Re: [VOTE] Release Apache Tomcat 11.0.25
Rainer Jung <[email protected]>
| Newsgroups | gmane.comp.jakarta.tomcat.devel |
|---|---|
| Message-ID | <[email protected]> |
Am 12.08.26 um 16:02 schrieb Mark Thomas:
> The proposed Apache Tomcat 11.0.25 release is now available for voting.
>
> The notable changes compared to 11.0.24 include:
>
> - Add a new attribute to the Context, urlPatternsProvidedInDecodedForm.
> This attribute controls whether URLs and URL patterns provided in the
> deployment descriptor (web.xml), annotations and/or their programmatic
> equivalents are treated as being provided in URL-encoded form (i.e.
> using %nn encoding) or in decoded form. The Servlet specification
> requires that they are provided in decoded form. However, Tomcat has
> historically treated them as if they are provided in encoded form. In
> Tomcat 12, they will always be treated as if they are provided in
> decoded form. This setting enables migration from encoded form to
> decoded form on an application by application basis. This attribute
> will be removed in Tomcat 12 where it will effectively be hard-coded
> to true.
> - Require every HTTP/2 request to provide an authority (either an
> :authority pseudo header or a Host header)
> - Change the default encryptionAlgorithm for the EncryptInterceptor to
> AES/GCM/NoPadding. This is a breaking change for the
> EncryptInterceptor.
>
> For full details, see the change log:
> https://nightlies.apache.org/tomcat/tomcat-11.0.x/docs/changelog.html
>
> Applications that run on Tomcat 9 and earlier will not run on Tomcat 11
> without changes. Java EE applications designed for Tomcat 9 and earlier
> may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat
> will automatically convert them to Jakarta EE and copy them to the
> webapps directory. Applications using deprecated APIs may require
> further changes.
>
> It can be obtained from:
> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-11/v11.0.25/
>
> The Maven staging repo is:
> https://repository.apache.org/content/repositories/orgapachetomcat-1600
> The tag is:
> https://github.com/apache/tomcat/tree/11.0.25
> cbe6e15ee81e2fc6232954292a80cca5d1e84009
>
> The proposed 11.0.25 release is:
> [ ] -1 Broken - do not release
> [X] +1 Stable - go ahead and release as 11.0.25
+1 to release.
Reproducibility of the build checked (including the Windows installer)
using "ant verify-release" on Linux Mint 22.3. OK after setting LANG.
Original Windows installer signature verified with osslsigncode 2.10.
Unit tests ran on platforms
- RHEL 8, 9 and 10 and SLES 15
using
- recent patch versions of JDK 17, 21, 25, 26 and 27+28 (EA)
from
- Eclipse Adoptium, Azul Zulu, Amazon Coretto, Oracle, RedHat (26
missing) and from OpenJDK for 27+28
Also tested with
- tcnative 2.0.15 and panama
based on
- OpenSSL 3.5.7, 3.6.3 and 4.0.1
Each combination of platform, JVM and JSSE or tcnative or panama only
tested for NIO or NIO2 (randomized). Total number of test combinations:
41 nio jsse.out
71 nio panama
119 nio tcnative
40 nio2 jsse.out
58 nio2 panama
124 nio2 tcnative
Test observations:
- IMHO nothing critical
- in addition
- few crashes with tcnative (4 in 243 runs)
- no crash failures with panama (129 runs)
- few non-crash failures with jsse (3 in 81 runs)
- no non-crash failures with tcnative (243 runs)
- no non-crash failures with panama (129 runs)
Thanks for RM!
Best regards,
Rainer