6
0
forked from pool/jetty-minimal

Compare commits

...

33 Commits

Author SHA256 Message Date
2d1ee51310 Accepting request 1280113 from Java:packages
security fixes

OBS-URL: https://build.opensuse.org/request/show/1280113
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=28
2025-05-26 16:40:28 +00:00
d174cb7c90 OBS-URL: https://build.opensuse.org/package/show/Java:packages/jetty-minimal?expand=0&rev=95 2025-05-26 10:39:23 +00:00
553a2d00d0 OBS-URL: https://build.opensuse.org/package/show/Java:packages/jetty-minimal?expand=0&rev=94 2025-04-24 11:42:25 +00:00
c4b2bfac17 Accepting request 1226462 from Java:packages
Allow building against servlet api 4

OBS-URL: https://build.opensuse.org/request/show/1226462
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=27
2024-11-26 19:56:17 +00:00
1f3c5d7b92 OBS-URL: https://build.opensuse.org/package/show/Java:packages/jetty-minimal?expand=0&rev=92 2024-11-26 09:54:39 +00:00
0f1b6b7ca0 OBS-URL: https://build.opensuse.org/package/show/Java:packages/jetty-minimal?expand=0&rev=91 2024-11-11 16:55:13 +00:00
4a2b7e1222 Accepting request 1208738 from Java:packages
Package the infrastructure pom artifacts too

OBS-URL: https://build.opensuse.org/request/show/1208738
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=26
2024-10-18 13:57:43 +00:00
5aec8cdb3f OBS-URL: https://build.opensuse.org/package/show/Java:packages/jetty-minimal?expand=0&rev=89 2024-10-18 00:29:14 +00:00
ed713c164a Accepting request 1208602 from Java:packages
OBS-URL: https://build.opensuse.org/request/show/1208602
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=25
2024-10-17 16:40:46 +00:00
313ec6767b OBS-URL: https://build.opensuse.org/package/show/Java:packages/jetty-minimal?expand=0&rev=87 2024-10-17 12:27:55 +00:00
cf309dd847 Accepting request 1208241 from Java:packages
CVE-2024-8184, bsc#1231651

OBS-URL: https://build.opensuse.org/request/show/1208241
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=24
2024-10-16 21:47:34 +00:00
4ff6b84951 Accepting request 1207481 from Java:packages
add jetty-alpn and jetty-http2 spec files

OBS-URL: https://build.opensuse.org/request/show/1207481
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=23
2024-10-14 11:06:31 +00:00
387bb3e788 Accepting request 1152265 from Java:packages
CVE-2024-22201, bsc#1220437

OBS-URL: https://build.opensuse.org/request/show/1152265
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=22
2024-02-27 21:49:15 +00:00
686bb2ee47 Accepting request 1121238 from Java:packages
Do not force java 11 on i586

OBS-URL: https://build.opensuse.org/request/show/1121238
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=21
2023-10-30 21:11:34 +00:00
d054ef8e42 Accepting request 1117494 from Java:packages
Misc. security fixes

OBS-URL: https://build.opensuse.org/request/show/1117494
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=20
2023-10-12 21:44:38 +00:00
af5bb53f56 Accepting request 1109972 from Java:packages
Reproducible builds improvement

OBS-URL: https://build.opensuse.org/request/show/1109972
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=19
2023-09-10 11:10:43 +00:00
80725d8401 Accepting request 1088154 from Java:packages
Security fixes

OBS-URL: https://build.opensuse.org/request/show/1088154
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=18
2023-05-22 11:14:17 +00:00
bf6bef1272 Accepting request 1084662 from Java:packages
OBS-URL: https://build.opensuse.org/request/show/1084662
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=17
2023-05-04 15:11:22 +00:00
2d3e3fd937 Accepting request 1010950 from Java:packages
Fix i386 build breakages by requiring java 11

OBS-URL: https://build.opensuse.org/request/show/1010950
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=16
2022-10-15 14:37:30 +00:00
22fd19a848 Accepting request 987945 from Java:packages
bsc#1201316 and bsc#1201317

OBS-URL: https://build.opensuse.org/request/show/987945
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=15
2022-07-09 15:03:20 +00:00
25c5afb386 Accepting request 965688 from Java:packages
9.4.46.v20220328

OBS-URL: https://build.opensuse.org/request/show/965688
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=14
2022-03-29 19:06:56 +00:00
4d9dc2fb36 Accepting request 963998 from Java:packages
Build with source and target levels 8

OBS-URL: https://build.opensuse.org/request/show/963998
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=13
2022-03-22 18:41:08 +00:00
8398687178 Accepting request 926144 from Java:packages
make import of package sun.misc optional

OBS-URL: https://build.opensuse.org/request/show/926144
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=12
2021-10-19 21:03:51 +00:00
c72c8ee15f Accepting request 907107 from Java:packages
bsc#1188438, CVE-2021-34429

OBS-URL: https://build.opensuse.org/request/show/907107
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=11
2021-07-20 13:39:14 +00:00
d65994d7bc Accepting request 902968 from Java:packages
Distribute some more modules

OBS-URL: https://build.opensuse.org/request/show/902968
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=10
2021-06-29 20:43:22 +00:00
0af9f061d5 Accepting request 898823 from Java:packages
Security fixes + some missing bug numbers

OBS-URL: https://build.opensuse.org/request/show/898823
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=9
2021-06-09 19:53:06 +00:00
325ce7e478 Accepting request 893309 from Java:packages
Security fixes

OBS-URL: https://build.opensuse.org/request/show/893309
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=8
2021-05-15 21:16:20 +00:00
d470deff50 Accepting request 878530 from Java:packages
bsc#1182898, CVE-2020-27223

OBS-URL: https://build.opensuse.org/request/show/878530
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=7
2021-03-12 12:33:52 +00:00
a9d2d48c26 Accepting request 853651 from Java:packages
bsc#1179727, CVE-2020-27218

OBS-URL: https://build.opensuse.org/request/show/853651
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=6
2020-12-10 14:58:03 +00:00
e1916ce1c2 Accepting request 849426 from Java:packages
9.4.30.v20200611

OBS-URL: https://build.opensuse.org/request/show/849426
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=5
2020-11-19 15:47:50 +00:00
b7694a7a84 Accepting request 791023 from Java:packages
9.4.22 -> 9.4.27

OBS-URL: https://build.opensuse.org/request/show/791023
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=4
2020-04-04 10:24:37 +00:00
32ec8e7578 Accepting request 751538 from Java:packages
remove obsolete patch

OBS-URL: https://build.opensuse.org/request/show/751538
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=3
2019-12-03 11:40:07 +00:00
917d32f5f3 Accepting request 747070 from Java:packages
Upgrade to 9.4.22 + websocket subpackage and spec file

OBS-URL: https://build.opensuse.org/request/show/747070
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/jetty-minimal?expand=0&rev=2
2019-11-10 21:42:51 +00:00
13 changed files with 176 additions and 21 deletions

View File

@@ -1,3 +1,20 @@
-------------------------------------------------------------------
Mon May 26 10:30:44 UTC 2025 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 9.4.57.v20241219
* Security fixes:
+ CVE-2024-6763, bsc#1231652: the HttpURI class does
insufficient validation on the authority segment of a URI
+ CVE-2024-13009, bsc#1243271: Gzip Request Body Buffer
Corruption
* Changes:
+ #12268 - IteratingCallback may iterate too much when process()
returns Action.IDLE
+ #12648 - Backport improved handling of bad Gzip content (and
Gzip Exceptions)
+ #12532 - Backport of deprecation of UserInfo on URI (in
violation of RFC2616 spec)
-------------------------------------------------------------------
Tue Oct 15 21:27:27 UTC 2024 - Fridrich Strba <fstrba@suse.com>

View File

@@ -1,7 +1,7 @@
#
# spec file for package jetty-alpn
#
# Copyright (c) 2024 SUSE LLC
# Copyright (c) 2025 SUSE LLC
# Copyright (c) 2000-2007, JPackage Project
#
# All modifications and additions to the file contributed by third parties
@@ -18,10 +18,10 @@
%global base_name jetty
%global addver .v20240826
%global addver .v20241219
%define src_name %{base_name}.project-%{base_name}-%{version}%{addver}
Name: %{base_name}-alpn
Version: 9.4.56
Version: 9.4.57
Release: 0
Summary: The alpn modules for Jetty
License: Apache-2.0 OR EPL-1.0

View File

@@ -1,3 +1,20 @@
-------------------------------------------------------------------
Mon May 26 10:30:44 UTC 2025 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 9.4.57.v20241219
* Security fixes:
+ CVE-2024-6763, bsc#1231652: the HttpURI class does
insufficient validation on the authority segment of a URI
+ CVE-2024-13009, bsc#1243271: Gzip Request Body Buffer
Corruption
* Changes:
+ #12268 - IteratingCallback may iterate too much when process()
returns Action.IDLE
+ #12648 - Backport improved handling of bad Gzip content (and
Gzip Exceptions)
+ #12532 - Backport of deprecation of UserInfo on URI (in
violation of RFC2616 spec)
-------------------------------------------------------------------
Tue Oct 15 21:27:27 UTC 2024 - Fridrich Strba <fstrba@suse.com>

View File

@@ -1,7 +1,7 @@
#
# spec file for package jetty-http2
#
# Copyright (c) 2024 SUSE LLC
# Copyright (c) 2025 SUSE LLC
# Copyright (c) 2000-2007, JPackage Project
#
# All modifications and additions to the file contributed by third parties
@@ -18,10 +18,10 @@
%global base_name jetty
%global addver .v20240826
%global addver .v20241219
%define src_name %{base_name}.project-%{base_name}-%{version}%{addver}
Name: %{base_name}-http2
Version: 9.4.56
Version: 9.4.57
Release: 0
Summary: The http2 modules for Jetty
License: Apache-2.0 OR EPL-1.0

View File

@@ -1,3 +1,32 @@
-------------------------------------------------------------------
Mon May 26 10:30:44 UTC 2025 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 9.4.57.v20241219
* Security fixes:
+ CVE-2024-6763, bsc#1231652: the HttpURI class does
insufficient validation on the authority segment of a URI
+ CVE-2024-13009, bsc#1243271: Gzip Request Body Buffer
Corruption
* Changes:
+ #12268 - IteratingCallback may iterate too much when process()
returns Action.IDLE
+ #12648 - Backport improved handling of bad Gzip content (and
Gzip Exceptions)
+ #12532 - Backport of deprecation of UserInfo on URI (in
violation of RFC2616 spec)
-------------------------------------------------------------------
Mon Nov 11 16:51:57 UTC 2024 - Fridrich Strba <fstrba@suse.com>
- Added patch:
* jetty-port-to-servlet-4.0.patch
+ Fix build against the javax.servlet-api 4.x
-------------------------------------------------------------------
Thu Oct 17 12:27:25 UTC 2024 - Fridrich Strba <fstrba@suse.com>
- Package the infrastructure pom artifacts too
-------------------------------------------------------------------
Thu Oct 17 09:47:04 UTC 2024 - Anton Shvetz <shvetz.anton@gmail.com>

View File

@@ -1,7 +1,7 @@
#
# spec file for package jetty-minimal
#
# Copyright (c) 2024 SUSE LLC
# Copyright (c) 2025 SUSE LLC
# Copyright (c) 2000-2007, JPackage Project
#
# All modifications and additions to the file contributed by third parties
@@ -18,16 +18,17 @@
%global base_name jetty
%global addver .v20240826
%global addver .v20241219
%define src_name %{base_name}.project-%{base_name}-%{version}%{addver}
Name: %{base_name}-minimal
Version: 9.4.56
Version: 9.4.57
Release: 0
Summary: Java Webserver and Servlet Container
License: Apache-2.0 OR EPL-1.0
Group: Productivity/Networking/Web/Servers
URL: https://www.eclipse.org/jetty/
Source0: https://github.com/eclipse/%{base_name}.project/archive/%{base_name}-%{version}%{addver}.tar.gz#/%{src_name}.tar.gz
Patch0: jetty-port-to-servlet-4.0.patch
BuildRequires: fdupes
BuildRequires: java-devel >= 1.8
BuildRequires: maven-local
@@ -263,6 +264,12 @@ Group: Productivity/Networking/Web/Servers
%description -n %{base_name}-xml
%{extdesc} %{summary}.
%package -n %{base_name}-project
Summary: POM files for Jetty
%description -n %{base_name}-project
%{extdesc} %{summary}.
%package javadoc
Summary: Javadoc for %{name}
Group: Productivity/Networking/Web/Servers
@@ -272,6 +279,7 @@ Group: Productivity/Networking/Web/Servers
%prep
%setup -q -n %{src_name}
%patch -P 0 -p1
find . -name "*.?ar" -exec rm {} \;
find . -name "*.class" -exec rm {} \;
@@ -403,9 +411,9 @@ sed -i '/<SystemProperty name="jetty.state"/d' \
%{mvn_package} :jetty-distribution __noinstall
# Separate package for POMs
%{mvn_package} ':*-project' __noinstall
%{mvn_package} ':*-parent' __noinstall
%{mvn_package} ':*-bom' __noinstall
%{mvn_package} ':*-project' project
%{mvn_package} ':*-parent' project
%{mvn_package} ':*-bom' project
# artifact used by demo
%{mvn_package} :test-mock-resources
@@ -497,6 +505,8 @@ ln -s %{_javadir}/%{base_name}/%{base_name}-ant.jar %{buildroot}%{_datadir}/ant/
%files -n %{base_name}-plus -f .mfiles-jetty-plus
%files -n %{base_name}-project -f .mfiles-project
%files -n %{base_name}-quickstart -f .mfiles-jetty-quickstart
%files -n %{base_name}-rewrite -f .mfiles-jetty-rewrite

View File

@@ -0,0 +1,48 @@
--- jetty.project-jetty-9.4.56.v20240826/jetty-server/src/main/java/org/eclipse/jetty/server/handler/ContextHandler.java 2024-11-11 17:39:19.269641330 +0100
+++ jetty.project-jetty-9.4.56.v20240826/jetty-server/src/main/java/org/eclipse/jetty/server/handler/ContextHandler.java 2024-11-11 17:46:58.312710664 +0100
@@ -2971,6 +2971,45 @@
{
return null;
}
+
+ public void setResponseCharacterEncoding(String charset)
+ {
+ LOG.warn(UNIMPLEMENTED_USE_SERVLET_CONTEXT_HANDLER, "setResponseCharacterEncoding(String...)");
+ }
+
+ public String getResponseCharacterEncoding()
+ {
+ LOG.warn(UNIMPLEMENTED_USE_SERVLET_CONTEXT_HANDLER, "getResponseCharacterEncoding()");
+ return null;
+ }
+
+ public void setRequestCharacterEncoding(String charset)
+ {
+ LOG.warn(UNIMPLEMENTED_USE_SERVLET_CONTEXT_HANDLER, "setRequestCharacterEncoding(String...)");
+ }
+
+ public String getRequestCharacterEncoding()
+ {
+ LOG.warn(UNIMPLEMENTED_USE_SERVLET_CONTEXT_HANDLER, "getRequestCharacterEncoding()");
+ return null;
+ }
+
+ public void setSessionTimeout(int sessionTimeout)
+ {
+ LOG.warn(UNIMPLEMENTED_USE_SERVLET_CONTEXT_HANDLER, "setSessionTimeout(int...)");
+ }
+
+ public int getSessionTimeout()
+ {
+ LOG.warn(UNIMPLEMENTED_USE_SERVLET_CONTEXT_HANDLER, "getSessionTimeout()");
+ return 0;
+ }
+
+ public ServletRegistration.Dynamic addJspFile(String servletName, String jspFile)
+ {
+ LOG.warn(UNIMPLEMENTED_USE_SERVLET_CONTEXT_HANDLER, "addJspFile(String..., String...)");
+ return null;
+ }
}
/**

View File

@@ -1,3 +1,20 @@
-------------------------------------------------------------------
Mon May 26 10:30:44 UTC 2025 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 9.4.57.v20241219
* Security fixes:
+ CVE-2024-6763, bsc#1231652: the HttpURI class does
insufficient validation on the authority segment of a URI
+ CVE-2024-13009, bsc#1243271: Gzip Request Body Buffer
Corruption
* Changes:
+ #12268 - IteratingCallback may iterate too much when process()
returns Action.IDLE
+ #12648 - Backport improved handling of bad Gzip content (and
Gzip Exceptions)
+ #12532 - Backport of deprecation of UserInfo on URI (in
violation of RFC2616 spec)
-------------------------------------------------------------------
Tue Oct 15 21:27:27 UTC 2024 - Fridrich Strba <fstrba@suse.com>

View File

@@ -1,7 +1,7 @@
#
# spec file for package jetty-unixsocket
#
# Copyright (c) 2024 SUSE LLC
# Copyright (c) 2025 SUSE LLC
# Copyright (c) 2000-2007, JPackage Project
#
# All modifications and additions to the file contributed by third parties
@@ -18,10 +18,10 @@
%global base_name jetty
%global addver .v20240826
%global addver .v20241219
%define src_name %{base_name}.project-%{base_name}-%{version}%{addver}
Name: %{base_name}-unixsocket
Version: 9.4.56
Version: 9.4.57
Release: 0
Summary: The unixsocket modules for Jetty
License: Apache-2.0 OR EPL-1.0

View File

@@ -1,3 +1,20 @@
-------------------------------------------------------------------
Mon May 26 10:30:44 UTC 2025 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 9.4.57.v20241219
* Security fixes:
+ CVE-2024-6763, bsc#1231652: the HttpURI class does
insufficient validation on the authority segment of a URI
+ CVE-2024-13009, bsc#1243271: Gzip Request Body Buffer
Corruption
* Changes:
+ #12268 - IteratingCallback may iterate too much when process()
returns Action.IDLE
+ #12648 - Backport improved handling of bad Gzip content (and
Gzip Exceptions)
+ #12532 - Backport of deprecation of UserInfo on URI (in
violation of RFC2616 spec)
-------------------------------------------------------------------
Tue Oct 15 21:27:27 UTC 2024 - Fridrich Strba <fstrba@suse.com>

View File

@@ -1,7 +1,7 @@
#
# spec file for package jetty-websocket
#
# Copyright (c) 2024 SUSE LLC
# Copyright (c) 2025 SUSE LLC
# Copyright (c) 2000-2007, JPackage Project
#
# All modifications and additions to the file contributed by third parties
@@ -18,10 +18,10 @@
%global base_name jetty
%global addver .v20240826
%global addver .v20241219
%define src_name %{base_name}.project-%{base_name}-%{version}%{addver}
Name: %{base_name}-websocket
Version: 9.4.56
Version: 9.4.57
Release: 0
Summary: The websocket modules for Jetty
License: Apache-2.0 OR EPL-1.0

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:02955a9152023af2238ed5a5aa331b6b6ef2e2934f9d4871b318763254315968
size 19348893

View File

@@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:1614d3465f4c04075efc7731379ecaed2eb46168a3b0f722a88c282677a86046
size 19350745