Re: [VOTE] Release Apache Tomcat 10.1.59
Rainer Jung <[email protected]>
| Newsgroups | gmane.comp.jakarta.tomcat.devel |
|---|---|
| Message-ID | <[email protected]> |
Am 13.08.26 um 19:10 schrieb Christopher Schultz:
> The proposed Apache Tomcat 10.1.59 release is now available for
> voting.
>
> All committers and PMC members are kindly requested to provide a vote if
> possible. ANY TOMCAT USER MAY VOTE, though only PMC members votes are
> binding. We welcome non-committer votes or comments on release builds.
>
> The notable changes compared to 10.1.57[*] are:
>
> - Add a new attribute to the Context, urlPatternsProvidedInDecodedForm.
> This attribute controls whether URLs and URL patterns provided in the
> deployment descriptor (web.xml), annotations and/or their programmatic
> equivalents are treated as being provided in URL-encoded form (i.e.
> using %nn encoding) or in decoded form. The Servlet specification
> requires that they are provided in decoded form. However, Tomcat has
> historically treated them as if they are provided in encoded form. In
> Tomcat 12, they will always be treated as if they are provided in
> decoded form. This setting enables migration from encoded form to
> decoded form on an application by application basis. This attribute
> will be removed in Tomcat 12 where it will effectively be hard-coded
> to true.
>
> - Require every HTTP/2 request to provide an authority (either an
> :authority pseudo header or a Host header).
>
> - Change the default encryptionAlgorithm for the EncryptInterceptor to
> AES/GCM/NoPadding. **This is a breaking change for the
> EncryptInterceptor.**
>
> [*] A small bug was found and fixed from the 10.1.58 release, so the
> major changes remain the same for 10.1.59.
>
> For full details, see the change log:
> https://nightlies.apache.org/tomcat/tomcat-10.1.x/docs/changelog.html
>
> Applications that run on Tomcat 9 and earlier will not run on Tomcat 10
> without changes. Java EE applications designed for Tomcat 9 and earlier
> may be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat
> will automatically convert them to Jakarta EE and copy them to the
> webapps directory.
>
> It can be obtained from:
> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-10/v10.1.59/
>
> The Maven staging repo is:
> https://repository.apache.org/content/repositories/orgapachetomcat-1603
>
> The tag is:
> https://github.com/apache/tomcat/tree/10.1.59
> https://github.com/apache/tomcat/
> commit/08382643a5aaf23bea2915ff88143aedbf8764f5
>
> Please reply with a +1 for release or +0/-0/-1 with an explanation.
+1 to release.
Reproducibility of the build checked (including the Windows installer)
using "ant verify-release" on Linux Mint 22.3. OK after setting LANG.
Original Windows installer signature verified with osslsigncode 2.10.
Unit tests ran on platforms
- RHEL 7, 8, 9 and 10 and SLES 12 and 15
using
- recent patch versions of JDK 11, 17, 21, 25, 26 and 27+28 (EA)
from
- Eclipse Adoptium, Azul Zulu, Amazon Coretto, Oracle, RedHat (missing
26) and from OpenJDK for 27+28
Also tested with
- tcnative 2.0.15 and panama
based on
- OpenSSL 3.5.7, 3.6.3 and 4.0.1
Each combination of platform, JVM and JSSE or tcnative or panama only
tested for NIO or NIO2 (randomized). Total number of test combinations:
71 nio2 jsse
101 nio2 panama
214 nio2 tcnative
77 nio jsse
91 nio panama
230 nio tcnative
Test observations:
- IMHO nothing critical
- in addition
- one crash failure with JSSE (1 in 148 runs)
- very few crashes with tcnative (3 in 444 runs)
- no crash failures with panama (192 runs)
- few non-crash failures with jsse (5 in 148 runs)
- very few non-crash failures with tcnative (0 in 444 runs)
- no non-crash failures with panama (0 in 192 runs)
Thanks for RM!
Best regards,
Rainer