Re: JDK 14 - Early Access build 17 is available

2019-10-07 Thread Mark Thomas
On 04/10/2019 10:30, Rory O'Donnell wrote: > Hi Mark, > > *OpenJDK builds  *- JDK 14 - Early Access build 17 is available at > http://jdk.java.net/14/ 9.0.x builds without error 9.0.x runs and passes a simple smoke test 9.0.x unit tests all pass No concerns at this point. Mark

Re: JDK 14 - Early Access build 17 is available

2019-10-07 Thread Rory O'Donnell
Thanks for the update Mark! On 07/10/2019 09:41, Mark Thomas wrote: On 04/10/2019 10:30, Rory O'Donnell wrote: Hi Mark, *OpenJDK builds  *- JDK 14 - Early Access build 17 is available at http://jdk.java.net/14/ 9.0.x builds without error 9.0.x runs and passes a simple smoke test 9.0.x unit te

[tomcat] branch master updated: Remove new lines at start (not present in English version)

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new 1881e6e Remove new lines at start (not present i

[GitHub] [tomcat] markt-asf merged pull request #208: Fix typos

2019-10-07 Thread GitBox
markt-asf merged pull request #208: Fix typos URL: https://github.com/apache/tomcat/pull/208 This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above t

[GitHub] [tomcat] markt-asf commented on issue #208: Fix typos

2019-10-07 Thread GitBox
markt-asf commented on issue #208: Fix typos URL: https://github.com/apache/tomcat/pull/208#issuecomment-538918249 Many thanks. This is an automated message from the Apache Git Service. To respond to the message, please log on

[tomcat] branch master updated: Fix typos (#208)

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new 5daacce Fix typos (#208) 5daacce is described be

[tomcat] 01/01: Tag 9.0.27

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to tag 9.0.27 in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 34735123777fe15a5525b8242964293cddbfae64 Author: Mark Thomas AuthorDate: Mon Oct 7 10:50:40 2019 +0100 Tag 9.0.27 ---

[tomcat] tag 9.0.27 created (now 3473512)

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to tag 9.0.27 in repository https://gitbox.apache.org/repos/asf/tomcat.git. at 3473512 (commit) This tag includes the following new commits: new 3473512 Tag 9.0.27 The 1 revisions listed abov

Nexus: Staging Completed

2019-10-07 Thread Nexus Repository Manager
Message from: https://repository.apache.orgDeployer properties:"userAgent" = "maven-artifact/2.2.1 (Java 1.8.0_222; Windows 7 6.1)""userId" = "markt""ip" = "86.144.250.12"Details:The following artifacts have been staged/org/apache/tomcat/tomcat-i18n-de/9.0.27/tomcat-i18n-de-9.0.27.pom(SHA1: 6c855c9

svn commit: r36230 - in /dev/tomcat/tomcat-9/v9.0.27: ./ bin/ bin/embed/ src/

2019-10-07 Thread markt
Author: markt Date: Mon Oct 7 10:21:21 2019 New Revision: 36230 Log: Upload 9.0.27 for voting Added: dev/tomcat/tomcat-9/v9.0.27/ dev/tomcat/tomcat-9/v9.0.27/KEYS dev/tomcat/tomcat-9/v9.0.27/README.html dev/tomcat/tomcat-9/v9.0.27/RELEASE-NOTES dev/tomcat/tomcat-9/v9.0.27/bin

[VOTE] Release Apache Tomcat 9.0.27

2019-10-07 Thread Mark Thomas
The proposed Apache Tomcat 9.0.27 release is now available for voting. The major changes compared to the 9.0.26 release are: - Update to Commons Daemon 1.2.2 to pick up the fix for a regression in Commons Daemon 1.2.0 and 1.2.1 that triggered a crash on startup when running on a Windows OS th

[tomcat] 02/02: Increment version number for next dev cycle

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git commit e88f66986b476ecef76b06a8f27f78610245f09e Author: Mark Thomas AuthorDate: Mon Oct 7 14:25:14 2019 +0100 Increment ver

[tomcat] 01/02: Update changelog

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 69702e28a9e914767e98a4458fcefe725c6721ff Author: Mark Thomas AuthorDate: Mon Oct 7 10:35:32 2019 +0100 Update change

[tomcat] branch master updated (5daacce -> e88f669)

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git. from 5daacce Fix typos (#208) new 69702e2 Update changelog new e88f669 Increment version number for next dev c

[tomcat] 01/01: Tag 8.5.47

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to tag 8.5.47 in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 14bdacea996993a3b94ec0972cea92370e42ae4d Author: Mark Thomas AuthorDate: Mon Oct 7 14:28:13 2019 +0100 Tag 8.5.47 ---

[tomcat] tag 8.5.47 created (now 14bdace)

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to tag 8.5.47 in repository https://gitbox.apache.org/repos/asf/tomcat.git. at 14bdace (commit) This tag includes the following new commits: new 14bdace Tag 8.5.47 The 1 revisions listed abov

[Bug 63808] user and certificate info is not passed to tomcat

2019-10-07 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63808 Christopher Schultz changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

[tomcat] branch master updated: Fix typo

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new 63dc36b Fix typo 63dc36b is described below com

[tomcat] branch 8.5.x updated (37782c6 -> 9d6e09f)

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a change to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git. from 37782c6 Fix NPEs when looking for static methods new 434b5dd Increment version ready for next development cycle

[tomcat] 02/02: Fix typo

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 9d6e09f8a944e2a1a6ba5f0f250f65431137325c Author: Mark Thomas AuthorDate: Mon Oct 7 14:45:08 2019 +0100 Fix typo ---

[tomcat] 01/02: Increment version ready for next development cycle

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git commit 434b5ddfd288693212d7b33a54440c1b59b9292d Author: Mark Thomas AuthorDate: Mon Oct 7 14:46:26 2019 +0100 Increment vers

[tomcat] branch 7.0.x updated: Fix typo

2019-10-07 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 7.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/7.0.x by this push: new 0034a18 Fix typo 0034a18 is described below commi

Nexus: Staging Completed

2019-10-07 Thread Nexus Repository Manager
Message from: https://repository.apache.orgDeployer properties:"userAgent" = "maven-artifact/2.2.1 (Java 1.7.0_80; Windows 7 6.1)""userId" = "markt""ip" = "86.144.250.12"Details:The following artifacts have been staged/org/apache/tomcat/tomcat-i18n-de/8.5.47/tomcat-i18n-de-8.5.47.pom.asc(SHA1: 7783

svn commit: r36232 [2/2] - in /dev/tomcat/tomcat-8/v8.5.47: ./ bin/ bin/embed/ bin/extras/ src/

2019-10-07 Thread markt
Added: dev/tomcat/tomcat-8/v8.5.47/src/apache-tomcat-8.5.47-src.zip.asc == --- dev/tomcat/tomcat-8/v8.5.47/src/apache-tomcat-8.5.47-src.zip.asc (added) +++ dev/tomcat/tomcat-8/v8.5.47/src/apache-tomcat-8.5.47-src.zip.asc Mo

svn commit: r36232 [1/2] - in /dev/tomcat/tomcat-8/v8.5.47: ./ bin/ bin/embed/ bin/extras/ src/

2019-10-07 Thread markt
Author: markt Date: Mon Oct 7 13:54:40 2019 New Revision: 36232 Log: Upload 8.5.47 for voting Added: dev/tomcat/tomcat-8/v8.5.47/ dev/tomcat/tomcat-8/v8.5.47/KEYS dev/tomcat/tomcat-8/v8.5.47/README.html dev/tomcat/tomcat-8/v8.5.47/RELEASE-NOTES dev/tomcat/tomcat-8/v8.5.47/bin

[VOTE] Release Apache Tomcat 8.5.47

2019-10-07 Thread Mark Thomas
The proposed Apache Tomcat 8.5.47 release is now available for voting. The major changes compared to the 8.5.46 release are: - Update to Commons Daemon 1.2.2 to pick up the fix for a regression in Commons Daemon 1.2.0 and 1.2.1 that triggered a crash on startup when running on a Windows OS th

Re: [VOTE] Release Apache Tomcat 9.0.27

2019-10-07 Thread Rémy Maucherat
On Mon, Oct 7, 2019 at 1:51 PM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.27 release is now available for voting. > > The major changes compared to the 9.0.26 release are: > > - Update to Commons Daemon 1.2.2 to pick up the fix for a regression in > Commons Daemon 1.2.0 and 1.2.1 that

svn commit: r1868084 - in /tomcat/site/trunk: docs/presentations.html xdocs/presentations.xml

2019-10-07 Thread schultz
Author: schultz Date: Mon Oct 7 14:28:11 2019 New Revision: 1868084 URL: http://svn.apache.org/viewvc?rev=1868084&view=rev Log: Add "latest" presentation identifiers. Add javascript and styles to identify "targeted" anchors. Modified: tomcat/site/trunk/docs/presentations.html tomcat/site

[PROPOSAL] Tomcat 10: Drop APR Connector

2019-10-07 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, I recently gave a presentation on locking-down Apache Tomcat[1] and I briefly discussed the "sharp edges" present in Tomcat. Some of them are unnecessarily sharp and may be actually unnecessary. I'm going to make a few proposals to remove funct

[Bug 63808] user and certificate info is not passed to tomcat

2019-10-07 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63808 Arpad Magosanyi changed: What|Removed |Added Resolution|INVALID |--- Status|RESOLVED

[PROPOSAL] Tomcat 10: Remove Server-Side Includes (SSI)

2019-10-07 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, I recently gave a presentation on locking-down Apache Tomcat[1] and I briefly discussed the "sharp edges" present in Tomcat. Some of them are unnecessarily sharp and may be actually unnecessary. I'm going to make a few proposals to remove funct

[PROPOSAL] Tomcat 10: Remove WebDAV

2019-10-07 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, I recently gave a presentation on locking-down Apache Tomcat[1] and I briefly discussed the "sharp edges" present in Tomcat. Some of them are unnecessarily sharp and may be actually unnecessary. I'm going to make a few proposals to remove funct

Re: [PROPOSAL] Tomcat 10: Drop APR Connector

2019-10-07 Thread Coty Sutherland
On Mon, Oct 7, 2019 at 10:39 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them >

Re: [PROPOSAL] Tomcat 10: Drop APR Connector

2019-10-07 Thread Mark Thomas
> All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them > are unnecessarily sharp and may be actually unnecessary. I'm going to > make a few proposals to remove functions from Tomcat. > > Proposal: Remo

[PROPOSAL] Tomcat 10: Remove CGI Servlet

2019-10-07 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, I recently gave a presentation on locking-down Apache Tomcat[1] and I briefly discussed the "sharp edges" present in Tomcat. Some of them are unnecessarily sharp and may be actually unnecessary. I'm going to make a few proposals to remove funct

Re: [PROPOSAL] Tomcat 10: Remove Server-Side Includes (SSI)

2019-10-07 Thread Mark Thomas
> All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them > are unnecessarily sharp and may be actually unnecessary. I'm going to > make a few proposals to remove functions from Tomcat. > > Proposal: Remo

Re: [PROPOSAL] Tomcat 10: Remove CGI Servlet

2019-10-07 Thread Coty Sutherland
On Mon, Oct 7, 2019 at 11:00 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them >

Re: [PROPOSAL] Tomcat 10: Remove WebDAV

2019-10-07 Thread Mark Thomas
> All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them > are unnecessarily sharp and may be actually unnecessary. I'm going to > make a few proposals to remove functions from Tomcat. > > Proposal: Remo

Re: [PROPOSAL] Tomcat 10: Remove CGI Servlet

2019-10-07 Thread Mark Thomas
> All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them > are unnecessarily sharp and may be actually unnecessary. I'm going to > make a few proposals to remove functions from Tomcat. > > Proposal: Remo

Re: [PROPOSAL] Tomcat 10: Remove CGI Servlet

2019-10-07 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Coty, On 10/7/19 11:02, Coty Sutherland wrote: > On Mon, Oct 7, 2019 at 11:00 AM Christopher Schultz > > wrote: > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and > I briefly discus

Re: [PROPOSAL] Tomcat 10: Remove CGI Servlet

2019-10-07 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Mark, On 10/7/19 11:10, Mark Thomas wrote: >> All, >> >> I recently gave a presentation on locking-down Apache Tomcat[1] >> and I briefly discussed the "sharp edges" present in Tomcat. Some >> of them are unnecessarily sharp and may be actually unne

Re: [PROPOSAL] Tomcat 10: Remove WebDAV

2019-10-07 Thread Rémy Maucherat
On Mon, Oct 7, 2019 at 5:05 PM Mark Thomas wrote: > > All, > > > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > > briefly discussed the "sharp edges" present in Tomcat. Some of them > > are unnecessarily sharp and may be actually unnecessary. I'm going to > > make a few

Re: [PROPOSAL] Tomcat 10: Remove Server-Side Includes (SSI)

2019-10-07 Thread Coty Sutherland
On Mon, Oct 7, 2019 at 10:46 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them >

Re: [PROPOSAL] Tomcat 10: Drop APR Connector

2019-10-07 Thread Rémy Maucherat
On Mon, Oct 7, 2019 at 4:39 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them > a

Re: [PROPOSAL] Tomcat 10: Remove Server-Side Includes (SSI)

2019-10-07 Thread Igal Sapir
On 10/7/2019 7:46 AM, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, I recently gave a presentation on locking-down Apache Tomcat[1] and I briefly discussed the "sharp edges" present in Tomcat. Some of them are unnecessarily sharp and may be actually unnecessary

Re: [PROPOSAL] Tomcat 10: Remove CGI Servlet

2019-10-07 Thread Igal Sapir
On 10/7/2019 8:14 AM, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Mark, On 10/7/19 11:10, Mark Thomas wrote: All, I recently gave a presentation on locking-down Apache Tomcat[1] and I briefly discussed the "sharp edges" present in Tomcat. Some of them are unnece

Re: [VOTE] Release Apache Tomcat 9.0.27

2019-10-07 Thread Igal Sapir
Mark, On 10/7/2019 4:51 AM, Mark Thomas wrote: The proposed Apache Tomcat 9.0.27 release is now available for voting. I'm getting the failures below [1] for unit tests on Windows 10 with Java 1.8u181.  False positives? Igal [1] output\build\logs> grep -A 5 FAILED * */* TEST-org.apache.coyo

Re: [PROPOSAL] Tomcat 10: Remove Server-Side Includes (SSI)

2019-10-07 Thread Rémy Maucherat
On Mon, Oct 7, 2019 at 4:46 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them > a

[Bug 47795] service sticky_session not being set correctly with multiple isapi_redirect.dll loaded

2019-10-07 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=47795 Mark Thomas changed: What|Removed |Added Resolution|--- |WONTFIX Status|NEW

[Bug 53883] isapi_redirect v 1.2.37 crashes w3wp.exe on the production web servers - faulting module msvcrt.dll

2019-10-07 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=53883 Mark Thomas changed: What|Removed |Added Resolution|--- |DUPLICATE Status|NEEDINFO

[Bug 54117] access violation exception in isapi_redirect.dll

2019-10-07 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=54117 Mark Thomas changed: What|Removed |Added CC||frank.kavanagh@wbtsystems.c

Re: [PROPOSAL] Tomcat 10: Remove Server-Side Includes (SSI)

2019-10-07 Thread Emmanuel Bourg
>> Yes, basically I think we should remove both CGI and SSI, *but* actually >> keep them in a separate JAR. For CGI this is harder as it is directly in >> the servlets package, so it would have to be moved to servlets.cgi for >> Tomcat 10. +1, these things could be modularized and shared between

Re: [VOTE] Release Apache Tomcat 9.0.27

2019-10-07 Thread Emmanuel Bourg
Le 07/10/2019 à 13:51, Mark Thomas a écrit : > The proposed 9.0.27 release is: > [ ] Broken - do not release > [X] Stable - go ahead and release as 9.0.27 Tested on Debian with OpenJDK 11.0.5+6, OpenSSL 1.1.1d and Tomcat Native 1.2.23. No failure on the 3 test suites. Emmanuel Bourg ---

Re: [VOTE] Release Apache Tomcat 9.0.27

2019-10-07 Thread Coty Sutherland
On Mon, Oct 7, 2019 at 7:51 AM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.27 release is now available for voting. > > The major changes compared to the 9.0.26 release are: > > - Update to Commons Daemon 1.2.2 to pick up the fix for a regression in > Commons Daemon 1.2.0 and 1.2.1 that

Re: [VOTE] Release Apache Tomcat 8.5.47

2019-10-07 Thread Rémy Maucherat
On Mon, Oct 7, 2019 at 3:58 PM Mark Thomas wrote: > The proposed Apache Tomcat 8.5.47 release is now available for voting. > > The major changes compared to the 8.5.46 release are: > > - Update to Commons Daemon 1.2.2 to pick up the fix for a regression in > Commons Daemon 1.2.0 and 1.2.1 that

Re: [PROPOSAL] Tomcat 10: Drop APR Connector

2019-10-07 Thread Rémy Maucherat
On Mon, Oct 7, 2019 at 4:59 PM Mark Thomas wrote: > > All, > > > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > > briefly discussed the "sharp edges" present in Tomcat. Some of them > > are unnecessarily sharp and may be actually unnecessary. I'm going to > > make a few

[Bug 63214] Using JkAutoAlias, Filenames with Spaces Cannot be found

2019-10-07 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63214 --- Comment #1 from Mark Thomas --- Created attachment 36815 --> https://bz.apache.org/bugzilla/attachment.cgi?id=36815&action=edit Proposed fix I have attached a proposed fix for this. Essentially, it removes the calls to ap_os_escape_path.

[Bug 63808] user and certificate info is not passed to tomcat

2019-10-07 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63808 --- Comment #4 from Arpad Magosanyi --- The cause is found to be the fact that if you have a JkMount in a Location (or perhaps also a Directory) directive, all other autorization and authorization (or even all other?) directives are ineffective