dev
Thread
Date
Earlier messages
Later messages
Messages by Thread
(tomcat) 17/25: Capture and send the final session delta in DeltaSession.expire() before acquiring the session monitor to avoid a lock order inversion against the delta lock
remm
(tomcat) 23/25: Make SimpleTcpCluster.stopInternal() cleanup robust: guard each step so a channel stop failure cannot skip listener removal and cluster valve unregistration, and unregister the MBeans of all cluster members from the member name map on stop
remm
(tomcat) 03/25: Skip auto-assigned-port connector thread pool MBeans in CollectedInfo since their name carries a name index rather than a port
remm
(tomcat) 21/25: Snapshot the request counter in ReplicationValve.updateStats() and guard against zero so that a concurrent resetStatistics() cannot cause a division by zero
remm
(tomcat) 06/25: Close the multicast socket in MultiCastSender when socket setup fails after creation to avoid leaking one socket per heartbeat and validate the TTL range in HeartbeatListener
remm
(tomcat) 02/25: Guard ClusterSingleSignOn.stopInternal() against a ClassCastException when the ReplicatedMap was never created after a failed start
remm
(tomcat) 07/25: Move attributes set during web application startup into the replicated attribute map when it is installed in ReplicatedContext so they are replicated to the other nodes
remm
Re: (tomcat) 07/25: Move attributes set during web application startup into the replicated attribute map when it is installed in ReplicatedContext so they are replicated to the other nodes
Mark Thomas
Re: (tomcat) 07/25: Move attributes set during web application startup into the replicated attribute map when it is installed in ReplicatedContext so they are replicated to the other nodes
Rémy Maucherat
(tomcat) 20/25: Make hasMembers volatile so that membership changes made on the tribes membership thread are visible to the request threads that read it
remm
(tomcat) 01/25: Replicate SSO session key set changes from removeSession() and sessionChangedId() in ClusterSingleSignOn so SSO entries are deregistered on all nodes when the last associated session expires
remm
(tomcat) 08/25: Fire ServletContextAttributeListener events for attributes stored in the local map of a ReplicatedContext by extracting the event firing logic of ApplicationContext into overridable hooks
remm
(tomcat) 04/25: Bound connect and read operations in TcpSender with timeouts since the heartbeat runs on the shared server utility executor, and close connections on read failure
remm
(tomcat) 16/25: Log a clear configuration error and disable watching when FarmWarDeployer has watchEnabled set without a watchDir rather than failing with a NullPointerException on start
remm
(tomcat) 10/25: Correct the calculation of the total number of fragment messages in FileMessageFactory which declared one message too many for files whose size is an exact multiple of the fragment size, so WAR deployments via FarmWarDeployer never completed for those files
remm
(tomcat) 25/25: Merge branch 'main' of
[email protected]
:apache/tomcat.git into main
remm
(tomcat) 22/25: Fire the SEND_MESSAGE_FAILURE_EVENT lifecycle event with the failing message, destination and exception from SimpleTcpCluster.send() when notifyLifecycleListenerOnFailure is enabled, making the previously declared but never fired event work as documented
remm
(tomcat) 24/25: Name the fallback manager created by SimpleTcpCluster.createManager() when cloning the manager template fails so that its replication messages carry a context name and are not routed to every context on the receiving nodes
remm
(tomcat) 09/25: Make MultiEnumeration.nextElement throw NoSuchElementException when exhausted and report attribute names present in both stores only once
remm
(tomcat) 18/25: Reset noContextManagerReceived in DeltaManager.getAllClusterSessions() alongside stateTransferred so that a repeated state transfer does not exit immediately on a stale response
remm
(tomcat) 12/25: Use a concurrent map for WarWatcher.currentStatus since clear() may run on the stop thread while check() iterates the map on the container background thread
remm
(tomcat) 15/25: Avoid logging a spurious delete failure for a context.xml that never existed and log a warning when a cluster undeploy targets a context that is not present on the node in FarmWarDeployer
remm
(tomcat) 11/25: Synchronize FileMessageFactory.isValid() with the write path and remove expired factories by instance to avoid racing with in-flight transfers
remm
(tomcat) branch main updated: Attempt to fix buildbot failure
markt
(tomcat) branch 9.0.x updated (59ef2708a3 -> 041c531d54)
remm
(tomcat) 05/09: Synchronise the check for an existing nonce cache with its creation in CsrfPreventionFilter to prevent concurrent requests on the same session discarding a cache containing already-issued nonces, which could trigger spurious rejections
remm
(tomcat) 04/09: Use an instanceof check when instantiating the configured rateLimitClassName in RateLimitFilter.init() so a class that does not implement RateLimiter produces the intended ServletException rather than a raw ClassCastException
remm
(tomcat) 07/09: Validate the port header value in RemoteIpFilter and RemoteIpValve so that values outside the 1-65535 range fall back to the default server port rather than being applied as an invalid port
remm
(tomcat) 06/09: Clamp the max-age value generated by the ExpiresFilter to a minimum of zero to avoid emitting the invalid negative delta-seconds value when the computed expiration time is already in the past
remm
(tomcat) 09/09: Fix compilation errors
remm
(tomcat) 02/09: Make the content-type checks in the AddDefaultCharsetFilter response wrapper case-insensitive as required by RFC 9110 for media types and parameter names
remm
(tomcat) 01/09: Ignore a null charset in the AddDefaultCharsetFilter response wrapper rather than storing it and later appending a literal charset=null parameter to the Content-Type header
remm
(tomcat) 08/09: Remove the placeholder from the http.403 message of the filters package which was rendered literally in the non-HTTP deny response of RequestFilter since no argument was ever provided
remm
(tomcat) 03/09: Use an instanceof check when instantiating the configured randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random subclass produces the intended ServletException rather than a raw ClassCastException
remm
(tomcat) branch 10.1.x updated (5301caf434 -> 1765a0eb20)
remm
(tomcat) 04/09: Use an instanceof check when instantiating the configured rateLimitClassName in RateLimitFilter.init() so a class that does not implement RateLimiter produces the intended ServletException rather than a raw ClassCastException
remm
(tomcat) 07/09: Validate the port header value in RemoteIpFilter and RemoteIpValve so that values outside the 1-65535 range fall back to the default server port rather than being applied as an invalid port
remm
(tomcat) 02/09: Make the content-type checks in the AddDefaultCharsetFilter response wrapper case-insensitive as required by RFC 9110 for media types and parameter names
remm
(tomcat) 05/09: Synchronise the check for an existing nonce cache with its creation in CsrfPreventionFilter to prevent concurrent requests on the same session discarding a cache containing already-issued nonces, which could trigger spurious rejections
remm
(tomcat) 03/09: Use an instanceof check when instantiating the configured randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random subclass produces the intended ServletException rather than a raw ClassCastException
remm
(tomcat) 06/09: Clamp the max-age value generated by the ExpiresFilter to a minimum of zero to avoid emitting the invalid negative delta-seconds value when the computed expiration time is already in the past
remm
(tomcat) 08/09: Remove the placeholder from the http.403 message of the filters package which was rendered literally in the non-HTTP deny response of RequestFilter since no argument was ever provided
remm
(tomcat) 01/09: Ignore a null charset in the AddDefaultCharsetFilter response wrapper rather than storing it and later appending a literal charset=null parameter to the Content-Type header
remm
(tomcat) 09/09: Fix compilation errors
remm
(tomcat) branch 11.0.x updated (78036375a6 -> 677e69a178)
remm
(tomcat) 06/08: Clamp the max-age value generated by the ExpiresFilter to a minimum of zero to avoid emitting the invalid negative delta-seconds value when the computed expiration time is already in the past
remm
(tomcat) 01/08: Ignore a null charset in the AddDefaultCharsetFilter response wrapper rather than storing it and later appending a literal charset=null parameter to the Content-Type header
remm
(tomcat) 04/08: Use an instanceof check when instantiating the configured rateLimitClassName in RateLimitFilter.init() so a class that does not implement RateLimiter produces the intended ServletException rather than a raw ClassCastException
remm
(tomcat) 05/08: Synchronise the check for an existing nonce cache with its creation in CsrfPreventionFilter to prevent concurrent requests on the same session discarding a cache containing already-issued nonces, which could trigger spurious rejections
remm
(tomcat) 02/08: Make the content-type checks in the AddDefaultCharsetFilter response wrapper case-insensitive as required by RFC 9110 for media types and parameter names
remm
(tomcat) 08/08: Remove the placeholder from the http.403 message of the filters package which was rendered literally in the non-HTTP deny response of RequestFilter since no argument was ever provided
remm
(tomcat) 07/08: Validate the port header value in RemoteIpFilter and RemoteIpValve so that values outside the 1-65535 range fall back to the default server port rather than being applied as an invalid port
remm
(tomcat) 03/08: Use an instanceof check when instantiating the configured randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random subclass produces the intended ServletException rather than a raw ClassCastException
remm
(tomcat) branch main updated (9c6823e159 -> 8443c1d858)
remm
(tomcat) 04/11: Use an instanceof check when instantiating the configured rateLimitClassName in RateLimitFilter.init() so a class that does not implement RateLimiter produces the intended ServletException rather than a raw ClassCastException
remm
(tomcat) 07/11: Validate the port header value in RemoteIpFilter and RemoteIpValve so that values outside the 1-65535 range fall back to the default server port rather than being applied as an invalid port
remm
(tomcat) 11/11: Merge branch 'main' of
[email protected]
:apache/tomcat.git into main
remm
(tomcat) 05/11: Synchronise the check for an existing nonce cache with its creation in CsrfPreventionFilter to prevent concurrent requests on the same session discarding a cache containing already-issued nonces, which could trigger spurious rejections
remm
(tomcat) 03/11: Use an instanceof check when instantiating the configured randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random subclass produces the intended ServletException rather than a raw ClassCastException
remm
(tomcat) 06/11: Clamp the max-age value generated by the ExpiresFilter to a minimum of zero to avoid emitting the invalid negative delta-seconds value when the computed expiration time is already in the past
remm
(tomcat) 10/11: Merge branch 'main' of
[email protected]
:apache/tomcat.git into main
remm
(tomcat) 02/11: Make the content-type checks in the AddDefaultCharsetFilter response wrapper case-insensitive as required by RFC 9110 for media types and parameter names
remm
(tomcat) 08/11: Remove the placeholder from the http.403 message of the filters package which was rendered literally in the non-HTTP deny response of RequestFilter since no argument was ever provided
remm
(tomcat) 01/11: Ignore a null charset in the AddDefaultCharsetFilter response wrapper rather than storing it and later appending a literal charset=null parameter to the Content-Type header
remm
(tomcat) 09/11: Merge branch 'main' of
[email protected]
:apache/tomcat.git into main
remm
(tomcat) branch 11.0.x updated: Tomcat 11 baseline is Java 17 not Java 21
markt
(tomcat) branch 9.0.x updated: Update to Bouncy Castle 1.86
markt
(tomcat) branch 10.1.x updated: Update to Bouncy Castle 1.86
markt
(tomcat) branch 11.0.x updated: Update to Bouncy Castle 1.86
markt
(tomcat) branch main updated: Update to Bouncy Castle 1.8.6
markt
(tomcat) branch 9.0.x updated: Update to Byte Buddy 1.18.14
markt
(tomcat) branch main updated: Update to Checkstyle 14.3.0
markt
(tomcat) branch 10.1.x updated: Update to Byte Buddy 1.18.14
markt
(tomcat) branch 11.0.x updated: Update to Byte Buddy 1.18.14
markt
(tomcat) branch main updated: Update to Byte Buddy 1.18.14
markt
(tomcat) branch 9.0.x updated: Update NSIS to 3.13
markt
(tomcat) branch 10.1.x updated: Update NSIS to 3.13
markt
(tomcat) branch 11.0.x updated: Correct location
markt
(tomcat) branch 11.0.x updated: Correct location
markt
(tomcat) branch 11.0.x updated (f386b930f1 -> 04acaa8e32)
markt
(tomcat) 01/02: Update to the Eclipse JDT compiler 4.41
markt
(tomcat) 02/02: Update NSIS to 3.13
markt
(tomcat) branch main updated: Update NSIS to 3.13
markt
(tomcat) branch main updated: Update to the Eclipse JDT compiler 4.41
markt
[Bug 70251] New: CloseableURLConnection closes shared Jar file
bugzilla
[Bug 70251] CloseableURLConnection closes shared Jar file
bugzilla
[Bug 70251] CloseableURLConnection closes shared Jar file
bugzilla
[Bug 70251] CloseableURLConnection closes shared Jar file
bugzilla
(tomcat) branch 11.0.x updated: Treat close() the same was as shutdown()
markt
(tomcat) branch main updated: Treat close() the same was as shutdown()
markt
(tomcat) branch 9.0.x updated: Rename tests to match standard naming convention.
markt
(tomcat) branch 11.0.x updated: Rename tests to match standard naming convention.
markt
(tomcat) branch main updated: Rename tests to match standard naming convention.
markt
(tomcat) branch 10.1.x updated: Rename tests to match standard naming convention.
markt
(tomcat) branch 9.0.x updated: Explicitly state virtual host and SNI matching are separate
markt
(tomcat) branch 11.0.x updated: Explicitly state virtual host and SNI matching are separate
markt
(tomcat) branch main updated: Follow-up to 87ed9d47
markt
(tomcat) branch 9.0.x updated (2fb3864f0e -> 006099e16a)
markt
(tomcat) 02/02: Follow-up to 4127ca5f
markt
(tomcat) 01/02: Follow-on to 1141d547
markt
(tomcat) branch 9.0.x updated: Follow-up to 87ed9d47
markt
(tomcat) branch main updated: Follow-up to 34315ac0
markt
(tomcat) branch 9.0.x updated: Partial revert of 6fd26942
markt
(tomcat) branch 10.1.x updated: Fix CharChunk.indexOf(char) for chunks with a non-zero start
markt
(tomcat) branch 10.1.x updated (792859bdb8 -> bd356f1714)
remm
(tomcat) 06/08: Only release the shared naming entry name in NamingResourcesImpl remove*() methods when the type-specific map actually held the entry, preventing the removal of the JNDI name reservation of a differently typed descriptor with the same name
remm
(tomcat) 08/08: Fix return statement
remm
(tomcat) 01/08: Delegate awaitTermination() in StandardThreadExecutor and StandardVirtualThreadExecutor to the wrapped executor rather than unconditionally returning false which violates the ExecutorService contract
remm
(tomcat) 05/08: Merge branch '10.1.x' of
[email protected]
:apache/tomcat.git into 10.1.x
remm
(tomcat) 03/08: Validate the incoming entry at the start of NamingResourcesImpl.addEnvironment() so that an entry which is ignored or rejected cannot first destroy the existing environment entry or resource link with the same name
remm
(tomcat) 02/08: Synchronise the check and assignment of the servlet instance in getServletMethods() to prevent a race which could result in a second, never initialised instance being retained by the wrapper
remm
(tomcat) 04/08: Retain an existing resource link in NamingResourcesImpl.addEnvironment() when the link's global target is not an overridable global environment rather than adding an environment entry with the same name which would create a duplicate JNDI binding
remm
(tomcat) 07/08: Use the atomic add() of the shared entries set as the name claim in all NamingResourcesImpl add*() methods to close the check-then-act race which could allow two descriptors with the same JNDI name to both be registered
remm
(tomcat) branch 10.1.x updated: Partial revert of 99d1d567
markt
(tomcat) branch 10.1.x updated: Fix IDE resource leak warnings
markt
(tomcat) branch 9.0.x updated: Fix IDE resource leak warnings
markt
(tomcat) branch 11.0.x updated: Fix IDE resource leak warnings
markt
(tomcat) branch main updated: Fix IDE resource leak warnings
markt
(tomcat) branch 10.1.x updated: Route JspC context logging through Ant
markt
(tomcat) branch 9.0.x updated: Route JspC context logging through Ant
markt
(tomcat) branch 11.0.x updated: Route JspC context logging through Ant
markt
(tomcat) branch 10.1.x updated (ce5f2588a8 -> ae6ad90929)
remm
(tomcat) 02/07: Record an error in CoyoteWriter.close() when the underlying OutputBuffer close fails, rather than swallowing the IOException silently, so checkError() reflects the failure
remm
(tomcat) 07/07: Make FrameworkListener registration idempotent so repeated Server start events do not add duplicate container listeners or orphan previous per-context lifecycle listeners that can no longer be removed
remm
(tomcat) 04/07: Return a snapshot enumeration from Request.getLocales() to prevent ConcurrentModificationExceptions when the locales list is modified while a previously returned enumeration is being iterated
remm
(tomcat) 06/07: Fall back to the raw trimmed filename value in ApplicationPart.getSubmittedFileName() when HttpParser.unquote() rejects an invalid quoted-string, keeping the result consistent with the file-vs-field classification performed by FileUploadBase.getFileName() for malformed Content-Disposition headers
remm
(tomcat) 05/07: Add spec-mandated validation to ApplicationServletRegistration: throw IllegalStateException when the registration is modified after the context has been initialised (using a deliberately lenient availability test to avoid breaking existing applications that configure registrations before start) and IllegalArgumentException from addMapping for null or empty URL patterns
remm
(tomcat) 01/07: Fix InputBuffer.skip() consuming and returning more characters than requested by comparing and advancing by the remaining count (n - nRead) rather than the original count, and add a regression test
remm
(tomcat) 03/07: Return 0 rather than -1 for zero-length reads from InputBuffer at end of stream, as required by the InputStream/Reader contract, and avoid the unnecessary blocking fill these requests previously triggered
remm
(tomcat) branch main updated: Route JspC context logging through Ant
markt
(tomcat) branch 9.0.x updated: Fix CharChunk.indexOf(char) for chunks with a non-zero start
markt
(tomcat) branch 11.0.x updated: Fix CharChunk.indexOf(char) for chunks with a non-zero start
markt
(tomcat) branch main updated: Fix CharChunk.indexOf(char) for chunks with a non-zero start
markt
(tomcat) branch 9.0.x updated: Partial revert of 99d1d567
markt
(tomcat) branch main updated: Skip test on MacOS
remm
(tomcat) branch 10.1.x updated: Remove unnecessary cast
markt
(tomcat) branch 10.1.x updated: Follow-up to ba91d79a
markt
(tomcat) branch 9.0.x updated: Follow-up to ba91d79a
markt
(tomcat) branch 11.0.x updated: Follow-up to ba91d79a
markt
(tomcat) branch main updated: Follow-up to ba91d79a
markt
(tomcat) branch 11.0.x updated: Follow-up to 34315ac0
markt
(tomcat) branch 9.0.x updated (1e8b11fd73 -> 6080ad30f1)
remm
(tomcat) 02/08: Synchronise the check and assignment of the servlet instance in getServletMethods() to prevent a race which could result in a second, never initialised instance being retained by the wrapper
remm
(tomcat) 05/08: Merge branch '10.1.x' of
[email protected]
:apache/tomcat.git into 10.1.x
remm
(tomcat) 04/08: Retain an existing resource link in NamingResourcesImpl.addEnvironment() when the link's global target is not an overridable global environment rather than adding an environment entry with the same name which would create a duplicate JNDI binding
remm
(tomcat) 06/08: Only release the shared naming entry name in NamingResourcesImpl remove*() methods when the type-specific map actually held the entry, preventing the removal of the JNDI name reservation of a differently typed descriptor with the same name
remm
(tomcat) 08/08: Fix return statement
remm
(tomcat) 03/08: Validate the incoming entry at the start of NamingResourcesImpl.addEnvironment() so that an entry which is ignored or rejected cannot first destroy the existing environment entry or resource link with the same name
remm
(tomcat) 01/08: Delegate awaitTermination() in StandardThreadExecutor and StandardVirtualThreadExecutor to the wrapped executor rather than unconditionally returning false which violates the ExecutorService contract
remm
(tomcat) 07/08: Use the atomic add() of the shared entries set as the name claim in all NamingResourcesImpl add*() methods to close the check-then-act race which could allow two descriptors with the same JNDI name to both be registered
remm
(tomcat) branch 11.0.x updated: Partial revert of 99d1d567
markt
(tomcat) branch main updated: Partial revert of 99d1d567
markt
(tomcat) branch 10.1.x updated (f1dca9e463 -> 792859bdb8)
remm
(tomcat) 02/04: Synchronize access to the StandardHost childClassLoaders map which is written by context start threads and read by findReloadedContextMemoryLeaks() from Manager/JMX threads, preventing concurrent modification of the underlying WeakHashMap during iteration
remm
(tomcat) 01/04: Add the missing standardService.connector.startFailed and standardService.connector.stopFailed localization keys so connector start and stop failures produce readable messages rather than the raw key
remm
(tomcat) 03/04: Merge branch '10.1.x' of
[email protected]
:apache/tomcat.git into 10.1.x
remm
(tomcat) 04/04: Merge branch '10.1.x' of
[email protected]
:apache/tomcat.git into 10.1.x
remm
(tomcat) branch 10.1.x updated: Partial revert of 6fd26942
markt
(tomcat) branch 11.0.x updated: Partial revert of 6fd26942
markt
(tomcat) branch main updated: Partial revert of 6fd26942
markt
(tomcat) branch 11.0.x updated (a0733659dc -> 8119db0676)
remm
(tomcat) 05/10: Validate the incoming entry at the start of NamingResourcesImpl.addEnvironment() so that an entry which is ignored or rejected cannot first destroy the existing environment entry or resource link with the same name
remm
(tomcat) 07/10: Walk the class hierarchy in NamingResourcesImpl getSetterType() and getFieldType() so that injection targets resolving to inherited fields or setters are no longer rejected at deployment, matching the behaviour of the runtime injection engine
remm
(tomcat) 02/10: Synchronise access to the StandardHost childClassLoaders map which is written by context start threads and read by findReloadedContextMemoryLeaks() from Manager/JMX threads, preventing concurrent modification of the underlying WeakHashMap during iteration
remm
(tomcat) 09/10: Use the atomic add() of the shared entries set as the name claim in all NamingResourcesImpl add*() methods to close the check-then-act race which could allow two descriptors with the same JNDI name to both be registered
remm
(tomcat) 06/10: Retain an existing resource link in NamingResourcesImpl.addEnvironment() when the link's global target is not an overridable global environment rather than adding an environment entry with the same name which would create a duplicate JNDI binding
remm
(tomcat) 01/10: Add the missing standardService.connector.startFailed and standardService.connector.stopFailed localization keys so connector start and stop failures produce readable messages rather than the raw key
remm
(tomcat) 08/10: Only release the shared naming entry name in NamingResourcesImpl remove*() methods when the type-specific map actually held the entry, preventing the removal of the JNDI name reservation of a differently typed descriptor with the same name
remm
(tomcat) 04/10: Synchronise the check and assignment of the servlet instance in getServletMethods() to prevent a race which could result in a second, never initialised instance being retained by the wrapper
remm
(tomcat) 03/10: Delegate awaitTermination() in StandardThreadExecutor and StandardVirtualThreadExecutor to the wrapped executor rather than unconditionally returning false which violates the ExecutorService contract
remm
(tomcat) 10/10: Merge branch '11.0.x' of
[email protected]
:apache/tomcat.git into 11.0.x
remm
(tomcat) branch 9.0.x updated: Remove unnecessary cast
markt
(tomcat) branch main updated: Remove unnecessary cast
markt
(tomcat) branch 11.0.x updated: Remove unnecessary cast
markt
October release timeline
Mark Thomas
Re: October release timeline
Mark Thomas
Re: October release timeline
Rémy Maucherat
Re: October release timeline
Mark Thomas
Re: October release timeline
Rémy Maucherat
Re: October release timeline
Mark Thomas
Re: October release timeline
Mark Thomas
Re: October release timeline
Christopher Schultz
Re: October release timeline
Mark Thomas
(tomcat) branch 10.1.x updated: Partial revert of c817143f and a further correction
markt
(tomcat) branch main updated: Partial revert of c817143f and a further correction
markt
(tomcat) branch 11.0.x updated: Partial revert of c817143f and a further correction
markt
(tomcat) branch 9.0.x updated: Partial revert of c817143f and a further correction
markt
Re: (tomcat) branch 9.0.x updated: Partial revert of c817143f and a further correction
Rémy Maucherat
(tomcat) branch main updated (1c6560001f -> 4f1ec70d54)
remm
(tomcat) 04/10: Synchronise the check and assignment of the servlet instance in getServletMethods() to prevent a race which could result in a second, never initialised instance being retained by the wrapper
remm
(tomcat) 05/10: Validate the incoming entry at the start of NamingResourcesImpl.addEnvironment() so that an entry which is ignored or rejected cannot first destroy the existing environment entry or resource link with the same name
remm
(tomcat) 09/10: Use the atomic add() of the shared entries set as the name claim in all NamingResourcesImpl add*() methods to close the check-then-act race which could allow two descriptors with the same JNDI name to both be registered
remm
(tomcat) 08/10: Only release the shared naming entry name in NamingResourcesImpl remove*() methods when the type-specific map actually held the entry, preventing the removal of the JNDI name reservation of a differently typed descriptor with the same name
remm
(tomcat) 02/10: Synchronise access to the StandardHost childClassLoaders map which is written by context start threads and read by findReloadedContextMemoryLeaks() from Manager/JMX threads, preventing concurrent modification of the underlying WeakHashMap during iteration
remm
(tomcat) 03/10: Delegate awaitTermination() in StandardThreadExecutor and StandardVirtualThreadExecutor to the wrapped executor rather than unconditionally returning false which violates the ExecutorService contract
remm
(tomcat) 06/10: Retain an existing resource link in NamingResourcesImpl.addEnvironment() when the link's global target is not an overridable global environment rather than adding an environment entry with the same name which would create a duplicate JNDI binding
remm
(tomcat) 10/10: Merge branch 'main' of
[email protected]
:apache/tomcat.git into main
remm
(tomcat) 07/10: Walk the class hierarchy in NamingResourcesImpl getSetterType() and getFieldType() so that injection targets resolving to inherited fields or setters are no longer rejected at deployment, matching the behaviour of the runtime injection engine
remm
(tomcat) 01/10: Add the missing standardService.connector.startFailed and standardService.connector.stopFailed localization keys so connector start and stop failures produce readable messages rather than the raw key
remm
(tomcat) branch 10.1.x updated: Follow-up to 87ed9d47
markt
Earlier messages
Later messages