[Bug 59206] When catalina.base is not specified, ConfigFileLoader throws an NPE in a static initializer

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59206 --- Comment #3 from Jeff Stark --- Are there any new updates to Apache Tomcat 9 (9.0.21)? I cannot open the pdf file The Challenges Tomcat Faces in High Throughput Production Systems by Huxing Zhang. Is NPE cause by sendfile? Sources: https://s

[GitHub] [tomcat] rmaucher commented on issue #171: Added new interface for pluggable paramater configuration

2019-06-20 Thread GitBox
rmaucher commented on issue #171: Added new interface for pluggable paramater configuration URL: https://github.com/apache/tomcat/pull/171#issuecomment-504219438 Tomcat maintains API compatibility in major branches (unless there's an extremely good reason to do otherwise). As a result, the

[GitHub] [tomcat] rmaucher closed pull request #171: Added new interface for pluggable paramater configuration

2019-06-20 Thread GitBox
rmaucher closed pull request #171: Added new interface for pluggable paramater configuration URL: https://github.com/apache/tomcat/pull/171 This is an automated message from the Apache Git Service. To respond to the message,

[Bug 63523] JSSEutilBase in tomcat-embed-core getParameters() visibility change breaks compatability and prevents OCSP SOFT_FAIL configuration

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63523 Remy Maucherat changed: What|Removed |Added Resolution|--- |FIXED Status|NEW

[tomcat] branch 8.5.x updated: 63523: Restore SSLUtilBase methods as protected to preserve compatibility (second attempt)

2019-06-20 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 15cd795 63523: Restore SSLUtilBase methods as prote

[tomcat] branch 8.5.x updated: 63523: Restore SSLUtilBase methods as protected to preserve compatibility

2019-06-20 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new b7a2aa3 63523: Restore SSLUtilBase methods as prote

[tomcat] branch master updated: 63523: Restore SSLUtilBase methods as protected to preserve compatibility

2019-06-20 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new b9e9801 63523: Restore SSLUtilBase methods as pro

[Bug 63523] New: JSSEutilBase in tomcat-embed-core getParameters() visibility change breaks compatability and prevents OCSP SOFT_FAIL configuration

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63523 Bug ID: 63523 Summary: JSSEutilBase in tomcat-embed-core getParameters() visibility change breaks compatability and prevents OCSP SOFT_FAIL configuration Product: Tomcat 9

[tomcat] branch master updated: Fix date

2019-06-20 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new 5bc2c10 Fix date 5bc2c10 is described below comm

[SECURITY][CORRECTION] CVE-2019-10072 Apache Tomcat HTTP/2 DoS

2019-06-20 Thread Mark Thomas
This updated notice corrects the version numbers in the mitigation section. CVE-2019-10072 Apache Tomcat HTTP/2 DoS Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.19 Apache Tomcat 8.5.0 to 8.5.40 Description: The fix for CVE-2019-01

[SECURITY] CVE-2019-10072 Apache Tomcat HTTP/2 DoS

2019-06-20 Thread Mark Thomas
CVE-2019-10072 Apache Tomcat HTTP/2 DoS Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.19 Apache Tomcat 8.5.0 to 8.5.40 Description: The fix for CVE-2019-0199 was incomplete and did not address connection window exhaustion on write. B

[tomcat] branch 8.5.x updated: Add reference to CVE-2019-10072

2019-06-20 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 6a46a68 Add reference to CVE-2019-10072 6a46a68 is

[tomcat] branch master updated: Add reference to CVE-2019-10072

2019-06-20 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new 400fe18 Add reference to CVE-2019-10072 400fe18

svn commit: r1861711 - in /tomcat/site/trunk: docs/security-8.html docs/security-9.html xdocs/security-8.xml xdocs/security-9.xml

2019-06-20 Thread markt
Author: markt Date: Thu Jun 20 19:20:22 2019 New Revision: 1861711 URL: http://svn.apache.org/viewvc?rev=1861711&view=rev Log: Add CVE-2019-10072 Modified: tomcat/site/trunk/docs/security-8.html tomcat/site/trunk/docs/security-9.html tomcat/site/trunk/xdocs/security-8.xml tomcat/s

Re: JDK 13 enters Rampdown Phase One

2019-06-20 Thread Mark Thomas
On 20/06/2019 08:05, Rory O'Donnell wrote: > Hi Remy, > > We would be very interested in hearing of any issues you uncover ? I ran the 7.0.x test suite under the JDK13 ea 25 and did not encounter any errors. Mark > > Rgds,Rory > > On 17/06/2019 13:01, Rémy Maucherat wrote: >> On Sun, Jun 16,

[Bug 63500] Core dump using APR tomcat native with certificateRevocationListFile

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63500 --- Comment #10 from Mark Thomas --- Current plans are: - 9.0.x early July - Native 1.2.22 before then so it can be packaged in the next 9.0.x release You can follow progress on the dev@ list. -- You are receiving this mail because: You are

[Bug 63500] Core dump using APR tomcat native with certificateRevocationListFile

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63500 --- Comment #9 from Bruno --- Thank you for the investigation and fix. What is the release cycle for tomcat native and tomcat 9? -- You are receiving this mail because: You are the assignee for the bug. --

[Bug 63310] Update Commons Daemon for improved Java 11 support

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63310 --- Comment #2 from Mark Thomas --- Another note to self: Commons Daemon 1.2.0 onwards will default to running the service as the LocalService user rather than LocalSystem. That will break a default Tomcat install via the installer since Local

Re: [tomcat-native] 02/02: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=63500

2019-06-20 Thread Konstantin Kolinko
чт, 20 июн. 2019 г. в 16:54, : > > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch master > in repository https://gitbox.apache.org/repos/asf/tomcat-native.git > > commit 02fcf97f1b2a1db04b7dd674daf6ab3a5f77312e > Author: Mark Thomas > Author

Time for a Tomcat Native release

2019-06-20 Thread Mark Thomas
Hi, I'd like to get the crash on start with APR and CRL configured fixed in the next round of Tomcat releases so that means we need a Tomcat Native release fairly soon. My current plan is to tag sometime between late tomorrow and early next week with a view to getting the release out by the end o

[tomcat-native] 02/02: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=63500

2019-06-20 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat-native.git commit 02fcf97f1b2a1db04b7dd674daf6ab3a5f77312e Author: Mark Thomas AuthorDate: Wed Jun 19 18:19:25 2019 +0100 Fix h

[tomcat-native] branch master updated (2925e14 -> 02fcf97)

2019-06-20 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch master in repository https://gitbox.apache.org/repos/asf/tomcat-native.git. from 2925e14 More ignores for the native build new aabc687 ws new 02fcf97 Fix https://bz.apache.org/bug

[tomcat-native] 01/02: ws

2019-06-20 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat-native.git commit aabc68777034d67388921cd93741cd4ad0e505be Author: Mark Thomas AuthorDate: Wed Jun 19 17:08:16 2019 +0100 ws --

[Bug 62911] Add support for proxying ocsp requests via ProxyHost and ProxyPort in TomcAt

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=62911 --- Comment #3 from Mark Thomas --- The APR/native connector does not support OCSP stapling. This is being tracked as under bug 56148 -- You are receiving this mail because: You are the assignee for the bug. --

[Bug 63405] Tomcat 7.0.91.0 EXCEPTION_ACCESS_VIOLATION - Problematic frame tcnative-1.dll+0x802e

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63405 Mark Thomas changed: What|Removed |Added Status|NEW |NEEDINFO OS|

[Bug 59286] Socket binding failures when using APR

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59286 Mark Thomas changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

[Bug 63521] New: javax.websocket.server.ServerContainer.addEndpoint(Class endpointClass) throws DeploymentException

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63521 Bug ID: 63521 Summary: javax.websocket.server.ServerContainer.addEndpoint(Cla ss endpointClass) throws DeploymentException Product: Tomcat 8 Version: 8.5.x-trunk Hardware

[Bug 59449] org.apache.catalina.core.ContainerBase#removeChild remove order

2019-06-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59449 --- Comment #2 from ralphcorrales --- Read https://theessayservice.org/buy-book-review/ for issues on standard implementation of ServletContext that represents a web application's execution environment descriptions. -- You are receiving this

Re: JDK 13 enters Rampdown Phase One

2019-06-20 Thread Rory O'Donnell
Hi Remy, We would be very interested in hearing of any issues you uncover ? Rgds,Rory On 17/06/2019 13:01, Rémy Maucherat wrote: On Sun, Jun 16, 2019 at 8:01 AM Rory O'Donnell mailto:rory.odonn...@oracle.com>> wrote: Hi Mark, *JDK 13 Early Access build **25 is now available **at : -