[Bug 66609] invalid XML in directory listing with file names containing "&" and "'"

2023-05-24 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=66609 Han Li changed: What|Removed |Added Resolution|DUPLICATE |FIXED --- Comment #5 from Han Li --- Fixed i

[tomcat] branch 8.5.x updated: Drop files Windows doesn't like.

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 5400a8616e Drop files Windows doesn't like. 5400a86

[tomcat] branch 9.0.x updated: Drop files Windows doesn't like.

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 1b95bf7e32 Drop files Windows doesn't like. 1b95bf7

[tomcat] branch 10.1.x updated: Drop files Windows doesn't like.

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 21a5c1ddf7 Drop files Windows doesn't like. 21a5c

[tomcat] branch main updated: Drop files Windows doesn't like.

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 4ad8e490b0 Drop files Windows doesn't like. 4ad8e490b

[tomcat] branch 10.1.x updated (a810f2c54a -> 7828614e36)

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git from a810f2c54a Reduce code duplication new 7d9cacdfc2 Don't set 'C-L: 0' for HEAD requests if Servlet doesn't specify

[tomcat] 02/02: Fix failing test. There should be no C-L for HEAD unless Servlet sets it

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 7828614e36069ef1d08ad7eab36b4708bfaae9a2 Author: Mark Thomas AuthorDate: Wed May 24 19:39:17 2023 +0100 Fix failing

[tomcat] 01/02: Don't set 'C-L: 0' for HEAD requests if Servlet doesn't specify C-L

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 7d9cacdfc2e073ef4b1493d14f5c8f9f47a00c7f Author: Mark Thomas AuthorDate: Wed May 24 19:38:36 2023 +0100 Don't set 'C

[tomcat] branch main updated: Correct test for Tomcat 11 HEAD behaviour

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 26ae3185b8 Correct test for Tomcat 11 HEAD behaviour

Buildbot failure in on tomcat-10.1.x

2023-05-24 Thread buildbot
Build status: BUILD FAILED: failed compile (failure) Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/44/builds/812 Blamelist: Mark Thomas Build Text: failed compile (failure) Status Detected: new failure Build Source Stamp: [branch 10.1.x] a810f2c54a82ca0a7df8726fe5aa9abcdefb1

[tomcat] branch 8.5.x updated: Reduce code duplication

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 12a482dc82 Reduce code duplication 12a482dc82 is de

[tomcat] branch 9.0.x updated: Reduce code duplication

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 2945547cff Reduce code duplication 2945547cff is de

[tomcat] branch 10.1.x updated: Reduce code duplication

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new a810f2c54a Reduce code duplication a810f2c54a is

[tomcat] branch main updated: Reduce code duplication

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new bc12accbb9 Reduce code duplication bc12accbb9 is desc

[tomcat] branch 8.5.x updated: Fix BZ 66609. Correctly escape XML directory listings

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 8e725713e8 Fix BZ 66609. Correctly escape XML direc

[tomcat] branch 9.0.x updated: Fix BZ 66609. Correctly escape XML directory listings

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new ae809134ca Fix BZ 66609. Correctly escape XML direc

[tomcat] branch 10.1.x updated: Fix BZ 66609. Correctly escape XML directory listings

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 46a319e216 Fix BZ 66609. Correctly escape XML dir

[tomcat] branch 8.5.x updated: Refactor WebDAV servlet escaping for XML. Add test case.

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 601cd77ba8 Refactor WebDAV servlet escaping for XML

[tomcat] branch 9.0.x updated: Refactor WebDAV servlet escaping for XML. Add test case.

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 9f761db6f5 Refactor WebDAV servlet escaping for XML

[tomcat] branch 10.1.x updated: Refactor WebDAV servlet escaping for XML. Add test case.

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 415cb610e4 Refactor WebDAV servlet escaping for X

[GitHub] [tomcat] markt-asf closed pull request #621: Bug 66609 - invalid XML in directory listing with file names containing "&" and "'"

2023-05-24 Thread via GitHub
markt-asf closed pull request #621: Bug 66609 - invalid XML in directory listing with file names containing "&" and "'" URL: https://github.com/apache/tomcat/pull/621 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the UR

[GitHub] [tomcat] markt-asf commented on pull request #621: Bug 66609 - invalid XML in directory listing with file names containing "&" and "'"

2023-05-24 Thread via GitHub
markt-asf commented on PR #621: URL: https://github.com/apache/tomcat/pull/621#issuecomment-1561136901 Thanks for the PR. Applied manually with a few tweaks (e.g. CheckStyle config). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to G

[tomcat] branch main updated (63461b3bed -> 9a6bc65e50)

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git from 63461b3bed Code clean-up. Formatting. No functional change. new bc161f3204 Fix BZ 66609. Correctly escape XML direct

[tomcat] 01/02: Fix BZ 66609. Correctly escape XML directory listings

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit bc161f3204b41f5f580d4ff4466b25aaea073c4e Author: Mark Thomas AuthorDate: Wed May 24 14:11:32 2023 +0100 Fix BZ 66609.

[tomcat] 02/02: Refactor WebDAV servlet escaping for XML. Add test case.

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 9a6bc65e50df5b8d138b5373e48575d043981c24 Author: Mark Thomas AuthorDate: Wed May 24 14:16:13 2023 +0100 Refactor WebDA

Buildbot success in on tomcat-8.5.x

2023-05-24 Thread buildbot
Build status: Build succeeded! Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/36/builds/498 Blamelist: Mark Thomas Build Text: build successful Status Detected: restored build Build Source Stamp: [branch 8.5.x] a4509e62097ce2cd952fe2224a7683a4b07eae42 Steps: worker_prepa

[GitHub] [tomcat] alexkachanov commented on a diff in pull request #621: Bug 66609 - invalid XML in directory listing with file names containing "&" and "'"

2023-05-24 Thread via GitHub
alexkachanov commented on code in PR #621: URL: https://github.com/apache/tomcat/pull/621#discussion_r1203991514 ## java/org/apache/catalina/servlets/DefaultServlet.java: ## @@ -1650,7 +1650,7 @@ protected InputStream renderXml(HttpServletRequest request, String contextPath,

[GitHub] [tomcat] alexkachanov commented on pull request #621: Bug 66609 - invalid XML in directory listing with file names containing "&" and "'"

2023-05-24 Thread via GitHub
alexkachanov commented on PR #621: URL: https://github.com/apache/tomcat/pull/621#issuecomment-1560963105 I was using URLEncoder class because it was used in original rewriteUrl method. So I wanted to keep it consistent and keep the changes it to minimum. I see that Escape.xml(String conten

Re: RFC 9113 (HTTP/2) and HTTP upgrade to h2c

2023-05-24 Thread Rémy Maucherat
On Tue, May 23, 2023 at 1:10 PM Mark Thomas wrote: > > Hi all, > > The latest HTTP/2 RFC (9113, June 2022) deprecates the use of HTTP > upgrade to start an HTTP/2 clear text connection. > > Interestingly, a range of vocabulary is used. Section 3.1 says it is > "deprecated". Section 11.2 says it is

[GitHub] [tomcat] markt-asf commented on pull request #621: Bug 66609 - invalid XML in directory listing with file names containing "&" and "'"

2023-05-24 Thread via GitHub
markt-asf commented on PR #621: URL: https://github.com/apache/tomcat/pull/621#issuecomment-1560920115 (Ab)using the URLEncoder for this seems wrong. Tomcat has a class specifically for escaping values in content - `org.apache.tomcat.util.security.Escape`. The fix should use this. Fu

[Bug 66548] Tomcat does not validate value of Sec-Websocket-Key header

2023-05-24 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=66548 Mark Thomas changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

[tomcat] branch 8.5.x updated: Add release date for 8.5.89

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new a4509e6209 Add release date for 8.5.89 a4509e6209 i

[tomcat] branch 10.1.x updated: Add release date for 10.1.9

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 0d06e06e34 Add release date for 10.1.9 0d06e06e34

[tomcat] branch 8.5.x updated: Fix BZ 66548 - Add validation of Sec-Websocket-Key header

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new 4c55385d05 Fix BZ 66548 - Add validation of Sec-Web

[tomcat] branch 9.0.x updated: Fix BZ 66548 - Add validation of Sec-Websocket-Key header

2023-05-24 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 37f979762b Fix BZ 66548 - Add validation of Sec-Web

[Bug 66548] Tomcat does not validate value of Sec-Websocket-Key header

2023-05-24 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=66548 Mark Thomas changed: What|Removed |Added Status|NEEDINFO|NEW --- Comment #9 from Mark Thomas ---

[Bug 66613] Developing wiki page: Unclear reference to "service wrapper" in Debugging

2023-05-24 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=66613 Mark Thomas changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

Re: Timing for June releases

2023-05-24 Thread Han Li
> On May 24, 2023, at 16:28, Mark Thomas wrote: > > Hi all, > > OpenSSL has just announced a security fix release for 30 May. > > We won't know what the security issues are until then so my tentative plan is > to tag and release Native 1.2.x and 2.0.x on 31 May, release Native 1.2.x and >

Re: Timing for June releases

2023-05-24 Thread Rémy Maucherat
On Wed, May 24, 2023 at 10:29 AM Mark Thomas wrote: > > Hi all, > > OpenSSL has just announced a security fix release for 30 May. > > We won't know what the security issues are until then so my tentative > plan is to tag and release Native 1.2.x and 2.0.x on 31 May, release > Native 1.2.x and 2.0.

Timing for June releases

2023-05-24 Thread Mark Thomas
Hi all, OpenSSL has just announced a security fix release for 30 May. We won't know what the security issues are until then so my tentative plan is to tag and release Native 1.2.x and 2.0.x on 31 May, release Native 1.2.x and 2.0.x relatively quickly, update all Tomcat versions to use the new