[INFO] DB Report for January, 2023

2023-01-11 Thread Bryan Pendleton
Below is the quarterly report I submitted to the board. Thank you to all the project communities for the feedback about project status and activities, much appreciated! thanks, bryan ## Description: The mission of the Apache DB project is to create and maintain commercial-quality, open-source,

Re: FW: Re: [External] : Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2023-01-10 Thread Rick Hillegas
Thanks, Kevin. When your fix turns up in a JDK release, I'll test drive it. Then I may be able to back out the changes which I made to the Derby tests and docs. On 1/10/23 6:20 AM, Kevin Walls wrote: Hi, that's great! Maybe the remoteDeserializationEnabled() method is no longer needed? (

Re: Topics for our January report to the board?

2023-01-10 Thread Rick Hillegas
Hi Bryan, Thanks again for taking care of this chore. Nothing comes to mind. On 1/10/23 4:45 AM, Bryan Pendleton wrote: Apparently, during the holiday season, I forgot about our reporting schedule, and our quarterly report to the board is due tomorrow. Please let me know of any topics we

Topics for our January report to the board?

2023-01-10 Thread Bryan Pendleton
Apparently, during the holiday season, I forgot about our reporting schedule, and our quarterly report to the board is due tomorrow. Please let me know of any topics we should include in our January report. thanks, bryan

Re: FW: Re: [External] : Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2023-01-09 Thread Rick Hillegas
Thanks for running that experiment, Kevin. I have reproduced your results, re-enabled the skipped MBean tests, and documented this on https://issues.apache.org/jira/browse/DERBY-7149. While I have your attention, what should developers do when they see a "java.io.InvalidClassException: filter

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-09 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17656291#comment-17656291 ] ASF subversion and git services commented on DERBY-7149: Commit 1906522 from

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-09 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17656289#comment-17656289 ] Richard N. Hillegas commented on DERBY-7149: Attaching derby-7149-05-aa-reenableJMXTest.diff.

[jira] [Updated] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-09 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7149: --- Attachment: derby-7149-05-aa-reenableJMXTest.diff > Make it possible to build and

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-09 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17656287#comment-17656287 ] Richard N. Hillegas commented on DERBY-7149: In a private email, Kevin Walls from the Open

Re: [jira] [Commented] (DERBY-7145) MERGE UPDATE failing: Restore of a serializable or SQLData object of class , attempted to read more data than was originally stored

2023-01-06 Thread Stanimir Stamenkov via derby-dev
Thu, 5 Jan 2023 08:26:03 -0800, /Rick Hillegas/: Happy New Year, Stanimir. I have not looked into this further. I gave up after sinking a fair amount of time into a seemingly plausible solution. The MERGE implementation is unfortunately limited and brittle. It is hard to fix one problem

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2023-01-05 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: releaseNote.html > LDAP injection vulnerability in

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2023-01-05 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Issue & fix info: Release Note Needed > LDAP injection vulnerability in

Re: [External] : Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2023-01-05 Thread Rick Hillegas
Hi David, Derby now builds and tests cleanly after the changes introduced by Open JDK build 20-ea+27-2213. Our experience is described at https://issues.apache.org/jira/browse/DERBY-7149. Thanks, -Rick On 12/21/22 2:27 AM, David Delabassee wrote: Hi Rick, There's now a default

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-05 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17655068#comment-17655068 ] Richard N. Hillegas commented on DERBY-7149: Derby now builds and tests cleanly after the

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17655067#comment-17655067 ] ASF subversion and git services commented on DERBY-7149: Commit 1906409 from

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-05 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17655066#comment-17655066 ] Richard N. Hillegas commented on DERBY-7149: Tests passed cleanly on

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17655064#comment-17655064 ] ASF subversion and git services commented on DERBY-7149: Commit 1906408 from

Re: [jira] [Commented] (DERBY-7145) MERGE UPDATE failing: Restore of a serializable or SQLData object of class , attempted to read more data than was originally stored

2023-01-05 Thread Rick Hillegas
Happy New Year, Stanimir. I have not looked into this further. I gave up after sinking a fair amount of time into a seemingly plausible solution. The MERGE implementation is unfortunately limited and brittle. It is hard to fix one problem without breaking something else. At this time, I don't

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-04 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17654690#comment-17654690 ] Richard N. Hillegas commented on DERBY-7149: Attaching

[jira] [Updated] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-04 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7149: --- Attachment: derby-7149-04-aa-suppress-ThreadDeath-removalWarnings.diff > Make it

Re: [jira] [Commented] (DERBY-7145) MERGE UPDATE failing: Restore of a serializable or SQLData object of class , attempted to read more data than was originally stored

2023-01-04 Thread Stanimir Stamenkov via derby-dev
Hi Rick. Happy new year! I've wondered if you had a chance to look further into this one? – Stanimir Tue, 11 Oct 2022 22:53:00 + (UTC): [

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-04 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17654569#comment-17654569 ] Richard N. Hillegas commented on DERBY-7149: The remaining disruption caused by Open JDK

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-04 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17654539#comment-17654539 ] Richard N. Hillegas commented on DERBY-7149: Attaching derby-7149-03-aa-JMXdocs.diff and a

[jira] [Updated] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-04 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7149: --- Attachment: derby-7149-03-aa-JMXdocs.diff > Make it possible to build and test Derby

[jira] [Updated] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-04 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7149: --- Attachment: derby-7149-03-aa-JMXdocs.tar > Make it possible to build and test Derby

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-04 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17654506#comment-17654506 ] ASF subversion and git services commented on DERBY-7149: Commit 1906395 from

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-03 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17654124#comment-17654124 ] Bryan Pendleton commented on DERBY-7149: {quote}I intend to modify CacheManagerMBeanTest so that

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-03 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17654119#comment-17654119 ] Richard N. Hillegas commented on DERBY-7149: Attaching derby-7149-02-aa-disableJMXtest.diff.

[jira] [Updated] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-03 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7149: --- Attachment: derby-7149-02-aa-disableJMXtest.diff > Make it possible to build and

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2023-01-03 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17654117#comment-17654117 ] Richard N. Hillegas commented on DERBY-7149: The breakage in CacheManagerMBeanTest is caused

Re: [External] : Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2022-12-22 Thread Rick Hillegas
Thanks for the quick response, David. I'm afraid I'm still confused. Editing conf/management/management.properties to set   com.sun.management.jmxremote.serial.filter.pattern=* causes   java junit.textui.TestRunner org.apache.derbyTesting.functionTests.tests.management.CacheManagerMBeanTest

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-22 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17651455#comment-17651455 ] ASF subversion and git services commented on DERBY-7149: Commit 1906178 from

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-22 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17651454#comment-17651454 ] ASF subversion and git services commented on DERBY-7149: Commit 1906177 from

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-22 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17651447#comment-17651447 ] ASF subversion and git services commented on DERBY-7149: Commit 1906176 from

Re: [External] : Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2022-12-21 Thread David Delabassee
Hi Rick, Just to confirm, the params passed below in your tests are passed to the JVM that is throwing the exception, right ? Can you try to comment the filter in `JDK/conf/management/management.properties` ? --David On 21/12/2022 19:25, Rick Hillegas wrote: Thanks for those pointers,

Re: [External] : Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2022-12-21 Thread Rick Hillegas
Thanks for those pointers, David. I'm afraid that my naive attempts have failed to circumvent this filtering. All of the following commands fail with the same "java.io.InvalidClassException: filter status: REJECTED" error: java junit.textui.TestRunner

Re: [External] : Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2022-12-21 Thread David Delabassee
Hi Rick, There's now a default serialization filter for JMX since 20-EA build 22 (1), see release notes (2) and test (3). To confirm this is indeed the issue, you can either relax the filter to allow your target classes to be deserialized, or disable the filter. (1)

Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2022-12-20 Thread Rick Hillegas
Hi David, Open JDK build 20-ea+27-2213 introduces another problem. I see the following error when unmarshalling an object on behalf of an MBean:   java.io.InvalidClassException: filter status: REJECTED I do not see this problem under build 19+36-2238. Can you point me at the experts who can

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-20 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17650044#comment-17650044 ] Richard N. Hillegas commented on DERBY-7149: Attaching

[jira] [Updated] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-20 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7149: --- Attachment: derby-7149-01-ac-deprecateURLconstructor.diff > Make it possible to

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-20 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17650037#comment-17650037 ] Richard N. Hillegas commented on DERBY-7149: Open JDK build 20-ea+27-2213 introduces another

Re: [External] : Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2022-12-15 Thread David Delabassee
Hi Rick, I suggest to bring this on https://mail.openjdk.org/mailman/listinfo/net-dev Thanks, --David On 15/12/2022 00:06, Rick Hillegas wrote: Thanks for the heads-up, David. I see many deprecation warnings and javadoc warnings when I build Derby with Open JDK build 20-ea+27-2213. Right

Re: JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2022-12-14 Thread Rick Hillegas
Thanks for the heads-up, David. I see many deprecation warnings and javadoc warnings when I build Derby with Open JDK build 20-ea+27-2213. Right now, I am trying to track down a fix for the problems introduced by this change: - JDK-8294241: Deprecate URL public constructors My naive attempt

[jira] [Updated] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-14 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7149: --- Attachment: derby-7149-01-aa-deprecateURLconstructor.diff > Make it possible to

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-14 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17647734#comment-17647734 ] Richard N. Hillegas commented on DERBY-7149: Attaching

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-12 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17646349#comment-17646349 ] Richard N. Hillegas commented on DERBY-7149: And I see the following new warnings when I

[jira] [Commented] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-12 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17646293#comment-17646293 ] Richard N. Hillegas commented on DERBY-7149: I see the following new warnings when I build

[jira] [Created] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-12 Thread Richard N. Hillegas (Jira)
Richard N. Hillegas created DERBY-7149: -- Summary: Make it possible to build and test Derby cleanly with JDK 20 Key: DERBY-7149 URL: https://issues.apache.org/jira/browse/DERBY-7149 Project:

[jira] [Assigned] (DERBY-7149) Make it possible to build and test Derby cleanly with JDK 20

2022-12-12 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas reassigned DERBY-7149: -- Assignee: Richard N. Hillegas > Make it possible to build and test Derby

[jira] [Closed] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-12 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas closed DERBY-7147. -- > LDAP injection vulnerability in LDAPAuthenticationImpl >

[jira] [Resolved] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-12 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas resolved DERBY-7147. Fix Version/s: 10.14.3 10.15.2.1 10.16.1.2

JDK 20 Rampdown Phase 1 & Valhalla LW4 Early-Access builds

2022-12-12 Thread David Delabassee
Welcome to the final OpenJDK Quality Outreach update for 2022! JDK 20, scheduled for General Availability on March 21 2023, is now in Rampdown Phase One (RDP1) [1]. At this point, the overall JDK 20 [2] feature set is frozen (see below the final list of JEPs integrated into JDK 20) and only

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-08 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17645003#comment-17645003 ] Richard N. Hillegas commented on DERBY-7147: I'm done with the work I plan to do on this

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-07 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17644419#comment-17644419 ] ASF subversion and git services commented on DERBY-7147: Commit 1905843 from

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-07 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17644418#comment-17644418 ] Richard N. Hillegas commented on DERBY-7147: Attaching

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-07 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: derby-7147-04-aa-pointLDAPTestAtInstructions.diff > LDAP injection

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-07 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17644408#comment-17644408 ] ASF subversion and git services commented on DERBY-7147: Commit 1905842 from

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-06 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17643970#comment-17643970 ] ASF subversion and git services commented on DERBY-7147: Commit 1905800 from

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-04 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17643043#comment-17643043 ] Richard N. Hillegas commented on DERBY-7147: I think that the LDAP provider should take

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17642921#comment-17642921 ] Bryan Pendleton commented on DERBY-7147: Perhaps we can proceed with what we have now, and in a

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17642879#comment-17642879 ] Bryan Pendleton commented on DERBY-7147: Actually, I think I did my ldaps test incorrectly.

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17642863#comment-17642863 ] Richard N. Hillegas commented on DERBY-7147: Thanks for that feedback, Bryan. Attaching

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: derby-7147-03-ab-updateLDAPinstructions.diff > LDAP injection

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: derby-7147-03-ab-updateLDAPinstructions.tar > LDAP injection

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17642851#comment-17642851 ] Bryan Pendleton commented on DERBY-7147: Those documentation updates seem like good improvements

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-29 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17640966#comment-17640966 ] Richard N. Hillegas commented on DERBY-7147: Attaching

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-29 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: derby-7147-03-aa-updateLDAPinstructions.diff > LDAP injection

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-29 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: derby-7147-03-aa-updateLDAPinstructions.tar > LDAP injection

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-29 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17640774#comment-17640774 ] Richard N. Hillegas commented on DERBY-7147: I think that we need to update the security

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-29 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17640706#comment-17640706 ] Bryan Pendleton commented on DERBY-7147: Fine with me to make just a 10.16.2 release.  What in

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-28 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17640294#comment-17640294 ] Richard N. Hillegas commented on DERBY-7147: At a minimum, I think that we need to publish

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-28 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17640286#comment-17640286 ] ASF subversion and git services commented on DERBY-7147: Commit 1905586 from

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-28 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17640283#comment-17640283 ] ASF subversion and git services commented on DERBY-7147: Commit 1905585 from

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-27 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17639730#comment-17639730 ] ASF subversion and git services commented on DERBY-7147: Commit 1905560 from

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17639555#comment-17639555 ] ASF subversion and git services commented on DERBY-7147: Commit 1905550 from

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17639554#comment-17639554 ] Richard N. Hillegas commented on DERBY-7147: Thanks for testing the patch, Bryan. Your notes

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17639540#comment-17639540 ] Bryan Pendleton commented on DERBY-7147: Rick, a possible difference between your 'ant

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17639539#comment-17639539 ] Bryan Pendleton commented on DERBY-7147: Anyway, if it wasn't clear from the above, +1 from me to

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17639538#comment-17639538 ] Bryan Pendleton commented on DERBY-7147: Yay! I've successfully run LDAPAuthenticationTest with

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17639510#comment-17639510 ] Richard N. Hillegas commented on DERBY-7147: The ant command works for me against a sane

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17639509#comment-17639509 ] Bryan Pendleton commented on DERBY-7147: Hi Rick, sorry for these stupid questions. Do you think

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-23 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: derby-7147-02-ab-escapeLDAPsearchFilter.diff > LDAP injection

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-23 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17637898#comment-17637898 ] Richard N. Hillegas commented on DERBY-7147: Attaching

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-23 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17637772#comment-17637772 ] Bryan Pendleton commented on DERBY-7147: Rick, my fairly casual read of [RFC

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17637475#comment-17637475 ] Bryan Pendleton commented on DERBY-7147: Uh-oh! Reverting your patch makes the problem go away.

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17637473#comment-17637473 ] Bryan Pendleton commented on DERBY-7147: That's a good point! I do have your patch applied. I'll

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17637466#comment-17637466 ] Richard N. Hillegas commented on DERBY-7147: Thanks for slogging through this, Bryan. Just

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17637439#comment-17637439 ] Bryan Pendleton commented on DERBY-7147: My attempts to connect to the ApacheDS server using the

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17637437#comment-17637437 ] Bryan Pendleton commented on DERBY-7147: I've been trying to verify that Derby can use the

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636981#comment-17636981 ] Bryan Pendleton commented on DERBY-7147: Here's a tiny little bit of instructions on how to run

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636980#comment-17636980 ] Bryan Pendleton commented on DERBY-7147: Archive.org finds that ancient broken link:

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: derby-7147-02-aa-escapeLDAPsearchFilter.diff > LDAP injection

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636844#comment-17636844 ] Richard N. Hillegas commented on DERBY-7147: Attaching

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636778#comment-17636778 ] ASF subversion and git services commented on DERBY-7147: Commit 1905442 from

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636777#comment-17636777 ] Richard N. Hillegas commented on DERBY-7147: Attaching

[jira] [Updated] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richard N. Hillegas updated DERBY-7147: --- Attachment: derby-7147-01-aa-reformatForReadability.diff > LDAP injection

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-20 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636344#comment-17636344 ] Bryan Pendleton commented on DERBY-7147: I can test on Linux, and possibly (if we really think

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-20 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636303#comment-17636303 ] Richard N. Hillegas commented on DERBY-7147: If you can figure out how to run a directory

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-19 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636217#comment-17636217 ] Bryan Pendleton commented on DERBY-7147: That seems like it could be a useful step forward! I

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-19 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17636207#comment-17636207 ] Richard N. Hillegas commented on DERBY-7147: There are other dead links in the LDAP

<    1   2   3   4   5   6   7   8   9   10   >