Re: Plans for 11.0.8 tag

2025-06-04 Thread Rémy Maucherat
On Wed, Jun 4, 2025 at 12:47 PM Mark Thomas wrote: > > Hi all, > > My current plan for 11.0.8 is to tag towards the end of this week. There > are a few PRs to review, I need to do the usual dependency checks and > i18n updates as well as a couple of fixes I have sat locally that I need > to clean

Re: (tomcat) branch 9.0.x updated: Code clean-up - formatting. No functional change.

2025-05-27 Thread Rémy Maucherat
On Tue, May 27, 2025 at 12:16 PM Mark Thomas wrote: > > On 22/05/2025 17:53, ma...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > markt pushed a commit to branch 9.0.x > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > Th

Re: [VOTE] Release Apache Tomcat Native 2.0.9

2025-05-26 Thread Rémy Maucherat
On Fri, May 23, 2025 at 7:24 PM Mark Thomas wrote: > > The key differences of version 2.0.9 compared to 2.0.8 are: > > - Update Windows build to use Visual Studio 2022 > - The windows binaries in this release have been built with OpenSSL >3.5.0 and APR 1.7.6 > > The 2.0.x branch is primarily i

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Rémy Maucherat
On Thu, May 22, 2025 at 4:09 PM Christopher Schultz wrote: > > Mark, > > On 5/22/25 3:13 AM, Mark Thomas wrote: > > All, > > > > The last Tomcat Native releases were in July 2024. The Windows binaries > > were built with 3.0.14. > > > > There are some low severity CVEs in 3.0.14 that we don't beli

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Rémy Maucherat
On Thu, May 22, 2025 at 9:13 AM Mark Thomas wrote: > > All, > > The last Tomcat Native releases were in July 2024. The Windows binaries > were built with 3.0.14. > > There are some low severity CVEs in 3.0.14 that we don't believe apply > to Tomcat's usage of OpenSSL but that may trigger a securit

Re: NIO2 connector

2025-05-15 Thread Rémy Maucherat
On Thu, May 15, 2025 at 7:34 PM Christopher Schultz wrote: > > Rémy, > > On 5/14/25 6:31 PM, Rémy Maucherat wrote: > > On Wed, May 14, 2025 at 8:52 PM Christopher Schultz > > wrote: > >> > >> Mark, > >> > >> On 5/13/25 11:20 AM,

Re: NIO2 connector

2025-05-14 Thread Rémy Maucherat
On Wed, May 14, 2025 at 8:52 PM Christopher Schultz wrote: > > Mark, > > On 5/13/25 11:20 AM, Mark Thomas wrote: > > All, > > > > This was mentioned briefly before (I think on a BZ issue) but needs a > > wider discussion before taking action - if we do anything. > > > > It has been suggested that

Re: NIO2 connector

2025-05-13 Thread Rémy Maucherat
On Tue, May 13, 2025 at 5:22 PM Mark Thomas wrote: > > All, > > This was mentioned briefly before (I think on a BZ issue) but needs a > wider discussion before taking action - if we do anything. > > It has been suggested that there isn't much benefit to maintaining the > NIO2 connector and that we

Re: [ANN] Apache Tomcat 9.0.105 available

2025-05-13 Thread Rémy Maucherat
On Tue, May 13, 2025 at 10:14 AM Michael Osipov wrote: > > Please fix the release changelog for jakarta.el.ImportHandler. It is fixed, but after the 9.0.105 tag, so it will be in 9.0.106. Rémy - To unsubscribe, e-mail: dev-unsu

[ANN] Apache Tomcat 9.0.105 available

2025-05-12 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.105. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.104 is a bugfix and fe

[VOTE][RESULT] Release Apache Tomcat 9.0.105

2025-05-12 Thread Rémy Maucherat
The following votes were cast: Binding: +1: schultz, dsoumis, rjung, isapir The vote therefore passes. Thanks to everyone who contributed to this release. Rémy - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For ad

Re: [VOTE] Release Apache Tomcat 11.0.7

2025-05-09 Thread Rémy Maucherat
On Wed, May 7, 2025 at 8:22 PM Mark Thomas wrote: > > The proposed Apache Tomcat 11.0.7 release is now available for voting. > > The notable changes compared to 11.0.6 include: > > - Process possible path parameters rewrite production in the rewrite >valve. > > - Enable allowLinking to be set

Re: [VOTE] Release Apache Tomcat 10.1.41

2025-05-09 Thread Rémy Maucherat
On Thu, May 8, 2025 at 2:56 PM Christopher Schultz wrote: > > The proposed Apache Tomcat 10.1.41 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are > binding. We

Re: [VOTE] Release Apache Tomcat 9.0.105

2025-05-09 Thread Rémy Maucherat
On Thu, May 8, 2025 at 9:52 PM Michael Osipov wrote: > > On 2025/05/07 19:03:01 Rémy Maucherat wrote: > > The proposed Apache Tomcat 9.0.105 release is now available for voting. > > > > The notable changes compared to 9.0.104 are: > > > > - Process possible p

[VOTE] Release Apache Tomcat 9.0.105

2025-05-07 Thread Rémy Maucherat
The proposed Apache Tomcat 9.0.105 release is now available for voting. The notable changes compared to 9.0.104 are: - Process possible path parameters rewrite production in the rewrite valve. - Enable allowLinking to be set on PreResources, JarResources and PostResources. If not set expli

Re: Plans for May releases

2025-05-06 Thread Rémy Maucherat
On Tue, May 6, 2025 at 9:48 AM Mark Thomas wrote: > > Hi all, > > I am currently working on a couple of platform specific test failures. I > also want to try and fix the issue described in "Content type unknown > after upgrading Tomcat 10.1.39 => 10.1.40" on the users list. I had missed it. It se

[ANN] Apache Tomcat 9.0.104 available

2025-04-09 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.104. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.104 is a bugfix and fe

[VOTE][RESULT] Release Apache Tomcat 9.0.104

2025-04-09 Thread Rémy Maucherat
The following votes were cast: Binding: +1: markt, remm, rjung, dsoumis, schultz The vote therefore passes. Thanks to everyone who contributed to this release. Rémy - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org F

Re: [VOTE] Release Apache Tomcat 9.0.104

2025-04-04 Thread Rémy Maucherat
On Fri, Apr 4, 2025 at 7:33 PM Mark Thomas wrote: > > On 04/04/2025 14:11, Rémy Maucherat wrote: > > > The proposed 9.0.104 release is: > > [ ] -1, Broken - do not release > > [X] +1, Stable - go ahead and release as 9.0.104 > > Windows installer has valid signat

[VOTE] Release Apache Tomcat 9.0.104

2025-04-04 Thread Rémy Maucherat
The proposed Apache Tomcat 9.0.104 release is now available for voting. The notable changes compared to 9.0.102 are: - Remove the requirement that an MD5 implementation must be provided by JRE. - Improve the handling of %nn URL encoding in the RewriteValve - Various improvements to the JsonE

Re: [VOTE] Release Apache Tomcat 9.0.103

2025-04-04 Thread Rémy Maucherat
On Tue, Apr 1, 2025 at 8:56 PM Rémy Maucherat wrote: > > The proposed Apache Tomcat 9.0.103 release is now available for voting. > > The notable changes compared to 9.0.102 are: > > - Remove the requirement that an MD5 implementation must be provided >by JRE. > > -

Re: [VOTE] Release Apache Tomcat 9.0.103

2025-04-03 Thread Rémy Maucherat
On Thu, Apr 3, 2025 at 9:10 PM Mark Thomas wrote: > > On 03/04/2025 19:34, Christopher Schultz wrote: > > Mark, > > > > On 4/3/25 1:38 PM, Mark Thomas wrote: > >> On 01/04/2025 19:56, Rémy Maucherat wrote: > >> > >>> The proposed 9.0.103 rele

Re: [VOTE] Release Apache Tomcat 9.0.103

2025-04-03 Thread Rémy Maucherat
On Thu, Apr 3, 2025 at 3:40 PM Dimitris Soumis wrote: > > On Thu, Apr 3, 2025 at 4:05 PM Rémy Maucherat wrote: > > > On Thu, Apr 3, 2025 at 2:52 PM Dimitris Soumis wrote: > > > > > > On Tue, Apr 1, 2025 at 10:05 PM Rémy Maucherat wrote: > > > > >

Re: [VOTE] Release Apache Tomcat 9.0.103

2025-04-03 Thread Rémy Maucherat
On Thu, Apr 3, 2025 at 3:16 PM Christopher Schultz wrote: > > Rémy, > > Thanks for RMing. > > On 4/1/25 2:56 PM, Rémy Maucherat wrote: > > The proposed Apache Tomcat 9.0.103 release is now available for voting. > > > > The notable changes compared to 9.0.102 a

Re: [VOTE] Release Apache Tomcat 9.0.103

2025-04-03 Thread Rémy Maucherat
On Thu, Apr 3, 2025 at 3:01 PM Rainer Jung wrote: > > Am 03.04.25 um 14:29 schrieb Dimitris Soumis: > > On Tue, Apr 1, 2025 at 10:05 PM Rémy Maucherat wrote: > > > >> The proposed Apache Tomcat 9.0.103 release is now available for voting. > >> > >>

Re: [VOTE] Release Apache Tomcat 9.0.103

2025-04-03 Thread Rémy Maucherat
On Thu, Apr 3, 2025 at 2:52 PM Dimitris Soumis wrote: > > On Tue, Apr 1, 2025 at 10:05 PM Rémy Maucherat wrote: > > > The proposed Apache Tomcat 9.0.103 release is now available for voting. > > > > The notable changes compared to 9.0.102 are: > > > &g

Re: Unit test failure in TestAccessLogValve line 316

2025-04-02 Thread Rémy Maucherat
On Wed, Apr 2, 2025 at 9:49 PM Rainer Jung wrote: > > Am 02.04.25 um 21:04 schrieb Rainer Jung: > > Am 02.04.25 um 15:07 schrieb Rainer Jung: > >> I get sporadic failures in test[62: Name[pct-t-begin:umlaut_time_S], > >> Type[text]] and in test[63: Name[pct-t-begin:umlaut_time_S], Type[json]] > >>

Re: [VOTE] Release Apache Tomcat 11.0.6

2025-04-02 Thread Rémy Maucherat
On Tue, Apr 1, 2025 at 6:07 PM Mark Thomas wrote: > > The proposed Apache Tomcat 11.0.6 release is now available for voting. > > The notable changes compared to 11.0.5 include: > > - Remove the requirement that an MD5 implementation must be provided >by JRE. > > - Improve the handling of %nn U

Re: [VOTE] Release Apache Tomcat 10.1.40

2025-04-02 Thread Rémy Maucherat
On Tue, Apr 1, 2025 at 8:42 PM Christopher Schultz wrote: > > The proposed Apache Tomcat 10.1.40 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are > binding. We

Re: [VOTE] Release Apache Tomcat 9.0.103

2025-04-02 Thread Rémy Maucherat
On Tue, Apr 1, 2025 at 8:56 PM Rémy Maucherat wrote: > > The proposed Apache Tomcat 9.0.103 release is now available for voting. > > The notable changes compared to 9.0.102 are: > > - Remove the requirement that an MD5 implementation must be provided >by JRE. > > -

[VOTE] Release Apache Tomcat 9.0.103

2025-04-01 Thread Rémy Maucherat
The proposed Apache Tomcat 9.0.103 release is now available for voting. The notable changes compared to 9.0.102 are: - Remove the requirement that an MD5 implementation must be provided by JRE. - Improve the handling of %nn URL encoding in the RewriteValve - Various improvements to the JsonE

Re: (tomcat) branch main updated: Restore final keywords

2025-03-31 Thread Rémy Maucherat
On Mon, Mar 31, 2025 at 6:27 PM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch main > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > The following commit(s) were added to refs/heads/main by this push: > ne

Re: (tomcat) branch main updated: Update JDT to 4.35 / 3.41

2025-03-28 Thread Rémy Maucherat
On Fri, Mar 28, 2025 at 2:09 PM Rémy Maucherat wrote: > > On Fri, Mar 28, 2025 at 12:48 PM wrote: > > > > This is an automated email from the ASF dual-hosted git repository. > > > > markt pushed a commit to branch main > > in repository https://gi

Re: (tomcat) branch main updated: Update JDT to 4.35 / 3.41

2025-03-28 Thread Rémy Maucherat
On Fri, Mar 28, 2025 at 12:48 PM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch main > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > The following commit(s) were added to refs/heads/main by this push: > n

Re: (tomcat) 02/02: Mostly revert changes

2025-03-20 Thread Rémy Maucherat
On Thu, Mar 20, 2025 at 2:16 PM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch 11.0.x > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > commit c49a53f1a1ad887cb19f431944a5e3c04c675ed2 > Author: remm > AuthorDate:

Re: (tomcat) branch main updated: Fix type related warnings

2025-03-20 Thread Rémy Maucherat
On Thu, Mar 20, 2025 at 12:11 PM Mark Thomas wrote: > > On 20/03/2025 10:09, r...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > remm pushed a commit to branch main > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > The f

Re: (tomcat) branch main updated: Add new registry factory that does not return null

2025-03-20 Thread Rémy Maucherat
On Thu, Mar 20, 2025 at 11:49 AM Mark Thomas wrote: > > On 20/03/2025 10:22, Mark Thomas wrote: > > On 19/03/2025 09:51, r...@apache.org wrote: > >> This is an automated email from the ASF dual-hosted git repository. > >> > >> remm pushed a commit to branch main > >> in repository https://gitbox.a

Re: (tomcat) branch main updated: Revert "Use unnamed variable to avoid IDE warnings after refactoring"

2025-03-19 Thread Rémy Maucherat
On Wed, Mar 19, 2025 at 6:27 AM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch main > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > The following commit(s) were added to refs/heads/main by this push: > ne

Additional Java language features

2025-03-17 Thread Rémy Maucherat
Hi, Would it be ok to use records and pattern variables (which replace the instanceof then cast code) in Tomcat ? I think they would improve the code overall, esp records. Although it would make the branches a bit more different, this is "boilerplate" (as they say ;) ) code so unlikely to cause r

Re: (tomcat) branch main updated: Fix test failures seen on Gump. Use approach from TestAccessLogValve.

2025-03-13 Thread Rémy Maucherat
On Thu, Mar 13, 2025 at 11:58 AM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch main > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > The following commit(s) were added to refs/heads/main by this push: > n

Re: Default Servlet and POST

2025-03-12 Thread Rémy Maucherat
On Wed, Mar 12, 2025 at 1:23 PM Mark Thomas wrote: > > All, > > I have been working through the some specification compliance questions > raised by some research into HTTP conformance [1]. > > That paper's focus is security but I don't see any security concerns for > Tomcat. I do see a number of f

Re: Buildbot failure in on tomcat-12.0.x

2025-03-10 Thread Rémy Maucherat
On Mon, Mar 10, 2025 at 1:05 PM Rainer Jung wrote: > > Am 10.03.25 um 12:41 schrieb build...@apache.org: > > Build status: BUILD FAILED: failed compile (failure) > > Worker used: bb_worker2_ubuntu > > URL: https://ci2.apache.org/#builders/120/builds/435 > > Blamelist: Rainer Jung > > Build Text:

[ANN] Apache Tomcat 9.0.102 available

2025-03-06 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.102. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.102 is a bugfix and fe

[VOTE][RESULT] Release Apache Tomcat 9.0.102

2025-03-06 Thread Rémy Maucherat
The following votes were cast: Binding: +1: remm, schultz, markt, funkman, rjung Non-binding: +1: jengebr The vote therefore passes. Thanks to everyone who contributed to this release. Rémy - To unsubscribe, e-mail: dev-unsub

Re: [VOTE] Release Apache Tomcat 10.1.39

2025-03-04 Thread Rémy Maucherat
On Tue, Mar 4, 2025 at 8:15 PM Christopher Schultz wrote: > > The proposed Apache Tomcat 10.1.39 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are > binding. We

Re: [VOTE] Release Apache Tomcat 9.0.102

2025-03-04 Thread Rémy Maucherat
On Mon, Mar 3, 2025 at 8:52 PM Rémy Maucherat wrote: > > The proposed Apache Tomcat 9.0.102 release is now available for voting. > > The notable changes compared to 9.0.100 are: > > - Improve the checks for exposure to and protection against >CVE-2024-56337 so that r

[VOTE] Release Apache Tomcat 9.0.102

2025-03-03 Thread Rémy Maucherat
The proposed Apache Tomcat 9.0.102 release is now available for voting. The notable changes compared to 9.0.100 are: - Improve the checks for exposure to and protection against CVE-2024-56337 so that reflection is not used unless required. The checks for whether the file system is case sens

Re: (tomcat) branch 9.0.x updated: Add makensis as an option for building the Windows installer

2025-03-03 Thread Rémy Maucherat
On Mon, Mar 3, 2025 at 1:45 PM Rémy Maucherat wrote: > > On Mon, Mar 3, 2025 at 1:27 PM Mark Thomas wrote: > > > > On 03/03/2025 10:54, Mark Thomas wrote: > > > > > > > > > I don't recall if I tested with wine after the changes were complete.

Re: [VOTE] Release Apache Tomcat 9.0.101

2025-03-03 Thread Rémy Maucherat
On Sun, Mar 2, 2025 at 11:42 AM Rémy Maucherat wrote: > > The proposed Apache Tomcat 9.0.101 release is now available for voting. > > The notable changes compared to 9.0.100 are: > > - Improve the checks for exposure to and protection against >CVE-2024-56337 so that r

Re: (tomcat) branch 9.0.x updated: Add makensis as an option for building the Windows installer

2025-03-03 Thread Rémy Maucherat
On Mon, Mar 3, 2025 at 1:27 PM Mark Thomas wrote: > > On 03/03/2025 10:54, Mark Thomas wrote: > > > > > I don't recall if I tested with wine after the changes were complete. I > > do recall installing and uninstalling wine multiple times. I'll retest now. > > So clearly I didn't test this with Wi

Re: (tomcat) branch main updated: 69602: Allow weak etags in If-Range header

2025-03-03 Thread Rémy Maucherat
On Mon, Mar 3, 2025 at 10:30 AM Mark Thomas wrote: > > On 28/02/2025 22:41, r...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > remm pushed a commit to branch main > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > The fo

Re: (tomcat) branch 9.0.x updated: Add makensis as an option for building the Windows installer

2025-03-03 Thread Rémy Maucherat
On Sun, Mar 2, 2025 at 10:20 PM Rainer Jung wrote: > > Am 02.03.25 um 21:00 schrieb Rémy Maucherat: > > On Sun, Mar 2, 2025 at 5:10 PM Rainer Jung wrote: > >> > >> Hi Rémy, > >> > >> Am 02.03.25 um 11:06 schrieb Rémy Maucherat: > >>&

Re: [VOTE] Release Apache Tomcat 11.0.5

2025-03-03 Thread Rémy Maucherat
On Fri, Feb 28, 2025 at 6:06 PM Mark Thomas wrote: > > The proposed Apache Tomcat 11.0.5 release is now available for voting. > > The notable changes compared to 11.0.4 include: > > - Improve the checks for exposure to and protection against >CVE-2024-56337 so that reflection is not used unles

Re: (tomcat) branch 9.0.x updated: Add makensis as an option for building the Windows installer

2025-03-02 Thread Rémy Maucherat
On Sun, Mar 2, 2025 at 5:10 PM Rainer Jung wrote: > > Hi Rémy, > > Am 02.03.25 um 11:06 schrieb Rémy Maucherat: > > On Thu, Feb 13, 2025 at 6:11 PM wrote: > >> @@ -163,6 +157,9 @@ Var ServiceInstallLog > >> InstType Minimum > >> InstType

[VOTE] Release Apache Tomcat 9.0.101

2025-03-02 Thread Rémy Maucherat
The proposed Apache Tomcat 9.0.101 release is now available for voting. The notable changes compared to 9.0.100 are: - Improve the checks for exposure to and protection against CVE-2024-56337 so that reflection is not used unless required. The checks for whether the file system is case sens

Re: (tomcat) 01/01: Tag 10.1.37

2025-03-02 Thread Rémy Maucherat
On Sat, Mar 1, 2025 at 7:04 AM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > schultz pushed a commit to tag 10.1.37 > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > commit e4338ee7a3e0f22d85f7cb2e04dacee752eaa619 > Author: Christopher Schultz

Re: (tomcat) 01/01: Tag 9.0.101

2025-03-02 Thread Rémy Maucherat
On Sun, Mar 2, 2025 at 11:26 AM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > remm pushed a commit to tag 9.0.101 > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > commit cf9caee37dd3d2dbb0294983e921c12a318c1f5e > Author: remm > AuthorDate: Su

Re: (tomcat) branch 9.0.x updated: Add makensis as an option for building the Windows installer

2025-03-02 Thread Rémy Maucherat
On Thu, Feb 13, 2025 at 6:11 PM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch 9.0.x > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > The following commit(s) were added to refs/heads/9.0.x by this push: >

Re: (tomcat) branch main updated: Update with transfer-encoding support

2025-02-21 Thread Rémy Maucherat
On Fri, Feb 21, 2025 at 4:08 PM Christopher Schultz wrote: > > Rémy, > > On 2/20/25 12:58 PM, r...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > remm pushed a commit to branch main > > in repository https://gitbox.apache.org/repos/asf/tomcat.git

Re: Further improvements to the CVE-2024-56337 protection

2025-02-20 Thread Rémy Maucherat
On Thu, Feb 20, 2025 at 2:42 PM Mark Thomas wrote: > > On 20/02/2025 13:36, Rémy Maucherat wrote: > > On Thu, Feb 20, 2025 at 1:06 PM Mark Thomas wrote: > >> > >> All, > >> > >> The recent releases have improved things for users of embedded T

Re: Further improvements to the CVE-2024-56337 protection

2025-02-20 Thread Rémy Maucherat
On Thu, Feb 20, 2025 at 1:06 PM Mark Thomas wrote: > > All, > > The recent releases have improved things for users of embedded Tomcat > but there are still some issues. I am seeing reports via $work related > to Spring Boot. > > The problem is on Windows and Mac. The file systems are case insensit

Re: Case sensitivity checks

2025-02-19 Thread Rémy Maucherat
On Wed, Feb 19, 2025 at 7:15 PM Mark Thomas wrote: > > All, > > A case sensitivity test was added to DirResourceSet as part of the fix > for CVE-2024-50379. It is also used to check whether the JVM setting > described in CVE-2024-56337 is required. > > The current case sensitivity check is imperfe

[ANN] Apache Tomcat 9.0.100 available

2025-02-17 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.100. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.100 is a bugfix and fe

[VOTE][RESULT] Release Apache Tomcat 9.0.100

2025-02-17 Thread Rémy Maucherat
The following votes were cast: Binding: +1: schultz, markt, remm Non-binding: +1: dsoumis The vote therefore passes. Thanks to everyone who contributed to this release. Rémy - To unsubscribe, e-mail: dev-unsubscr...@tomcat.ap

Re: [VOTE] Release Apache Tomcat 11.0.4

2025-02-14 Thread Rémy Maucherat
On Thu, Feb 13, 2025 at 12:16 PM Mark Thomas wrote: > > The proposed Apache Tomcat 11.0.4 release is now available for voting. > > The notable changes compared to 11.0.3 include: > > - Fix 69576. Add a catch for InaccessibleObjectException to avoid >embedded users having to add an additional -

Re: [VOTE] Release Apache Tomcat 10.1.36

2025-02-14 Thread Rémy Maucherat
On Thu, Feb 13, 2025 at 2:26 PM Christopher Schultz wrote: > > The proposed Apache Tomcat 10.1.36 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are > binding. W

[VOTE] Release Apache Tomcat 9.0.100

2025-02-13 Thread Rémy Maucherat
The proposed Apache Tomcat 9.0.100 release is now available for voting. The notable changes compared to 9.0.99 are: - Fix 69576. Add a catch for InaccessibleObjectException to avoid embedded users having to add an additional --add-opens - Add a JSON formatter to JULI For full details, see th

Re: Tagging 11.0.4

2025-02-12 Thread Rémy Maucherat
On Wed, Feb 12, 2025 at 11:08 AM Mark Thomas wrote: > > All, > > Given the regression described in [1], we seem to be heading towards > consensus that a release sooner than the March release round is needed. > > What are the views on timing for that tag? How much longer do we want to > wait for an

[ANN] Apache Tomcat 9.0.99 available

2025-02-10 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.99. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.99 is a bugfix and feat

[VOTE][RESULT] Release Apache Tomcat 9.0.99

2025-02-10 Thread Rémy Maucherat
The following votes were cast: Binding: +1: isapir, remm, markt, rjung, schultz Non-binding: +1: dsoumis The vote therefore passes. Thanks to everyone who contributed to this release. Rémy - To unsubscribe, e-mail: dev-unsubs

Re: [VOTE] Release Apache Tomcat 10.1.35

2025-02-05 Thread Rémy Maucherat
On Tue, Feb 4, 2025 at 11:10 PM Christopher Schultz wrote: > > The proposed Apache Tomcat 10.1.35 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are > binding. W

Re: [VOTE] Release Apache Tomcat 11.0.3

2025-02-05 Thread Rémy Maucherat
On Tue, Feb 4, 2025 at 7:35 PM Mark Thomas wrote: > > The proposed Apache Tomcat 11.0.3 release is now available for voting. > > The notable changes compared to 11.0.2 include: > > - Allow readOnly attribute configuration on the Resources element and >allow configuration of the readOnly attrib

[VOTE] Release Apache Tomcat 9.0.99

2025-02-04 Thread Rémy Maucherat
The proposed Apache Tomcat 9.0.99 release is now available for voting. The notable changes compared to 9.0.98 are: - Allow readOnly attribute configuration on the Resources element and allow configuration of the readOnly attribute value of the main resources. The attribute value will also b

Re: (tomcat) 01/02: Revert "Update JSign to 7.0"

2025-02-04 Thread Rémy Maucherat
On Tue, Feb 4, 2025 at 7:15 PM wrote: > > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch main > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > commit fb6184445ea00fb8fde4f2de997ee77e39440ffa > Author: Mark Thomas > AuthorD

Re: Tomcat 9 extended support

2025-01-31 Thread Rémy Maucherat
On Thu, Jan 30, 2025 at 5:52 PM Mark Thomas wrote: > > All, > > We have discussed plans for extended Tomcat 9 support several times. It > is still probably a couple of years away but I thought it would be worth > starting the discussion again. > > There are a wide range of options. This is a brain

Re: Buildbot failure in on tomcat-11.0.x

2025-01-30 Thread Rémy Maucherat
On Thu, Jan 30, 2025 at 4:35 PM Mark Thomas wrote: > > On 30/01/2025 11:20, Rémy Maucherat wrote: > > On Thu, Jan 30, 2025 at 12:10 PM Mark Thomas wrote: > >> > >> On 30/01/2025 10:32, Rémy Maucherat wrote: > >>> Yes, there's an off by one issue,

Re: Buildbot failure in on tomcat-11.0.x

2025-01-30 Thread Rémy Maucherat
On Thu, Jan 30, 2025 at 12:10 PM Mark Thomas wrote: > > On 30/01/2025 10:32, Rémy Maucherat wrote: > > Yes, there's an off by one issue, still don't understand what's > > causing it (anything that gets into the available = 0 situations in > > available()

Re: Buildbot failure in on tomcat-11.0.x

2025-01-30 Thread Rémy Maucherat
On Thu, Jan 30, 2025 at 11:21 AM Mark Thomas wrote: > > On 30/01/2025 09:36, Rémy Maucherat wrote: > > On Thu, Jan 30, 2025 at 12:26 AM wrote: > >> > >> Build status: BUILD FAILED: failed compile (failure) > >> Worker used: bb_worker2_ubuntu > >>

Re: Buildbot failure in on tomcat-11.0.x

2025-01-30 Thread Rémy Maucherat
On Thu, Jan 30, 2025 at 12:26 AM wrote: > > Build status: BUILD FAILED: failed compile (failure) > Worker used: bb_worker2_ubuntu > URL: https://ci2.apache.org/#builders/112/builds/1490 > Blamelist: remm > Build Text: failed compile (failure) > Status Detected: new failure > Build Source Stamp: [

Re: (tomcat) branch main updated: Work around available tricks

2025-01-29 Thread Rémy Maucherat
On Wed, Jan 29, 2025 at 2:05 PM Mark Thomas wrote: > > On 29/01/2025 12:50, Rémy Maucherat wrote: > > On Wed, Jan 29, 2025 at 1:14 PM Mark Thomas wrote: > >> > >> On 29/01/2025 09:56, r...@apache.org wrote: > >>> This is an automated ema

Re: (tomcat) branch main updated: Work around available tricks

2025-01-29 Thread Rémy Maucherat
On Wed, Jan 29, 2025 at 1:14 PM Mark Thomas wrote: > > On 29/01/2025 09:56, r...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > remm pushed a commit to branch main > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > The fo

Re: Request dispatcher decoding and normalization

2025-01-22 Thread Rémy Maucherat
On Wed, Jan 22, 2025 at 3:11 PM Mark Thomas wrote: > > As a result of a user request, I am looking at Tomcat's handling of %2f > (encoded '/') and %5c (encoded '\'). > > I have already added a new attribute (encodedReverseSolidusHandling) to > the Connector to align options for %5c handling with o

Re: (tomcat) branch 9.0.x updated: Automate protection for CVE-2024-56337

2025-01-17 Thread Rémy Maucherat
On Thu, Jan 16, 2025 at 5:42 PM Mark Thomas wrote: > > On 16/01/2025 16:38, ma...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > markt pushed a commit to branch 9.0.x > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > The

Re: (tomcat) branch main updated: Refactor so the buffered data is used directly rather than copied

2025-01-13 Thread Rémy Maucherat
On Mon, Jan 13, 2025 at 8:53 PM Rémy Maucherat wrote: > > On Mon, Jan 13, 2025 at 8:39 PM Mark Thomas wrote: > > > > On 13/01/2025 08:10, Rémy Maucherat wrote: > > > On Thu, Jan 9, 2025 at 4:31 PM Mark Thomas wrote: > > >> > > >> On 09/01/2025

Re: (tomcat) branch main updated: Refactor so the buffered data is used directly rather than copied

2025-01-13 Thread Rémy Maucherat
On Mon, Jan 13, 2025 at 8:39 PM Mark Thomas wrote: > > On 13/01/2025 08:10, Rémy Maucherat wrote: > > On Thu, Jan 9, 2025 at 4:31 PM Mark Thomas wrote: > >> > >> On 09/01/2025 14:53, Rémy Maucherat wrote: > >>> On Thu, Jan 9, 2025 at 3:17 PM Mark Thomas

Re: (tomcat) branch main updated: Refactor so the buffered data is used directly rather than copied

2025-01-13 Thread Rémy Maucherat
On Thu, Jan 9, 2025 at 4:31 PM Mark Thomas wrote: > > On 09/01/2025 14:53, Rémy Maucherat wrote: > > On Thu, Jan 9, 2025 at 3:17 PM Mark Thomas wrote: > > > > >> My current plan is to create InputBuffer with bb set to a zero length > >> ByteBuffer and h

Re: (tomcat) branch main updated: Refactor so the buffered data is used directly rather than copied

2025-01-09 Thread Rémy Maucherat
On Thu, Jan 9, 2025 at 3:17 PM Mark Thomas wrote: > > On 09/01/2025 14:01, ma...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > markt pushed a commit to branch main > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > The f

Re: [VOTE] Apache Tomcat migration tool for Jakarta EE 1.0.9

2025-01-08 Thread Rémy Maucherat
On Wed, Jan 8, 2025 at 11:32 AM Mark Thomas wrote: > > The proposed Apache Tomcat migration tool for Jakarta EE 1.0.9 is now > available for voting. > > The significant changes since 1.0.8 are: > > - Fix issue that matchExcludesAgainstPathName didn't work for files. >Part of PR#60 provided by

Re: (tomcat) branch main updated: BZ69521: Allow more non latin languages in EL

2025-01-07 Thread Rémy Maucherat
On Tue, Jan 7, 2025 at 12:57 PM Mark Thomas wrote: > > On 07/01/2025 10:55, r...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > remm pushed a commit to branch main > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > The fo

Re: Test cases for RFC 9110 Section 13

2024-12-12 Thread Rémy Maucherat
On Thu, Dec 12, 2024 at 9:35 AM Mark Thomas wrote: > > Hi all, > > Two test classes have been added for RFC 9110 section 13: > > TestDefaultServletRfc9110Section13 > TestDefaultServletRfc9110Section13Parameterized > > The parameterized version is a subset of the non-parameterized. I have > confirm

Re: (tomcat) branch main updated: Improve HTTP If headers processing according to RFC 9110

2024-12-11 Thread Rémy Maucherat
On Wed, Dec 11, 2024 at 4:28 PM Mark Thomas wrote: > > On 11/12/2024 09:56, r...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > remm pushed a commit to branch main > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > The fo

Re: (tomcat) branch main updated: Improve HTTP If headers processing according to RFC 9110

2024-12-11 Thread Rémy Maucherat
On Wed, Dec 11, 2024 at 4:28 PM Mark Thomas wrote: > > On 11/12/2024 09:56, r...@apache.org wrote: > > This is an automated email from the ASF dual-hosted git repository. > > > > remm pushed a commit to branch main > > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > > > > The fo

Re: Future of JNI in Tomcat

2024-12-10 Thread Rémy Maucherat
On Tue, Dec 10, 2024 at 1:01 PM Rainer Jung wrote: > > Am 12.09.24 um 16:15 schrieb Rémy Maucherat: > > This JEP has the potential to have a significant impact with Tomcat's > > JNI use starting with Java 26. > > https://openjdk.org/jeps/471 > > > > Un

[ANN] Apache Tomcat 9.0.98 available

2024-12-09 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.98. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.98 is a bugfix and feat

Re: [VOTE] Release Apache Tomcat 9.0.98

2024-12-09 Thread Rémy Maucherat
On Mon, Dec 9, 2024 at 1:36 PM Christopher Schultz wrote: > > Rainer, > > On 12/8/24 5:59 PM, Rainer Jung wrote: > > Am 05.12.24 um 21:13 schrieb Rémy Maucherat: > >> The proposed Apache Tomcat 9.0.98 release is now available for voting. > >> > >&g

[VOTE][RESULT] Release Apache Tomcat 9.0.98

2024-12-09 Thread Rémy Maucherat
The following votes were cast: Binding: +1: markt, remm, schultz, rjung Non-binding: +1: dsoumis The vote therefore passes. Thanks to everyone who contributed to this release. Rémy - To unsubscribe, e-mail: dev-unsubscr...@to

Re: [VOTE] Release Apache Tomcat 10.1.34

2024-12-06 Thread Rémy Maucherat
On Thu, Dec 5, 2024 at 6:15 PM Christopher Schultz wrote: > > The proposed Apache Tomcat 10.1.34 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are > binding. We

Re: [VOTE] Release Apache Tomcat 11.0.2

2024-12-06 Thread Rémy Maucherat
On Thu, Dec 5, 2024 at 5:52 PM Mark Thomas wrote: > > The proposed Apache Tomcat 11.0.1 release is now available for voting. > > The notable changes compared to 11.0.1 include: > > - Add strong ETag support for the WebDAV and default servlet, which can >be enabled by using the useStrongETags i

Re: [VOTE] Release Apache Tomcat 9.0.98

2024-12-06 Thread Rémy Maucherat
On Thu, Dec 5, 2024 at 9:13 PM Rémy Maucherat wrote: > > The proposed Apache Tomcat 9.0.98 release is now available for voting. > > The notable changes compared to 9.0.97 are: > > - Add strong ETag support for the WebDAV and default servlet, which can >be enabled by usi

[VOTE] Release Apache Tomcat 9.0.98

2024-12-05 Thread Rémy Maucherat
The proposed Apache Tomcat 9.0.98 release is now available for voting. The notable changes compared to 9.0.97 are: - Add strong ETag support for the WebDAV and default servlet, which can be enabled by using the useStrongETags init parameter with a value set to true. The ETag generated will

  1   2   3   4   5   6   7   8   9   10   >