#1012016 libapache-poi-java breaks octave-io autopkgtest: assert (size (d) == [1001, 2]) failed #1012016
- Package:
- libapache-poi-java
- Source:
- libapache-poi-java
- Submitter:
- Paul Gevers
- Date:
- 2026-09-21 11:43:05 UTC
- Severity:
- serious
- Tags:
Dear maintainer(s),
With a recent upload of libapache-poi-java the autopkgtest of octave-io
fails in testing when that autopkgtest is run with the binary packages
of libapache-poi-java from unstable. It passes when run with only
packages from testing. In tabular form:
pass fail
libapache-poi-java from testing 4.0.1-4
octave-io from testing 2.6.4-1
all others from testing from testing
I copied some of the output at the bottom of this report.
Currently this regression is blocking the migration of
libapache-poi-java to testing [1]. Due to the nature of this issue, I
filed this bug report against both packages. Can you please investigate
the situation and reassign the bug to the right package?
More information about this bug and the reason for filing it can be found on
https://wiki.debian.org/ContinuousIntegration/RegressionEmailInformation
Paul
[1] https://qa.debian.org/excuses.php?package=libapache-poi-java
https://ci.debian.net/data/autopkgtest/testing/amd64/o/octave-io/22169972/log.gz
Testing default interface for XLSX...
warning: xlsopen: no'.xlsx' spreadsheet I/O support with available
interfaces.
warning: xlsopen: no'.xlsx' spreadsheet I/O support with available
interfaces.
error: assert (size (d) == [1001, 2]) failed
error: called from
assert at line 107 column 11
testhelper at line 14 column 5
autopkgtest [15:22:44]: test xlsx-default
Hi, Le samedi 28 mai 2022 à 21:28 +0200, Paul Gevers a écrit : 4.0.1-4 is the upgrade to xmlbeans 4.0.0. Attached is a minimal test case that reproduces what octave-io does in its autopkgtest. Before running it, you should put the following file in your current directory: https://salsa.debian.org/pkg-octave-team/octave-io/-/blob/debian/latest/debian/tests/test.xlsx The example can be run with: java -cp /usr/share/java/poi.jar:/usr/share/java/poi-ooxml.jar:/usr/share/java/commons-compress.jar:/usr/share/java/commons-collections4.jar:/usr/share/java/xmlbeans.jar bug1012016.java This example works fine with libapache-poi-java 4.0.1-3 and libxmlbeans-java 3.0.2-1. But it crashes with libapache-poi-java 4.0.1- 4 and libxmlbeans-java 4.0.0-1 (currently in unstable). The relevant part seems to be: Caused by: java.lang.ClassNotFoundException: org.apache.xmlbeans.metadata.system.s036263A03D2D3FD117889707DB51207A.TypeSystemHolder at java.base/jdk.internal.loader.BuiltinClassLoader.loadClass(BuiltinClassLoader.java:581) at java.base/jdk.internal.loader.ClassLoaders$AppClassLoader.loadClass(ClassLoaders.java:178) at java.base/java.lang.ClassLoader.loadClass(ClassLoader.java:522) ... 31 more My Java skills are limited so I cannot make further debugging. Could some Java expert chime in? P.S.: Why was libapache-poi-java 4.0.1-4 allowed to migrate to testing? Autopkgtest regressions are supposed to be blockers for testing migration. Cheers,
Hi Sébastien, Because the octave-io test regressed in testing. https://ci.debian.net/data/autopkgtest/testing/amd64/o/octave-io/22226297/log.gz has Get:307 http://deb.debian.org/debian testing/main amd64 libxmlbeans-java all 4.0.0-1 [2,071 kB] Get:308 http://deb.debian.org/debian testing/main amd64 libapache-poi-java all 4.0.1-3 [10.5 MB] It's probably because libxmlbeans wasn't blocked from migrating. So indeed, it's not libapachage-poi-java that breaks octave-io. Paul
Le mardi 07 juin 2022 à 16:45 +0200, Sébastien Villemot a écrit : I’m reassigning this issue to libapache-poi-java. octave-io’s upstream thinks that the problem comes from an incorrect combination of versions between libapache-poi-java and xmlbeans. That seems confirmed by the minimal test case that I attached to my previous email (which used to work but no longer does, without any indication that the API used therein is deprecated).
Control: retitle -1 libapache-poi-java needs updates for newer xmlbeans So, let's give this bug a (hopefully) better title such that it's potentially a bit clearer during RC bug triaging for bookworm. Would the new upstream version solve the issue? Paul
Le mercredi 28 décembre 2022 à 22:46 +0100, Paul Gevers a écrit : My minimal test case works fine if I combine the latest Apache POI (5.2.3) with the latest XMLBeans (5.1.1). So it seems that upgrading these two packages to newer versions in Debian would fix the problem (just upgrading Apache POI to the latest version is not enough, because that version requires a newer XMLBeans than the one currently in Debian). However, I don’t know if it is realistic to expect this to happen for Bookworm, given the stage we’re at in the freeze. I am not familiar enough with this ecosystem to NMU, and the maintainers have been unresponsive so far. Alternatively, I could try to patch octave-io so that it no longer uses libapache-poi-java for reading XLSX files. That is an inferior solution, because that will remove an important functionality from the package, but I may not have the choice.
Le mardi 31 janvier 2023 à 18:09 +0100, Sébastien Villemot a écrit : I ended up implementing this “solution” in octave-io 2.4.6-3. So in effect it no longer relies on libapache-poi-java + libxmlbeans-java for reading XLSX files (fortunately octave-io has another, less efficient, backend for reading XLSX files). As a consequence, downgrading the severity of this bug.
Le mercredi 01 mars 2023 à 17:58 +0100, Sébastien Villemot a écrit : Sorry, I meant octave-io 2.6.4-3
when upgrading to debian bookworm I found a problem that is probably
related to this bugreport here and I got no idea on how to workaround.
I created this minimal testcase:
cat >problem.java <<EOF
public class problem {
public static void main(String[] args) throws Exception {
System.out.println("debugpoint 1");
new org.apache.poi.hssf.usermodel.HSSFWorkbook();
System.out.println("debugpoint 2");
new org.apache.poi.xssf.usermodel.XSSFWorkbook();
System.out.println("debugpoint 3");
}
}
EOF
export CLASSPATH="/usr/share/java/poi-ooxml.jar:/usr/share/java/commons-collections4.jar:/usr/share/java/commons-compress.jar:."
javac problem.java && java problem
now you get this output:
debugpoint 1
debugpoint 2
Exception in thread "main" java.lang.NoClassDefFoundError: org/apache/xmlbeans/metadata/system/s036263A03D2D3FD117889707DB51207A/TypeSystemHolder
at org.openxmlformats.schemas.spreadsheetml.x2006.main.CTWorkbook$Factory.getTypeLoader(Unknown Source)
at org.openxmlformats.schemas.spreadsheetml.x2006.main.CTWorkbook$Factory.newInstance(Unknown Source)
at org.apache.poi.xssf.usermodel.XSSFWorkbook.onWorkbookCreate(XSSFWorkbook.java:460)
at org.apache.poi.xssf.usermodel.XSSFWorkbook.<init>(XSSFWorkbook.java:263)
at org.apache.poi.xssf.usermodel.XSSFWorkbook.<init>(XSSFWorkbook.java:257)
at org.apache.poi.xssf.usermodel.XSSFWorkbook.<init>(XSSFWorkbook.java:245)
at problem.main(problem.java:6)
Caused by: java.lang.ClassNotFoundException: org.apache.xmlbeans.metadata.system.s036263A03D2D3FD117889707DB51207A.TypeSystemHolder
at java.base/jdk.internal.loader.BuiltinClassLoader.loadClass(BuiltinClassLoader.java:641)
at java.base/jdk.internal.loader.ClassLoaders$AppClassLoader.loadClass(ClassLoaders.java:188)
at java.base/java.lang.ClassLoader.loadClass(ClassLoader.java:525)
... 7 more
it does not reach debugpoint 3.
does anybody know how I can workaround here?
The complete XSSFWorkbook system in apachepoi is not working.
cu
Erik
Hi all, I am a Java developer and I faced the same problem after upgrading debian from bullseye to bookworm. I compared the file /usr/share/java/poi-ooxml-schemas-4.0.1.jar between bullseye, bookworm and those from the maven central repo. The version of bookworm contains a very reduced amount of files. So I tested the reproducer problem.java from Erik with the corresponding jar from bullseye and the test was OK. I assume, that there has been a problem in creating the poi-ooxml-schemas-4.0.1.jar for bookworm. Could a maintainer please fix this file? Thank you and best regards Florian Paul
Dear maintainers, the file /usr/share/java/poi-ooxml-schemas-4.0.1.jar is broken for the bookworm release. With this broken file the apache poi library is currently not usable. Is there a chance that this file is getting fixed soon? How can I help, as it is pretty important for my use? Thank you and best regards Florian Paul
as already reported, the filesize of poi-ooxml-schemas-4.0.1.jar is obviously a problem: Debian GNU/Linux 10 (buster): libapache-poi-java 4.0.1-1 root@xxx:/usr/share/java# -rw-r--r-- 1 root root 1757334 Jan 21 2019 poi-ooxml-4.0.1.jar -rw-r--r-- 1 root root 7855345 Jan 21 2019 poi-ooxml-schemas-4.0.1.jar Debian GNU/Linux 12 (bookworm): libapache-poi-java 4.0.1-4 root@yyy:/usr/share/java# -rw-r--r-- 1 root root 1757319 16. Mai 2022 poi-ooxml-4.0.1.jar -rw-r--r-- 1 root root 99850 16. Mai 2022 poi-ooxml-schemas-4.0.1.jar for a workaround, i have replaced these two files by their old versions. I also had to replace xmlbeans-4.0.0 by xmlbeans-3.0.2. Then it worked. this means it is not enough to replace poi-ooxml-schemas-4.0.1 but also poi-ooxml-4.0.1 and xmlbeans... maybe this helps anybody - at least to work around. cu Erik
We believe that the bug you reported is fixed in the latest version of
libapache-poi-java, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1012016@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Emmanuel Bourg <ebourg@apache.org> (supplier of updated libapache-poi-java package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 21 Sep 2026 11:56:32 +0200
Source: libapache-poi-java
Architecture: source
Version: 4.1.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Emmanuel Bourg <ebourg@apache.org>
Closes: 943565 1012016
Changes:
libapache-poi-java (4.1.1-1) unstable; urgency=medium
.
* New upstream release
- Fixes CVE-2019-12415 (Closes: #943565)
- Refreshed the patches
- New build dependency on libmockito-java
- New dependency on libbatik-java for the SVG image renderer
- New build dependency on libguava-java
* Adapted the build to the XMLBeans 4 metadata layout, the compiled
schemas were dropped from poi-ooxml-schemas.jar and no OOXML document
could be opened (Closes: #1012016)
* Added commons-io to the test classpath, commons-compress requires it
* Removed the libapache-poi-java-doc package
* Repaired debian/orig-tar.sh (ECMA and ETSI URLs, SVN tag naming)
* Standards-Version updated to 4.7.4
Checksums-Sha1:
1f5312b51f497ae9ce6bd9cbc8ba5c0fb83b8762 2542 libapache-poi-java_4.1.1-1.dsc
c060feab6a55b193b0f1fedf54192b603a8cda3d 79453564 libapache-poi-java_4.1.1.orig.tar.xz
8e74d306a284931bd5a058f1676b1d80c3e081dd 17648 libapache-poi-java_4.1.1-1.debian.tar.xz
ef46587114c713998b34cea4389c3bcc5e04203a 17887 libapache-poi-java_4.1.1-1_source.buildinfo
Checksums-Sha256:
2867578083525b9a046519f537a869f77a331b19de275ce4251f8597428704d2 2542 libapache-poi-java_4.1.1-1.dsc
d9799ada064a68fc8ab46e55534ff9a6b09279a4b6212bc75da57c5875b14262 79453564 libapache-poi-java_4.1.1.orig.tar.xz
a82d518cc150772f430eeb3e030d6ed76072916fde516e0c901a6f4c235f75ec 17648 libapache-poi-java_4.1.1-1.debian.tar.xz
0a9bb400d8753ae0554aa25ed005b5fdcd4ed5d5ce32cc2c37266a95d83e9962 17887 libapache-poi-java_4.1.1-1_source.buildinfo
Files:
f5234e851337a4bd1687c4ee26d58923 2542 java optional libapache-poi-java_4.1.1-1.dsc
993a31f89f806d7be4b50bf38fc60424 79453564 java optional libapache-poi-java_4.1.1.orig.tar.xz
1791eca4b0ec505e96bc22342e2cd0c0 17648 java optional libapache-poi-java_4.1.1-1.debian.tar.xz
118a820f4c47c4d9df3bd440ca3a5958 17887 java optional libapache-poi-java_4.1.1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEEuM5N4hCA3PkD4WxA9RPEGeS50KwFAmqxB4ASHGVib3VyZ0Bh
cGFjaGUub3JnAAoJEPUTxBnkudCslkQQAMaOetlIDGL2ukiKFmTUej2Z3BRasGYp
sQhrFxqg3IfBOr6WeshpXLdIjL2Ua5yj2RSRvX/9DKDWRkvjiWs4kE3rj4FyMXfw
zVDcHCppkDtBLVNOkZ1ADia8NekR7VA+yBQof3i7Wq70C/QO+3kJvpJ/md/qYBuO
3NfmGqcR/KfkwaygKokZFxe1uYAU9V6o+4rdCKoO6+tPu5qRX8jVzxQTX1q5hkFO
Bk2wSYCSc8aFhzbH2Gzq3vT1OdiHRNaMiD3/DaWyZhxRfFj/KxwD2ZOox4GNEhu/
01BcFHAna4Dp+K0TUDcMVM3BSn9RDkw8RL8q9Hp/3lz+pNsZK7gsE4BN2NQm05S0
Hmzj5LViYtjghz1QznbuH+zGqV1yQC2f9uClKPrz2QqFaMp4fQn35+uQ1JgABLT4
Y67CZF+ENFwSMBwOCbXh5RYeVCeR2l5WsoSVljgSe1lUX0JYe1sLU3SbquB1XR3m
16zY34HVqF0S7ctLwFogJTUD21DqpOH5eyWr2nuwU3fW4Fp9R3T37J6v3L5pTt4E
Nq/rD7k2mv7LcitzzYoAV3fzI2rP/pvUDiEP2Y3Oeq9YZ+/P6aKI+K5Ute39/WNw
i9XCySCUwf7gfdCt3sjtGK58ewrcnC/L/0oQH+y8/MeoOlk9LKwTGQZzRrg4WYpe
uP6Xn0ZxaKJV
=uAu9
-----END PGP SIGNATURE-----