svn commit: r1571608 - in /tomcat/trunk: build.properties.default webapps/docs/changelog.xml

2014-02-25 Thread markt
Author: markt Date: Tue Feb 25 08:15:31 2014 New Revision: 1571608 URL: http://svn.apache.org/r1571608 Log: Update Commons Pool 2 to 2.2. Modified: tomcat/trunk/build.properties.default tomcat/trunk/webapps/docs/changelog.xml Modified: tomcat/trunk/build.properties.default URL:

[Bug 56184] Async servlet

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56184 --- Comment #3 from Mark Thomas ma...@apache.org --- Bugzilla is not a support forum. Please use the Apache Tomcat users mailing lists if you require help understanding how Servlet async processing works. -- You are receiving this mail

[Bug 56183] pkcs12 windows and AprLifecycleListener

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56183 Mark Thomas ma...@apache.org changed: What|Removed |Added Status|NEW |RESOLVED

Re: Connectors, blocking, and keepalive

2014-02-25 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 25/02/2014 06:03, Christopher Schultz wrote: All, I'm looking at the comparison table at the bottom of the HTTP connectors page, and I have a few questions about it. First, what does Polling size mean? Maximum number of connections in the

[Bug 56186] New: javax.websocket-api.jar exists in the war package, then Cannot load custom ServerApplicationConfig

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56186 Bug ID: 56186 Summary: javax.websocket-api.jar exists in the war package, then Cannot load custom ServerApplicationConfig Product: Tomcat 7 Version: 7.0.52 Hardware:

[Bug 56186] javax.websocket-api.jar exists in the war package, then Cannot load custom ServerApplicationConfig

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56186 Mark Thomas ma...@apache.org changed: What|Removed |Added Status|NEW |RESOLVED

[SECURITY] CVE-2014-0033 Session fixation still possible with disableURLRewriting enabled

2014-02-25 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2014-0033 Session fixation still possible with disableURLRewriting enabled Severity: Low Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 6.0.33 to 6.0.37 Description: Previous fixes to path parameter handling [1]

[SECURITY] CVE-2013-4590 Information disclosure via XXE when running untrusted web applications

2014-02-25 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013-4590 Information disclosure via XXE when running untrusted web applications Severity: Low Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 8.0.0-RC1 to 8.0.0-RC5 - - Apache Tomcat 7.0.0 to 7.0.47 - - Apache

[SECURITY] CVE-2013-4322 Incomplete fix for CVE-2012-3544 (Denial of Service)

2014-02-25 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013-4322 Incomplete fix for CVE-2012-3544 (Denial of Service) Severity: Important Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 8.0.0-RC1 to 8.0.0-RC5 - - Apache Tomcat 7.0.0 to 7.0.47 - - Apache Tomcat 6.0.0 to

[SECURITY] CVE-2013-4286 Incomplete fix for CVE-2005-2090 (Information disclosure)

2014-02-25 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013-4286 Incomplete fix for CVE-2005-2090 (Information disclosure) Severity: Important Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 8.0.0-RC1 - - Apache Tomcat 7.0.0 to 7.0.42 - - Apache Tomcat 6.0.0 to 6.0.37

svn commit: r1571649 - in /tomcat/site/trunk: docs/security-4.html docs/security-5.html docs/security-6.html docs/security-7.html docs/security-8.html xdocs/security-4.xml xdocs/security-5.xml xdocs/s

2014-02-25 Thread markt
Author: markt Date: Tue Feb 25 11:18:51 2014 New Revision: 1571649 URL: http://svn.apache.org/r1571649 Log: Add: CVE-2013-4286 CVE-2013-4322 CVE-2013-4590 CVE-2014-0033 Also fix a couple of typos. Modified: tomcat/site/trunk/docs/security-4.html tomcat/site/trunk/docs/security-5.html

svn propchange: r1552565 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1552565 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:24:25 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:24:25 2014 @@ -1 +1,2 @@ Better adherence to RFC2616 for

svn propchange: r1556540 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1556540 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:25:16 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:25:16 2014 @@ -1 +1,2 @@ Add support for limiting the size of

svn propchange: r1558822 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1558822 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:26:12 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:26:12 2014 @@ -1 +1,2 @@ Ensure that sessions IDs are not

svn propchange: r1558828 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1558828 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:25:45 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:25:45 2014 @@ -1 +1,2 @@ Add an option to the Context to

svn propchange: r1521864 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1521864 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:26:54 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:26:54 2014 @@ -1,2 +1,2 @@ -Add support for limiting the size of

svn propchange: r1549529 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1549529 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:27:45 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:27:45 2014 @@ -1 +1,2 @@ Add an option to the Context to

svn propchange: r1549523 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1549523 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:27:11 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:27:11 2014 @@ -1 +1,2 @@ Improve parsing of trailing headers

svn propchange: r1521854 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1521854 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:28:16 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:28:16 2014 @@ -1 +1,2 @@ Better adherence to RFC2616 for

svn propchange: r1521834 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1521834 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:28:57 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:28:57 2014 @@ -1,2 +1,3 @@ Add support for limiting the size of

svn propchange: r1549522 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1549522 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:29:29 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:29:29 2014 @@ -1 +1,2 @@ Improve parsing of trailing headers

svn propchange: r1549528 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1549528 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:29:56 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:29:56 2014 @@ -1 +1,2 @@ Add an option to the Context to

svn propchange: r1521829 - svn:log

2014-02-25 Thread markt
Author: markt Revision: 1521829 Modified property: svn:log Modified: svn:log at Tue Feb 25 11:30:41 2014 -- --- svn:log (original) +++ svn:log Tue Feb 25 11:30:41 2014 @@ -1 +1,2 @@ Better adherence to RFC2616 for

svn commit: r1571654 - /tomcat/trunk/build.xml

2014-02-25 Thread kkolinko
Author: kkolinko Date: Tue Feb 25 11:36:25 2014 New Revision: 1571654 URL: http://svn.apache.org/r1571654 Log: Followup to r1570629 Simplify include patterns in patternset id=files.tomcat-util. Modified: tomcat/trunk/build.xml Modified: tomcat/trunk/build.xml URL:

Re: svn commit: r1570115 - in /tomcat/tc7.0.x/trunk: ./ build.xml webapps/docs/changelog.xml

2014-02-25 Thread Konstantin Kolinko
2014-02-21 19:40 GMT+04:00 Mark Thomas ma...@apache.org: On 21/02/2014 15:35, Konstantin Kolinko wrote: 2014-02-20 13:53 GMT+04:00 Konstantin Kolinko knst.koli...@gmail.com: 2014-02-20 13:26 GMT+04:00 Mark Thomas ma...@apache.org: On 20/02/2014 09:10, Konstantin Kolinko wrote: 2014-02-20

[Bug 56187] New: Websocket text message limit does not change from default 8192.

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56187 Bug ID: 56187 Summary: Websocket text message limit does not change from default 8192. Product: Tomcat 7 Version: 7.0.52 Hardware: PC Status: NEW

[Bug 56187] Websocket text message limit does not change from default 8192.

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56187 Shailesh 05.shail...@gmail.com changed: What|Removed |Added Keywords||APIBug

[Bug 56187] Websocket text buffer maximum limit does not change from default 8192.

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56187 Shailesh 05.shail...@gmail.com changed: What|Removed |Added Summary|Websocket text message |Websocket text

[Bug 56187] Websocket text buffer maximum limit does not change from default 8192.

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56187 --- Comment #2 from Konstantin Kolinko knst.koli...@gmail.com --- There are 2 different web socket protocol implementations available in Tomcat 7: 1) JSR-356 (a new one) 2) legacy The settings that you changed are used by the JSR-356

svn commit: r1571699 - in /tomcat/trunk: build.properties.default webapps/docs/changelog.xml

2014-02-25 Thread markt
Author: markt Date: Tue Feb 25 14:00:59 2014 New Revision: 1571699 URL: http://svn.apache.org/r1571699 Log: Another DBCP 2 update. This is the last functional update expected before the DBCP 2.0 release. There may be a few more interim updates as things are cleaned up in preparation for the

svn commit: r1571700 - /tomcat/tc6.0.x/trunk/webapps/docs/changelog.xml

2014-02-25 Thread kkolinko
Author: kkolinko Date: Tue Feb 25 14:04:17 2014 New Revision: 1571700 URL: http://svn.apache.org/r1571700 Log: Add CVE numbers to changelog. Modified: tomcat/tc6.0.x/trunk/webapps/docs/changelog.xml Modified: tomcat/tc6.0.x/trunk/webapps/docs/changelog.xml URL:

svn commit: r1571701 - in /tomcat/site/trunk: docs/security-6.html xdocs/security-6.xml

2014-02-25 Thread kkolinko
Author: kkolinko Date: Tue Feb 25 14:07:40 2014 New Revision: 1571701 URL: http://svn.apache.org/r1571701 Log: Merge two identical notes into one. Modified: tomcat/site/trunk/docs/security-6.html tomcat/site/trunk/xdocs/security-6.xml Modified: tomcat/site/trunk/docs/security-6.html

svn commit: r1571705 - /tomcat/tc6.0.x/trunk/webapps/docs/changelog.xml

2014-02-25 Thread kkolinko
Author: kkolinko Date: Tue Feb 25 14:21:51 2014 New Revision: 1571705 URL: http://svn.apache.org/r1571705 Log: Add CVE numbers to changelog. Modified: tomcat/tc6.0.x/trunk/webapps/docs/changelog.xml Modified: tomcat/tc6.0.x/trunk/webapps/docs/changelog.xml URL:

svn commit: r1571707 - /tomcat/tc7.0.x/trunk/webapps/docs/changelog.xml

2014-02-25 Thread kkolinko
Author: kkolinko Date: Tue Feb 25 14:27:35 2014 New Revision: 1571707 URL: http://svn.apache.org/r1571707 Log: Add CVE numbers to changelog. Modified: tomcat/tc7.0.x/trunk/webapps/docs/changelog.xml Modified: tomcat/tc7.0.x/trunk/webapps/docs/changelog.xml URL:

svn commit: r1571718 - /tomcat/jk/tags/JK_1_2_38/

2014-02-25 Thread mturk
Author: mturk Date: Tue Feb 25 15:10:05 2014 New Revision: 1571718 URL: http://svn.apache.org/r1571718 Log: Tag Tomcat Connectors 1.2.38 Added: tomcat/jk/tags/JK_1_2_38/ - copied from r1571717, tomcat/jk/trunk/ - To

Re: Connectors, blocking, and keepalive

2014-02-25 Thread Konstantin Kolinko
2014-02-25 12:31 GMT+04:00 Mark Thomas ma...@apache.org: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 25/02/2014 06:03, Christopher Schultz wrote: All, I'm looking at the comparison table at the bottom of the HTTP connectors page, and I have a few questions about it. First, what does

[Bug 56185] Jasper to compile compile complicated EL expression

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56185 Konstantin Kolinko knst.koli...@gmail.com changed: What|Removed |Added Status|NEW

[Bug 56179] ParseException for EL expression ${((test == true))}

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56179 Konstantin Kolinko knst.koli...@gmail.com changed: What|Removed |Added CC|

svn commit: r1571725 - in /tomcat/trunk/test/org/apache/el/parser: TestELParser.java TesterBeanC.java

2014-02-25 Thread kkolinko
Author: kkolinko Date: Tue Feb 25 16:27:40 2014 New Revision: 1571725 URL: http://svn.apache.org/r1571725 Log: Test for https://issues.apache.org/bugzilla/show_bug.cgi?id=56185 Added: tomcat/trunk/test/org/apache/el/parser/TesterBeanC.java (with props) Modified:

svn commit: r1571731 - in /tomcat/tc7.0.x/trunk: ./ test/org/apache/el/parser/TestELParser.java test/org/apache/el/parser/TesterBeanC.java

2014-02-25 Thread kkolinko
Author: kkolinko Date: Tue Feb 25 16:34:59 2014 New Revision: 1571731 URL: http://svn.apache.org/r1571731 Log: Add tests for https://issues.apache.org/bugzilla/show_bug.cgi?id=56179 https://issues.apache.org/bugzilla/show_bug.cgi?id=56185 (Backport of r1571245, r1571725) Added:

buildbot success in ASF Buildbot on tomcat-7-trunk

2014-02-25 Thread buildbot
The Buildbot has detected a restored build on builder tomcat-7-trunk while building ASF Buildbot. Full details are available at: http://ci.apache.org/builders/tomcat-7-trunk/builds/1783 Buildbot URL: http://ci.apache.org/ Buildslave for this Build: bb-vm_ubuntu Build Reason: scheduler Build

[Bug 56187] Websocket text buffer maximum limit does not change from default 8192.

2014-02-25 Thread bugzilla
https://issues.apache.org/bugzilla/show_bug.cgi?id=56187 --- Comment #3 from Shailesh 05.shail...@gmail.com --- Atmosphere 1.0.18 uses legacy protocol. I tried to debug the issue reached to org.apache.catalina.websocket.WsOutbound. public static final int DEFAULT_BUFFER_SIZE = 8192; public