[GitHub] [solr-site] anshumg merged pull request #49: Fix the date on Log4j2 security vulnerability (CVE-2021-44228) announcement

2021-12-11 Thread GitBox
anshumg merged pull request #49: URL: https://github.com/apache/solr-site/pull/49 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr.

[GitHub] [solr-site] thelabdude merged pull request #53: Wrap url in < and > to make it clickable

2021-12-11 Thread GitBox
thelabdude merged pull request #53: URL: https://github.com/apache/solr-site/pull/53 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubs

[GitHub] [solr-site] uschindler commented on pull request #49: Fix the date on Log4j2 security vulnerability (CVE-2021-44228) announcement

2021-12-11 Thread GitBox
uschindler commented on pull request #49: URL: https://github.com/apache/solr-site/pull/49#issuecomment-991265867 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubsc

[GitHub] [solr-site] madrob merged pull request #51: Update which versions have Log4J2

2021-12-11 Thread GitBox
madrob merged pull request #51: URL: https://github.com/apache/solr-site/pull/51 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr..

[GitHub] [solr] betulince commented on pull request #436: SOLR-15824 Improved Query Screen raw query parameters section

2021-12-11 Thread GitBox
betulince commented on pull request #436: URL: https://github.com/apache/solr/pull/436#issuecomment-991616637 I'll fix what you mentioned above with this PR. On Sat, Dec 11, 2021, 12:55 AM Timothy Potter ***@***.***> wrote: > Confirmed ... the query form getting submitted 2x

[GitHub] [solr] gerlowskija commented on a change in pull request #450: SOLR-15745: Convert create-core v2 API to annotations

2021-12-11 Thread GitBox
gerlowskija commented on a change in pull request #450: URL: https://github.com/apache/solr/pull/450#discussion_r767067405 ## File path: solr/core/src/test/org/apache/solr/handler/admin/V2CoresAPIMappingTest.java ## @@ -0,0 +1,146 @@ +/* + * Licensed to the Apache Software Fou

[GitHub] [solr] andyetitmoves commented on pull request #383: Update transaction log options descriptions

2021-12-11 Thread GitBox
andyetitmoves commented on pull request #383: URL: https://github.com/apache/solr/pull/383#issuecomment-991238699 > I skimmed the code and believe you are right. Do you agree @andyetitmoves ? Yep, that's correct. -- This is an automated message from the Apache Git Service. To respo

[GitHub] [solr-site] thelabdude commented on a change in pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
thelabdude commented on a change in pull request #52: URL: https://github.com/apache/solr-site/pull/52#discussion_r767063125 ## File path: content/solr/security/2021-12-10-cve-2021-44228.md ## @@ -11,7 +11,7 @@ Critical **Description:** Apache Solr releases prior to 8.11.1 we

[GitHub] [solr-site] uschindler edited a comment on pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
uschindler edited a comment on pull request #52: URL: https://github.com/apache/solr-site/pull/52#issuecomment-991578265 Hi, According to newest information in the linked issue, log4j v1 ist NOT vulnerable. It can execute jndi links, but not execute Code as no java serialization is poss

[GitHub] [solr] dsmiley commented on pull request #221: SOLR-15258: ConfigSetService operations ought to throw IOException

2021-12-11 Thread GitBox
dsmiley commented on pull request #221: URL: https://github.com/apache/solr/pull/221#issuecomment-991257166 This wasn't done; it's follow-up tiny stuff. @NazerkeBS there are a couple things remaining I asked of you -- the empty catch, and loadConfigSetProperties -- This is an automated

[GitHub] [solr] thelabdude edited a comment on pull request #436: SOLR-15824 Improved Query Screen raw query parameters section

2021-12-11 Thread GitBox
thelabdude edited a comment on pull request #436: URL: https://github.com/apache/solr/pull/436#issuecomment-991330781 Confirmed ... the query form getting submitted 2x each time you push the `Execute Query` button exists on main! So that's bad and looks to be the cause of why having `stats

[GitHub] [solr-site] GameScripting removed a comment on pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
GameScripting removed a comment on pull request #52: URL: https://github.com/apache/solr-site/pull/52#issuecomment-991626488 @uschindler does this mean, that it suffers from the [data-exfiltration issue](https://github.com/apache/logging-log4j2/pull/608#issuecomment-991354707)? -- This i

[GitHub] [solr-operator] plumdog commented on issue #384: How to apply mitigation for CVE-2021-44228

2021-12-11 Thread GitBox
plumdog commented on issue #384: URL: https://github.com/apache/solr-operator/issues/384#issuecomment-991251103 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscri

[GitHub] [solr-site] GameScripting commented on pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
GameScripting commented on pull request #52: URL: https://github.com/apache/solr-site/pull/52#issuecomment-991626488 @uschindler does this mean, that it suffers from the [data-exfiltration issue](https://github.com/apache/logging-log4j2/pull/608#issuecomment-991354707)? -- This is an aut

[GitHub] [solr-site] uschindler commented on pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
uschindler commented on pull request #52: URL: https://github.com/apache/solr-site/pull/52#issuecomment-991578265 Hi, According to newest information in the linked issue, log4j v1 ist NOT vulnerable. It can execute jndi links, but not execute Code as no java serialization is possible.

[GitHub] [solr-operator] sylus edited a comment on issue #384: How to apply mitigation for CVE-2021-44228

2021-12-11 Thread GitBox
sylus edited a comment on issue #384: URL: https://github.com/apache/solr-operator/issues/384#issuecomment-991401716 I'm not sure whether this effects zookeeper but I think you first would need access to the solr pod so first mitigation suffices? -- This is an automated message from the

[GitHub] [solr-site] madrob merged pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
madrob merged pull request #52: URL: https://github.com/apache/solr-site/pull/52 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr..

[GitHub] [solr-site] uschindler commented on a change in pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
uschindler commented on a change in pull request #52: URL: https://github.com/apache/solr-site/pull/52#discussion_r767030548 ## File path: content/solr/security/2021-12-10-cve-2021-44228.md ## @@ -11,7 +11,7 @@ Critical **Description:** Apache Solr releases prior to 8.11.1 we

[GitHub] [solr] janhoy commented on pull request #383: Update transaction log options descriptions

2021-12-11 Thread GitBox
janhoy commented on pull request #383: URL: https://github.com/apache/solr/pull/383#issuecomment-991344883 Thanks! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsub

[GitHub] [solr] anshumg merged pull request #442: Fix RPT documentation

2021-12-11 Thread GitBox
anshumg merged pull request #442: URL: https://github.com/apache/solr/pull/442 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@

[GitHub] [solr-operator] plumdog edited a comment on issue #384: How to apply mitigation for CVE-2021-44228

2021-12-11 Thread GitBox
plumdog edited a comment on issue #384: URL: https://github.com/apache/solr-operator/issues/384#issuecomment-991251103 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To un

[GitHub] [solr-operator] sylus commented on issue #384: How to apply mitigation for CVE-2021-44228

2021-12-11 Thread GitBox
sylus commented on issue #384: URL: https://github.com/apache/solr-operator/issues/384#issuecomment-991399854 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe

[GitHub] [solr-site] anshumg merged pull request #50: Merge changes from main to production to fix date on Log4j2 security vulnerability announcement

2021-12-11 Thread GitBox
anshumg merged pull request #50: URL: https://github.com/apache/solr-site/pull/50 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr.

[GitHub] [solr] janhoy merged pull request #383: Update transaction log options descriptions

2021-12-11 Thread GitBox
janhoy merged pull request #383: URL: https://github.com/apache/solr/pull/383 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@s

[GitHub] [solr-operator] gthvidsten commented on issue #382: Can't specify nodeSelector for SolrCloud / ZK / Busybox

2021-12-11 Thread GitBox
gthvidsten commented on issue #382: URL: https://github.com/apache/solr-operator/issues/382#issuecomment-991717712 Setting Zookeeper to linux as well helped greatly. Now all pods are starting. You should probably consider hvaing these values as default so that other users with mixed

[GitHub] [solr] thelabdude commented on pull request #436: SOLR-15824 Improved Query Screen raw query parameters section

2021-12-11 Thread GitBox
thelabdude commented on pull request #436: URL: https://github.com/apache/solr/pull/436#issuecomment-991321741 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscrib

[GitHub] [solr-site] anshumg commented on pull request #49: Fix the date on Log4j2 security vulnerability (CVE-2021-44228) announcement

2021-12-11 Thread GitBox
anshumg commented on pull request #49: URL: https://github.com/apache/solr-site/pull/49#issuecomment-991221939 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscrib

[jira] [Commented] (SOLR-9963) Add Apache Calcite Avatica handler to Solr

2021-12-11 Thread David Smiley (Jira)
[ https://issues.apache.org/jira/browse/SOLR-9963?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457812#comment-17457812 ] David Smiley commented on SOLR-9963: If you do work on this and open-source it, please

[jira] [Commented] (SOLR-15843) Update Log4J dependency

2021-12-11 Thread Mike Drob (Jira)
[ https://issues.apache.org/jira/browse/SOLR-15843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457702#comment-17457702 ] Mike Drob commented on SOLR-15843: -- > We could add something to the solr-upgrade-notes p

[jira] [Commented] (SOLR-9963) Add Apache Calcite Avatica handler to Solr

2021-12-11 Thread Courtney (Jira)
[ https://issues.apache.org/jira/browse/SOLR-9963?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457699#comment-17457699 ] Courtney commented on SOLR-9963: [~jbernste] I can agree with the general sentiment of the

[jira] [Commented] (SOLR-14346) Solr fails to check zombie server in LbHttpSolrClient

2021-12-11 Thread Xiaobin Dai (Jira)
[ https://issues.apache.org/jira/browse/SOLR-14346?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457698#comment-17457698 ] Xiaobin Dai commented on SOLR-14346: let solrBaseUrl contains a specified collection

[GitHub] [solr-operator] gthvidsten opened a new issue #385: Solr can't connect to Zookeeper

2021-12-11 Thread GitBox
gthvidsten opened a new issue #385: URL: https://github.com/apache/solr-operator/issues/385 I've installed the SolrCloud with just about all default values except for storage, where I've added a `storageClassName` to both Zookeeper and Solr. When I'm accessing `Cloud > ZK Status` in

[GitHub] [solr-operator] gthvidsten commented on issue #382: Can't specify nodeSelector for SolrCloud / ZK / Busybox

2021-12-11 Thread GitBox
gthvidsten commented on issue #382: URL: https://github.com/apache/solr-operator/issues/382#issuecomment-991717712 Setting Zookeeper to linux as well helped greatly. Now all pods are starting. You should probably consider hvaing these values as default so that other users with mixed

[jira] [Commented] (SOLR-9963) Add Apache Calcite Avatica handler to Solr

2021-12-11 Thread Kevin Risden (Jira)
[ https://issues.apache.org/jira/browse/SOLR-9963?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457646#comment-17457646 ] Kevin Risden commented on SOLR-9963: I can't seem to find the branch I was working on.

[jira] [Commented] (SOLR-9963) Add Apache Calcite Avatica handler to Solr

2021-12-11 Thread Kevin Risden (Jira)
[ https://issues.apache.org/jira/browse/SOLR-9963?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457644#comment-17457644 ] Kevin Risden commented on SOLR-9963: I haven't spent any time on this since the last u

[jira] [Commented] (SOLR-9963) Add Apache Calcite Avatica handler to Solr

2021-12-11 Thread Joel Bernstein (Jira)
[ https://issues.apache.org/jira/browse/SOLR-9963?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457642#comment-17457642 ] Joel Bernstein commented on SOLR-9963: -- I'm curious to see what others think of this

[GitHub] [solr-operator] sylus commented on issue #384: How to apply mitigation for CVE-2021-44228

2021-12-11 Thread GitBox
sylus commented on issue #384: URL: https://github.com/apache/solr-operator/issues/384#issuecomment-991690754 Thanks @plumdog really happy with how quickly solr-operator responded to this. Awesome work! -- This is an automated message from the Apache Git Service. To respond to the messag

[GitHub] [solr-site] GameScripting removed a comment on pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
GameScripting removed a comment on pull request #52: URL: https://github.com/apache/solr-site/pull/52#issuecomment-991626488 @uschindler does this mean, that it suffers from the [data-exfiltration issue](https://github.com/apache/logging-log4j2/pull/608#issuecomment-991354707)? -- This i

[GitHub] [solr-site] GameScripting commented on pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
GameScripting commented on pull request #52: URL: https://github.com/apache/solr-site/pull/52#issuecomment-991626488 @uschindler does this mean, that it suffers from the [data-exfiltration issue](https://github.com/apache/logging-log4j2/pull/608#issuecomment-991354707)? -- This is an aut

[GitHub] [solr] betulince commented on pull request #436: SOLR-15824 Improved Query Screen raw query parameters section

2021-12-11 Thread GitBox
betulince commented on pull request #436: URL: https://github.com/apache/solr/pull/436#issuecomment-991616637 I'll fix what you mentioned above with this PR. On Sat, Dec 11, 2021, 12:55 AM Timothy Potter ***@***.***> wrote: > Confirmed ... the query form getting submitted 2x

[GitHub] [solr-operator] plumdog commented on issue #384: How to apply mitigation for CVE-2021-44228

2021-12-11 Thread GitBox
plumdog commented on issue #384: URL: https://github.com/apache/solr-operator/issues/384#issuecomment-991615749 Ok, from https://github.com/pravega/zookeeper-operator/issues/422#issuecomment-991602681, believe Zookeeper not impacted, so I think the mitigation above is sufficient. -- Thi

[GitHub] [solr-site] uschindler edited a comment on pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
uschindler edited a comment on pull request #52: URL: https://github.com/apache/solr-site/pull/52#issuecomment-991578265 Hi, According to newest information in the linked issue, log4j v1 ist NOT vulnerable. It can execute jndi links, but not execute Code as no java serialization is poss

[GitHub] [solr-site] uschindler commented on pull request #52: More details on log4j 1.2

2021-12-11 Thread GitBox
uschindler commented on pull request #52: URL: https://github.com/apache/solr-site/pull/52#issuecomment-991578265 Hi, According to newest information in the linked issue, log4j v1 ist NOT vulnerable. It can execute jndi links, but not execute Code as no java serialization is possible.

[GitHub] [solr-operator] plumdog commented on issue #384: How to apply mitigation for CVE-2021-44228

2021-12-11 Thread GitBox
plumdog commented on issue #384: URL: https://github.com/apache/solr-operator/issues/384#issuecomment-991569350 Have opened https://github.com/pravega/zookeeper-operator/issues/422 to try to work out how zookeeper-operator is impacted and how to mitigate. -- This is an automated message

[jira] [Commented] (SOLR-9963) Add Apache Calcite Avatica handler to Solr

2021-12-11 Thread Courtney (Jira)
[ https://issues.apache.org/jira/browse/SOLR-9963?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457559#comment-17457559 ] Courtney commented on SOLR-9963: I see the patches here and no update since 2019. What bec