Re: [VOTE] Release Apache Tomcat 10.1.59

Rainer Jung <[email protected]>
Newsgroups gmane.comp.jakarta.tomcat.devel
Message-ID <[email protected]>
Am 13.08.26 um 19:10 schrieb Christopher Schultz:
> The proposed Apache Tomcat 10.1.59 release is now available for
> voting.
> 
> All committers and PMC members are kindly requested to provide a vote if 
> possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are 
> binding. We welcome non-committer votes or comments on release builds.
> 
> The notable changes compared to 10.1.57[*] are:
> 
> - Add a new attribute to the Context, urlPatternsProvidedInDecodedForm.
>    This attribute controls whether URLs and URL patterns provided in the
>    deployment descriptor (web.xml), annotations and/or their programmatic
>    equivalents are treated as being provided in URL-encoded form (i.e.
>    using %nn encoding) or in decoded form. The Servlet specification
>    requires that they are provided in decoded form. However, Tomcat has
>    historically treated them as if they are provided in encoded form. In
>    Tomcat 12, they will always be treated as if they are provided in
>    decoded form. This setting enables migration from encoded form to
>    decoded form on an application by application basis. This attribute
>    will be removed in Tomcat 12 where it will effectively be hard-coded
>    to true.
> 
> - Require every HTTP/2 request to provide an authority (either an
>    :authority pseudo header or a Host header).
> 
> - Change the default encryptionAlgorithm for the EncryptInterceptor to
>    AES/GCM/NoPadding. **This is a breaking change for the
>    EncryptInterceptor.**
> 
> [*] A small bug was found and fixed from the 10.1.58 release, so the 
> major changes remain the same for 10.1.59.
> 
> For full details, see the change log:
> https://nightlies.apache.org/tomcat/tomcat-10.1.x/docs/changelog.html
> 
> Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 
> without changes. Java EE applications designed for Tomcat 9 and earlier 
> may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat 
> will automatically convert them to Jakarta EE and copy them to the 
> webapps directory.
> 
> It can be obtained from:
> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.1.59/
> 
> The Maven staging repo is:
> https://repository.apache.org/content/repositories/orgapachetomcat-1603
> 
> The tag is:
> https://github.com/apache/tomcat/tree/10.1.59
> https://github.com/apache/tomcat/ 
> commit/08382643a5aaf23bea2915ff88143aedbf8764f5
> 
> Please reply with a +1 for release or +0/-0/-1 with an explanation.
+1 to release.

Reproducibility of the build checked (including the Windows installer) 
using "ant verify-release" on Linux Mint 22.3. OK after setting LANG.

Original Windows installer signature verified with osslsigncode 2.10.

Unit tests ran on platforms

- RHEL 7, 8, 9 and 10 and SLES 12 and 15

using

- recent patch versions of JDK 11, 17, 21, 25, 26 and 27+28 (EA)

from

- Eclipse Adoptium, Azul Zulu, Amazon Coretto, Oracle, RedHat (missing 
26) and from OpenJDK for 27+28

Also tested with

- tcnative 2.0.15 and panama

based on

- OpenSSL 3.5.7, 3.6.3 and 4.0.1

Each combination of platform, JVM and JSSE or tcnative or panama only 
tested for NIO or NIO2 (randomized). Total number of test combinations:

      71 nio2 jsse
     101 nio2 panama
     214 nio2 tcnative
      77 nio jsse
      91 nio panama
     230 nio tcnative

Test observations:

   - IMHO nothing critical

   - in addition
     - one crash failure with JSSE (1 in 148 runs)
     - very few crashes with tcnative (3 in 444 runs)
     - no crash failures with panama (192 runs)
     - few non-crash failures with jsse (5 in 148 runs)
     - very few non-crash failures with tcnative (0 in 444 runs)
     - no non-crash failures with panama (0 in 192 runs)

Thanks for RM!

Best regards,

Rainer
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.