DO NOT REPLY [Bug 48587] Basic Authentication failed with multibyte username

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=48587

--- Comment #5 from Julian Reschke  2011-07-13 08:57:48 
UTC ---
FYI

http://greenbytes.de/tech/webdav/draft-reschke-basicauth-enc-latest.html

and

https://bugzilla.mozilla.org/show_bug.cgi?id=41489

and

https://bugzilla.mozilla.org/show_bug.cgi?id=656213

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



tomcat-native and OS/X

2011-07-13 Thread Henri Gomez
Hi guys,

I just seen my tomcat-native 1.1.20 is not working anymore on OS/X (10.6.8).

INFO: The APR based Apache Tomcat Native library which allows optimal
performance in production environments was not found on the
java.library.path:
.:/Library/Java/Extensions:/System/Library/Java/Extensions:/usr/lib/java
Jul 13, 2011 11:02:30 AM org.apache.coyote.http11.Http11Protocol init

I usually build and install like this :

./configure --with-apr=/usr/bin/apr-1-config
--with-java-home=/System/Library/Frameworks/JavaVM.framework/Versions/1.6.0/Home/
make clean
make

sudo cp .libs/libtcnative-1.0.1.20.dylib /usr/lib/java
sudo ln -s /usr/lib/java/libtcnative-1.0.1.20.dylib
/usr/lib/java/libtcnative-1.dylib

I tried to rebuild and install under latest OS/X 10.6.8 but Tomcat 6
still didn't detect it.

Any advice is more than welcome.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



[Tomcat Wiki] Update of "AddOns" by KonstantinKolinko

2011-07-13 Thread Apache Wiki
Dear Wiki user,

You have subscribed to a wiki page or wiki category on "Tomcat Wiki" for change 
notification.

The "AddOns" page has been changed by KonstantinKolinko:
http://wiki.apache.org/tomcat/AddOns?action=diff&rev1=1&rev2=2

Comment:
Add UrlRewriteFilter link

  = Realms =
   * [[OrientDBRealm]] - Realms for Tomcat 6 and 7 that connect to an OrientDB
  
+ = UrlRewrite =
+  * [[http://www.tuckey.org/urlrewrite/|UrlRewriteFilter]] by Paul Tuckey, 
also on [[http://code.google.com/p/urlrewritefilter/|googlecode]] - Filter that 
performs URL rewriting and redirections, like mod_rewrite in Apache HTTPD, and 
other typical tasks, like setting request attributes, headers or cookies.
+ 

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



Re: tomcat-native and OS/X

2011-07-13 Thread Konstantin Kolinko
2011/7/13 Henri Gomez :
> Hi guys,
>
> I just seen my tomcat-native 1.1.20 is not working anymore on OS/X (10.6.8).
>
> INFO: The APR based Apache Tomcat Native library which allows optimal
> performance in production environments was not found on the
> java.library.path:
> .:/Library/Java/Extensions:/System/Library/Java/Extensions:/usr/lib/java
> Jul 13, 2011 11:02:30 AM org.apache.coyote.http11.Http11Protocol init
>
> I usually build and install like this :
>
> ./configure --with-apr=/usr/bin/apr-1-config
> --with-java-home=/System/Library/Frameworks/JavaVM.framework/Versions/1.6.0/Home/
> make clean
> make
>
> sudo cp .libs/libtcnative-1.0.1.20.dylib /usr/lib/java
> sudo ln -s /usr/lib/java/libtcnative-1.0.1.20.dylib
> /usr/lib/java/libtcnative-1.dylib
>
> I tried to rebuild and install under latest OS/X 10.6.8 but Tomcat 6
> still didn't detect it.
>

Is it 1.0.1.20 or 1.1.20.0?
Was it always dylib (and not so)?

Best regards,
Konstantin Kolinko

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1145934 - in /tomcat/site/trunk: docs/lists.html xdocs/lists.xml

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 09:50:44 2011
New Revision: 1145934

URL: http://svn.apache.org/viewvc?rev=1145934&view=rev
Log:
Fix indent

Modified:
tomcat/site/trunk/docs/lists.html
tomcat/site/trunk/xdocs/lists.xml

Modified: tomcat/site/trunk/docs/lists.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/lists.html?rev=1145934&r1=1145933&r2=1145934&view=diff
==
--- tomcat/site/trunk/docs/lists.html (original)
+++ tomcat/site/trunk/docs/lists.html Wed Jul 13 09:50:44 2011
@@ -716,7 +716,7 @@ and how they can be used.
 older archives), at
 http://markmail.org/list/org.apache.jakarta.taglibs-user/"; 
rel="nofollow">MarkMail (both old and new) and at
 http://www.mail-archive.com/taglibs-user@tomcat.apache.org/"; 
rel="nofollow">Mail Archive (also
- http://www.mail-archive.com/taglibs-user@jakarta.apache.org/"; 
rel="nofollow">older archives)
+http://www.mail-archive.com/taglibs-user@jakarta.apache.org/"; 
rel="nofollow">older archives)
   
  
  

Modified: tomcat/site/trunk/xdocs/lists.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/lists.xml?rev=1145934&r1=1145933&r2=1145934&view=diff
==
--- tomcat/site/trunk/xdocs/lists.xml (original)
+++ tomcat/site/trunk/xdocs/lists.xml Wed Jul 13 09:50:44 2011
@@ -371,9 +371,9 @@ and how they can be used.
 http://markmail.org/list/org.apache.jakarta.taglibs-user/";
 rel="nofollow">MarkMail (both old and new) and at
 http://www.mail-archive.com/taglibs-user@tomcat.apache.org/";
- rel="nofollow">Mail Archive (also
- http://www.mail-archive.com/taglibs-user@jakarta.apache.org/";
-  rel="nofollow">older archives)
+rel="nofollow">Mail Archive (also
+http://www.mail-archive.com/taglibs-user@jakarta.apache.org/";
+rel="nofollow">older archives)
   
  
  



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



[Tomcat Wiki] Update of "FrontPage" by markt

2011-07-13 Thread Apache Wiki
Dear Wiki user,

You have subscribed to a wiki page or wiki category on "Tomcat Wiki" for change 
notification.

The "FrontPage" page has been changed by markt:
http://wiki.apache.org/tomcat/FrontPage?action=diff&rev1=23&rev2=24

Comment:
Minor description change

   * '''[[WhatIsComet|What is Comet]]''' - What is the Tomcat Comet API.
   * '''[[DocumentInOtherLanguages|Translations]]''' - List of Tomcat documents 
in other languages.
   * '''[[GSOC]]''' - Google Summer of Code
-  * '''[[AddOns]]''' - Third party add-ons not included in the official 
distribution
+  * '''[[AddOns]]''' - Third party tools and add-ons not included in the 
official distribution
  
  = Special Wiki pages =
   * '''HelpContents''' - A basic guide to the MoinMoin wiki (including 
information about wiki syntax).

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



[Tomcat Wiki] Update of "AddOns" by markt

2011-07-13 Thread Apache Wiki
Dear Wiki user,

You have subscribed to a wiki page or wiki category on "Tomcat Wiki" for change 
notification.

The "AddOns" page has been changed by markt:
http://wiki.apache.org/tomcat/AddOns?action=diff&rev1=2&rev2=3

Comment:
Minor description change

- Here is a list of third party add-ons that are not included in the main 
distribution
+ Here is a list of third party tools and add-ons that are not included in the 
main distribution
  
  = Realms =
   * [[OrientDBRealm]] - Realms for Tomcat 6 and 7 that connect to an OrientDB

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1145937 - in /tomcat/site/trunk: docs/resources.html xdocs/resources.xml

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 09:57:36 2011
New Revision: 1145937

URL: http://svn.apache.org/viewvc?rev=1145937&view=rev
Log:
Replace broken links and links to out of date products with a link to the wiki.

Modified:
tomcat/site/trunk/docs/resources.html
tomcat/site/trunk/xdocs/resources.xml

Modified: tomcat/site/trunk/docs/resources.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/resources.html?rev=1145937&r1=1145936&r2=1145937&view=diff
==
--- tomcat/site/trunk/docs/resources.html (original)
+++ tomcat/site/trunk/docs/resources.html Wed Jul 13 09:57:36 2011
@@ -197,11 +197,11 @@
 
 
 
-
+
 
 
-
-Free Tools
+
+Third party tools and add-ons
 
 
 
@@ -211,21 +211,12 @@
 
 
 
-  The Apache Tomcat project doesn't endorse any of the products mentioned
- here.  Please also see (and edit as you wish) the 
- http://wiki.apache.org";>Wiki pages.
-
-  
-
-  http://openknows.free.fr/";>Tomcat for Eclipse
-
-
-  http://www.sysdeo.com/eclipse/tomcatPlugin.html";>Sysdeo Eclipse 
Tomcat Launcher plugin
-
-
-  http://www.day.com/en/product/communiqu1/cqenterprise/communiqu1/dnlogin.html";>DAY
 Communique JSP Debugger
-
-  
+  A http://wiki.apache.org/tomcat/AddOns"/>list of third party
+  tools and add-ons (most of them free) is maintained on the
+  http://wiki.apache.org/tomcat/FrontPage";>Apache Tomcat wiki.
+  Please note that the Apache Tomcat project doesn't endorse any of the 
products
+  listed. If you use or develop a tool or add-on for Apache Tomcat please feel
+  free to add it to the list on the wiki.
 
 
 

Modified: tomcat/site/trunk/xdocs/resources.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/resources.xml?rev=1145937&r1=1145936&r2=1145937&view=diff
==
--- tomcat/site/trunk/xdocs/resources.xml (original)
+++ tomcat/site/trunk/xdocs/resources.xml Wed Jul 13 09:57:36 2011
@@ -8,23 +8,14 @@
 
 
 
-
+
 
-  The Apache Tomcat project doesn't endorse any of the products mentioned
- here.  Please also see (and edit as you wish) the 
- http://wiki.apache.org";>Wiki pages.
-
-  
-
-  http://openknows.free.fr/";>Tomcat for Eclipse
-
-
-  http://www.sysdeo.com/eclipse/tomcatPlugin.html";>Sysdeo Eclipse 
Tomcat Launcher plugin
-
-
-  http://www.day.com/en/product/communiqu1/cqenterprise/communiqu1/dnlogin.html";>DAY
 Communique JSP Debugger
-
-  
+  A http://wiki.apache.org/tomcat/AddOns";>list of third party
+  tools and add-ons (most of them free) is maintained on the
+  http://wiki.apache.org/tomcat/FrontPage";>Apache Tomcat wiki.
+  Please note that the Apache Tomcat project doesn't endorse any of the 
products
+  listed. If you use or develop a tool or add-on for Apache Tomcat please feel
+  free to add it to the list on the wiki.
 
 
 



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1145941 - in /tomcat/site/trunk: docs/resources.html xdocs/resources.xml

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 10:06:29 2011
New Revision: 1145941

URL: http://svn.apache.org/viewvc?rev=1145941&view=rev
Log:
Replace broken links with a link to the wiki.

Modified:
tomcat/site/trunk/docs/resources.html
tomcat/site/trunk/xdocs/resources.xml

Modified: tomcat/site/trunk/docs/resources.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/resources.html?rev=1145941&r1=1145940&r2=1145941&view=diff
==
--- tomcat/site/trunk/docs/resources.html (original)
+++ tomcat/site/trunk/docs/resources.html Wed Jul 13 10:06:29 2011
@@ -246,24 +246,16 @@
   
 
   
-http://blog.covalent.net/roller/covalent/entry/20070308";>
- Can Servlet Containers Scale?  16,000 Concurrent Connections using 
Tomcat 6!
-, a performance
- study and benchmark analysis by Filip Hanik.
-
-
-  
 So Much Static
-, a traffic and performance benchmark
-  analysis by Peter Lin.
+, a
+  traffic and performance benchmark analysis by Peter Lin.
 
 
-  
-http://johnturner.com/howto/apache-tomcat-howto.html";>mod_jk 
HOWTOs
-, 
-  by John Turner.  Please note that this is one of many documents 
explaining how to 
-  connect Apache HTTP Server and Apache Tomcat in various environment.  A 
list is maintained in
-  the tomcat http://wiki.apache.org/tomcat/Tomcat_2fLinks";>wiki 
links page.
+  There are many documents explaining how to connect various versions of
+  Apache Web Server (httpd) or Microsoft IIS and Apache Tomcat. Some of
+  these documents are more up to date than others. Links to some of the 
more
+  useful documents are listed on the Apache Tomcat wiki's
+  http://wiki.apache.org/tomcat/UsefulLinks";>useful links 
page.
 
 
   
@@ -271,18 +263,6 @@
 , 
   by Peter Lin
 
-
-  
-http://www.ubeans.com/tomcat/index.html";>Tomcat 4.0 Load 
-  Balancing with Apache 1.3
-, by Pascal Forget
-
-
-  
-http://www.theserverside.com/resources/article.jsp?l=Tomcat";>
-  In Memory Session Replication in Tomcat 4.0
-, by Filip Hanik
-
   
 
 

Modified: tomcat/site/trunk/xdocs/resources.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/resources.xml?rev=1145941&r1=1145940&r2=1145941&view=diff
==
--- tomcat/site/trunk/xdocs/resources.xml (original)
+++ tomcat/site/trunk/xdocs/resources.xml Wed Jul 13 10:06:29 2011
@@ -23,32 +23,20 @@
 
   
 
-  http://blog.covalent.net/roller/covalent/entry/20070308";>
- Can Servlet Containers Scale?  16,000 Concurrent Connections using 
Tomcat 6!, a performance
- study and benchmark analysis by Filip Hanik.
+  So Much Static, a
+  traffic and performance benchmark analysis by Peter Lin.
 
 
-  So Much Static, a 
traffic and performance benchmark
-  analysis by Peter Lin.
-
-
-  http://johnturner.com/howto/apache-tomcat-howto.html";>mod_jk 
HOWTOs, 
-  by John Turner.  Please note that this is one of many documents 
explaining how to 
-  connect Apache HTTP Server and Apache Tomcat in various environment.  A 
list is maintained in
-  the tomcat http://wiki.apache.org/tomcat/Tomcat_2fLinks";>wiki 
links page.
+  There are many documents explaining how to connect various versions of
+  Apache Web Server (httpd) or Microsoft IIS and Apache Tomcat. Some of
+  these documents are more up to date than others. Links to some of the 
more
+  useful documents are listed on the Apache Tomcat wiki's
+  http://wiki.apache.org/tomcat/UsefulLinks";>useful links 
page.
 
 
   Tomcat Performance, 
   by Peter Lin
 
-
-  http://www.ubeans.com/tomcat/index.html";>Tomcat 4.0 Load 
-  Balancing with Apache 1.3, by Pascal Forget
-
-
-  http://www.theserverside.com/resources/article.jsp?l=Tomcat";>
-  In Memory Session Replication in Tomcat 4.0, by Filip Hanik
-
   
 
 



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1145943 - in /tomcat/site/trunk: docs/resources.html xdocs/resources.xml

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 10:08:22 2011
New Revision: 1145943

URL: http://svn.apache.org/viewvc?rev=1145943&view=rev
Log:
More no-follow links

Modified:
tomcat/site/trunk/docs/resources.html
tomcat/site/trunk/xdocs/resources.xml

Modified: tomcat/site/trunk/docs/resources.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/resources.html?rev=1145943&r1=1145942&r2=1145943&view=diff
==
--- tomcat/site/trunk/docs/resources.html (original)
+++ tomcat/site/trunk/docs/resources.html Wed Jul 13 10:08:22 2011
@@ -300,57 +300,57 @@
   
 
   
-http://www.packtpub.com/tomcat-6-developers-guide/book?utm_source=tomcat.apache.org&utm_medium=link&utm_content=pod&utm_campaign=mdb_002136";>Tomcat
 6 Developer's Guide
+http://www.packtpub.com/tomcat-6-developers-guide/book?utm_source=tomcat.apache.org&utm_medium=link&utm_content=pod&utm_campaign=mdb_002136";
 rel="nofollow">Tomcat 6 Developer's Guide
 , by Damodar Chetty
   Packt Publishing (12/2009)
 
 
   
-http://www.amazon.com/exec/obidos/tg/detail/-/0596003188/qid=1043089531/sr=1-6/ref=sr_1_6/002-9433156-6683214?v=glance&s=books";>Tomcat:
 The Definitive Guide (2nd ed.)
+http://www.amazon.com/exec/obidos/tg/detail/-/0596003188/qid=1043089531/sr=1-6/ref=sr_1_6/002-9433156-6683214?v=glance&s=books";
 rel="nofollow">Tomcat: The Definitive Guide (2nd ed.)
 , by Jason Brittain, Ian F. Darwin
 
   O'Reilly & Associates (10/2007)
 
 
   
-http://www.brainysoftware.com/";>How Tomcat Works
+http://www.brainysoftware.com/"; rel="nofollow">How Tomcat Works
 , by Budi Kurniawan
   ? (09/2003)
 
 
   
-http://www.amazon.com/exec/obidos/tg/detail/-/0764526065/qid=1043089531/sr=1-9/ref=sr_1_9/002-9433156-6683214?v=glance&s=books";>Apache
 Tomcat Bible
+http://www.amazon.com/exec/obidos/tg/detail/-/0764526065/qid=1043089531/sr=1-9/ref=sr_1_9/002-9433156-6683214?v=glance&s=books";
 rel="nofollow">Apache Tomcat Bible
 , by Jon Eaves, Warner Godfrey, Rupert Jones
   Hungry Minds, Inc (06/2003)
 
 
   
-http://www.amazon.com/exec/obidos/tg/detail/-/1861008309/qid=1043089531/sr=1-8/ref=sr_1_8/002-9433156-6683214?v=glance&s=books";>Apache
 Tomcat Security Handbook
+http://www.amazon.com/exec/obidos/tg/detail/-/1861008309/qid=1043089531/sr=1-8/ref=sr_1_8/002-9433156-6683214?v=glance&s=books";
 rel="nofollow">Apache Tomcat Security Handbook
 , by Vivek Chopra, Ben Galbriaths, Gotham Pollysetty, Brian Rickabaugh, 
John Turner
 
   Wrox Press (02/2003)
 
 
   
-http://www.amazon.com/exec/obidos/tg/detail/-/0672324393/qid=1043089531/sr=1-5/ref=sr_1_5/002-9433156-6683214?v=glance&s=books";>Tomcat
 Kick Start
+http://www.amazon.com/exec/obidos/tg/detail/-/0672324393/qid=1043089531/sr=1-5/ref=sr_1_5/002-9433156-6683214?v=glance&s=books";
 rel="nofollow">Tomcat Kick Start
 , by Martin Bond, Debbie Law
   Sams (11/2002)
 
 
   
-http://www.amazon.com/exec/obidos/tg/detail/-/0471237647/qid=1043089531/sr=1-1/ref=sr_1_1/002-9433156-6683214?v=glance&s=books";>Mastering
 Tomcat Development
+http://www.amazon.com/exec/obidos/tg/detail/-/0471237647/qid=1043089531/sr=1-1/ref=sr_1_1/002-9433156-6683214?v=glance&s=books";
 rel="nofollow">Mastering Tomcat Development
 , by Peter Harrison, Ian McFarland
   John Wiley & Sons (10/2002)
 
 
   
-http://www.amazon.com/exec/obidos/tg/detail/-/1861007736/ref=pd_sbs_b_1/002-9433156-6683214?v=glance&s=books";>Professional
 Apache Tomcat
+http://www.amazon.com/exec/obidos/tg/detail/-/1861007736/ref=pd_sbs_b_1/002-9433156-6683214?v=glance&s=books";
 rel="nofollow">Professional Apache Tomcat
 , by Chanoch Wiggers, Ben Galbraith, Vivek Chopra, Sing Li, Debashish 
Bhattacharjee, Amit Bakore, Romin Irani, Sandip Bhattacharya, Chad Fowler
   Wrox Press (09/2002)
 
 
   
-http://www.amazon.com/Professional-Apache-Tomcat-WROX-Guides/dp/0471753610";>Professional
 Apache Tomcat 6
+http://www.amazon.com/Professional-Apache-Tomcat-WROX-Guides/dp/0471753610";
 rel="nofollow">Professional Apache Tomcat 6
 , by by Vivek Chopra, Sing Li, Jeff Genender.
   
 Wrox Press (August 2007)
@@ -358,12 +358,12 @@
 
 
   
-http://tomcatbook.sourceforge.net/";>Tomcat Book Project
+http://tomcatbook.sourceforge.net/"; rel="nofollow">Tomcat Book 
Project
 
 
 
   
-http://www.amazon.com/exec/obidos/tg/detail/-/1893115364/qid=1043089531/sr=1-4/ref=sr_1_4/002-9433156-6683214?v=glance&s=books";>Apache
 Jakarta-Tomcat
+http://www.amazon.com/exec/obidos/tg/detail/-/1893115364/qid=1043089531/sr=1-4/ref=sr_1_4/002-9433156-6683214?v=glance&s=books";
 rel="nofollow">Apache Jakarta-Tomcat
 , by James Goodwill
   APress (12/2001)
 

Modified: tomcat/site/trunk/xdocs/resources.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/resources.xml?rev=1145943&r1=1145942&r2=1145943&view=diff

Re: tomcat-native and OS/X

2011-07-13 Thread Mladen Turk

On 07/13/2011 11:35 AM, Henri Gomez wrote:


I just seen my tomcat-native 1.1.20 is not working anymore on OS/X (10.6.8).

I tried to rebuild and install under latest OS/X 10.6.8 but Tomcat 6
still didn't detect it.



Have you tried starting tomcat with 'java -d32/-d64'
Might be the wrong ABI (32/64-bit) gets used.

Regards
--
^TM

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 47516] parameters in conf/context.xml and context.xml.default are ignored

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=47516

Martin Harm  changed:

   What|Removed |Added

 Status|RESOLVED|REOPENED
 Resolution|WORKSFORME  |

--- Comment #4 from Martin Harm  2011-07-13 12:22:36 UTC ---
Parameters with override="false" in Context-Files dont overrule the
 in the corresponding web-app.
See: 
 org.apache.catalina.core.StandardContext.mergeParameters() 
  --> set (twice) on the context and override property is honored 
but will be ignored, because in 
  org.apache.catalina.core.ApplicationContext.setInitParameter(...)
the value wont change

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 47516] parameters in conf/context.xml and context.xml.default are ignored

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=47516

Martin Harm  changed:

   What|Removed |Added

Version|6.0.26  |6.0.32

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 47516] parameters in conf/context.xml and context.xml.default are ignored

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=47516

Konstantin Kolinko  changed:

   What|Removed |Added

 Status|REOPENED|RESOLVED
 Resolution||DUPLICATE

--- Comment #5 from Konstantin Kolinko  2011-07-13 
12:35:10 UTC ---
The issue in 6.0.32 is known and already fixed in 7.0 since 7.0.9 and 6.0.33
(not yet released) - see bug 50700.

Cannot comment about the old WORKSFORME issue that was reported for 6.0.26.

*** This bug has been marked as a duplicate of bug 50700 ***

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 50700] Context parameters are being overridden with parameters from the web application deployment descriptor

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=50700

Konstantin Kolinko  changed:

   What|Removed |Added

 CC||w...@wg.be

--- Comment #8 from Konstantin Kolinko  2011-07-13 
12:35:10 UTC ---
*** Bug 47516 has been marked as a duplicate of this bug. ***

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 51503] New: Tomcat service don't stop properly

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=51503

 Bug #: 51503
   Summary: Tomcat service don't stop properly
   Product: Tomcat 7
   Version: trunk
  Platform: PC
OS/Version: Windows Server 2003
Status: NEW
  Severity: normal
  Priority: P2
 Component: Connectors
AssignedTo: dev@tomcat.apache.org
ReportedBy: etienne.mas...@gmail.com
Classification: Unclassified


With 7.0.18 packaged as a candidate for release and finally unreleased, when I
stop the Tomcat service (only 1 war deployed), the service takes a lot of time
to stop and finally was killed by system.

Having a look into the stderr log, I see it paused right after the folowing
line :

INFO: Stopping ProtocolHandler [http-apr-0]

Then went into a slow loop and fill the log with these lines :

13 juil. 2011 14:30:30 org.apache.tomcat.util.net.AprEndpoint stopInternal
ATTENTION: Acceptor thread [http-apr-0-Acceptor-0] failed to unlock. Forcing
hard socket shutdown.
13 juil. 2011 14:30:31 org.apache.tomcat.util.net.AprEndpoint stopInternal
ATTENTION: Acceptor thread [http-apr-0-Acceptor-0] failed to unlock. Forcing
hard socket shutdown.
13 juil. 2011 14:30:32 org.apache.tomcat.util.net.AprEndpoint stopInternal
ATTENTION: Acceptor thread [http-apr-0-Acceptor-0] failed to unlock. Forcing
hard socket shutdown.
etc. (about 30 times before it was killed)

I think there was no such issue with 7.0.16.

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 51503] Tomcat service don't stop properly

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=51503

Mark Thomas  changed:

   What|Removed |Added

 Status|NEW |RESOLVED
 Resolution||FIXED

--- Comment #1 from Mark Thomas  2011-07-13 12:43:23 UTC ---
This has already been fixed in trunk and will be included in 7.0.19 onwards.

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1145981 - /tomcat/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 12:45:57 2011
New Revision: 1145981

URL: http://svn.apache.org/viewvc?rev=1145981&view=rev
Log:
No need to include class in message, results in "classclass"

Modified:
tomcat/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java

Modified: tomcat/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java
URL: 
http://svn.apache.org/viewvc/tomcat/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java?rev=1145981&r1=1145980&r2=1145981&view=diff
==
--- tomcat/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java 
(original)
+++ tomcat/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java Wed 
Jul 13 12:45:57 2011
@@ -429,7 +429,7 @@ public class DefaultInstanceManager impl
 private void checkAccess(Class clazz, Properties restricted) {
 while (clazz != null) {
 if ("restricted".equals(restricted.getProperty(clazz.getName( {
-throw new SecurityException("Restricted class" + clazz);
+throw new SecurityException("Restricted " + clazz);
 }
 clazz = clazz.getSuperclass();
 }



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146005 - in /tomcat/trunk/java/org/apache/catalina/connector: LocalStrings.properties Request.java

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 13:28:24 2011
New Revision: 1146005

URL: http://svn.apache.org/viewvc?rev=1146005&view=rev
Log:
When running under a security manager and using sendfile, validate sendfile 
attributes to prevent sendfile being used to bypass the security manager.
Part of the fix for CVE-2011-2526

Modified:
tomcat/trunk/java/org/apache/catalina/connector/LocalStrings.properties
tomcat/trunk/java/org/apache/catalina/connector/Request.java

Modified: 
tomcat/trunk/java/org/apache/catalina/connector/LocalStrings.properties
URL: 
http://svn.apache.org/viewvc/tomcat/trunk/java/org/apache/catalina/connector/LocalStrings.properties?rev=1146005&r1=1146004&r2=1146005&view=diff
==
--- tomcat/trunk/java/org/apache/catalina/connector/LocalStrings.properties 
(original)
+++ tomcat/trunk/java/org/apache/catalina/connector/LocalStrings.properties Wed 
Jul 13 13:28:24 2011
@@ -66,6 +66,7 @@ coyoteRequest.noLoginConfig=No authentic
 coyoteRequest.authenticate.ise=Cannot call authenticate() after the reponse 
has been committed
 coyoteRequest.uploadLocationInvalid=The temporary upload location [{0}] is not 
valid
 coyoteRequest.sessionEndAccessFail=Exception triggered ending access to 
session while recycling request
+coyoteRequest.sendfileNotCanonical=Unable to determine canonical name of file 
[{0}] specified for use with sendfile
 
 requestFacade.nullRequest=The request object has been recycled and is no 
longer associated with this facade
 

Modified: tomcat/trunk/java/org/apache/catalina/connector/Request.java
URL: 
http://svn.apache.org/viewvc/tomcat/trunk/java/org/apache/catalina/connector/Request.java?rev=1146005&r1=1146004&r2=1146005&view=diff
==
--- tomcat/trunk/java/org/apache/catalina/connector/Request.java (original)
+++ tomcat/trunk/java/org/apache/catalina/connector/Request.java Wed Jul 13 
13:28:24 2011
@@ -1525,6 +1525,26 @@ public class Request
 return;
 }
 
+// Do the security check before any updates are made
+if (Globals.IS_SECURITY_ENABLED &&
+name.equals("org.apache.tomcat.sendfile.filename")) {
+// Use the canonical file name to avoid any possible symlink and
+// relative path issues
+String canonicalPath;
+try {
+canonicalPath = new File(value.toString()).getCanonicalPath();
+} catch (IOException e) {
+throw new SecurityException(sm.getString(
+"coyoteRequest.sendfileNotCanonical", value), e);
+}
+// Sendfile is performed in Tomcat's security context so need to
+// check if the web app is permitted to access the file while still
+// in the web app's security context
+System.getSecurityManager().checkRead(canonicalPath);
+// Update the value so the canonical path is used
+value = canonicalPath;
+}
+
 oldValue = attributes.put(name, value);
 if (oldValue != null) {
 replaced = true;



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn propchange: r1145383 - svn:log

2011-07-13 Thread markt
Author: markt
Revision: 1145383
Modified property: svn:log

Modified: svn:log at Wed Jul 13 13:30:14 2011
--
--- svn:log (original)
+++ svn:log Wed Jul 13 13:30:14 2011
@@ -1 +1,2 @@
 Protect against infinite loops in the HTTP NIO connector if sendfile is 
configured to send more data than is available in the file. (markt)
+Part of the fix for CVE-2011-2526


-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn propchange: r1145489 - svn:log

2011-07-13 Thread markt
Author: markt
Revision: 1145489
Modified property: svn:log

Modified: svn:log at Wed Jul 13 13:30:32 2011
--
--- svn:log (original)
+++ svn:log Wed Jul 13 13:30:32 2011
@@ -1 +1,2 @@
 Correct a comment
+Part of the fix for CVE-2011-2526


-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn propchange: r1145571 - svn:log

2011-07-13 Thread markt
Author: markt
Revision: 1145571
Modified property: svn:log

Modified: svn:log at Wed Jul 13 13:30:48 2011
--
--- svn:log (original)
+++ svn:log Wed Jul 13 13:30:48 2011
@@ -1 +1,2 @@
 Socket has been closed, return false so an attempt is not made to re-use the 
socket
+Part of the fix for CVE-2011-2526


-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn propchange: r1145694 - svn:log

2011-07-13 Thread markt
Author: markt
Revision: 1145694
Modified property: svn:log

Modified: svn:log at Wed Jul 13 13:31:24 2011
--
--- svn:log (original)
+++ svn:log Wed Jul 13 13:31:24 2011
@@ -1 +1,2 @@
 Protect against crashes in the HTTP APR connector if sendfile is configured to 
send more data than is available in the file.
+Part of the fix for CVE-2011-2526


-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



Tagging 7.0.19

2011-07-13 Thread Mark Thomas
On 13/07/2011 14:28, ma...@apache.org wrote:
> Author: markt
> Date: Wed Jul 13 13:28:24 2011
> New Revision: 1146005

With this commit I am going to start the process of running the unit and
TCK tests prior to tagging 7.0.19. Assuming everything passes, expect
the tag in the next 10 hours or so.

Mark



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146010 - /tomcat/trunk/webapps/docs/changelog.xml

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 13:36:44 2011
New Revision: 1146010

URL: http://svn.apache.org/viewvc?rev=1146010&view=rev
Log:
Add CVE reference for sendfile issues

Modified:
tomcat/trunk/webapps/docs/changelog.xml

Modified: tomcat/trunk/webapps/docs/changelog.xml
URL: 
http://svn.apache.org/viewvc/tomcat/trunk/webapps/docs/changelog.xml?rev=1146010&r1=1146009&r2=1146010&view=diff
==
--- tomcat/trunk/webapps/docs/changelog.xml (original)
+++ tomcat/trunk/webapps/docs/changelog.xml Wed Jul 13 13:36:44 2011
@@ -121,9 +121,9 @@
 is used. Fixes null thread name in access log and JMX MBean. (rjung)
   
   
-Protect against infinite loops (HTTP NIO) and crashes (HTTP APR) if
-sendfile is configured to send more data than is available in the file.
-(markt)
+Fix CVE-2011-2526. Protect against infinite loops (HTTP NIO) and 
crashes
+(HTTP APR) if sendfile is configured to send more data than is 
available
+in the file. (markt)
   
   
 Prevent NPEs when a socket is closed in non-error conditions after



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146018 - /tomcat/tc6.0.x/trunk/STATUS.txt

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 13:42:54 2011
New Revision: 1146018

URL: http://svn.apache.org/viewvc?rev=1146018&view=rev
Log:
Proposal

Modified:
tomcat/tc6.0.x/trunk/STATUS.txt

Modified: tomcat/tc6.0.x/trunk/STATUS.txt
URL: 
http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/STATUS.txt?rev=1146018&r1=1146017&r2=1146018&view=diff
==
--- tomcat/tc6.0.x/trunk/STATUS.txt (original)
+++ tomcat/tc6.0.x/trunk/STATUS.txt Wed Jul 13 13:42:54 2011
@@ -249,3 +249,10 @@ PATCHES PROPOSED TO BACKPORT:
   https://issues.apache.org/bugzilla/attachment.cgi?id=27280 (JMX)
   +1: kkolinko
   -1:
+
+* Fix various sendfile issues. CVE-2011-2526
+  This is a port of r1145380, r1145383, r1145489, r1145571, r1145694 and
+  r1146005
+  http://people.apache.org/~markt/patches/2011-07-13-cve-2011-2526-tc6.patch
+  +1: markt
+  -1:



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146029 - /tomcat/tc5.5.x/trunk/STATUS.txt

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 13:55:00 2011
New Revision: 1146029

URL: http://svn.apache.org/viewvc?rev=1146029&view=rev
Log:
Proposal

Modified:
tomcat/tc5.5.x/trunk/STATUS.txt

Modified: tomcat/tc5.5.x/trunk/STATUS.txt
URL: 
http://svn.apache.org/viewvc/tomcat/tc5.5.x/trunk/STATUS.txt?rev=1146029&r1=1146028&r2=1146029&view=diff
==
--- tomcat/tc5.5.x/trunk/STATUS.txt (original)
+++ tomcat/tc5.5.x/trunk/STATUS.txt Wed Jul 13 13:55:00 2011
@@ -136,3 +136,9 @@ PATCHES PROPOSED TO BACKPORT:
   http://svn.apache.org/viewvc?rev=1133014&view=rev
   +1: kkolinko
   -1:
+
+* Fix various sendfile issues. CVE-2011-2526
+  This is a port of r1145380, r1145694 and r1146005
+  http://people.apache.org/~markt/patches/2011-07-13-cve-2011-2526-tc5.patch
+  +1: markt
+  -1:



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146033 - in /tomcat/site/trunk: docs/security-5.html docs/security-6.html docs/security-7.html xdocs/security-5.xml xdocs/security-6.xml xdocs/security-7.xml

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 13:56:53 2011
New Revision: 1146033

URL: http://svn.apache.org/viewvc?rev=1146033&view=rev
Log:
Add CVE-2011-2526 info

Modified:
tomcat/site/trunk/docs/security-5.html
tomcat/site/trunk/docs/security-6.html
tomcat/site/trunk/docs/security-7.html
tomcat/site/trunk/xdocs/security-5.xml
tomcat/site/trunk/xdocs/security-6.xml
tomcat/site/trunk/xdocs/security-7.xml

Modified: tomcat/site/trunk/docs/security-5.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-5.html?rev=1146033&r1=1146032&r2=1146033&view=diff
==
--- tomcat/site/trunk/docs/security-5.html (original)
+++ tomcat/site/trunk/docs/security-5.html Wed Jul 13 13:56:53 2011
@@ -215,6 +215,9 @@
 Apache Tomcat 5.x 
vulnerabilities
 
 
+To be fixed 
in Apache Tomcat 5.5.34 (not yet released)
+
+
 Fixed in Apache 
Tomcat 5.5.34 (not yet released)
 
 
@@ -337,6 +340,70 @@
 
 
 
+
+
+
+
+To be fixed in Apache Tomcat 5.5.34 (not yet released)
+
+
+
+
+
+
+
+
+
+
+Low: Information disclosure
+   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2526"; 
rel="nofollow">CVE-2011-2526
+
+
+Tomcat provides support for sendfile with the HTTP NIO and HTTP APR
+   connectors. sendfile is used automatically for content served via the
+   DefaultServlet and deployed web applications may use it directly via
+   setting request attributes. These request attributes were not validated.
+   When running under a security manager, this lack of validation allowed a
+   malicious web application to do one or more of the following that would
+   normally be prevented by a security manager:
+   
+ return files to users that the security manager should make
+ inaccessible
+ terminate (via a crash) the JVM
+   
+   Additionally, these vulnerabilities only occur when all of the following
+   are true:
+   
+ untrusted web applications are being used
+ the SecurityManager is used to limit the untrusted web 
applications
+ 
+ the HTTP NIO or HTTP APR connector is used
+ sendfile is enabled for the connector (this is the default)
+   
+
+
+There is a http://people.apache.org/~markt/patches/2011-07-13-cve-2011-2526-tc5.patch";>
+   proposed patch for this issue.
+
+This was identified by the Tomcat security team on 7 July 2011 and
+   made public on 13 July 2011.
+
+Affects: 5.5.0-5.5.33
+
+  
+
+
+
+
+
+
+
+
+
+
+
+
+
 
 
 

Modified: tomcat/site/trunk/docs/security-6.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-6.html?rev=1146033&r1=1146032&r2=1146033&view=diff
==
--- tomcat/site/trunk/docs/security-6.html (original)
+++ tomcat/site/trunk/docs/security-6.html Wed Jul 13 13:56:53 2011
@@ -215,6 +215,9 @@
 Apache Tomcat 6.x 
vulnerabilities
 
 
+To be fixed 
in Apache Tomcat 6.0.33 (not yet released)
+
+
 Fixed in Apache 
Tomcat 6.0.33 (not yet released)
 
 
@@ -313,6 +316,70 @@
 
 
 
+
+
+
+
+To be fixed in Apache Tomcat 6.0.33 (not yet released)
+
+
+
+
+
+
+
+
+
+
+Low: Information disclosure
+   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2526"; 
rel="nofollow">CVE-2011-2526
+
+
+Tomcat provides support for sendfile with the HTTP NIO and HTTP APR
+   connectors. sendfile is used automatically for content served via the
+   DefaultServlet and deployed web applications may use it directly via
+   setting request attributes. These request attributes were not validated.
+   When running under a security manager, this lack of validation allowed a
+   malicious web application to do one or more of the following that would
+   normally be prevented by a security manager:
+   
+ return files to users that the security manager should make
+ inaccessible
+ terminate (via a crash) the JVM
+   
+   Additionally, these vulnerabilities only occur when all of the following
+   are true:
+   
+ untrusted web applications are being used
+ the SecurityManager is used to limit the untrusted web 
applications
+ 
+ the HTTP NIO or HTTP APR connector is used
+ sendfile is enabled for the connector (this is the default)
+   
+
+
+There is a http://people.apache.org/~markt/patches/2011-07-13-cve-2011-2526-tc6.patch";>
+   proposed patch for this issue.
+
+This was identified by the Tomcat security team on 7 July 2011 and
+   made public on 13 July 2011.
+
+Affects: 6.0.0-6.0.32
+
+  
+
+
+
+
+
+
+
+
+
+
+
+
+
 
 
 

Modified: tomcat/site/trunk/docs/security-7.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-7.html?rev=1146033&r1=1146032&r2=1146033&view=diff
===

svn commit: r1146041 - /tomcat/tc6.0.x/trunk/STATUS.txt

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 14:04:22 2011
New Revision: 1146041

URL: http://svn.apache.org/viewvc?rev=1146041&view=rev
Log:
Simplify

Modified:
tomcat/tc6.0.x/trunk/STATUS.txt

Modified: tomcat/tc6.0.x/trunk/STATUS.txt
URL: 
http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/STATUS.txt?rev=1146041&r1=1146040&r2=1146041&view=diff
==
--- tomcat/tc6.0.x/trunk/STATUS.txt (original)
+++ tomcat/tc6.0.x/trunk/STATUS.txt Wed Jul 13 14:04:22 2011
@@ -144,13 +144,8 @@ PATCHES PROPOSED TO BACKPORT:
   http://svn.apache.org/viewvc?rev=1138950&view=rev
   http://svn.apache.org/viewvc?rev=1138953&view=rev
   http://svn.apache.org/viewvc?rev=1140693&view=rev
-  +1: markt
-  +1: kkolinko (with r1142043)
-  -1:
-
-  Additional patch:
   http://svn.apache.org/viewvc?rev=1142043&view=rev
-  +1: kkolinko, markt
+  +1: markt, kkolinko
   -1:
 
 * Multiple improvements to the Windows Installer



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146042 - /tomcat/tc5.5.x/trunk/STATUS.txt

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 14:04:47 2011
New Revision: 1146042

URL: http://svn.apache.org/viewvc?rev=1146042&view=rev
Log:
Simplify

Modified:
tomcat/tc5.5.x/trunk/STATUS.txt

Modified: tomcat/tc5.5.x/trunk/STATUS.txt
URL: 
http://svn.apache.org/viewvc/tomcat/tc5.5.x/trunk/STATUS.txt?rev=1146042&r1=1146041&r2=1146042&view=diff
==
--- tomcat/tc5.5.x/trunk/STATUS.txt (original)
+++ tomcat/tc5.5.x/trunk/STATUS.txt Wed Jul 13 14:04:47 2011
@@ -87,14 +87,9 @@ PATCHES PROPOSED TO BACKPORT:
   Handle tag files with attribute names that are not valid Java identifiers
   http://svn.apache.org/viewvc?rev=1138950&view=rev
   http://svn.apache.org/viewvc?rev=1138953&view=rev
-  +1: markt
-  +1: kkolinko: with r1140693 and r1142043
-  -1:
-
-  Additional patches:
   http://svn.apache.org/viewvc?rev=1140693&view=rev
   http://svn.apache.org/viewvc?rev=1142043&view=rev
-  +1: kkolinko
+  +1: markt, kkolinko
   -1:
 
 * Multiple improvements to the Windows Installer



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 36362] missing check for Java reserved keywords in tag file processing

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=36362

--- Comment #7 from Mark Thomas  2011-07-13 14:05:12 UTC ---
The regression with underscores has been fixed and updated patches proposed for
6.0.x and 5.5.x.

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



Re: Tagging 7.0.19

2011-07-13 Thread Rainer Jung
On 13.07.2011 15:32, Mark Thomas wrote:
> On 13/07/2011 14:28, ma...@apache.org wrote:
>> Author: markt
>> Date: Wed Jul 13 13:28:24 2011
>> New Revision: 1146005
> 
> With this commit I am going to start the process of running the unit and
> TCK tests prior to tagging 7.0.19. Assuming everything passes, expect
> the tag in the next 10 hours or so.

+1

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146051 - /tomcat/tc6.0.x/trunk/STATUS.txt

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 14:22:17 2011
New Revision: 1146051

URL: http://svn.apache.org/viewvc?rev=1146051&view=rev
Log:
Vote, update reasoning for veto

Modified:
tomcat/tc6.0.x/trunk/STATUS.txt

Modified: tomcat/tc6.0.x/trunk/STATUS.txt
URL: 
http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/STATUS.txt?rev=1146051&r1=1146050&r2=1146051&view=diff
==
--- tomcat/tc6.0.x/trunk/STATUS.txt (original)
+++ tomcat/tc6.0.x/trunk/STATUS.txt Wed Jul 13 14:22:17 2011
@@ -135,8 +135,7 @@ PATCHES PROPOSED TO BACKPORT:
   Based on https://issues.jboss.org/browse/JBWEB-196
   http://people.apache.org/~jfclere/patches/patch.110622.txt
   +1: jfclere
-  -1: markt Separators are defined by the HTTP specification and as per section
-2.2 of RFC 2616 must be quoted to be used within a parameter value.
+  -1: markt Should use same mechanism for this as Tomcat 7 
   -1
 
 * Fix https://issues.apache.org/bugzilla/show_bug.cgi?id=36362
@@ -242,7 +241,7 @@ PATCHES PROPOSED TO BACKPORT:
  and also fix wrong mapping for "enabled" property - it is getEnabled().
   https://issues.apache.org/bugzilla/attachment.cgi?id=27279
   https://issues.apache.org/bugzilla/attachment.cgi?id=27280 (JMX)
-  +1: kkolinko
+  +1: kkolinko, markt
   -1:
 
 * Fix various sendfile issues. CVE-2011-2526



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



Re: tomcat-native and OS/X

2011-07-13 Thread Henri Gomez
The latest one, aka 1.1.20

-rwxr-xr-x  1 root  wheel  186680 13 jul 11:00 libtcnative-1.0.1.20.dylib
lrwxr-xr-x  1 root  wheel  40 13 jul 10:53 libtcnative-1.dylib ->
/usr/lib/java/libtcnative-1.0.1.20.dylib
lrwxr-xr-x  1 root  wheel  40 13 jul 11:02 libtcnative.dylib ->
/usr/lib/java/libtcnative-1.0.1.20.dylib

yes, dylib, it was working with previous SnowLeopard release but seems
broken in 10.6.8 (and may be before)


2011/7/13 Konstantin Kolinko :
> 2011/7/13 Henri Gomez :
>> Hi guys,
>>
>> I just seen my tomcat-native 1.1.20 is not working anymore on OS/X (10.6.8).
>>
>> INFO: The APR based Apache Tomcat Native library which allows optimal
>> performance in production environments was not found on the
>> java.library.path:
>> .:/Library/Java/Extensions:/System/Library/Java/Extensions:/usr/lib/java
>> Jul 13, 2011 11:02:30 AM org.apache.coyote.http11.Http11Protocol init
>>
>> I usually build and install like this :
>>
>> ./configure --with-apr=/usr/bin/apr-1-config
>> --with-java-home=/System/Library/Frameworks/JavaVM.framework/Versions/1.6.0/Home/
>> make clean
>> make
>>
>> sudo cp .libs/libtcnative-1.0.1.20.dylib /usr/lib/java
>> sudo ln -s /usr/lib/java/libtcnative-1.0.1.20.dylib
>> /usr/lib/java/libtcnative-1.dylib
>>
>> I tried to rebuild and install under latest OS/X 10.6.8 but Tomcat 6
>> still didn't detect it.
>>
>
> Is it 1.0.1.20 or 1.1.20.0?
> Was it always dylib (and not so)?
>
> Best regards,
> Konstantin Kolinko
>
> -
> To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
> For additional commands, e-mail: dev-h...@tomcat.apache.org
>
>

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



Re: tomcat-native and OS/X

2011-07-13 Thread Henri Gomez
>> I tried to rebuild and install under latest OS/X 10.6.8 but Tomcat 6
>> still didn't detect it.
>>
>
> Have you tried starting tomcat with 'java -d32/-d64'
> Might be the wrong ABI (32/64-bit) gets used.

You got it Mladen :)

I was using -d32 and in such case it didn't works
back to normal with -d64.

I should figure how to build a 32bits version.
32/64 bits mixed models on OS/X are sometime complex :)

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146096 - /tomcat/trunk/bin/catalina.bat

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 15:20:43 2011
New Revision: 1146096

URL: http://svn.apache.org/viewvc?rev=1146096&view=rev
Log:
CATALINA_BASE is always set, so simplify

Modified:
tomcat/trunk/bin/catalina.bat

Modified: tomcat/trunk/bin/catalina.bat
URL: 
http://svn.apache.org/viewvc/tomcat/trunk/bin/catalina.bat?rev=1146096&r1=1146095&r2=1146096&view=diff
==
--- tomcat/trunk/bin/catalina.bat (original)
+++ tomcat/trunk/bin/catalina.bat Wed Jul 13 15:20:43 2011
@@ -137,12 +137,12 @@ rem but allow them to be specified in se
 set CLASSPATH=
 
 rem Get standard environment variables
-if "%CATALINA_BASE%" == "" goto gotSetenvHome
-if exist "%CATALINA_BASE%\bin\setenv.bat" call "%CATALINA_BASE%\bin\setenv.bat"
-goto gotSetenvBase
-:gotSetenvHome
+if not exist "%CATALINA_BASE%\bin\setenv.bat" goto checkSetenvHome
+call "%CATALINA_BASE%\bin\setenv.bat"
+goto setenvDone
+:checkSetenvHome
 if exist "%CATALINA_HOME%\bin\setenv.bat" call "%CATALINA_HOME%\bin\setenv.bat"
-:gotSetenvBase
+:setenvDone
 
 rem Get standard Java environment variables
 if exist "%CATALINA_HOME%\bin\setclasspath.bat" goto okSetclasspath



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146097 - in /tomcat/tc6.0.x/trunk: ./ STATUS.txt bin/catalina.bat bin/catalina.sh

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 15:25:05 2011
New Revision: 1146097

URL: http://svn.apache.org/viewvc?rev=1146097&view=rev
Log:
Fix https://issues.apache.org/bugzilla/show_bug.cgi?id=51206
Make CATALINA_BASE visible to setenv.[sh|bat] (rjung)

Modified:
tomcat/tc6.0.x/trunk/   (props changed)
tomcat/tc6.0.x/trunk/STATUS.txt
tomcat/tc6.0.x/trunk/bin/catalina.bat
tomcat/tc6.0.x/trunk/bin/catalina.sh

Propchange: tomcat/tc6.0.x/trunk/
--
--- svn:mergeinfo (original)
+++ svn:mergeinfo Wed Jul 13 15:25:05 2011
@@ -1 +1 @@
-/tomcat/trunk:601180,606992,612607,630314,640888,652744,653247,666232,673796,673820,677910,683969,683982,684001,684081,684234,684269-684270,685177,687503,687645,689402,690781,691392,691805,692748,693378,694992,695053,695311,696780,696782,698012,698227,698236,698613,699427,699634,701355,709294,709811,709816,710063,710066,710125,710205,711126,711600,712461,712467,713953,714002,718360,719119,719124,719602,719626,719628,720046,720069,721040,721286,721708,721886,723404,723738,726052,727303,728032,728768,728947,729057,729567,729569,729571,729681,729809,729815,729934,730250,730590,731651,732859,732863,734734,740675,740684,742677,742697,742714,744160,744238,746321,746384,746425,747834,747863,748344,750258,750291,750921,751286-751287,751289,751295,752323,753039,757335,757774,758249,758365,758596,758616,758664,759074,761601,762868,762929,762936-762937,763166,763183,763193,763228,763262,763298,763302,763325,763599,763611,763654,763681,763706,764985,764997,765662,768335,769979,770716,77
 
0809,770876,772872,776921,776924,776935,776945,777464,777466,777576,777625,778379,778523-778524,781528,781779,782145,782791,783316,783696,783724,783756,783762,783766,783863,783934,784453,784602,784614,785381,785688,785768,785859,786468,786487,786490,786496,786667,787627,787770,787985,789389,790405,791041,791184,791194,791224,791243,791326,791328,791789,792740,793372,793757,793882,793981,794082,794673,794822,795043,795152,795210,795457,795466,797168,797425,797596,797607,802727,802940,804462,804544,804734,805153,809131,809603,810916,810977,812125,812137,812432,813001,813013,813866,814180,814708,814876,815972,816252,817442,817822,819339,819361,820110,820132,820874,820954,821397,828196,828201,828210,828225,828759,830378-830379,830999,831106,831774,831785,831828,831850,831860,832214,832218,833121,833545,834047,835036,835336,836405,881396,881412,883130,883134,883146,883165,883177,883362,883565,884341,885038,885231,885241,885260,885901,885991,886019,888072,889363,889606,889716,8901
 
39,890265,890349-890350,890417,891185-891187,891583,892198,892341,892415,892464,892555,892812,892814,892817,892843,892887,893321,893493,894580,894586,894805,894831,895013,895045,895057,895191,895392,895703,896370,896384,897380-897381,897776,898126,898256,898468,898527,898555,898558,898718,898836,898906,899284,899348,899420,899653,899769-899770,899783,899788,899792,899916,899918-899919,899935,899949,903916,905020,905151,905722,905728,905735,907311,907513,907538,907652,907819,907825,907864,908002,908721,908754,908759,909097,909206,909212,909525,909636,909869,909875,909887,910266,910370,910442,910471,910485,910974,915226,915737,915861,916097,916141,916157,916170,917598,917633,918093,918489,918594,918684,918787,918792,918799,918803,918885,919851,919914,920025,920055,920298,920449,920596,920824,920840,921444,922010,926716,927062,927621,928482,928695,928732,928798,931709,932357,932967,935105,935983,939491,939551,940064,941356,941463,943112,944409,944416,945231,945808,945835,945841
 
,946686,948057,950164,950596,950614,950851,950905,951615,953434,954435,955648,955655,956832,957130,957830,958192,960701,961948,962865,962872,962881,962900,963106,963865,963868,964614,966177-966178,966292,966692,966863,981815,988448,991837,993042,1001955,1002185,1002263,1002274,1002349,1002359,1002362,1002481,1002514,1003461,1003481,1003488,1003556,1003572,1003581,1003861,1004393,1004409,1004415,1004868-1004869,1004912,1005452,1005467,1005647,1005802,1022120,1022134,1022323,1022415,1022606,1022623,1024224,1024251,1026042,1026784,1026912,1026920,1029767,1033415,1033448,1033842,1033897,1037715,1037794,1037887,1037924,1038041,1042022,1042029,1042447,1042452,1042494,1044944,1044987,1050249,1055055,1055236,1055458,1055975,1056264,1056828,1056889,1059881,1061412,1061442,1061446,1062398,1064652,1066244,1067039,1067139,1069824,1070139,1070420,1070609,1072042,1075458,1076212,1078409,1078412,1079801,1081334,1088179,1088460,1094069,1094089,1097899,1099575,1099586,1099772,1099789,1100145
 ,1100822,1101094,1101144,1124680,1130774,1137996,1141104
+/tomcat/trunk:601180,606992,612607,630314,640888,652744,653247,666232,673796,673820,677910,683969,683982,684001,684081,684234,684269-684270,685177,687503,687645,689402,690781,691392,691805,692748,693378,694992,695053,695311,696780,696782,698012,698227,698236,698613,699427,699634,701355,709294,709811,709816,710063,710066,710125,710205,711126,711600,712461,7

DO NOT REPLY [Bug 51206] CATALINA_BASE is not visible to setenv.sh

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=51206

Mark Thomas  changed:

   What|Removed |Added

 Status|NEW |RESOLVED
 Resolution||FIXED

--- Comment #4 from Mark Thomas  2011-07-13 15:26:09 UTC ---
This has been fixed in 6.0.x and will be included in 6.0.33 onwards.

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



Re: tomcat-native and OS/X

2011-07-13 Thread Henri Gomez
I added both arch in build and it seems to works :

CFLAGS='-arch i386 -arch x86_64' APXSLDFLAGS='-arch i386 -arch x86_64'
./configure --with-apr=/usr --with-ssl=/usr
--with-java-home=/System/Library/Frameworks/JavaVM.framework/

You may also add PowerPC support like this :

CFLAGS='-arch ppc -arch i386 -arch ppc64 -arch x86_64'
APXSLDFLAGS='-arch ppc -arch i386 -arch ppc64 -arch x86_64'
./configure --with-apr=/usr --with-ssl=/usr
--with-java-home=/System/Library/Frameworks/JavaVM.framework/

Thanks again Mladen, you pointed the problem

2011/7/13 Henri Gomez :
>>> I tried to rebuild and install under latest OS/X 10.6.8 but Tomcat 6
>>> still didn't detect it.
>>>
>>
>> Have you tried starting tomcat with 'java -d32/-d64'
>> Might be the wrong ABI (32/64-bit) gets used.
>
> You got it Mladen :)
>
> I was using -d32 and in such case it didn't works
> back to normal with -d64.
>
> I should figure how to build a 32bits version.
> 32/64 bits mixed models on OS/X are sometime complex :)
>

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



[SECURITY] CVE-2011-2526 Apache Tomcat Information disclosure and availability vulnerabilities

2011-07-13 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

CVE-2011-2526: Apache Tomcat Information disclosure and availability
   vulnerabilities

Severity: low

Vendor:
The Apache Software Foundation

Versions Affected:
Tomcat 7.0.0 to 7.0.18
Tomcat 6.0.0 to 6.0.32
Tomcat 5.5.0 to 5.0.33
Previous, unsupported versions may be affected
Additionally, these vulnerabilities only occur when all of the following
are true:
a) untrusted web applications are being used
b) the SecurityManager is used to limit the untrusted web applications
c) the HTTP NIO or HTTP APR connector is used
d) sendfile is enabled for the connector (this is the default)

Description:
Tomcat provides support for sendfile with the HTTP NIO and HTTP APR
connectors. sendfile is used automatically for content served via the
DefaultServlet and deployed web applications may use it directly via
setting request attributes. These request attributes were not validated.
When running under a security manager, this lack of validation allowed a
malicious web application to do one or more of the following that would
normally be prevented by a security manager:
a) return files to users that the security manager should make inaccessible
b) terminate (via a crash) the JVM

Mitigation:
Affected users of all versions can mitigate these vulnerabilities by
taking any of the following actions:
a) undeploy untrusted web applications
b) switch to the HTTP BIO connector (which does not support sendfile)
c) disable sendfile be setting useSendfile="false" on the connector
d) apply the patch(es) listed on the Tomcat security pages (see references)
e) upgrade to a version where the vulnerabilities have been fixed
   Tomcat 7.0.x users may upgrade to 7.0.19 or later once released
   Tomcat 6.0.x users may upgrade to 6.0.33 or later once released
   Tomcat 5.5.x users may upgrade to 5.5.34 or later once released

Example:
Exposing the first 1000 bytes of /etc/passwd
HttpServletRequest.setAttribute(
"org.apache.tomcat.sendfile.filename","/etc/passwd");
HttpServletRequest.setAttribute(
"org.apache.tomcat.sendfile.start",Long.valueOf(0));
HttpServletRequest.setAttribute(
"org.apache.tomcat.sendfile.end",Long.valueOf(1000));
Specifying a end point after the end of the file will trigger a JVM
crash with the HTTP APR connector and an infinite loop with the HTTP NIO
connector.

Credit:
These issues were identified by the Tomcat security team.

References:
http://tomcat.apache.org/security.html
http://tomcat.apache.org/security-7.html
http://tomcat.apache.org/security-6.html
http://tomcat.apache.org/security-5.html

The Apache Tomcat Security Team

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJOHbrCAAoJEBDAHFovYFnnUZsQANIh02dK4r0cYCwsD59Xvg0R
cCpx0MCzsrVBKU/fJ5nQtVTtZnOVfH2PnZBPFlYxQXpBCgIQh+ZIp9ntGdSNP0kH
e7XgHaG6NipfIPusnQyH8yYmcfRl4BDnQdHyrl1JqApDtqnzPJ4Re9SVQC5VymJP
i9DlvuV4atAdSCgOZzBb3+wMV0uoZqjXcUZrQEXCYBhtGFtOQM/JyMUa7iu5+FhI
AuUchlHw3N+nZ+b4QeXGdFowHMTlJoj0gv5eMCEMVfiaoM5COcaQYBRQxkbNhkfN
7zkcKKyDG2ARIJ7WB3Ncj7A4RfF2KY98q69px6RU2ho8umOycl32dw3wT1AtPWUx
3TkTgkN4FXDprCLp1r/csbYO15GSoI0selWzKxmOOuMIIamQ36HreUInZzXohuOJ
VSdR/LBekdfiLNkNtIwK7oeaZoYqPT14F15C+gkzw8a7ETzN6kyYwZz2+dnnWvxM
lV5WhEksulVfrfro6OBFI4k4KVyCq/QYRUH2WfyaRyUhRB8of6tnweB46upzzoAU
+YtyLPimURofJbcw4Ut4VBvjVJTdts3air32vCKxpfnjdn9Gd3GH3phjrsYzJHTl
fg3RcqrmV9I0gxLn5oWIMx17gOGpFOgSwMyGgm/WEJLyiEV5suSPFVjMFq3znj+7
zAlePYK10YSe5XiZ9g8F
=MeHU
-END PGP SIGNATURE-



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



Re: [SECURITY] CVE-2011-2526 Apache Tomcat Information disclosure and availability vulnerabilities

2011-07-13 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

All,

Great catch to all who were involved in discovery and mitigation of this
vulnerability.

Since the APR flavor of this vulnerability uses native code to crash the
JVM and/or read files without asking the SecurityManager for permission,
does that mean that the APR SSL configuration could be similarly
attacked by specifying certificate file, etc. paths that shouldn't be
allowed by the SecurityManager?

I don't think there's a disclosure here (specifying /etc/passwd for a
certificate file doesn't dump /etc/passwd) but there might be
opportunities for a JVM crash.

- -chris

On 7/13/2011 11:33 AM, Mark Thomas wrote:
> CVE-2011-2526: Apache Tomcat Information disclosure and availability 
> vulnerabilities
> 
> Severity: low
> 
> Vendor: The Apache Software Foundation
> 
> Versions Affected: Tomcat 7.0.0 to 7.0.18 Tomcat 6.0.0 to 6.0.32 
> Tomcat 5.5.0 to 5.0.33 Previous, unsupported versions may be
> affected Additionally, these vulnerabilities only occur when all of
> the following are true: a) untrusted web applications are being used 
> b) the SecurityManager is used to limit the untrusted web
> applications c) the HTTP NIO or HTTP APR connector is used d)
> sendfile is enabled for the connector (this is the default)
> 
> Description: Tomcat provides support for sendfile with the HTTP NIO
> and HTTP APR connectors. sendfile is used automatically for content
> served via the DefaultServlet and deployed web applications may use
> it directly via setting request attributes. These request attributes
> were not validated. When running under a security manager, this lack
> of validation allowed a malicious web application to do one or more
> of the following that would normally be prevented by a security
> manager: a) return files to users that the security manager should
> make inaccessible b) terminate (via a crash) the JVM
> 
> Mitigation: Affected users of all versions can mitigate these
> vulnerabilities by taking any of the following actions: a) undeploy
> untrusted web applications b) switch to the HTTP BIO connector (which
> does not support sendfile) c) disable sendfile be setting
> useSendfile="false" on the connector d) apply the patch(es) listed on
> the Tomcat security pages (see references) e) upgrade to a version
> where the vulnerabilities have been fixed Tomcat 7.0.x users may
> upgrade to 7.0.19 or later once released Tomcat 6.0.x users may
> upgrade to 6.0.33 or later once released Tomcat 5.5.x users may
> upgrade to 5.5.34 or later once released
> 
> Example: Exposing the first 1000 bytes of /etc/passwd 
> HttpServletRequest.setAttribute( 
> "org.apache.tomcat.sendfile.filename","/etc/passwd"); 
> HttpServletRequest.setAttribute( 
> "org.apache.tomcat.sendfile.start",Long.valueOf(0)); 
> HttpServletRequest.setAttribute( 
> "org.apache.tomcat.sendfile.end",Long.valueOf(1000)); Specifying a
> end point after the end of the file will trigger a JVM crash with the
> HTTP APR connector and an infinite loop with the HTTP NIO connector.
> 
> Credit: These issues were identified by the Tomcat security team.
> 
> References: http://tomcat.apache.org/security.html 
> http://tomcat.apache.org/security-7.html 
> http://tomcat.apache.org/security-6.html 
> http://tomcat.apache.org/security-5.html
> 
> The Apache Tomcat Security Team
> 
> 
> 
> 
> -
>
> 
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
> For additional commands, e-mail: dev-h...@tomcat.apache.org
> 
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.10 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk4dxHoACgkQ9CaO5/Lv0PDykgCeNvC61SVMsawzVre/6ZxvR/+2
tvoAnRyoZQd14OJSo7+ExfWKSMnBTRex
=jpLx
-END PGP SIGNATURE-

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146113 - /tomcat/tc6.0.x/trunk/STATUS.txt

2011-07-13 Thread jfclere
Author: jfclere
Date: Wed Jul 13 16:20:17 2011
New Revision: 1146113

URL: http://svn.apache.org/viewvc?rev=1146113&view=rev
Log:
My vote.

Modified:
tomcat/tc6.0.x/trunk/STATUS.txt

Modified: tomcat/tc6.0.x/trunk/STATUS.txt
URL: 
http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/STATUS.txt?rev=1146113&r1=1146112&r2=1146113&view=diff
==
--- tomcat/tc6.0.x/trunk/STATUS.txt (original)
+++ tomcat/tc6.0.x/trunk/STATUS.txt Wed Jul 13 16:20:17 2011
@@ -237,5 +237,5 @@ PATCHES PROPOSED TO BACKPORT:
   This is a port of r1145380, r1145383, r1145489, r1145571, r1145694 and
   r1146005
   http://people.apache.org/~markt/patches/2011-07-13-cve-2011-2526-tc6.patch
-  +1: markt
+  +1: markt, jfclere
   -1:



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146211 - in /tomcat/site/trunk: docs/resources.html xdocs/resources.xml

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 18:40:29 2011
New Revision: 1146211

URL: http://svn.apache.org/viewvc?rev=1146211&view=rev
Log:
Link what I meant to link

Modified:
tomcat/site/trunk/docs/resources.html
tomcat/site/trunk/xdocs/resources.xml

Modified: tomcat/site/trunk/docs/resources.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/resources.html?rev=1146211&r1=1146210&r2=1146211&view=diff
==
--- tomcat/site/trunk/docs/resources.html (original)
+++ tomcat/site/trunk/docs/resources.html Wed Jul 13 18:40:29 2011
@@ -211,8 +211,8 @@
 
 
 
-  A http://wiki.apache.org/tomcat/AddOns"/>list of third party
-  tools and add-ons (most of them free) is maintained on the
+  A http://wiki.apache.org/tomcat/AddOns";>list of third party
+  tools and add-ons (most of them free) is maintained on the
   http://wiki.apache.org/tomcat/FrontPage";>Apache Tomcat wiki.
   Please note that the Apache Tomcat project doesn't endorse any of the 
products
   listed. If you use or develop a tool or add-on for Apache Tomcat please feel

Modified: tomcat/site/trunk/xdocs/resources.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/resources.xml?rev=1146211&r1=1146210&r2=1146211&view=diff
==
--- tomcat/site/trunk/xdocs/resources.xml (original)
+++ tomcat/site/trunk/xdocs/resources.xml Wed Jul 13 18:40:29 2011
@@ -10,8 +10,8 @@
 
 
 
-  A http://wiki.apache.org/tomcat/AddOns";>list of third party
-  tools and add-ons (most of them free) is maintained on the
+  A http://wiki.apache.org/tomcat/AddOns";>list of third party
+  tools and add-ons (most of them free) is maintained on the
   http://wiki.apache.org/tomcat/FrontPage";>Apache Tomcat wiki.
   Please note that the Apache Tomcat project doesn't endorse any of the 
products
   listed. If you use or develop a tool or add-on for Apache Tomcat please feel



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146504 - in /tomcat/tc7.0.x/tags/TOMCAT_7_0_19: ./ build.properties.default modules/bayeux/ modules/tomcat-lite/

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 22:29:07 2011
New Revision: 1146504

URL: http://svn.apache.org/viewvc?rev=1146504&view=rev
Log:
Tag 7.0.19

Added:
tomcat/tc7.0.x/tags/TOMCAT_7_0_19/
  - copied from r1146503, tomcat/trunk/
Removed:
tomcat/tc7.0.x/tags/TOMCAT_7_0_19/modules/bayeux/
tomcat/tc7.0.x/tags/TOMCAT_7_0_19/modules/tomcat-lite/
Modified:
tomcat/tc7.0.x/tags/TOMCAT_7_0_19/build.properties.default

Modified: tomcat/tc7.0.x/tags/TOMCAT_7_0_19/build.properties.default
URL: 
http://svn.apache.org/viewvc/tomcat/tc7.0.x/tags/TOMCAT_7_0_19/build.properties.default?rev=1146504&r1=1146503&r2=1146504&view=diff
==
--- tomcat/tc7.0.x/tags/TOMCAT_7_0_19/build.properties.default (original)
+++ tomcat/tc7.0.x/tags/TOMCAT_7_0_19/build.properties.default Wed Jul 13 
22:29:07 2011
@@ -29,7 +29,7 @@ version.major=7
 version.minor=0
 version.build=19
 version.patch=0
-version.suffix=-dev
+version.suffix=
 
 # - Build control flags -
 # Note enabling validation uses Checkstyle which is LGPL licensed



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



svn commit: r1146505 - in /tomcat/trunk: build.properties.default res/maven/mvn.properties.default

2011-07-13 Thread markt
Author: markt
Date: Wed Jul 13 22:31:04 2011
New Revision: 1146505

URL: http://svn.apache.org/viewvc?rev=1146505&view=rev
Log:
Update ready for next release

Modified:
tomcat/trunk/build.properties.default
tomcat/trunk/res/maven/mvn.properties.default

Modified: tomcat/trunk/build.properties.default
URL: 
http://svn.apache.org/viewvc/tomcat/trunk/build.properties.default?rev=1146505&r1=1146504&r2=1146505&view=diff
==
--- tomcat/trunk/build.properties.default (original)
+++ tomcat/trunk/build.properties.default Wed Jul 13 22:31:04 2011
@@ -27,7 +27,7 @@
 # - Version Control Flags -
 version.major=7
 version.minor=0
-version.build=19
+version.build=20
 version.patch=0
 version.suffix=-dev
 

Modified: tomcat/trunk/res/maven/mvn.properties.default
URL: 
http://svn.apache.org/viewvc/tomcat/trunk/res/maven/mvn.properties.default?rev=1146505&r1=1146504&r2=1146505&view=diff
==
--- tomcat/trunk/res/maven/mvn.properties.default (original)
+++ tomcat/trunk/res/maven/mvn.properties.default Wed Jul 13 22:31:04 2011
@@ -33,12 +33,12 @@ maven.snapshot.repo.repositoryId=apache.
 #Maven release properties for Tomcat staging
 
maven.release.repo.url=scp://people.apache.org/www/tomcat.apache.org/dev/dist/m2-repository
 maven.release.repo.repositoryId=tomcat-staging
-maven.release.deploy.version=7.0.19
+maven.release.deploy.version=7.0.20
 
 #Maven release properties for the main ASF repo
 
maven.asf.release.repo.url=scp://people.apache.org/www/people.apache.org/repo/m2-ibiblio-rsync-repository
 maven.asf.release.repo.repositoryId=apache.releases
-maven.asf.release.deploy.version=7.0.19
+maven.asf.release.deploy.version=7.0.20
 
 
 #Where do we load the libraries from



-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 51505] New: Blue Screen When shutdown the Tomcat Window

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=51505

 Bug #: 51505
   Summary: Blue Screen When shutdown the Tomcat Window
   Product: Tomcat 7
   Version: 7.0.16
  Platform: PC
Status: NEW
  Severity: critical
  Priority: P2
 Component: Catalina
AssignedTo: dev@tomcat.apache.org
ReportedBy: yzhang8...@126.com
Classification: Unclassified


Created attachment 27283
  --> https://issues.apache.org/bugzilla/attachment.cgi?id=27283
Blue Screen Error Info

问题签名:
  问题事件名称:BlueScreen
  OS 版本:6.1.7600.2.0.0.256.1
  区域设置 ID:2052

有关该问题的其他信息:
  BCCode:f4
  BCP1:0003
  BCP2:884F8D40
  BCP3:884F8EAC
  BCP4:84245D50
  OS Version:6_1_7600
  Service Pack:0_0
  Product:256_1

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.
-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org



DO NOT REPLY [Bug 51505] Blue Screen When shutdown the Tomcat Window

2011-07-13 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=51505

Ying Zhang  changed:

   What|Removed |Added

 CC||yzhang8...@126.com
 OS/Version||All

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.

-
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org