Skip to content

Fix #800: Upgrade ion-java to 1.12.1 (from 1.11.11) - #802

Merged
cowtowncoder merged 1 commit into
2.xfrom
tatu-claude/2.x/800-ion-java-1.12.1
Sep 19, 2026
Merged

cowtowncoder merged 1 commit into
2.xfrom
tatu-claude/2.x/800-ion-java-1.12.1

Conversation

@cowtowncoder

Copy link
Copy Markdown
Member

Fixes #800 on the 2.x line. Parallel to #801, which does the same on 3.1.

Bumps ion/pom.xml from ion-java 1.11.11 to 1.12.1, with the release note under 2.23.0 in release-notes/VERSION-2.x.

Why

1.11.11 is the one release carrying a binary-write corruption bug, fixed in 1.12.0 by amazon-ion/ion-java#1150: stale PatchPoints in IonRawBinaryWriter get applied on a subsequent finish(), producing invalid Ion binary. It triggers on binary writers with container length preallocation (1 byte by default) when the writer is flushed or finished and then written to again.

Jackson's own generator paths do not appear to trigger it — IonGenerator.flush() flushes the destination rather than the IonWriter, and nothing calls finish() — so the exposure is to callers passing their own IonWriter to IonFactory.createGenerator(IonWriter). Still not a version to stay pinned to.

Also picked up: incremental reader buffer growth instead of allocating the full declared length up front, text read optimizations, and GZIP auto-decompression changes (new IonReaderBuilder.withGzipDecompressionEnabled opt-out, plus removal of a second auto-decompression layer).

Compatibility

1.12.1 is Java 8 bytecode (major version: 52, OSGi Require-Capability: JavaSE 1.8), so it meets the 2.x baseline.

./mvnw clean verify in the ion module: 267 tests, 0 failures.

Note on branch choice

Targeting 2.x (2.23.0) means the 2.21 and 2.22 patch lines keep shipping 1.11.11; moving it to 2.21 instead would carry it into those releases and forward from there. Also note both this and #801 change the same line of ion/pom.xml to the same value, so the eventual 2.x -> 3.1 merge-forward resolves cleanly; release notes live in different files on the two lines.

🤖 Generated with Claude Code

1.11.11 carries a binary-write corruption bug (amazon-ion/ion-java#1150):
stale `PatchPoint`s in `IonRawBinaryWriter` produce invalid Ion binary when
a writer is flushed or finished and then written to again. Fixed in 1.12.0.

1.12.1 is Java 8 bytecode, so no baseline change for the 2.x line.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@cowtowncoder cowtowncoder changed the title Fix #800: Upgrade ion-java to 1.12.1 (from 1.11.11) [2.x] Fix #800: Upgrade ion-java to 1.12.1 (from 1.11.11) Sep 19, 2026
@cowtowncoder
cowtowncoder merged commit fd71f3b into 2.x Sep 19, 2026
3 checks passed
@cowtowncoder
cowtowncoder deleted the tatu-claude/2.x/800-ion-java-1.12.1 branch September 19, 2026 16:39
@cowtowncoder cowtowncoder added this to the 2.23.0 milestone Sep 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant