Re: [VOTE] Release Apache Tomcat 11.0.0-M3

2023-02-20 Thread Mark Thomas
On 17/02/2023 18:18, Mark Thomas wrote: The proposed 11.0.0-M3 release is: [ ] Broken - do not release [X] Stable - go ahead and release as 11.0.0-M3 Still haven't remembered to update that to Alpha Test pass on Linux, Windows and MacOS (Intel & M1). Mark

[tomcat] branch main updated: Increment version for next dev cycle

2023-02-20 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new d97bf3be48 Increment version for next dev cycle

[Bug 66482] Nio2 websocket timeout cause the response is no longer possible, always pending

2023-02-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=66482 --- Comment #3 from Mark Thomas --- It might be because 01f2cf25b270a84d0daeefc4f215aa2f56e1df99 also changed the WebSocket implementation to use AsyncIO. -- You are receiving this mail because: You are the assignee for the bug.

Re: [VOTE] Release Apache Tomcat 9.0.72

2023-02-20 Thread Felix Schumacher
Am 18.02.23 um 10:44 schrieb Rémy Maucherat: The proposed Apache Tomcat 9.0.72 release is now available for voting. The notable changes compared to 9.0.71 are: - Add an error report valve that allows redirecting to or proxying from an external web server. - Log basic information for

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Mark Thomas
On 19/02/2023 18:15, Igal Sapir wrote: I get a failure on TestImportHandlerStandardPackages on both Java 11 and Java 17. Any thoughts? Output below: Testsuite: jakarta.el.TestImportHandlerStandardPackages Tests run: 1, Failures: 1, Errors: 0, Skipped: 0, Time elapsed: 0.319 sec That

Re: [tomcat] branch main updated: Many improvements.

2023-02-20 Thread Mark Thomas
On 18/02/2023 05:43, Han Li wrote: On Feb 17, 2023, at 17:17, Rémy Maucherat wrote: On Fri, Feb 17, 2023 at 4:32 AM wrote: -ciphers.removeAll(movedCiphers); +movedCiphers.forEach(ciphers::remove); Ok for some of them maybe, but I don't understand why one this is better.

Re: [VOTE] Release Apache Tomcat 11.0.0-M3

2023-02-20 Thread Felix Schumacher
Am 17.02.23 um 19:18 schrieb Mark Thomas: The proposed Apache Tomcat 11.0.0-M3 release is now available for voting. Apache Tomcat 11.0.0-M3 is a milestone release of the 11.0.x branch and has been made to provide users with early access to the new features in Apache Tomcat 11.0.x so that

[Bug 66482] Nio2 websocket timeout cause the response is no longer possible, always pending

2023-02-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=66482 Remy Maucherat changed: What|Removed |Added OS||All --- Comment #2 from Remy

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Felix Schumacher
Am 20.02.23 um 12:41 schrieb Mark Thomas: On 20/02/2023 11:30, Felix Schumacher wrote: The source tar seem to be missing two files, that might be important:   res/META-INF/catalina.jar/services/java.net.spi.URLStreamHandlerProvider   

[tomcat] branch 9.0.x updated: Next is 9.0.73

2023-02-20 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 694a93a6d5 Next is 9.0.73 694a93a6d5 is described

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Felix Schumacher
Am 19.02.23 um 15:11 schrieb Christopher Schultz: The proposed Apache Tomcat 10.1.6 release is now available for voting. The notable changes compared to 10.1.5 are: - Switch to using the ServiceLoader mechanism to load the custom URL   protocol handlers that Tomcat uses. - Update the

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Mark Thomas
On 20/02/2023 11:30, Felix Schumacher wrote: The source tar seem to be missing two files, that might be important:  res/META-INF/catalina.jar/services/java.net.spi.URLStreamHandlerProvider   res/META-INF/tomcat-embed-core.jar/services/java.net.spi.URLStreamHandlerProvider I see those files

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Mark Thomas
On 19/02/2023 14:11, Christopher Schultz wrote: The proposed 10.1.6 release is: [ ] Broken - do not release [X] Stable - go ahead and release as 10.1.6 Build is reproducible. Tests pass on Linux, Windows and MacOS (Intel and M1). Mark

Re: [VOTE] Release Apache Tomcat 8.5.86

2023-02-20 Thread Felix Schumacher
Am 18.02.23 um 14:56 schrieb Christopher Schultz: The proposed Apache Tomcat 8.5.86 release is now available for voting. The notable changes compared to 8.5.85 are: - Add an error report valve that allows redirecting to or proxying from   an external web server. - Add the shared address

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Christopher Schultz
Konstantin, On 2/20/23 08:43, Konstantin Kolinko wrote: пн, 20 февр. 2023 г. в 16:16, Christopher Schultz : All, I'm getting a failure on jakarta.servlet.http.TestHttpServletDoHeadValidWrite0.NIO on Windows Looks like 11 failures all of the form: Failed to delete at least one file I'm

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Christopher Schultz
Mark, On 2/20/23 08:27, Mark Thomas wrote: You'll probably need to change the default ephemeral (dynamic in MS speak) port range to avoid issues with port exhaustion. I'm using: netsh int ipv4 set dynamicport tcp start=1025 num=64511 I suspect running out of ports is causing odd errors. I

[SECURITY] CVE-2023-24998 Apache Tomcat - FileUpload DoS with excessive parts

2023-02-20 Thread Mark Thomas
Re-sending with corrected credit CVE-2023-24998 Apache Tomcat - FileUpload DoS with excessive parts Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 Apache Tomcat 10.1.0-M1 to 10.1.4 Apache Tomcat 9.0.0-M1 to 9.0.70 Apache Tomcat 8.5.0 to

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Konstantin Kolinko
пн, 20 февр. 2023 г. в 16:16, Christopher Schultz : > > All, > > I'm getting a failure on > jakarta.servlet.http.TestHttpServletDoHeadValidWrite0.NIO on Windows > > Looks like 11 failures all of the form: > >Failed to delete at least one file > > I'm assuming that this is a spurious error, but

Re: [VOTE] Release Apache Tomcat 9.0.72

2023-02-20 Thread Mark Thomas
On 18/02/2023 09:44, Rémy Maucherat wrote: The proposed 9.0.72 release is: [ ] Broken - do not release [X] Stable - go ahead and release as 9.0.72 Build is reproducible. Tests pass on Linux, Windows and MacOS (Intel and M1). Mark

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Christopher Schultz
All, I'm getting a failure on jakarta.servlet.http.TestHttpServletDoHeadValidWrite0.NIO on Windows Looks like 11 failures all of the form: Failed to delete at least one file I'm assuming that this is a spurious error, but the test keeps failing at that point and stopping, despite having

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Mark Thomas
You'll probably need to change the default ephemeral (dynamic in MS speak) port range to avoid issues with port exhaustion. I'm using: netsh int ipv4 set dynamicport tcp start=1025 num=64511 I suspect running out of ports is causing odd errors. Mark On 20/02/2023 13:16, Christopher

Re: [VOTE] Release Apache Tomcat 8.5.86

2023-02-20 Thread Mark Thomas
On 18/02/2023 13:56, Christopher Schultz wrote: The proposed 8.5.86 release is: [ ] Broken - do not release [X] Stable - go ahead and release as 8.5.86 (stable) The binary distributions are reproducible. The source distributions are not reproducible because the tag is missing the

Re: [VOTE] Release Apache Tomcat 8.5.86

2023-02-20 Thread Rémy Maucherat
On Sat, Feb 18, 2023 at 2:57 PM Christopher Schultz wrote: > > The proposed Apache Tomcat 8.5.86 release is now available for voting. > > The notable changes compared to 8.5.85 are: > > - Add an error report valve that allows redirecting to or proxying from >an external web server. > > - Add

[Bug 66482] Nio2 websocket timeout cause the response is no longer possible, always pending

2023-02-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=66482 --- Comment #4 from Remy Maucherat --- Ok, so that makes sense. I checked the code and both read and write can throw this undocumented exception (there are other exceptions but they don't occur, unlike this one apparently). The easiest is

svn commit: r1907777 - in /tomcat/site/trunk: docs/security-10.html docs/security-11.html docs/security-8.html docs/security-9.html xdocs/security-10.xml xdocs/security-11.xml xdocs/security-8.xml xdo

2023-02-20 Thread markt
Author: markt Date: Mon Feb 20 16:36:44 2023 New Revision: 190 URL: http://svn.apache.org/viewvc?rev=190=rev Log: Update site for CVE-2023-24998 Modified: tomcat/site/trunk/docs/security-10.html tomcat/site/trunk/docs/security-11.html tomcat/site/trunk/docs/security-8.html

[SECURITY] CVE-2023-24998 Apache Tomcat - FileUpload DoS with excessive parts

2023-02-20 Thread Mark Thomas
CVE-2023-24998 Apache Tomcat - FileUpload DoS with excessive parts Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 11.0.0-M1 Apache Tomcat 10.1.0-M1 to 10.1.4 Apache Tomcat 9.0.0-M1 to 9.0.70 Apache Tomcat 8.5.0 to 8.5.84 Description: Apache Tomcat

Re: [VOTE] Release Apache Tomcat 11.0.0-M3

2023-02-20 Thread Rémy Maucherat
On Fri, Feb 17, 2023 at 7:18 PM Mark Thomas wrote: > > The proposed Apache Tomcat 11.0.0-M3 release is now available for > voting. > > Apache Tomcat 11.0.0-M3 is a milestone release of the 11.0.x branch and > has been made to provide users with early access to the new features in > Apache Tomcat

Re: [VOTE] Release Apache Tomcat 9.0.72

2023-02-20 Thread Rémy Maucherat
On Sat, Feb 18, 2023 at 10:44 AM Rémy Maucherat wrote: > > The proposed Apache Tomcat 9.0.72 release is now available for voting. > > The notable changes compared to 9.0.71 are: > > - Add an error report valve that allows redirecting to or proxying from an >external web server. > > - Log

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Igal Sapir
Mark, On Mon, Feb 20, 2023 at 1:22 AM Mark Thomas wrote: > On 19/02/2023 18:15, Igal Sapir wrote: > > I get a failure on TestImportHandlerStandardPackages on both Java 11 and > > Java 17. Any thoughts? Output below: > > > > Testsuite: jakarta.el.TestImportHandlerStandardPackages > > Tests

Re: [VOTE] Release Apache Tomcat 10.1.6

2023-02-20 Thread Igal Sapir
On Sun, Feb 19, 2023 at 6:11 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > The proposed Apache Tomcat 10.1.6 release is now available for > voting. > > The notable changes compared to 10.1.5 are: > > - Switch to using the ServiceLoader mechanism to load the custom URL >

[Bug 66482] Nio2 websocket timeout cause the response is no longer possible, always pending

2023-02-20 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=66482 --- Comment #5 from zhougang --- (In reply to Remy Maucherat from comment #4) > Ok, so that makes sense. I checked the code and both read and write can > throw this undocumented exception (there are other exceptions but they don't > occur,

[GitHub] [tomcat] zengwei2000 opened a new pull request, #593: Update CONTRIBUTING.md

2023-02-20 Thread via GitHub
zengwei2000 opened a new pull request, #593: URL: https://github.com/apache/tomcat/pull/593 fix typo -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe,

[GitHub] [tomcat] markt-asf commented on pull request #593: Update CONTRIBUTING.md

2023-02-20 Thread via GitHub
markt-asf commented on PR #593: URL: https://github.com/apache/tomcat/pull/593#issuecomment-1437964475 That spelling is correct for US English. Given the range of contributors to Tomcat, there is a mix of UK and US English used in the Tomcat docs. -- This is an automated message from

[GitHub] [tomcat] markt-asf closed pull request #593: Update CONTRIBUTING.md

2023-02-20 Thread via GitHub
markt-asf closed pull request #593: Update CONTRIBUTING.md URL: https://github.com/apache/tomcat/pull/593 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe,