Am 10.09.26 um 01:12 schrieb Mark Thomas:
The proposed Apache Tomcat 11.0.26 release is now available for voting.

The notable changes compared to 11.0.25 include:

- Update Tomcat Native to 2.0.16 (built with OpenSSL 3.5.8 for Windows)
   and make 2.0.16b the minimum required version.

- Various improvements to the RewriteValve

- Various TLS improvements including more robust OCSP and ALPN handling

- Ensure that WebSocket write timeouts apply to the complete message and
   are not lost if two writes have the same timeout.


For full details, see the change log:
https://nightlies.apache.org/tomcat/tomcat-11.0.x/docs/changelog.html

Applications that run on Tomcat 9 and earlier will not run on Tomcat 11 without changes. Java EE applications designed for Tomcat 9 and earlier may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will automatically convert them to Jakarta EE and copy them to the webapps directory. Applications using deprecated APIs may require further changes.

It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-11/v11.0.26/

The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1604
The tag is:
https://github.com/apache/tomcat/tree/11.0.26 3592f2541fe608f78bf755e6e79140768b8d07ae

The proposed 11.0.26 release is:
[ ] -1 Broken - do not release
[X] +1 Stable - go ahead and release as 11.0.26
+1 to release.

Reproducibility of the build checked (including the Windows installer) using "ant verify-release" on Linux Mint 22.3. OK after setting LANG.

Original Windows installer signature verified with osslsigncode 2.10.

Unit tests ran on platforms

- RHEL 8, 9 and 10 and SLES 15

using

- almost recent patch versions of JDK 17, 21, 25, 26 and 27+28 (EA)
(most tests used the JVM July releases, some were run again with the .1 releases from August)

from

- Eclipse Adoptium, Azul Zulu, Amazon Coretto, Oracle, RedHat (26 missing) and from OpenJDK for 27+28

Also tested with

- tcnative 2.0.16 and panama

based on

- OpenSSL 3.5.8, 3.6.4, 4.0.2 and for some combinations also with 4.1.0alpha1.

Each combination of platform, JVM and JSSE or tcnative or panama only tested for NIO or NIO2 (randomized). Total number of test combinations:

     48 nio2 jsse
     65 nio2 panama
    130 nio2 tcnative
     57 nio jsse
     64 nio panama
    133 nio tcnative

Test observations:

  - IMHO nothing critical

  - in addition
    - few crashes with tcnative (6 in 263 runs)
    - no crash failures with panama (129 runs)
    - few non-crash failures with jsse (7 in 105 runs)
    - few non-crash failures with tcnative (2 in 263 runs)
    - no non-crash failures with panama (129 runs)

Especially OpenSSL 4.1.0alpha1 does not show anything problematic.

Thanks for RM!

Best regards,

Rainer

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to