Re: [VOTE] Release Apache Tomcat 8.0.2

2014-02-06 Thread Konstantin Kolinko
2014-02-07 Ognjen Blagojevic : > On 6.2.2014 21:23, Mark Thomas wrote: >> >> - Update to the latest DBCP 2 snapshot > > (...) >> >> The proposed 8.0.2 release is: >> [X] Broken - do not release >> >> [ ] Alpha - go ahead and release as 8.0.2 (alpha) >> [ ] Beta - go ahead and release as 8.0.2 (b

svn commit: r1565512 - in /tomcat/trunk: build.xml webapps/docs/changelog.xml

2014-02-06 Thread kkolinko
Author: kkolinko Date: Fri Feb 7 01:34:16 2014 New Revision: 1565512 URL: http://svn.apache.org/r1565512 Log: Fix build of DBCP2. The project structure has changed and the classes are now in src/main, like in Pool2. This issue was reported in the VOTE thread for 8.0.2. Modified: tomcat/trun

Re: Time for 7.0.51

2014-02-06 Thread Konstantin Kolinko
2014-02-05 Violeta Georgieva : > Hi, > > I want to start the release procedure for Tomcat 7.0.51. > If you would like to add something to this release please respond to this > mail. > Running testsuite BIO,NIO,APR on current 7.0.x (@ r1565513) Win7, Java 6u45 (+7u51) 32-bit. (TC Native 1.1.29).

buildbot success in ASF Buildbot on tomcat-trunk

2014-02-06 Thread buildbot
The Buildbot has detected a restored build on builder tomcat-trunk while building ASF Buildbot. Full details are available at: http://ci.apache.org/builders/tomcat-trunk/builds/5482 Buildbot URL: http://ci.apache.org/ Buildslave for this Build: bb-vm_ubuntu Build Reason: scheduler Build Source

Re: [VOTE] Release Apache Tomcat 8.0.2

2014-02-06 Thread Ognjen Blagojevic
On 6.2.2014 21:23, Mark Thomas wrote: - Update to the latest DBCP 2 snapshot (...) The proposed 8.0.2 release is: [X] Broken - do not release [ ] Alpha - go ahead and release as 8.0.2 (alpha) [ ] Beta - go ahead and release as 8.0.2 (beta) [ ] Stable - go ahead and release as 8.0.2 (stable)

buildbot success in ASF Buildbot on tomcat-7-trunk

2014-02-06 Thread buildbot
The Buildbot has detected a restored build on builder tomcat-7-trunk while building ASF Buildbot. Full details are available at: http://ci.apache.org/builders/tomcat-7-trunk/builds/1744 Buildbot URL: http://ci.apache.org/ Buildslave for this Build: bb-vm_ubuntu Build Reason: scheduler Build So

[Bug 56115] Need to provide parameters to Ant's get task to reliably download behind firewall and proxy

2014-02-06 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56115 --- Comment #2 from Anthony --- Created attachment 31290 --> https://issues.apache.org/bugzilla/attachment.cgi?id=31290&action=edit Additional default properties to add to build.properties.default -- You are receiving this mail because:

[Bug 56115] Need to provide parameters to Ant's get task to reliably download behind firewall and proxy

2014-02-06 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56115 --- Comment #1 from Anthony --- Created attachment 31289 --> https://issues.apache.org/bugzilla/attachment.cgi?id=31289&action=edit Change of trydownload target in build.xml -- You are receiving this mail because: You are the assignee f

svn commit: r1565458 - in /tomcat/tc7.0.x/trunk: ./ test/org/apache/catalina/valves/TesterAccessLogValve.java

2014-02-06 Thread kkolinko
Author: kkolinko Date: Thu Feb 6 22:08:25 2014 New Revision: 1565458 URL: http://svn.apache.org/r1565458 Log: Merged revisions r1562458, r1565451 from tomcat/trunk: Provide more info if test fails in access log valve check. Modified: tomcat/tc7.0.x/trunk/ (props changed) tomcat/tc7.0.

[Bug 56115] New: Need to provide parameters to Ant's get task to reliably download behind firewall and proxy

2014-02-06 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56115 Bug ID: 56115 Summary: Need to provide parameters to Ant's get task to reliably download behind firewall and proxy Product: Tomcat 7 Version: 7.0.47 Hardware: Sun

svn commit: r1565451 - /tomcat/trunk/test/org/apache/catalina/valves/TesterAccessLogValve.java

2014-02-06 Thread kkolinko
Author: kkolinko Date: Thu Feb 6 21:49:31 2014 New Revision: 1565451 URL: http://svn.apache.org/r1565451 Log: Correct typo in message printed by validateAccessLog() when a testcase runs too long. Modified: tomcat/trunk/test/org/apache/catalina/valves/TesterAccessLogValve.java Modified: tom

buildbot failure in ASF Buildbot on tomcat-trunk

2014-02-06 Thread buildbot
The Buildbot has detected a new failure on builder tomcat-trunk while building ASF Buildbot. Full details are available at: http://ci.apache.org/builders/tomcat-trunk/builds/5480 Buildbot URL: http://ci.apache.org/ Buildslave for this Build: bb-vm_ubuntu Build Reason: scheduler Build Source St

[VOTE] Release Apache Tomcat 8.0.2

2014-02-06 Thread Mark Thomas
The proposed Apache Tomcat 8.0.2 release is now available for voting. The main changes since 8.0.1 are: - Fix CVE-2014-0050, a DoS related to multi-part processing - Enable non-blocking reads to take place on non-container threads - Update to the latest DBCP 2 snapshot - Fix WebDAV support broken

svn commit: r4323 [2/2] - in /dev/tomcat/tomcat-8/v8.0.2: ./ bin/ bin/embed/ bin/extras/ src/

2014-02-06 Thread markt
Added: dev/tomcat/tomcat-8/v8.0.2/src/apache-tomcat-8.0.2-src.tar.gz.md5 == --- dev/tomcat/tomcat-8/v8.0.2/src/apache-tomcat-8.0.2-src.tar.gz.md5 (added) +++ dev/tomcat/tomcat-8/v8.0.2/src/apache-tomcat-8.0.2-src.tar.gz.md5

svn commit: r4322 - /dev/tomcat/tomcat-8/v8.0.1/

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 19:59:06 2014 New Revision: 4322 Log: Drop 8.0.1 Removed: dev/tomcat/tomcat-8/v8.0.1/ - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomc

svn commit: r1565426 - in /tomcat/tc8.0.x/tags/TOMCAT_8_0_2: ./ build.properties.default

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 19:50:34 2014 New Revision: 1565426 URL: http://svn.apache.org/r1565426 Log: Tag 8.0.2 Added: tomcat/tc8.0.x/tags/TOMCAT_8_0_2/ - copied from r1565424, tomcat/trunk/ Modified: tomcat/tc8.0.x/tags/TOMCAT_8_0_2/build.properties.default Modified: tomcat/

svn commit: r1565425 - /tomcat/tc8.0.x/tags/TOMCAT_8_0_2/

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 19:50:26 2014 New Revision: 1565425 URL: http://svn.apache.org/r1565425 Log: Drop 8.0.2 tag to re-tag Removed: tomcat/tc8.0.x/tags/TOMCAT_8_0_2/ - To unsubscribe, e-mail: dev-unsubscr...@tomca

Re: svn commit: r1565424 - /tomcat/trunk/webapps/docs/changelog.xml

2014-02-06 Thread Mark Thomas
On 06/02/2014 19:47, kkoli...@apache.org wrote: > Author: kkolinko > Date: Thu Feb 6 19:47:31 2014 > New Revision: 1565424 > > URL: http://svn.apache.org/r1565424 > Log: > Changelog entry for r1565300, r1565416. I'll re-tag to pick that up. Mark ---

svn commit: r1565424 - /tomcat/trunk/webapps/docs/changelog.xml

2014-02-06 Thread kkolinko
Author: kkolinko Date: Thu Feb 6 19:47:31 2014 New Revision: 1565424 URL: http://svn.apache.org/r1565424 Log: Changelog entry for r1565300, r1565416. Modified: tomcat/trunk/webapps/docs/changelog.xml Modified: tomcat/trunk/webapps/docs/changelog.xml URL: http://svn.apache.org/viewvc/tomcat

svn commit: r1565423 - in /tomcat/tc8.0.x/tags/TOMCAT_8_0_2: ./ build.properties.default

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 19:46:40 2014 New Revision: 1565423 URL: http://svn.apache.org/r1565423 Log: Tag 8.0.2 Added: tomcat/tc8.0.x/tags/TOMCAT_8_0_2/ - copied from r1565422, tomcat/trunk/ Modified: tomcat/tc8.0.x/tags/TOMCAT_8_0_2/build.properties.default Modified: tomcat/

svn commit: r1565422 - in /tomcat/trunk: build.properties.default webapps/docs/changelog.xml

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 19:44:40 2014 New Revision: 1565422 URL: http://svn.apache.org/r1565422 Log: Update Commons DBCP snapshot Modified: tomcat/trunk/build.properties.default tomcat/trunk/webapps/docs/changelog.xml Modified: tomcat/trunk/build.properties.default URL: http://sv

svn commit: r1565419 - in /tomcat/tc7.0.x/trunk: ./ java/org/apache/catalina/manager/HTMLManagerServlet.java webapps/docs/changelog.xml

2014-02-06 Thread kkolinko
Author: kkolinko Date: Thu Feb 6 19:42:10 2014 New Revision: 1565419 URL: http://svn.apache.org/r1565419 Log: Merged revisions r1565300-r1565416 from tomcat/trunk: Improve handling of file upload errors. Display a message instead of error 500 page. Simplify parts handling code, as it is known th

svn commit: r1565416 - /tomcat/trunk/java/org/apache/catalina/manager/HTMLManagerServlet.java

2014-02-06 Thread kkolinko
Author: kkolinko Date: Thu Feb 6 19:29:48 2014 New Revision: 1565416 URL: http://svn.apache.org/r1565416 Log: Simplify code. There is no need to iterate over parts and cleanup them, Tomcat takes care of that in Request.recycle(). Modified: tomcat/trunk/java/org/apache/catalina/manager/HTMLM

Re: Time for 7.0.51

2014-02-06 Thread Mark Thomas
On 05/02/2014 10:10, Violeta Georgieva wrote: > Hi, > > I want to start the release procedure for Tomcat 7.0.51. > If you would like to add something to this release please respond to this > mail. Good to go from my point of view. Mark --

Re: [SECURITY] CVE-2014-0050 Apache Commons FileUpload and Apache Tomcat DoS

2014-02-06 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 06/02/2014 17:15, Christopher Schultz wrote: > Mark, > > On 2/6/14, 6:37 AM, Mark Thomas wrote: >> Mitigation: [...] - Limit the size of the Content-Type header to >> less than 4091 bytes > > Just confirming that I've read this properly: limiting

Re: [SECURITY] CVE-2014-0050 Apache Commons FileUpload and Apache Tomcat DoS

2014-02-06 Thread Christopher Schultz
Mark, On 2/6/14, 6:37 AM, Mark Thomas wrote: > Mitigation: > [...] > - Limit the size of the Content-Type header to less than 4091 bytes Just confirming that I've read this properly: limiting the size of the content-type *header* to 4901 bytes? So, don't accept "Content-Type: [4k worth of data]"

buildbot success in ASF Buildbot on tomcat-trunk

2014-02-06 Thread buildbot
The Buildbot has detected a restored build on builder tomcat-trunk while building ASF Buildbot. Full details are available at: http://ci.apache.org/builders/tomcat-trunk/builds/5479 Buildbot URL: http://ci.apache.org/ Buildslave for this Build: bb-vm_ubuntu Build Reason: scheduler Build Source

svn commit: r1565300 - /tomcat/trunk/java/org/apache/catalina/manager/HTMLManagerServlet.java

2014-02-06 Thread kkolinko
Author: kkolinko Date: Thu Feb 6 15:11:35 2014 New Revision: 1565300 URL: http://svn.apache.org/r1565300 Log: Followup to r1565163 Catch exceptions thrown by getParts() and report them as other upload errors (in the message box on the HTML page). Without this an uncaught exception resulted in E

Re: Re: support for salted passwords

2014-02-06 Thread Gabriel Sánchez Martínez
On 02/05/2014 05:12 PM, Christopher Schultz wrote: Gabriel, On 2/4/14, 3:29 PM, "Gabriel E. Sánchez Martínez" wrote: On 02/04/2014 12:20 PM, Christopher Schultz wrote: Nick, On 2/2/14, 2:51 AM, Nick Williams wrote: On Feb 2, 2014, at 1:23 AM, Gabriel E. Sánchez Martínez wrote: I am very ne

Re: support for salted passwords

2014-02-06 Thread Christopher Schultz
Ognjen, On 2/5/14, 6:36 AM, Ognjen Blagojevic wrote: > On 4.2.2014 21:29, "Gabriel E. Sánchez Martínez" wrote: >>> I've been tossing-around some upgrades in my mind for the realm >>> implementations that would allow for better pluggability for things like >>> this. Right now, the only way to imple

svn commit: r1565221 - in /tomcat/site/trunk: docs/security-7.html xdocs/security-7.xml

2014-02-06 Thread kkolinko
Author: kkolinko Date: Thu Feb 6 13:10:11 2014 New Revision: 1565221 URL: http://svn.apache.org/r1565221 Log: Followup to r1565181 Correct version numbers on Tomcat 7 page Modified: tomcat/site/trunk/docs/security-7.html tomcat/site/trunk/xdocs/security-7.xml Modified: tomcat/site/trunk

buildbot failure in ASF Buildbot on tomcat-trunk

2014-02-06 Thread buildbot
The Buildbot has detected a new failure on builder tomcat-trunk while building ASF Buildbot. Full details are available at: http://ci.apache.org/builders/tomcat-trunk/builds/5478 Buildbot URL: http://ci.apache.org/ Buildslave for this Build: bb-vm_ubuntu Build Reason: scheduler Build Source St

[Bug 51147] Deploy from Manager fail in 403

2014-02-06 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=51147 --- Comment #11 from Konstantin Kolinko --- (In reply to Madhiyalagan from comment #10) Not here. See Comment 1 above. http://tomcat.apache.org/bugreport.html#Bugzilla_is_not_a_support_forum -- You are receiving this mail because: You ar

buildbot failure in ASF Buildbot on tomcat-7-trunk

2014-02-06 Thread buildbot
The Buildbot has detected a new failure on builder tomcat-7-trunk while building ASF Buildbot. Full details are available at: http://ci.apache.org/builders/tomcat-7-trunk/builds/1742 Buildbot URL: http://ci.apache.org/ Buildslave for this Build: bb-vm_ubuntu Build Reason: scheduler Build Sourc

[Bug 51147] Deploy from Manager fail in 403

2014-02-06 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=51147 Madhiyalagan changed: What|Removed |Added CC||ma...@smartrx.in --- Comment #10 fr

svn commit: r1565187 - /tomcat/site/trunk/build.xml

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 11:52:14 2014 New Revision: 1565187 URL: http://svn.apache.org/r1565187 Log: Remove my local hack Modified: tomcat/site/trunk/build.xml Modified: tomcat/site/trunk/build.xml URL: http://svn.apache.org/viewvc/tomcat/site/trunk/build.xml?rev=1565187&r1=1565186&r

Re: svn commit: r1565181 - in /tomcat/site/trunk: build.xml docs/security-7.html docs/security-8.html xdocs/security-7.xml xdocs/security-8.xml

2014-02-06 Thread Mark Thomas
On 06/02/2014 11:50, Konstantin Kolinko wrote: > 2014-02-06 : >> Author: markt >> Date: Thu Feb 6 11:32:14 2014 >> New Revision: 1565181 >> >> URL: http://svn.apache.org/r1565181 >> Log: >> Add details for CVE-2014-0050 >> >> Modified: >> tomcat/site/trunk/build.xml >> tomcat/site/trunk/d

Re: svn commit: r1565181 - in /tomcat/site/trunk: build.xml docs/security-7.html docs/security-8.html xdocs/security-7.xml xdocs/security-8.xml

2014-02-06 Thread Konstantin Kolinko
2014-02-06 : > Author: markt > Date: Thu Feb 6 11:32:14 2014 > New Revision: 1565181 > > URL: http://svn.apache.org/r1565181 > Log: > Add details for CVE-2014-0050 > > Modified: > tomcat/site/trunk/build.xml > tomcat/site/trunk/docs/security-7.html > tomcat/site/trunk/docs/security-8.

[SECURITY] CVE-2014-0050 Apache Commons FileUpload and Apache Tomcat DoS

2014-02-06 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2014-0050 Apache Commons FileUpload and Apache Tomcat DoS Severity: Important Vendor: The Apache Software Foundation Versions Affected: - - Commons FileUpload 1.0 to 1.3 - - Apache Tomcat 8.0.0-RC1 to 8.0.1 - - Apache Tomcat 7.0.0 to 7.0.50 - -

svn commit: r1565181 - in /tomcat/site/trunk: build.xml docs/security-7.html docs/security-8.html xdocs/security-7.xml xdocs/security-8.xml

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 11:32:14 2014 New Revision: 1565181 URL: http://svn.apache.org/r1565181 Log: Add details for CVE-2014-0050 Modified: tomcat/site/trunk/build.xml tomcat/site/trunk/docs/security-7.html tomcat/site/trunk/docs/security-8.html tomcat/site/trunk/xdocs/sec

svn commit: r1565169 - in /tomcat/tc7.0.x/trunk: java/org/apache/tomcat/util/http/fileupload/ java/org/apache/tomcat/util/http/fileupload/FileUploadBase.java java/org/apache/tomcat/util/http/fileuploa

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 11:21:07 2014 New Revision: 1565169 URL: http://svn.apache.org/r1565169 Log: Fix CVE-2014-0050 DoS with malformed Content-Type header and multipart request processing. Update to latest code (r1565163) from Commons FileUpload Modified: tomcat/tc7.0.x/trunk/java/

svn commit: r1565163 - in /tomcat/trunk: java/org/apache/tomcat/util/http/fileupload/ java/org/apache/tomcat/util/http/fileupload/FileUploadBase.java java/org/apache/tomcat/util/http/fileupload/Multip

2014-02-06 Thread markt
Author: markt Date: Thu Feb 6 11:08:00 2014 New Revision: 1565163 URL: http://svn.apache.org/r1565163 Log: Fix CVE-2014-0050 DoS with malformed Content-Type header and multipart request processing. Update to latest code (r1565159) from Commons FileUpload Modified: tomcat/trunk/java/org/apac

[Bug 51966] Tomcat does not support ssha hashed passwords in all contexts

2014-02-06 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=51966 --- Comment #21 from S --- In order to illustrate how I understood possibilities and their use in Tomcat, I made a list of authentication mechanisms: 0) Compare the sent PW to the stored PW 1) Hashing the sent PW on the server, compare it