.
05 #128 (including #114), #115, #116, #117, #127 One coherent consumer front page plus release history, metadata and contributor guidance. Match final behavior and toolchain.
06 #142, #149 Record explicit keep/change/defer/reject decisions. Future API proposals are not approved simply by being organized.

Consolidation and single owners

Security and compatibility corrections made during organization

Open PR review

PR #168 at 7bfa00f3242c8918b7d201c8e55bbd7b1b31e00e contains delegating tag/TLD/test/doc changes with no core algorithm or dependency change. No new security regression identified in its diff. All 20 GitHub checks passed at review time, and independent local parity validation passed across 33 source files. A full local Maven rerun was not performed because Maven was unavailable in this session's PATH. Independent maintainer review remains required; triage did not approve or merge it. Its delivery batch includes the existing OSGi minimum-core problem.

Completion evidence and release gate

  • All initially open issues/PRs reviewed and assigned priority, area, disposition and numbered milestone.
  • Duplicated responsibilities consolidated; obsolete version assumptions and dangerous acceptance criteria corrected.
  • PR diff/checks reviewed and limits of local verification recorded.
  • For each batch, record merged PRs, validation and remaining blockers/explicit dispositions here as work completes.
  • Before any 1.5 release, re-inventory all then-open issues and PRs and satisfy the full backlog gate in RELEASING.md. Labeling, deferring, moving milestones or completing one batch is not release approval.

This tracker is the cross-batch index and intentionally has no single batch milestone. No source code, repository security setting, release asset, tag or PR merge is changed by this organization pass.

Batch 00 progress — 2026-09-25 (America/Los_Angeles)

Implementation: #171 merged at 2026-09-26 05:00:48 UTC as 6a3c3a9bd5d8eaa82c6ee956ab78ff9e11821b6f. All 20 GitHub checks passed on the PR head. After the normal merge was blocked by the approving-review requirement, Jim explicitly directed the merge and the administrator override was used. #112 is closed; batch 00 remains operationally incomplete under #111.

Detailed validation evidence.

Batch 01 complete — 2026-09-25 (America/Los_Angeles)

Batch 02 complete — 2026-09-25 (America/Los_Angeles)

Batch 03 complete — 2026-09-25 (America/Los_Angeles)

  • Constrain OSGi imports to actual adapter API requirements and freeze bundle identities #137 / Declare OSGi import ranges from actual API use and freeze bundle names #174: reviewed and approved the contributor's OSGi change at 28b57eb7d6cfb7b01dcbf7484da9d471e3ed1d3c, then merged normally as 159041aa5a668483d456d3c9e8e4a673b697e6cb after all 26 checks passed. Symbolic names are explicit and preserved, JSP/Jakarta core imports require [1.5,2) for JSON linkage, ESAPI uses the supported 1.4.1 security floor, and API ranges remain conservative. Real Felix R6/R8 consumers accept supported wiring and reject core 1.4.0; classpath/JPMS JSON linkage and 15 package guards pass. No embedded dependencies or new library/API baseline.
  • Add XML 1.1 tags and EL functions to both taglibs #131 / Add XML 1.1 tags and EL functions to both taglibs #168: reviewed and approved at ece754c3a094f591dc23213f317735f1b237b706, then merged normally as 2b8e7b3a90895fbcacb89c3b2894c461dc71843d after all 26 checks passed. Both adapters expose the three XML 1.1 contexts in advanced descriptors and forXml11 in basic descriptors, with direct Writer delegation and context restrictions. The intended forJava omission remains explicit. Existing contract tests expand automatically; 34-file JSP/Jakarta parity passes.
  • Render every current JSP and Jakarta tag/EL binding through isolated JSP engines #120 / Test every packaged taglib binding through real JSP engines #179: merged as e6bbebe8e8ee9043e9cd1328fdda18b3e55816b2 after all 26 checks passed on 96a1c64d0878fedf6919d6cadb65e542a974986f. Normal Docker-free verify now forks isolated maintained Tomcat/Jasper 9.0.122 and 10.1.60 engines. The actual packaged TLDs generate 144 bindings across both adapters, 1,152 complete response-byte assertions, and 144 JSP translation rejections for bodies/missing attributes. Coverage includes JSON/XML 1.1, hostile markup/Unicode/controls, buffer boundaries, null/missing values and EL coercion. Engine dependencies stay outside library test/runtime classpaths. Local clean verify passed 2,178 unit plus eight existing integration tests, API/signatures and the new engines; CI retains the Java 8/11/17/21/25 matrix and browser checks.
  • Decide and modernize the optional browser integration fixture without losing coverage #93 / Retain and modernize required browser and packaged WAR coverage #180: merged as 111d03390b96bba9fce33474cef413f8b07b6288 after all 26 checks passed on d215dc02f275d8cd9914fbaf6dd50cb8197e9446. Explicit decision: retain the required actual-browser suite because facade byte comparisons cannot replace its DOM, HTML parser and JavaScript grammar assertions. The optional fixture now uses supported Boot 4.1.1, coherent Tomcat 11.0.26 APIs, Testcontainers 2.0.5 and aligned Selenium 4.49.0; library support baselines remain unchanged. Browser/helper images are pinned by verified registry index digest, discarded recording is disabled, and browser/container/server cleanup is explicit. The executable WAR itself is launched and its packaged JSP/JSTL views and exact encoded cells are verified. Removed unused JSON/service/test scaffolding and duplicate API JARs while retaining required JSTL. The 34 packaged third-party coordinates returned no OSV advisories at review time; this does not cover OS images, build plugins or test-only dependencies.
  • Requested reviews: Sol reviewed all batch 02/03 changes in three scopes and independently read back the live repository controls. Its browser review identified unused JSP sessions rewriting a test URL; setting session=false fixed the startup assertion and the packaged test passed. Sol found no remaining actionable issues. Astra's final complete-diff review at 413177ce found no actionable correctness/security findings and independently passed 10 policy/parser tests, 15 artifact guards, parity, and exact WAR/JAR comparison. CI then exposed Testcontainers image-name compatibility handling; an explicit declaration retained the exact digest, and Astra reviewed the correction through d215dc02 with no findings. AI review is not recorded as independent maintainer approval. Jim explicitly directed review and merge; Test every packaged taglib binding through real JSP engines #179 and Retain and modernize required browser and packaged WAR coverage #180 used the documented PR-only review bypass, while required CI/security checks have no bypass and passed.
  • Final verification and cleanup: All 26 final PR checks passed, including five JavaScript browser tests, the server-rendered DOM test, executable-WAR test, exact reactor JAR inclusion, all required compatibility legs and CodeQL. All final-main workflows also passed: Java CI, packaged consumers, CodeQL, and dependency submission. All four batch issues are closed. Returned to clean synchronized main; removed the merged task/review branches and retained contributor fork branches, active Pages and unrelated work. The open automated dependency PRs remain for deliberate review in their owning batches. Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 and the full 1.5 release gate remain unchanged. Continue with batch 04 as directed.

Batch 04 — implementation merged; historical-key evidence gap remains

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: P1High priority: security contracts, CI protection or consumer compatibility.type: trackingCross-batch execution order and completion evidence.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions