DO NOT REPLY [Bug 10544] - crossContext for servlets not working

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

Re: Tomcat 4.1.12: Xerces 2.2 problems - > Struts 1.0.2 bug.

2002-10-09 Thread Henri Gomez
Jean-Francois Arcand wrote: > Hi, > > with Tomcat 4.1.12, Xerces 2.2 is throwing the following exception: > > org.xml.sax.SAXParseException: The string "--" is not permitted within > comments. >at org.apache.xerces.parsers.AbstractSAXParser.parse(Unknown Source) > > This is a bug in the or

DO NOT REPLY [Bug 13477] - tomcat 4.1.2 installed from rpms fails to start

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Henri Gomez
> If this reference is in your web.xml file, then my suggestion is already > being done. To test it, try temporarily copying the settings.xml file > into the WEB-INF directory and changing the relative URL appropriately. Putting the file in WEB-INF works, even if I use ../settings, ie directly

Re: [Proposal] Security Audit

2002-10-09 Thread Glenn Nielsen
The more who review/audit tomcat for security, the better. :-) Comments intermixed below. Jean-Francois Arcand wrote: > Hi, > > I'm looking to do a Security Audit on the current Tomcat 5.0 codebase. I > would like to collect as more as information as where you think I should > look at (code,

DO NOT REPLY [Bug 13477] New: - tomcat 4.1.2 installed from rpms fails to start

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

Re: mod_jk crash, please help

2002-10-09 Thread Bojan Smojver
Quoting Eugene Gluzberg <[EMAIL PROTECTED]>: > Please help. How can i trace this further? How do i get apache to > generate a core file so i can see where in apache code this is? Any > pointers for help here at all? Have a look at this: http://httpd.apache.org/dev/debugging.html Bojan -- To

cvs commit: jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/compiler JspReader.java

2002-10-09 Thread luehe
luehe 2002/10/09 17:49:21 Modified:jasper2/src/share/org/apache/jasper JspC.java JspCompilationContext.java jasper2/src/share/org/apache/jasper/compiler JspReader.java Log: Changed visibility of o.a.j.c.JspReader to package scope, and the vis

cvs commit: jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/compiler JspUtil.java

2002-10-09 Thread luehe
luehe 2002/10/09 15:46:41 Modified:jasper2/src/share/org/apache/jasper/compiler JspUtil.java Log: Removed redundant methods Revision ChangesPath 1.18 +3 -87 jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/compiler/JspUtil.java Index: JspUtil.ja

DO NOT REPLY [Bug 13392] - When tag pooling is enabled, release() is not called on tag instances

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

cvs commit: jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/runtime JspRuntimeLibrary.java

2002-10-09 Thread luehe
luehe 2002/10/09 14:59:08 Modified:jasper2/src/share/org/apache/jasper/resources Tag: tomcat_4_branch messages.properties messages_es.properties messages_ja.properties jasper2/src/share/org/apache/jasper/runtime Tag:

cvs commit: jakarta-servletapi-5/jsr152/examples/jsp2/misc config.jsp config.txt

2002-10-09 Thread kinman
kinman 2002/10/09 14:31:24 Modified:jsr152/examples/WEB-INF web.xml jsr152/examples/jsp2/misc config.jsp config.txt Log: - Modified the examples to use el-ignore and scripting-invalid Revision ChangesPath 1.4 +2 -2 jakarta-servletapi-5/jsr152/e

DO NOT REPLY [Bug 11678] - JNDIRealm times out/prompts for password with BASIC authentication

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

DO NOT REPLY [Bug 13206] - Invalid java bean property error message could be reported better.

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

cvs commit: jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/runtime JspRuntimeLibrary.java

2002-10-09 Thread luehe
luehe 2002/10/09 13:21:52 Modified:jasper2/src/share/org/apache/jasper/resources messages.properties messages_es.properties messages_ja.properties jasper2/src/share/org/apache/jasper/runtime JspRunt

DO NOT REPLY [Bug 11678] - JNDIRealm times out/prompts for password with BASIC authentication

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

DO NOT REPLY [Bug 13419] - Weird seg fault on Mac OS X for mod_jk2 + Apache2

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

DO NOT REPLY [Bug 11730] - build fails - can't find jni_md.h

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

Re: [Proposal] Security Audit

2002-10-09 Thread Jean-Francois Arcand
Costin Manolache wrote: AFAIK, the most important check is doPriviledged(). What we need to look for is if any of those blocks could be used by untrusted code to do something. The second very important check is the facades - making sure untrusted code can't get access to the real objec

Axis1.0 and chains/handlers

2002-10-09 Thread Costin Manolache
This is just FYI, in case you don't know all this already. I'm sure some of you are already using axis. One thing it would be worth looking at is the basic architecture they use for request processing. I think the model they're using is more powerfull than both 3.3 Interceptor and 4.0 Valve, an

Re: [JK2] make hostMap cache

2002-10-09 Thread Costin Manolache
+1 One question - do you think it's a good idea to extend the jk2_map to do the full mapping ? ( actually, all the code is there, but it's not used ). By full mapping I mean setting/sending the 'servletPath', 'pathInfo', 'wrapperName' and all the extra information that is needed - and bypassin

DO NOT REPLY [Bug 13467] New: - getResource() URL doesn't know the content type

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

Re: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread Bill Barker
> > > [X] Remove deprecated org.apache.catalina.connector components from the > j-t-catalina module > [ ] Leave them in > > -- To unsubscribe, e-mail: For additional commands, e-mail:

Re: [Proposal] Security Audit

2002-10-09 Thread Costin Manolache
AFAIK, the most important check is doPriviledged(). What we need to look for is if any of those blocks could be used by untrusted code to do something. The second very important check is the facades - making sure untrusted code can't get access to the real objects. We should also make sure th

[JK2] make hostMap cache

2002-10-09 Thread Mladen Turk
Hi, I would like to make the hostMap cache for hostname:port combination. Right now we doing hostMap over and over again for each request, so I would like to make a table that will save the once found hostEnv for requested hostname:port combination, skipping hostMap when already resolved. Any ob

Re: [Proposal] Security Audit

2002-10-09 Thread Bob Herrmann
FYI, Just to start off, I am going to review these classes. If someone else also reviews them, thats probably a good thing... # classes, package name 17 o.a.c.deploy 9 o.a.c.users 44 o.a.c.* 34 o.a.jk.* 15 j.s.http Briefly, I am going to look for - How/if a ClassLoader is used - privilege b

mod_jk crash, please help

2002-10-09 Thread Eugene Gluzberg
I am running apache 1.3 with mod_jk, my apache has apxs. I compiled and installed mod_jk from source, tag TOMCAT_4_1_12, configured it using the following options: ./configure --with-gnu-ld --with-apxs=/myapxpath/bin/apxs --enable-EAPI --with-java-home=/usr/java/jdk1.3.1 ran make installed m

Re: Tomcat4: Persistent http connection problem

2002-10-09 Thread mike thomas
I also have been surfing the web to find out how to implement an applet-to-servlet communication link over a persistent http connection. There is a working implementation available for download at http://www.ustobe.com/ After clicking on the 'news' item in the menu, there are links available to

cvs commit: jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/xmlparser ParserUtils.java

2002-10-09 Thread luehe
luehe 2002/10/09 11:25:39 Modified:jasper2/src/share/org/apache/jasper/compiler JspConfig.java TagLibraryInfoImpl.java TldLocationsCache.java jasper2/src/share/org/apache/jasper/xmlparser ParserUtils.java Log: Removed

DO NOT REPLY [Bug 13466] New: - Jikes compilation fails

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

JNDI Initial Context, outside webapp

2002-10-09 Thread Luca Zago
Hi, I noticed that is pratically impossible to retrieve a JNDI resource outside a webapp.If I need to access my resourse in some classes istantiated outside a single webapp, I always get an exception. Name jdbc/myDS is not bound in this Context I read the docs. If I understand well, the initia

DO NOT REPLY [Bug 13084] - jsp compilation with jikes fails

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

Re: administration-howto.html

2002-10-09 Thread Amy Roh
Glenn Nielsen wrote: > jean-frederic clere wrote: > > Hi, > > > > I am willing to use the administration tools of Tomcat but I am > > wondering where the administration-howto.html is located. > > > > If it is not existing I will create one similar to the existing > > manager-howto.xml. > > > > An

cvs commit: jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/compiler Compiler.java Generator.java JspConfig.java PageInfo.java TagFileProcessor.java Validator.java

2002-10-09 Thread kinman
kinman 2002/10/09 10:41:13 Modified:jasper2/src/share/org/apache/jasper/compiler Compiler.java Generator.java JspConfig.java PageInfo.java TagFileProcessor.java Validator.java Log: - Modified because of spec changes syntax and semanti

Re: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread Amy Roh
> > [X] Remove deprecated org.apache.catalina.connector components from the > j-t-catalina module > [ ] Leave them in > Amy -- To unsubscribe, e-mail: For additional commands, e-mail:

cvs commit: jakarta-servletapi-5/jsr154/src/share/dtd jsp_2_0.xsd

2002-10-09 Thread kinman
kinman 2002/10/09 10:38:49 Modified:jsr152/src/share/dtd jsp_2_0.xsd jsr152/src/share/javax/servlet/jsp/el Expression.java jsr154/src/share/dtd jsp_2_0.xsd Log: - Patch by Mark Roth jsr152/src/share/javax/serlvet/jsp/el/Expression.java - Re

Re: commons-daemon release ?

2002-10-09 Thread Costin Manolache
Remy Maucherat wrote: > Henri Gomez wrote: >> I wonder if a release of commons-daemon is planned. > > No, because promoting it to commons proper got vetoed. > At the moment, it looks like a split between daemon and launcher will > happen. For the record - nobody can 'veto' a promotion to common

Re: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread Costin Manolache
Remy Maucherat wrote: > > [X] Remove deprecated org.apache.catalina.connector components from the > j-t-catalina module > [ ] Leave them in > -- Costin -- To unsubscribe, e-mail: For additional commands, e-mail:

Re: tomcat4 write in conf files which is not FHS compliant

2002-10-09 Thread Costin Manolache
I'm not sure about this. AFAIK on RedHat and Mandrake ( and probably any other distro ) there are tools that are modifying config files ( in etc ). I don't know how the FHS can request 'read only' status. jk2.properties saving can be disabled. Right now the feature is not completely implemented

cvs commit: jakarta-tomcat-connectors/jk/native2/server/isapi jk_isapi_plugin.c

2002-10-09 Thread mturk
mturk 2002/10/09 10:11:22 Modified:jk/native2/server/isapi jk_isapi_plugin.c Log: Skip the checking of default hostname and port. Using that scheme the same behaviour is on all web servers. Revision ChangesPath 1.50 +5 -6 jakarta-tomcat-connectors/jk/nativ

cvs commit: jakarta-tomcat-connectors/jk/native2/server/apache2 mod_jk2.c

2002-10-09 Thread mturk
mturk 2002/10/09 10:10:52 Modified:jk/native2/server/apache2 mod_jk2.c Log: Skip the checking of default hostname and port. Using that scheme the same behaviour is on all web servers. Revision ChangesPath 1.54 +3 -7 jakarta-tomcat-connectors/jk/native2/serv

cvs commit: jakarta-tomcat-connectors/jk/native2/server/apache13 mod_jk2.c

2002-10-09 Thread mturk
mturk 2002/10/09 10:10:24 Modified:jk/native2/server/apache13 mod_jk2.c Log: Skip the checking of default hostname and port. Using that scheme the same behaviour is on all web servers. Revision ChangesPath 1.25 +4 -8 jakarta-tomcat-connectors/jk/native2/ser

cvs commit: jakarta-tomcat-connectors/jk/native2/common jk_uriMap.c

2002-10-09 Thread mturk
mturk 2002/10/09 10:08:10 Modified:jk/native2/common jk_uriMap.c Log: Fix the hostMap checking hostname:port then hostname Revision ChangesPath 1.51 +21 -14jakarta-tomcat-connectors/jk/native2/common/jk_uriMap.c Index: jk_uriMap.c ==

DO NOT REPLY [Bug 13223] - JSP pages in XML syntax do not compile properly

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

cvs commit: jakarta-tomcat-connectors/http11/src/java/org/apache/coyote/http11 Constants.java

2002-10-09 Thread remm
remm2002/10/09 09:56:17 Modified:http11/src/java/org/apache/coyote/http11 Constants.java Log: - Increase a little bit buffer sizes. Revision ChangesPath 1.10 +1 -1 jakarta-tomcat-connectors/http11/src/java/org/apache/coyote/http11/Constants.java Index

cvs commit: jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/util StringManager.java

2002-10-09 Thread luehe
luehe 2002/10/09 09:55:14 Removed: jasper2/src/share/org/apache/jasper/util StringManager.java Log: Removed redundant org.apache.jasper.util.StringManager -- To unsubscribe, e-mail: For additional commands, e-mail:

cvs commit: jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/xmlparser ParserUtils.java

2002-10-09 Thread luehe
luehe 2002/10/09 09:47:31 Modified:jasper2/src/share/org/apache/jasper/xmlparser ParserUtils.java Log: Removed dead code Revision ChangesPath 1.5 +1 -96 jakarta-tomcat-jasper/jasper2/src/share/org/apache/jasper/xmlparser/ParserUtils.j

Re: Tomcat 4.1.12: Xerces 2.2 problems - > Struts 1.0.2 bug.

2002-10-09 Thread Remy Maucherat
Jean-Francois Arcand wrote: > Hi, > > with Tomcat 4.1.12, Xerces 2.2 is throwing the following exception: > > org.xml.sax.SAXParseException: The string "--" is not permitted within > comments. >at org.apache.xerces.parsers.AbstractSAXParser.parse(Unknown Source) > > This is a bug in the or

Tomcat 4.1.12: Xerces 2.2 problems - > Struts 1.0.2 bug.

2002-10-09 Thread Jean-Francois Arcand
Hi, with Tomcat 4.1.12, Xerces 2.2 is throwing the following exception: org.xml.sax.SAXParseException: The string "--" is not permitted within comments. at org.apache.xerces.parsers.AbstractSAXParser.parse(Unknown Source) This is a bug in the org.apache.struts.digester.Digester class. If y

Re: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread Ian Darwin
> > [X ] Remove deprecated org.apache.catalina.connector components from the > j-t-catalina module > [ ] Leave them in > As long as it won't break builds of 4.1 :-) -- To unsubscribe, e-mail: For additional commands, e-mail:

Re: [Proposal] Security Audit

2002-10-09 Thread Ian Darwin
> I'm looking to do a Security Audit on the current Tomcat 5.0 codebase. I > would like to collect as more as information as where you think I should > look at (code, security hole, etc.). I'm planning to do the audit using > the default SecurityManager. Rigth now, I have started looking at: Alth

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Craig R. McClanahan
On Wed, 9 Oct 2002, Henri Gomez wrote: > Date: Wed, 09 Oct 2002 18:13:10 +0200 > From: Henri Gomez <[EMAIL PROTECTED]> > Reply-To: Tomcat Developers List <[EMAIL PROTECTED]> > To: Tomcat Developers List <[EMAIL PROTECTED]> > Subject: Re: apps conversion from 3.3.1 to 4.1.12 > > > > Haven't look

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Henri Gomez
> Haven't looked at the code, but here's a couple of thoughts that might > help: > > If your path above ("../../../settings.xml") is attempting to go above > the context root of the webapp, it's pretty much guaranteed to fail > because of the security restrictions. Undoing that restriction woul

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Henri Gomez
>> >org.apache.naming.resources.DirContextURLConnection.getInputStream(DirContextURLConnection.java:344) > >> >> at java.net.URL.openStream(URL.java:793) > > > Well, that's exactly the same. Where do you think that weird URL > connection goes ?? (hint: to the aforementioned FileDirContext

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Remy Maucherat
Henri Gomez wrote: > Remy Maucherat wrote: > >> Henri Gomez wrote: >> This is likely the protection against reading anything outside the webapp root (see the "allowLinking" of FileDirContext), although I don't know how the digester will try to load the included file. >>> >>> >>>

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Craig R. McClanahan
On Wed, 9 Oct 2002, Henri Gomez wrote: > Date: Wed, 09 Oct 2002 17:39:00 +0200 > From: Henri Gomez <[EMAIL PROTECTED]> > Reply-To: Tomcat Developers List <[EMAIL PROTECTED]> > To: Tomcat Developers List <[EMAIL PROTECTED]> > Subject: Re: apps conversion from 3.3.1 to 4.1.12 > > Remy Maucherat w

Re: [Proposal] Security Audit

2002-10-09 Thread Bob Herrmann
I can't think of anything more boring and tedious (bug fixing?) but I am willing to help. Maybe we should divide up the classes. Cheers, -bob On Tue, 2002-10-08 at 16:36, Jean-Francois Arcand wrote: > Hi, > > I'm looking to do a Security Audit on the current Tomcat 5.0 codebase. I > would

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Henri Gomez
Remy Maucherat wrote: > Henri Gomez wrote: > >>> This is likely the protection against reading anything outside the >>> webapp root (see the "allowLinking" of FileDirContext), although I >>> don't know how the digester will try to load the included file. >> >> >> >> Digester code is derived fro

DO NOT REPLY [Bug 13014] - OS/390/USS - Invalid  in servlet mapping

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

cvs commit: jakarta-tomcat-connectors/util/java/org/apache/tomcat/util/net/jsse JSSESupport.java

2002-10-09 Thread bobh
bobh2002/10/09 08:03:21 Modified:util/java/org/apache/tomcat/util/net/jsse JSSESupport.java Log: - make gump happy by getting rid of "1.4" only class java.net.SocketTimeoutException Revision ChangesPath 1.3 +3 -3 jakarta-tomcat-connectors/util/java/org/ap

DO NOT REPLY [Bug 13456] - allowChuncking="false" not working

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

DO NOT REPLY [Bug 13365] - JSP source disclosure vulnerability not fixed when invoking servlets by name

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

RE: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread Ignacio J. Ortega
> > [X] Remove deprecated org.apache.catalina.connector > components from the > j-t-catalina module > [ ] Leave them in > > Saludos, Ignacio J. Ortega -- To unsubscribe, e-mail: For additional commands, e-mail:

DO NOT REPLY [Bug 13456] New: - allowChuncking="false" not working

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

Re: administration-howto.html

2002-10-09 Thread Glenn Nielsen
jean-frederic clere wrote: > Hi, > > I am willing to use the administration tools of Tomcat but I am > wondering where the administration-howto.html is located. > > If it is not existing I will create one similar to the existing > manager-howto.xml. > > Any comments? > I know that Amy has b

[SECURITY] Apache Tomcat 4.x JSP source disclosure vulnerability;Apache Tomcat 4.0.6 released

2002-10-09 Thread Remy Maucherat
A security vulnerability has been confirmed to exist in Apache Tomcat 4.0.x releases (including Tomcat 4.0.5), which allows to use a specially crafted URL to return the unprocessed source of a JSP page, or, under special circumstances, a static resource which would otherwise have been protected by

Re: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread Jean-Francois Arcand
> > > [ X ] Remove deprecated org.apache.catalina.connector components from > the j-t-catalina module > [ ] Leave them in > -- Jeanfrancois -- To unsubscribe, e-mail: For additional commands, e-mail:

Re: commons-daemon release ?

2002-10-09 Thread jean-frederic clere
Remy Maucherat wrote: > Henri Gomez wrote: > >> I wonder if a release of commons-daemon is planned. > > > No, because promoting it to commons proper got vetoed. And the reasons why have not been changed... I had no time to write the needed code (and I was on holidays at the time of the veto:

cvs commit: jakarta-tomcat-connectors/jk/xdocs/jk2 confighowto.xml

2002-10-09 Thread mturk
mturk 2002/10/09 06:01:29 Modified:jk/xdocs/jk2 confighowto.xml Log: Add the JNI Minimum configuration. Revision ChangesPath 1.2 +57 -1 jakarta-tomcat-connectors/jk/xdocs/jk2/confighowto.xml Index: confighowto.xml ==

cvs commit: jakarta-tomcat-catalina/catalina/src/share/org/apache/catalina/core StandardWrapperValve.java

2002-10-09 Thread remm
remm2002/10/09 05:52:40 Modified:catalina/src/share/org/apache/catalina/core StandardWrapperValve.java Log: - Oops, not the right object. Revision ChangesPath 1.6 +5 -5 jakarta-tomcat-catalina/catalina/src/share/org/apache/catalina

cvs commit: jakarta-tomcat-catalina/catalina/src/share/org/apache/catalina/valves ErrorReportValve.java

2002-10-09 Thread remm
remm2002/10/09 05:42:51 Modified:catalina/src/share/org/apache/catalina/valves ErrorReportValve.java Log: - Port patch. Revision ChangesPath 1.3 +6 -9 jakarta-tomcat-catalina/catalina/src/share/org/apache/catalina/valves/ErrorRepor

Re: commons-daemon release ?

2002-10-09 Thread jean-frederic clere
Henri Gomez wrote: > I wonder if a release of commons-daemon is planned. > > JF ? > > > -- > To unsubscribe, e-mail: > > For additional commands, e-mail: > > > I am using it in a product named openIS. The FSC QA are still complaining

cvs commit: jakarta-tomcat-catalina/catalina/src/share/org/apache/catalina/core StandardWrapperValve.java

2002-10-09 Thread remm
remm2002/10/09 05:40:53 Modified:catalina/src/share/org/apache/catalina/core StandardWrapperValve.java Log: - The decoded URI should be used there. Revision ChangesPath 1.5 +15 -10 jakarta-tomcat-catalina/catalina/src/share/org/apach

Re: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread jean-frederic clere
[X] Remove deprecated org.apache.catalina.connector components from the j-t-catalina module [ ] Leave them in Cheers Jean-frederic -- To unsubscribe, e-mail: For additional commands, e-mail:

cvs commit: jakarta-tomcat-5/resources INSTALLLICENSE

2002-10-09 Thread remm
remm2002/10/09 05:20:40 Modified:.build.xml tomcat.nsi resources INSTALLLICENSE Log: - Cleanups and small fixes. Revision ChangesPath 1.40 +1 -1 jakarta-tomcat-5/build.xml Index: build.xml ==

Re: commons-daemon release ?

2002-10-09 Thread Remy Maucherat
Henri Gomez wrote: > I wonder if a release of commons-daemon is planned. No, because promoting it to commons proper got vetoed. At the moment, it looks like a split between daemon and launcher will happen. (like Costin, I'd really like to get rid of the Java code in daemon - the o.a.c.daemon p

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Remy Maucherat
Henri Gomez wrote: >> This is likely the protection against reading anything outside the >> webapp root (see the "allowLinking" of FileDirContext), although I >> don't know how the digester will try to load the included file. > > > Digester code is derived from XmlMapper which is able to locat

commons-daemon release ?

2002-10-09 Thread Henri Gomez
I wonder if a release of commons-daemon is planned. JF ? -- To unsubscribe, e-mail: For additional commands, e-mail:

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Henri Gomez
> This is likely the protection against reading anything outside the > webapp root (see the "allowLinking" of FileDirContext), although I don't > know how the digester will try to load the included file. Digester code is derived from XmlMapper which is able to locate entities in ../../../ dire

RE: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread John Trollinger
> > [ ] Remove deprecated org.apache.catalina.connector > components from the > j-t-catalina module > [X ] Leave them in > Atleast untill all the excessive log messages are removed from the coyote connectors (ie the socket error messages) or there is a way to disable them (ie give them a lo

[GUMP] Build Failure - jakarta-tomcat-util

2002-10-09 Thread Craig McClanahan
This email is autogenerated from the output from: Buildfile: build.xml detect: build-prepare: [mkdir] Created

Re: HttpSessionListener

2002-10-09 Thread Andreas Junghans
John Baker wrote: > I'm trying to write a bean so when sessions are closed, database > connections > and other resources are released. I realise when the sessionDestroyed > method > is called on HttpSessionListener the session is already invalidated (I > would > like to know why such a design

RE: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread iasandcb
[X] Remove deprecated org.apache.catalina.connector components from the j-t-catalina module [ ] Leave them in IAS Jakarta-Seoul Project Coordinator http://jakarta.apache-korea.org -Original Message- From: Remy Maucherat [mailto:[EMAIL PROTECTED]] Sent: Wednesday, October 09, 2002 6:

cvs commit: jakarta-tomcat-5 build.xml

2002-10-09 Thread remm
remm2002/10/09 03:07:48 Modified:.build.xml Log: - No reason to clean the release folder. Revision ChangesPath 1.39 +0 -2 jakarta-tomcat-5/build.xml Index: build.xml === RCS fi

cvs commit: jakarta-tomcat-5 .cvsignore

2002-10-09 Thread remm
remm2002/10/09 03:06:34 Modified:..cvsignore Log: - Update .cvsignore. Revision ChangesPath 1.3 +1 -0 jakarta-tomcat-5/.cvsignore Index: .cvsignore === RCS file: /home/cvs/jak

cvs commit: jakarta-tomcat-5/resources welcome.bin.html welcome.main.html INSTALLLICENSE

2002-10-09 Thread remm
remm2002/10/09 03:06:07 Modified:.build.xml resources INSTALLLICENSE Added: .CHANGELOG RELEASE-NOTES resources welcome.bin.html welcome.main.html Log: - Improve release target, so that it will create a ready to upload package

Re: [5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread Henri Gomez
Remy Maucherat wrote: > The connectors which depend on the org.apache.catalina.connector package > (including JK 1, webapp, and the old HTTP connectors) will either need > to be updated or removed. The Coyote family of connectors is well > supported and provides a suitable replacement (IMO). Co

DO NOT REPLY [Bug 13446] New: - Invalide error page with request attribute.

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

[5.0] [VOTE] Remove deprecated and unsupported components

2002-10-09 Thread Remy Maucherat
The connectors which depend on the org.apache.catalina.connector package (including JK 1, webapp, and the old HTTP connectors) will either need to be updated or removed. The Coyote family of connectors is well supported and provides a suitable replacement (IMO). Coyote is the default connector

DO NOT REPLY [Bug 13445] - Installing without the examples makes Tomcat startup fail

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

DO NOT REPLY [Bug 13445] New: - Installing without the examples makes Tomcat startup fail

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Remy Maucherat
Henri Gomez wrote: >>> While converting some applications from 3.3.1 to 4.1.12 I noticed >>> some little problems. >> >> >> >> Wot? 3.3.1 isn't good enough for you any more. ;-) > > > You're kidding, I'm preparing the future, which may be TC 5 for us > if we could avoid JDK 1.4 to be mandatory.

administration-howto.html

2002-10-09 Thread jean-frederic clere
Hi, I am willing to use the administration tools of Tomcat but I am wondering where the administration-howto.html is located. If it is not existing I will create one similar to the existing manager-howto.xml. Any comments? Cheers Jean-frederic -- To unsubscribe, e-mail:

Re: apps conversion from 3.3.1 to 4.1.12

2002-10-09 Thread Henri Gomez
>>While converting some applications from 3.3.1 to 4.1.12 I noticed >>some little problems. > > > Wot? 3.3.1 isn't good enough for you any more. ;-) You're kidding, I'm preparing the future, which may be TC 5 for us if we could avoid JDK 1.4 to be mandatory. And I'd like to do some internals b

cvs commit: jakarta-tomcat-catalina/catalina/src/share/org/apache/catalina/core DummyRequest.java DummyResponse.java ApplicationContext.java StandardWrapper.java MappingRequest.java

2002-10-09 Thread remm
remm2002/10/09 01:01:12 Modified:catalina/src/share/org/apache/catalina/core ApplicationContext.java StandardWrapper.java Added: catalina/src/share/org/apache/catalina/core DummyRequest.java DummyResponse.java Removed: ca

DO NOT REPLY [Bug 13443] New: - request.getRequestURI() problem with jsp:include tag

2002-10-09 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_b

UML Class Diagram

2002-10-09 Thread Budi Kurniawan
Hi, I was wondering if I can get the Catalina class diagram to help me understand how it works, or if it is available online. Thanks, budi -- To unsubscribe, e-mail: For additional commands, e-mail: