[Bug 59569] isWrapperFor/unwrap implementations incorrect

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59569 martin.gantenb...@gmail.com changed: What|Removed |Added CC||martin.gantenb...@gmail.co

[Bug 65736] New: Improve org.apache.naming.factory.BeanFactory to mitigate JNDI injection

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65736 Bug ID: 65736 Summary: Improve org.apache.naming.factory.BeanFactory to mitigate JNDI injection Product: Tomcat 9 Version: 9.0.55 Hardware: PC OS: Mac OS

Re: JDK 18: Rampdown Phase 1 & Early-Access builds 27

2021-12-10 Thread Martin Grigorov
Hi David, Apache Tomcat build and tests pass successfully with JDK 18-ea+27-1924 on both Linux x86_64 and aarch64! Regards, Martin On Fri, Dec 10, 2021 at 9:58 AM David Delabassee < david.delabas...@oracle.com> wrote: > Mark, > > Thank you for being part of the OpenJDK Quality Outreach Program.

Re: JDK 18: Rampdown Phase 1 & Early-Access builds 27

2021-12-10 Thread Rémy Maucherat
On Fri, Dec 10, 2021 at 8:58 AM David Delabassee wrote: > > Mark, > > Thank you for being part of the OpenJDK Quality Outreach Program. As > year-end 2021 approaches, I'd like to share some updates on JDK 18, > which is scheduled for General Availability on March 22, 2022. > > JDK 18 has now enter

[Bug 65736] Improve org.apache.naming.factory.BeanFactory to mitigate JNDI injection

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65736 --- Comment #1 from quaff --- Can we drop "forceString" supports? https://github.com/apache/tomcat/blob/f5a732e74e2a36442b2bf562c665917c4bb1167a/java/org/apache/naming/factory/BeanFactory.java#L150 -- You are receiving this mail because: You

Re: [External] : Re: JDK 18: Rampdown Phase 1 & Early-Access builds 27

2021-12-10 Thread David Delabassee
Great! Thanks for the prompt feedback! Regards, --David On 10/12/2021 09:54, Martin Grigorov wrote: Hi David, Apache Tomcat build and tests pass successfully with JDK 18-ea+27-1924 on both Linux x86_64 and aarch64! Regards, Martin On Fri, Dec 10, 2021 at 9:58 AM David Delabassee wrote:

[Bug 65714] HTTPS connection error using NIO2 with security manager enabled

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65714 --- Comment #18 from Mark Thomas --- I now have a clearer picture of what is going on. The fix for bug 65454 included an unintended change. The pre-starting of the core thread pool was removed. I'll restore that shortly. It also made a bug tha

[tomcat] 02/04: Revert the previous fix for BZ 65714.

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 072fcce0ef6569e4c6110a505c91799e21fc5e30 Author: Mark Thomas AuthorDate: Fri Dec 10 14:55:53 2021 + Revert the pre

[tomcat] branch main updated (ec74b01 -> 6f9eb19)

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git. from ec74b01 Document BZ 65714 as a known issue new 1fd977d Restore pre-starting of core threads lost in fix for BZ 65

[tomcat] 01/04: Restore pre-starting of core threads lost in fix for BZ 65454

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 1fd977d6947b3c44462f7695f79c33804eb0369c Author: Mark Thomas AuthorDate: Fri Dec 10 14:52:06 2021 + Restore pre-st

[tomcat] 03/04: Improved fix for BZ 65714

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 0be5c8d8b24ef961a97d55535689e7520c60921b Author: Mark Thomas AuthorDate: Fri Dec 10 15:24:51 2021 + Improved fix f

[tomcat] 04/04: Remove BZ 65714 from the known issues

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 6f9eb19a47ed8d414d718a782d671daa345d5940 Author: Mark Thomas AuthorDate: Fri Dec 10 15:37:03 2021 + Remove BZ 6571

[tomcat] branch 10.0.x updated (b00cc6a -> 56c50a8)

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch 10.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git. from b00cc6a Document BZ 65714 as a known issue new 5003b83 Restore pre-starting of core threads lost in fix for BZ

[tomcat] 01/04: Restore pre-starting of core threads lost in fix for BZ 65454

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 5003b83495df9be4a5caa4c72ddd48726171e965 Author: Mark Thomas AuthorDate: Fri Dec 10 14:52:06 2021 + Restore pre-

[tomcat] 02/04: Revert the previous fix for BZ 65714.

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit eb4cab1db0eb9c65a0ea3350f418f04a788a28ef Author: Mark Thomas AuthorDate: Fri Dec 10 14:55:53 2021 + Revert the p

[tomcat] 03/04: Improved fix for BZ 65714

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 9fa8196f024ce30c929c3543d0a41f41a0640d78 Author: Mark Thomas AuthorDate: Fri Dec 10 15:24:51 2021 + Improved fix

[tomcat] 04/04: Remove BZ 65714 from the known issues

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 56c50a8fb9deb73844cddd2e1ea59331a69f4dc9 Author: Mark Thomas AuthorDate: Fri Dec 10 15:37:03 2021 + Remove BZ 65

[tomcat] branch 9.0.x updated (9400421 -> c244c30)

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git. from 9400421 Document BZ 65714 as a known issue new 9bca801 Restore pre-starting of core threads lost in fix for BZ 6

[tomcat] 02/04: Revert the previous fix for BZ 65714.

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit e87af1001a09041ae221f024b10602f42b28d077 Author: Mark Thomas AuthorDate: Fri Dec 10 14:55:53 2021 + Revert the pr

[tomcat] 04/04: Remove BZ 65714 from the known issues

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit c244c3093531a35eb79f3a6204b9b1e69f3bed01 Author: Mark Thomas AuthorDate: Fri Dec 10 15:37:03 2021 + Remove BZ 657

[tomcat] 03/04: Improved fix for BZ 65714

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 9eb49f93f910df9f5408642a798bf39cbeb10804 Author: Mark Thomas AuthorDate: Fri Dec 10 15:24:51 2021 + Improved fix

[tomcat] 01/04: Restore pre-starting of core threads lost in fix for BZ 65454

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 9bca801bd4f7d0adbbad686110aa476b2829cad9 Author: Mark Thomas AuthorDate: Fri Dec 10 14:52:06 2021 + Restore pre-s

[tomcat] branch 8.5.x updated (d0cbf5e -> 4795df9)

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git. from d0cbf5e Document BZ 65714 as a known issue new 23c7850 Restore pre-starting of core threads lost in fix for BZ 6

[tomcat] 01/03: Restore pre-starting of core threads lost in fix for BZ 65454

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 23c78507b5d3dc4c0bd36d263e4f99aa8221205c Author: Mark Thomas AuthorDate: Fri Dec 10 14:52:06 2021 + Restore pre-s

[tomcat] 03/03: Improved fix for BZ 65714

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 4795df9bf89f84decafa276805d0c265f93eb368 Author: Mark Thomas AuthorDate: Fri Dec 10 15:24:51 2021 + Improved fix

[tomcat] 02/03: Revert the previous fix for BZ 65714.

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 07747b8ca36ffd29350af24d1c9fd05a174ba25d Author: Mark Thomas AuthorDate: Fri Dec 10 14:55:53 2021 + Revert the pr

[tomcat] branch 9.0.x updated: Fix backport

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 115334b Fix backport 115334b is described below c

[tomcat] branch 10.0.x updated: Fix backport

2021-12-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.0.x by this push: new 3de7930 Fix backport 3de7930 is described below

[Bug 65714] HTTPS connection error using NIO2 with security manager enabled

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65714 Mark Thomas changed: What|Removed |Added Resolution|--- |FIXED Status|REOPENED

[Bug 65714] HTTPS connection error using NIO2 with security manager enabled

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65714 --- Comment #20 from Allan --- Thanks Mark. This sounds promising. For test in advance, where can we pull this image? -- You are receiving this mail because: You are the assignee for the bug. --

[Bug 65714] HTTPS connection error using NIO2 with security manager enabled

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65714 --- Comment #21 from Mark Thomas --- Which version do you need and I'll create a test build for you. -- You are receiving this mail because: You are the assignee for the bug. ---

[Bug 65714] HTTPS connection error using NIO2 with security manager enabled

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65714 --- Comment #22 from Allan --- How about 8.5.74 and 9.0.57 on RHEL 7 and Windows? -- You are receiving this mail because: You are the assignee for the bug. - To unsubscribe,

[Bug 65736] Improve org.apache.naming.factory.BeanFactory to mitigate JNDI injection

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65736 Mark Thomas changed: What|Removed |Added Severity|normal |enhancement --- Comment #2 from Mark Tho

[Bug 65714] HTTPS connection error using NIO2 with security manager enabled

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65714 --- Comment #23 from Mark Thomas --- 8.5.x: https://people.apache.org/~markt/dev/v8.5.72-4795df9/ 9.0.x: https://people.apache.org/~markt/dev/v9.0.57-115334b/ These are not official releases. They are development builds solely to test whether

[Bug 65714] HTTPS connection error using NIO2 with security manager enabled

2021-12-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=65714 --- Comment #24 from Allan --- Thanks. Will work on it. -- You are receiving this mail because: You are the assignee for the bug. - To unsubscribe, e-mail: dev-unsubscr...@to

Tomcat Use of Log4j v1.2.17

2021-12-10 Thread Naresh Annangar
Hi Team, While checking for CVE-2021-44228, we noticed the presence of Log4j v1.2.17 packaged along with Tomcat. Log4j lists 1.x as unsupported. Is there any analysis or information available if this is vulnerable or exploitable? Regards, Naresh