Buildbot failure in on tomcat-9.0.x

2025-09-10 Thread buildbot
Build status: BUILD FAILED: failed compile (failure) Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/37/builds/1500 Blamelist: Mark Thomas Build Text: failed compile (failure) Status Detected: new failure Build Source Stamp: [branch 9.0.x] 93974670385df31fc3b7528278fd5e6fc0f0d

(tomcat) branch main updated: Cleanups

2025-09-10 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 7ca57ebd83 Cleanups 7ca57ebd83 is described below com

Re: Unit tests for CVEs

2025-09-10 Thread Rémy Maucherat
On Wed, Sep 10, 2025 at 1:23 PM Dimitris Soumis wrote: > > On Wed, Sep 10, 2025 at 12:15 PM Mark Thomas wrote: > > > All, > > > > One of the topics at the security day we held in Bratislava was adding > > unit tests for CVEs once the CVEs were public. > > > > I have just rediscovered a test case

(tomcat) branch 11.0.x updated: Fix IDE warnings

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new 479e02360f Fix IDE warnings 479e02360f is describ

Buildbot success in on tomcat-9.0.x

2025-09-10 Thread buildbot
Build status: Build succeeded! Worker used: bb_worker2_ubuntu URL: https://ci2.apache.org/#builders/37/builds/1499 Blamelist: Dimitris Soumis , Mark Thomas , Sebastian Build Text: build successful Status Detected: restored build Build Source Stamp: [branch 9.0.x] 7088a007d05fbf160c355cbad9c2e0b85

(tomcat) branch 9.0.x updated: HTTP method names are case sensitive (RFC 9110, 9.1)

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 9397467038 HTTP method names are case sensitive (RF

(tomcat) branch 10.1.x updated: HTTP method names are case sensitive (RFC 9110, 9.1)

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 8dc1c11088 HTTP method names are case sensitive (

(tomcat) branch main updated: HTTP method names are case sensitive (RFC 9110, 9.1)

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 65faf20496 HTTP method names are case sensitive (RFC

(tomcat) branch 11.0.x updated: HTTP method names are case sensitive (RFC 9110, 9.1)

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new 4338ab9911 HTTP method names are case sensitive (

Re: Unit tests for CVEs

2025-09-10 Thread Paul Lodge
Hi All, if you decide to have CVE tests made public I would suggest 1 small caveat, that the fixes should older than x number of months, that would permit users to upgrade their systems. Best Paul On 10/09/2025 14:18, Coty Sutherland wrote: On Wed, Sep 10, 2025 at 7:23 AM Dimitris Soumis

Re: (tomcat) branch main updated: Fix IDE warnings

2025-09-10 Thread Dimitris Soumis
On Wed, Sep 10, 2025 at 4:26 PM wrote: > This is an automated email from the ASF dual-hosted git repository. > > markt pushed a commit to branch main > in repository https://gitbox.apache.org/repos/asf/tomcat.git > > > The following commit(s) were added to refs/heads/main by this push: > new

(tomcat) branch 10.1.x updated: Add a unit test for CVE-2025-53506

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 87e8188a35 Add a unit test for CVE-2025-53506 87e

Re: (tomcat) branch main updated: Fix IDE warnings

2025-09-10 Thread Mark Thomas
On 10/09/2025 14:32, Dimitris Soumis wrote: On Wed, Sep 10, 2025 at 4:26 PM wrote: This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs

(tomcat) branch 9.0.x updated: Add a unit test for CVE-2025-53506

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 7088a007d0 Add a unit test for CVE-2025-53506 7088a

(tomcat) branch 11.0.x updated: Add a unit test for CVE-2025-53506

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new 45b6fbccb9 Add a unit test for CVE-2025-53506 45b

(tomcat) branch main updated: Add a unit test for CVE-2025-53506

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new efa70e1ac9 Add a unit test for CVE-2025-53506 efa70e1

(tomcat) branch 9.0.x updated: Fix IDE warnings

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 1fe31a971a Fix IDE warnings 1fe31a971a is described

(tomcat) branch 10.1.x updated: Fix IDE warnings

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 6ec16597b0 Fix IDE warnings 6ec16597b0 is describ

(tomcat) branch main updated: Fix IDE warnings

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 5262f92e10 Fix IDE warnings 5262f92e10 is described b

Re: Unit tests for CVEs

2025-09-10 Thread Coty Sutherland
On Wed, Sep 10, 2025 at 7:23 AM Dimitris Soumis wrote: > On Wed, Sep 10, 2025 at 12:15 PM Mark Thomas wrote: > > > All, > > > > One of the topics at the security day we held in Bratislava was adding > > unit tests for CVEs once the CVEs were public. > > > > I have just rediscovered a test case f

[Bug 69814] HttpSession.isNew() may return true on an existing session due to a race condition

2025-09-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69814 Sammy Chan changed: What|Removed |Added OS||All --- Comment #2 from Sammy Chan --- C

(tomcat) branch 9.0.x updated: Clarify the docs for maxPostSize

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/9.0.x by this push: new 7580f58d99 Clarify the docs for maxPostSize 7580f58

Re: Unit tests for CVEs

2025-09-10 Thread Dimitris Soumis
On Wed, Sep 10, 2025 at 12:15 PM Mark Thomas wrote: > All, > > One of the topics at the security day we held in Bratislava was adding > unit tests for CVEs once the CVEs were public. > > I have just rediscovered a test case for CVE-2025-53506 sat in a git > stash it would be good to get committed

svn commit: r1928331 - in tomcat/site/trunk: docs xdocs

2025-09-10 Thread schultz
Author: schultz Date: Wed Sep 10 11:28:16 2025 New Revision: 1928331 Log: Add notes about missing FileStore classes for two specific releases. Modified: tomcat/site/trunk/docs/migration-10.1.html tomcat/site/trunk/docs/migration-9.html tomcat/site/trunk/xdocs/migration-10.1.xml tomcat

(tomcat) branch 10.1.x updated: Clarify the docs for maxPostSize

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/10.1.x by this push: new 1176b8633e Clarify the docs for maxPostSize 1176b

svn commit: r1928330 - in tomcat/site/trunk: docs xdocs

2025-09-10 Thread schultz
Author: schultz Date: Wed Sep 10 11:22:50 2025 New Revision: 1928330 Log: Add a warning about 10.1.45 and 9.0.109 releases and FileStore. Modified: tomcat/site/trunk/docs/index.html tomcat/site/trunk/xdocs/index.xml Modified: tomcat/site/trunk/docs/index.html ==

(tomcat) branch 11.0.x updated: Clarify the docs for maxPostSize

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/11.0.x by this push: new bf07c3a7e3 Clarify the docs for maxPostSize bf07c

(tomcat) branch main updated: Clarify the docs for maxPostSize

2025-09-10 Thread markt
This is an automated email from the ASF dual-hosted git repository. markt pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/main by this push: new 1b8609d6ee Clarify the docs for maxPostSize 1b8609d6e

Re: [VOTE] Release Apache Tomcat 10.1.46

2025-09-10 Thread Christopher Schultz
All, On 9/8/25 11:08 AM, Christopher Schultz wrote: The proposed Apache Tomcat 10.1.46 release is now available for voting. All committers and PMC members are kindly requested to provide a vote if possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are binding. We welcome non-co

Re: Regression in 9.0.x/10.1.x - FileStore broken

2025-09-10 Thread Rainer Jung
Hi hi, Am 08.09.25 um 09:24 schrieb Rémy Maucherat: We can see if new issues pop up today and tomorrow, and then I'll produce a new 9.0 release. Is this still the plan for 9.0.x (tagging today)? Or does it need a bit more time to add something in-progress? Thanks and regards! Rainer

[Bug 69814] HttpSession.isNew() may return true on an existing session due to a race condition

2025-09-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69814 --- Comment #1 from Sammy Chan --- Created attachment 40098 --> https://bz.apache.org/bugzilla/attachment.cgi?id=40098&action=edit demo source, app, video -- You are receiving this mail because: You are the assignee for the bug. ---

[Bug 69814] New: HttpSession.isNew() may return true on an existing session due to a race condition

2025-09-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69814 Bug ID: 69814 Summary: HttpSession.isNew() may return true on an existing session due to a race condition Product: Tomcat 10 Version: 10.1.44 Hardware: PC Sta

Unit tests for CVEs

2025-09-10 Thread Mark Thomas
All, One of the topics at the security day we held in Bratislava was adding unit tests for CVEs once the CVEs were public. I have just rediscovered a test case for CVE-2025-53506 sat in a git stash it would be good to get committed. Before I commit anything, I was wondering how we wanted to

[Bug 69803] HTTP/1.1 Connector Content-Length header calculation regression causing Chrome/Edge net::ERR_CONTENT_LENGTH_MISMATCH

2025-09-10 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69803 --- Comment #5 from Mark Thomas --- Insufficient information has been provided for the Tomcat team to provide a definitive answer. The change log comment explicitly states it applies only when a Writer is being used. Your code example is using