Skip to content

TOMEE-4707 drop the standalone HTTP server from openejb-http - #2945

Merged
jungm merged 33 commits into
mainfrom
TOMEE-4707
Sep 30, 2026
Merged

jungm merged 33 commits into
mainfrom
TOMEE-4707

Conversation

@rzo1

@rzo1 rzo1 commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

TomEE serves HTTP through Tomcat, so the hand written HTTP server in openejb-http is unused attack surface. This removes the module:

  • The servlet bridge REST, web services and CXF build on (HttpListener, HttpRequest/HttpResponse, the servlet adapters) moves to openejb-server. ServerServlet, EEFilter and the CDI request listeners move to tomee-catalina; a web.xml exposing ejbd over HTTP now uses org.apache.tomee.catalina.remote.ServerServlet.
  • httpejbd, the Jetty backend, OpenEJBHttpRegistry, RsRegistryImpl and OpenEJBHttpWsRegistry are gone. Without Tomcat's registries RESTService/WsService don't deploy endpoints (logged at INFO); @WebServiceRef clients keep working.
  • openejb-standalone, arquillian-openejb-embedded and the ApplicationComposer have no HTTP server: @EnableServices(jaxrs/jaxws) and the ApplicationComposer's @JaxrsProviders handling are removed, and @RandomPort("http") is an ordinary name (it just sets http.port). Tests and examples that need HTTP run on TomEE embedded.
  • Settings only the embedded transport read are gone: the cxf-rs auth/realm service properties and cxf.jaxrs.static-resources-list. openejb.rest.wildcard defaults to *.
  • The root pom no longer manages Jetty versions.

Breaking, meant for the next major.

TomEE serves requests through Tomcat's connectors, so the hand written HTTP
server in openejb-http is unused attack surface. Removes it, the unreachable
Jetty backend, the httpejbd service and OpenEJBHttpRegistry.

isTextXml and reformat move to HttpUtil. RsRegistryImpl and
OpenEJBHttpWsRegistry extended OpenEJBHttpRegistry and were the non-Tomcat
fallbacks in RESTService and WsService; both go, so openejb-standalone and
arquillian-openejb-embedded lose embedded REST/WS wiring.

Everything Tomcat needs stays: listeners, the registry, request, response and
session, the servlet and filter adapters, ServerServlet and the CDI listeners.
The tests that drove the removed transport over a socket go with it.
@rzo1
rzo1 requested a review from jungm September 20, 2026 19:23

@jungm jungm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The socket server is gone, but several things still depend on httpejbd. CI builds with -DskipTests, so none of this shows up there. Fixes follow on this branch.

Broken, tests fail on this branch

  • RESTService.java:1072: without the RsRegistryImpl fallback, rsRegistry is null outside Tomcat and deployApplication (L543) NPEs. SimplePojoTest and CDIApplicationTest (openejb-cxf-rs) fail.
  • FilteredServiceManager.java:45: @EnableServices jaxrs/jaxws/http still map to httpejbd. ~57 tests in openejb-cxf-rs, 11 in openejb-cxf and ~25 examples call http://localhost:<httpejbd.port> and get ConnectException.
  • arquillian-openejb-embedded ServiceManagers.java:37: protocolMetaData looks up httpejbd, so it is always null and @ArquillianResource URL injection fails. ArquillianResourceURLTest and SessionDestroyTest fail.

Broken, from reading the code

  • OpenEJBDeployableContainer.java:275: metaData is always null now, but metaData.getContexts() runs before the null check at L291. NPE for WARs with servlets in web.xml.
  • Nothing constructs HttpListenerRegistry any more, so the HttpServletRequest/HttpSession thread-local proxies (incl. openejb.http.mock-request) and EmbeddedServletContext are no longer registered. @Inject HttpServletRequest is null in embedded mode; affects tck/cdi-embedded.
  • WsService.java:176: wsRegistry is null outside Tomcat, so @WebService endpoints are silently not published.
  • EJB-over-HTTP (/ejb on 4204 via ServerServiceAdapter) is also gone from openejb-standalone. Not in the description; assembly/openejb-standalone/src/main/conf/README.txt, start.examples CLI help and several docs/*.adoc still document httpejbd.

Leftovers

  • openejb-standalone/pom.xml still bundles openejb-http, openejb-cxf and openejb-cxf-rs.
  • Now unreachable: HttpRequestImpl.readMessage, HttpResponseImpl, HttpSessionImpl, SessionManager, OpenEJBAsyncContext, FilterListener, HttpListenerRegistry (incl. static resource serving), HttpUtil.add/removeServlet/Filter.
  • HttpUtil.isTextXml/reformat were moved instead of deleted; their only callers are unreachable. reformat also uses TransformerFactory without secure processing.
  • ApplicationComposers: @RandomPort("http") → httpejbd.port and httpDebug → httpejbd.print/indent.xml are no-ops.
  • Stale refs: ServletContextListenerRegistrationTest (@EnableServices({"httpejbd"})), AppScopeInitEventTest (@EnableServices("http")), FilteredServiceManagerTest, ServiceManager, TomEEServiceManager, tck/cdi-embedded.
  • openejb-http/pom.xml: openejb-itests-client/idb test deps, reserve-activemq-port + ActiveMQ surefire props, and test resources (META-INF/resources/foo.txt, other/foo.txt, conf/instantdb.properties) were only used by the deleted tests.
  • Unused HttpListenerRegistry import in RESTService and WsService.

RESTService and WsService log a warning and skip deployment when no registry
is available instead of failing with an NPE per application. The embedded
Arquillian adapter no longer advertises an HTTP URL, openejb-standalone stops
shipping the HTTP, CXF and CXF-RS modules, and the httpejbd aliases, debug
flags, docs and test leftovers go. cdi-embedded excludes the CDI TCK tests that
need an HTTP server; cdi-tomee runs them.
Moves the shared JAX-RS test beans to arquillian-tomee-jaxrs-tests, where the
tests using them run against Tomcat.
ApplicationComposer docs point to TomEE embedded and the Arquillian TomEE
adapters for testing JAX-RS and JAX-WS endpoints over HTTP.
rest-applicationcomposer, rest-applicationcomposer-mockito and
applicationcomposer-jaxws-cdi relied on ApplicationComposer serving HTTP.
…E embedded

Moves the Application/web.xml deployment, routing, provider and response tests
from openejb-cxf-rs to arquillian-tomee-jaxrs-tests, where they deploy a war on
Tomcat instead of the removed embedded HTTP server.
…edded

Moves the ApplicationComposer/EJBContainer based cxf-rs tests to arquillian-tomee-jaxrs-tests.
SecurityContextIsUsableTest logs in with BASIC auth against a webapp realm.
The provider, exception mapper, Johnzon/JSON-B and bean validation tests of
openejb-cxf-rs run in arquillian-tomee-jaxrs-tests; their altdd descriptors are
WEB-INF descriptors of each test archive.
The tests deploy each example with Arquillian to TomEE embedded and call the endpoints Tomcat serves;
the READMEs show the Arquillian tests and their output.
removePort returned early for every registered port and cleared the wrong map
for the service QName, so @WebServiceRef lookups by SEI kept seeing ports of
undeployed applications.
The REST example tests deploy to TomEE embedded with Arquillian and call the
endpoints over Tomcat; multiple-arquillian-adapters drops its embedded-remote variant.
Without httpejbd nothing registers HttpListenerRegistry or SessionManager, so the
request/response/session implementations, embedded servlet/filter/JSP registration
and multipart support behind them are dead. LightweightWebAppBuilder keeps listeners,
CDI and ServletContext events; HttpUtil keeps selectSingleAddress.
…embedded

Observers and the log capture register from a webapp listener before the JAX-RS deployment.
arquillian.xml enables the CXF JMX monitoring CxfUtilTest checks.
openejb-cxf keeps GlobalFeatureConfigTest, the other tests need a deployed endpoint.
DynamicPortTest only covered httpejbd.port=0.
@jungm

jungm commented Sep 22, 2026

Copy link
Copy Markdown
Member

Pushed follow-ups for the review above:

  • The HTTP-dependent tests keep their coverage: they moved to arquillian-tomee-jaxrs-tests / arquillian-tomee-jaxws-tests and run on tomee-embedded (73 JAX-RS, 13 JAX-WS test classes). 20 examples run on Arquillian tomee-embedded; rest-applicationcomposer, rest-applicationcomposer-mockito and applicationcomposer-jaxws-cdi are removed.
  • The rest of the unreachable transport is gone (HttpListenerRegistry, HttpRequestImpl/HttpResponseImpl, SessionManager, HttpUtil servlet/filter registration and reformat, ...).
  • RESTService/WsService log a warning instead of an NPE when no registry exists. Stale httpejbd references, docs and the openejb-standalone deps are cleaned up; cdi-embedded excludes the CDI TCK tests that need HTTP.

The ported tests surfaced pre-existing bugs:

  • Fixed in f8934e2: PortAddressRegistryImpl.removePort never removed a port (inverted null check).
  • @Ignored: EJB endpoints configured through <ejb-deployment> cxf.jaxrs.* properties answer 404 (CheckedExceptionMapperTest, CxfRsHttpListener#isCXFResource).
  • @Ignored: a POJO web service servlet without a mapping never gets its default address mapped in Tomcat (WsJMXTest, TomcatWsRegistry#setWsContainer).

Side note: CI doesn't run the CDI TCK (-Ptck-cdi isn't in master-build-full-tck), and it's currently broken (missing xalan:serializer, CDI TCK API mismatch).

rzo1 and others added 11 commits September 25, 2026 14:50
…ded only, enable CXF monitoring on remote adapters
# Conflicts:
#	examples/jsonb-configuration/pom.xml
#	examples/jsonb-custom-serializer/pom.xml
#	examples/mp-jsonb-configuration/pom.xml
#	examples/multiple-arquillian-adapters/pom.xml
#	examples/rest-applicationcomposer-mockito/pom.xml
#	examples/rest-applicationcomposer/pom.xml
#	examples/rest-cdi/pom.xml
#	examples/rest-on-ejb/pom.xml
#	examples/rest-xml-json/pom.xml
#	examples/simple-rest/pom.xml
The servlet bridge the REST, web service and CXF modules build on (HttpListener,
HttpRequest, HttpResponse, the servlet adapters, HttpUtil) moves to openejb-server.
ServerServlet, EEFilter and the CDI request listeners only run in Tomcat and move to
tomee-catalina; a web.xml exposing ejbd over HTTP now uses
org.apache.tomee.catalina.remote.ServerServlet.

HttpSession, ServletSessionAdapter and BasicAuthHttpListenerWrapper only served the
standalone server and go.
…he services start

Without a registry RESTService and WsService return from start() before they register
themselves or observe deployments, so the deployment paths no longer need null checks.
WsService registers the PortAddressRegistry first, @WebServiceRef clients need it
even when no endpoint can be published.
…mposer

The ApplicationComposer has no HTTP server. @EnableServices loses jaxrs/jaxws,
FilteredServiceManager its jaxrs/jaxws aliases and ApplicationComposers its
@JaxrsProviders handling; @RandomPort("http") fails instead of injecting a port nothing
listens on. The applicationcomposer-maven-plugin ships openejb-ejbd instead of
openejb-cxf-rs.
SWClassLoader.getWebResource served the removed embedded web resources, the itests
"http" mode targeted httpejbd, and the cdi-embedded TCK no longer needs CXF.
The Jetty dependency management was for the Jetty backend of openejb-http. Nothing
uses Jetty directly anymore, so tomee-security and the MicroProfile Rest Client TCK
drop their workarounds against it and HtmlUnit resolves a consistent Jetty 9.4.
@jungm

jungm commented Sep 26, 2026

Copy link
Copy Markdown
Member

Finished the removal, openejb-http is gone now:

  • Merged main (conflicts in the example poms from TOMEE-3234).
  • openejb-http deleted: the servlet bridge moved to openejb-server, the Tomcat-only classes to tomee-catalina; HttpSession, ServletSessionAdapter and BasicAuthHttpListenerWrapper were dead and are removed.
  • WsService registers PortAddressRegistry before checking for a WsRegistry, so @WebServiceRef clients work outside TomEE again. Both services check their registry once in start(), the other null checks are gone.
  • ApplicationComposer: @EnableServices(jaxrs/jaxws), the jaxrs/jaxws service aliases and @JaxrsProviders handling removed, @RandomPort("http") fails fast. applicationcomposer-maven-plugin ships openejb-ejbd instead of openejb-cxf-rs.
  • Leftovers removed: SWClassLoader.getWebResource, the itests http mode, CXF deps of the cdi-embedded TCK, stale docs; the JAX-RS tests use ArquillianUtil for the embedded check.
  • Jetty dependency management dropped, it only existed for the openejb-http Jetty backend.

Verified: clean install -DskipTests -Pstyle,rat; tests of openejb-core (4118), openejb-junit5, the server modules, tomee-catalina/jaxrs/webservices/embedded, the OpenEJB Arquillian adapter; Arquillian on TomEE embedded: JAX-RS 169, JAX-WS 32, web profile 159, all green. tomee-remote suites not run.

Not covered: the cdi-embedded TCK doesn't start on this branch with or without these changes (HtmlUnit's xalan misses its serializer, then a cdi-tck api/impl mismatch). The standalone assembly's NOTICE still lists libraries it no longer bundles (CXF and older ones), separate cleanup.

@jungm

jungm commented Sep 26, 2026

Copy link
Copy Markdown
Member

- Proxys, AppFinder.AppOrWebContextTransformer, LogCategory.HTTPSERVER,
  LightweightWebAppBuilder.LightServletContext and EmbeddedServletContextCreated
- the HttpRequest/HttpResponse members of the removed HTTP parser
- CxfRsHttpListener's static resource handling (CXFJAXRSFilter calls doInvoke)
- the cxf-rs auth/realm settings, TomcatRsRegistry ignores them
- @JaxrsProviders.applicationName and its METHOD target
- the regex REST wildcard: openejb.rest.wildcard defaults to "*"

A missing REST or web service registry is logged at INFO, the webprofile ships
openejb-cxf without a WsRegistry.
WsJMXTest runs again and ServerDestroyedTest checks the ServerDestroyed event.
SuspendedTest and CdiHandlersTest wait with a bound instead of racing the server,
RsInterceptorInjectionTest checks isUserInRole again, and httpejbd/EJBContainer
leftovers are gone.
…edded TCK

TckTlds and tomee-catalina only served the JSP support of the removed HTTP
server. The builtin servlet decorator tests need servlet objects the embedded
container no longer registers, and javaee-full tests are already skipped by group.
The openejb-standalone NOTICE/LICENSE no longer list CXF, XmlSchema and
libre-wsdl4j, its itest profile no longer runs the http mode, and dependabot no
longer ignores Jetty, which no pom declares.
@jungm

jungm commented Sep 27, 2026

Copy link
Copy Markdown
Member

Review pass pushed as 7 commits (b962f93..d8ed75b):

  • @RandomPort("http") is an ordinary name; the message of e5b087a still says it fails.
  • Code only the embedded transport used is gone: Proxys, AppFinder.AppOrWebContextTransformer, LogCategory.HTTPSERVER, LightServletContext/EmbeddedServletContextCreated, the parser-only HttpRequest/HttpResponse members, CxfRsHttpListener's static resource handling, the cxf-rs auth/realm settings, @JaxrsProviders.applicationName and the regex REST wildcard. A missing Rs/WsRegistry logs at INFO, the webprofile warned on every boot.
  • Tests: WsJMXTest runs again, new ServerDestroyedTest, SuspendedTest/CdiHandlersTest wait with a bound instead of racing the server, RsInterceptorInjectionTest checks isUserInRole again, httpejbd/EJBContainer leftovers removed.
  • cdi-embedded TCK: TckTlds and tomee-catalina removed, the builtin servlet decorator tests excluded, excludes already covered by javaee-full dropped.
  • Docs, examples (unused ziplock), openejb-standalone NOTICE/LICENSE (CXF, XmlSchema, libre-wsdl4j) and the dependabot Jetty rule.

Found with 9 rounds of multi-agent review (runtime, tests, examples/docs and build lanes, every finding challenged by a skeptic) until no finding survived.

Verified against branch-built jars: arquillian JAX-RS tests 169 run / 10 skipped, JAX-WS 33 run / 2 skipped, migrated examples pass. cdi-embedded is only compile-checked, its harness is broken on main too.

Out of scope: CheckedExceptionMapperTest stays @Ignored, deployment by endpoint 404s on TomEE on main as well.

Ready for review.

@jungm

jungm commented Sep 27, 2026

Copy link
Copy Markdown
Member

@rzo1
rzo1 requested a lite review from Copilot September 28, 2026 18:41

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

@jungm
jungm merged commit 5c6b5a3 into main Sep 30, 2026
3 checks passed
@jungm
jungm deleted the TOMEE-4707 branch September 30, 2026 09:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants