https://issues.apache.org/bugzilla/show_bug.cgi?id=46808
--- Comment #14 from Rainer Jung 2009-03-09 20:01:13
PST ---
I discussed with Mladen and we both committed a few changes.
But let's first express our expectation to what should happen.
We don't want the system to behave overly nervo
Author: rjung
Date: Tue Mar 10 02:23:51 2009
New Revision: 751965
URL: http://svn.apache.org/viewvc?rev=751965&view=rev
Log:
Make forced recovery work with local error states
in LB worker.
Modified:
tomcat/connectors/trunk/jk/native/common/jk_lb_worker.c
tomcat/connectors/trunk/jk/xdocs/m
Author: rjung
Date: Tue Mar 10 02:14:44 2009
New Revision: 751962
URL: http://svn.apache.org/viewvc?rev=751962&view=rev
Log:
We shouldn't overwrite global error state in cases
where we don't know the real state. If it was real
error before, then keep it in error.
So in all cases except previous g
Author: rjung
Date: Tue Mar 10 02:09:05 2009
New Revision: 751959
URL: http://svn.apache.org/viewvc?rev=751959&view=rev
Log:
Move JK_AJP_PROTOCOL_ERROR in front of JK_STATUS_ERROR
to keep JK_STATUS_ERROR and JK_STATUS_FATAL_ERROR
close together.
Modified:
tomcat/connectors/trunk/jk/native/com
Author: rjung
Date: Tue Mar 10 01:43:37 2009
New Revision: 751945
URL: http://svn.apache.org/viewvc?rev=751945&view=rev
Log:
Include error time in status worker display.
Modified:
tomcat/connectors/trunk/jk/native/common/jk_status.c
tomcat/connectors/trunk/jk/xdocs/miscellaneous/changelog
Author: rjung
Date: Tue Mar 10 01:41:22 2009
New Revision: 751942
URL: http://svn.apache.org/viewvc?rev=751942&view=rev
Log:
Fix crash in text display of status worker.
Modified:
tomcat/connectors/trunk/jk/native/common/jk_status.c
tomcat/connectors/trunk/jk/xdocs/miscellaneous/changelog.
Author: rjung
Date: Tue Mar 10 00:49:12 2009
New Revision: 751924
URL: http://svn.apache.org/viewvc?rev=751924&view=rev
Log:
Add error_escalation_time to the docs.
Modified:
tomcat/connectors/trunk/jk/xdocs/miscellaneous/changelog.xml
tomcat/connectors/trunk/jk/xdocs/reference/status.xml
Author: rjung
Date: Tue Mar 10 00:27:20 2009
New Revision: 751921
URL: http://svn.apache.org/viewvc?rev=751921&view=rev
Log:
Add error_escalation_time to status worker
(display and editing).
Modified:
tomcat/connectors/trunk/jk/native/common/jk_status.c
Modified: tomcat/connectors/trunk/jk/n
Author: rjung
Date: Tue Mar 10 00:25:25 2009
New Revision: 751920
URL: http://svn.apache.org/viewvc?rev=751920&view=rev
Log:
Also check local to global error escalation
during maintenance.
Add debug logging to both places where we escalate.
Modified:
tomcat/connectors/trunk/jk/native/common/j
Author: rjung
Date: Tue Mar 10 00:15:48 2009
New Revision: 751917
URL: http://svn.apache.org/viewvc?rev=751917&view=rev
Log:
Use new attribute error_escalation_time to decide,
whether an unspecified local error should be
escalated to a global error. Decision is based on
how long we already have a
Author: rjung
Date: Tue Mar 10 00:13:30 2009
New Revision: 751916
URL: http://svn.apache.org/viewvc?rev=751916&view=rev
Log:
Add new attribute error_escalation_time to structures,
initialize and add to pull and push.
Modified:
tomcat/connectors/trunk/jk/native/common/jk_lb_worker.c
tomcat
Author: rjung
Date: Tue Mar 10 00:10:49 2009
New Revision: 751914
URL: http://svn.apache.org/viewvc?rev=751914&view=rev
Log:
Add utility function to retrieve new attribute
error_escalation_time().
Modified:
tomcat/connectors/trunk/jk/native/common/jk_util.c
tomcat/connectors/trunk/jk/nati
Author: markt
Date: Mon Mar 9 22:18:26 2009
New Revision: 751878
URL: http://svn.apache.org/viewvc?rev=751878&view=rev
Log:
Fix typo in bug number reported on dev list
Modified:
tomcat/site/trunk/docs/security-4.html
tomcat/site/trunk/docs/security-5.html
Modified: tomcat/site/trunk/doc
Author: markt
Date: Mon Mar 9 22:18:05 2009
New Revision: 751877
URL: http://svn.apache.org/viewvc?rev=751877&view=rev
Log:
Fix typo in bug number reported on dev list
Modified:
tomcat/site/trunk/xdocs/security-4.xml
tomcat/site/trunk/xdocs/security-5.xml
Modified: tomcat/site/trunk/xdo
nambo.k...@oss.ntt.co.jp wrote:
> BTW I've found a typo in the security reports.
> http://tomcat.apache.org/security-5.html
> http://tomcat.apache.org/security-4.html
> low: Information disclosure CVE-2008-4308
> Bug 40711 may result in the disclosure of POSTed .
>
> 40711 -> 407
Author: fhanik
Date: Mon Mar 9 20:10:10 2009
New Revision: 751822
URL: http://svn.apache.org/viewvc?rev=751822&view=rev
Log:
Make a distinction between AM/PM by using the 24 hour format
Modified:
tomcat/trunk/java/org/apache/juli/OneLineFormatter.java
Modified: tomcat/trunk/java/org/apache/
From: ma...@apache.org
Subject: Re: [SECURITY] CVE-2008-4308: Tomcat information disclosure
vulnerability
Date: Thu, 05 Mar 2009 12:45:10 +0100
> nambo.k...@oss.ntt.co.jp wrote:
> > Hi, Mark.
> >
> >> The unsupported Tomcat 3.x, 4.0.x and 5.0.x versions may be also affected
> > I checked Tomcat
https://issues.apache.org/bugzilla/show_bug.cgi?id=46808
--- Comment #13 from Eiji Takahashi 2009-03-09 00:35:03
PST ---
> Nope this is completely valid. The node is retried in a conservative maner.
> Before pulling out the cable you should mark the node a Disabled, and
> when all sessions
18 matches
Mail list logo