Rework the fix for 56190 as the previous fix did not recycle
the request in all cases leading to mis-routing of requests. (markt)
Allow web applications to package tomcat-jdbc.jar and their JDBC driver
of choice in the web application. (markt)
56293: Cache resources loaded by the class loader from
/META-INF/services/ for better performance for repeated
look ups. (markt)
Coyote
Fix possibly incomplete final flush with NIO2 when using non blocking
mode. (remm)
Cleanup NIO2 endpoint shutdown. (remm)
Fix rare race condition notifying onWritePossible in the NIO2
HTTP/1.1 connector. (remm)
Jasper
54475: Add Java 8 support to SMAP generation for JSPs. Patch
by Robbie Gibson. (markt)
Web applications
56273: If the Manager web application does not perform an
operation because the web application is already being serviced, report
an error rather than reporting success. (markt)
56304: Add a note to the documentation about not using
WebSocket with BIO HTTP in production. (markt)
Tomcat 8.0.4 (markt)
Catalina
Restore the ability to use the addURL() method of the
web application class loader to add external resources to the web
application. (markt)
Improve the robustness of web application undeployment based on some
code analysis triggered by the report for 54315. (markt)
56125: Correctly construct the URL for a resource that
represents the root of a JAR file. (markt)
Generate a valid root element for the effective web.xml for a web
application for all supported versions of web.xml. (markt)
Make it easier for applications embedding and/or extending Tomcat to
modify the javaseClassLoader attribute of the
WebappClassLoader. (markt)
Add missing support for <deny-uncovered-http-methods>
element when merging web.xml files. (markt)
Improve merging process for web.xml files to take account of the
elements and attributes supported by the Servlet version of the merged
file. (markt)
Avoid NullPointerException in resource cache when making an
invalid request for a resource outside of the web application. (markt)
Remove an unnecessary null check identified by FindBugs. (markt)
In WebappClassLoader, when reporting threads that are still running
while web application is being stopped, print their stack traces to
the log. (kkolinko)
56190: The response should be closed (i.e. no further output
is permitted) when a call to AsyncContext.complete() takes
effect. (markt)
56236: Enable Tomcat to work with alternative Servlet and
JSP API JARs that package the XML schemas in such as way as to require
a dependency on the JSP API before enabling validation for web.xml.
Tomcat has no such dependency. (markt)
56244: Fix MBeans descriptor for WebappClassLoader MBean.
(kkolinko)
Add a work around for validating XML documents (often TLDs) that use
just the file name to refer to refer to the JavaEE schema on which they
are based. (markt)
Add methods of get the idle time from last client access time to
org.apache.catalina.Session. (kfujino)
56246: Fix NullPointerException in MemoryRealm when
authenticating an unknown user. (markt)
56248: Allow the deployer to update an existing WAR file
without undeploying the existing application if the update flag is set.
This allows any existing custom context.xml for the application to be
retained. To update an application and remove any existing context.xml
simply undeploy the old version of the application before deploying the
new version. (markt)
56253: When listing resources that are provided by a JAR, fix
possible StringIndexOutOfBoundsExceptions. Add some unit
tests for this and similar scenarios and fix the additional issues those
unit tests identified. Based on a patch by Larry Isaacs. (markt)
Redefine the globalXsltFile initialisation parameter of the
DefaultServlet as relative to CATALINA_BASE/conf or CATALINA_HOME/conf.
Prevent user supplied XSLTs used by the DefaultServlet from defining
external entities. (markt)
Coyote
In some circumstances asynchronous requests could time out too soon.
(markt)
56172: Avoid possible request corruption when using the AJP
NIO connector and a request is sent using more than one AJP message.
Patch provided by Amund Elstad. (markt)
Add experimental NIO2 connector. Based on code developed by
Nabil Benothman. (remm)
Improve processing of chuck size from chunked headers. Avoid overflow
and use a bit shift instead of a multiplication as it is marginally
faster. (markt/kkolinko)
Correct regression introduced in 8.0.0-RC2 as part of the Servlet 3.1
non-blocking IO support that broke handling of requests with an explicit
content length of zero. (markt/kkolinko)
Fix possible overflow when parsing long values from a byte array.
(markt)
Jasper
Change the default compiler source and compiler target versions to 1.7
since Tomcat 8 requires a minimum of Java 7. (markt)
56179: Fix parsing of EL expressions that contain unnecessary
parentheses. (markt)
56177: Handle dependency tracking for TLDs when using JspC
with a tag library JAR that is located outside of the web application.
(markt)
Remove an unnecessary null check identified by FindBugs. (markt)
56199: Restore validateXml option for JspC which determines
if web.xml will be parsed with a validating parser. (markt)
56223: Throw an IllegalStateException if a call
is made to ServletContext.setInitParameter() after the
ServletContext has been initialized. (markt)
56265: Do not escape values of dynamic tag attributes
containing EL expressions. (kkolinko)
Make the default compiler source and target versions for JSPs Java 7
since Tomcat 8 requires Java 7 as a minimum. (markt)
56283: Update to the Eclipse JDT Compiler P20140317-1600
which adds support for Java 8 syntax to JSPs. Add support for value
"1.8" for the compilerSourceVM and
compilerTargetVM options. (markt)
WebSocket
Avoid a possible deadlock when one thread is shutting down a connection
while another thread is trying to write to it. (markt)
Avoid NPE when flushing batched messages. (markt)
Web Applications
56093: Add the SSL Valve to the documentation web
application. (markt)
56217: Improve readability by using left alignment for the
table cell containing the request information on the Manager application
status page. (markt)
Fixed java.lang.NegativeArraySizeException when using
"Expire sessions" command in the manager web application on a
context where the session timeout is disabled. (kfujino)
Add support for LAST_ACCESS_AT_START system property to
Manager web application. (kfujino)
Other
56115: Expose the httpusecaches property of
Ant's get task as some users may need to change the
default. Based on a suggestion by Anthony. (markt)
56143: Improve service.bat so that it can be
launched from a non-UAC console. This includes using a single call to
tomcat8.exe to install the Windows service rather than
three calls, and using command line arguments instead of environment
variables to pass the settings. (markt/kkolinko)
Simplify Windows *.bat files: remove %OS% checks, as current java does
not run on ancient non-NT operating systems. (kkolinko)
Align options between service.bat and exe
Windows installer. For service.bat the changes are in
--Classpath, --DisplayName, --StartPath, --StopPath. For
exe installer the changes are in --JvmMs, --JvmMx options,
which are now 128 Mb and 256 Mb respectively instead of being empty.
Explicitly specify --LogPath path when uninstalling Windows service,
avoiding default value for that option. (kkolinko)
56137: Explicitly use NIO connector in SSL example in
server.xml so it doesn't break if APR is enabled. (markt)
56139: Avoid a web application class loader leak in some unit
tests when running on Windows. (markt)
Correct build script to avoid building JARs with empty packages. (markt)
Allow to limit JUnit test run to a number of selected test case
methods. (kkolinko)
Update Commons Pool 2 to 2.2. (markt)
Update Commons DBCP 2 to the 2.0 release. (markt)
56189: Remove used file cpappend.bat from the distribution.
(markt)
56204: Remove unnecessary dependency between tasks in the
build script. (markt)
Add definition of org.apache.catalina.ant.FindLeaksTask.
(kfujino)
Implement org.apache.catalina.ant.VminfoTask,
org.apache.catalina.ant.ThreaddumpTask and
org.apache.catalina.ant.SslConnectorCiphersTask. (kfujino)
Add the option to the Apache Ant tasks to ignore the constraint of the
first line of the response message that must be "OK -"
(ignoreResponseConstraint in AbstractCatalinaTask).
Default is false. (kfujino)
beta, 2014-02-11 Tomcat 8.0.3 (markt)
Other
Fix build of Apache Commons DBCP2 classes. (kkolinko)
Update Commons DBCP 2 to snapshot 170 dated 07 Feb 2014. This enables
DBCP to work with a SecurityManager such that only DBCP needs to be
granted the necessary permissions to communicate with the database.
(markt)
not released Tomcat 8.0.2 (markt)
Catalina
56082: Fix a concurrency bug in JULI's LogManager
implementation. (markt)
56085: ServletContext.getRealPath(String) should
return null for invalid input rather than throwing an
IllegalArgumentException. (markt)
Fix WebDAV support that was broken by the refactoring for the new
resources implementation. (markt)
Simplify Catalina.initDirs(). (kkolinko)
56096: When the attribute rmiBindAddress of the
JMX Remote Lifecycle Listener is specified it's value will be used when
constructing the address of a JMX API connector server. Patch is
provided by Jim Talbut. (violetagg)
When environment entry with one and the same name is defined in the web
deployment descriptor and with annotation then the one specified in the
web deployment descriptor is with priority. (violetagg)
Fix passing the value of false for xmlBlockExternal option
of Context to Jasper, as the default was changed in 8.0.1. (kkolinko)
Coyote
Enable non-blocking reads to take place on non-container threads.
(markt)
Cluster
Simplify the code of
o.a.c.ha.tcp.SimpleTcpCluster.createManager(String).
Remove unnecessary class cast. (kfujino)
Web applications
In Manager web application improve handling of file upload errors.
Display a message instead of error 500 page. Simplify. (kkolinko)
Other
56104: Correct the version number on the welcome page of the
Windows installer. (markt)
Update Commons DBCP 2 to snapshot 168 dated 05 Feb 2014. (markt)
Fix CVE-2014-0050, a denial of service with a malicious, malformed
Content-Type header and multipart request processing. Fixed by merging
latest code (r1565159) from Commons FileUpload. (markt)
beta, 2014-02-02 Tomcat 8.0.1 (markt)
Catalina
Change default value of xmlBlockExternal attribute of
Context. It is true now. (kkolinko)
Coyote
Correct regression in the fix for 55996 that meant that
asynchronous requests might timeout too early. (markt)
Jasper
Change default value of the blockExternal attribute of
JspC task. The default value is true. Add support for
-no-blockExternal switch when JspC is run as a
standalone application. (kkolinko)
WebSocket
Do not return an empty string for the
Sec-WebSocket-Protocol HTTP header when no sub-protocol has
been requested or no sub-protocol could be agreed as RFC6455 requires
that no Sec-WebSocket-Protocol header is returned in this
case. (markt)
not released Tomcat 8.0.0 (markt)
Catalina
Implement JSR 340 - Servlet 3.1. The JSR 340 implementation includes
contributions from Nick Williams and Jeremy Boynes. (markt)
Implement JSR 245 MR2 - JSP 2.3. (markt)
Implement JSR 341 - Unified Expression Language 3.0. (markt)
Implement JSR 356 - WebSockets. The JSR 356 implementation includes
contributions from Nick Williams, Rossen Stoyanchev and Niki Dokovski.
(markt)
46727: Refactor default servlet to make it easier to
sub-class to implement finer grained control of the file encoding. Based
on a patch by Fred Toth. (markt)
45995: Align Tomcat with Apache httpd and perform MIME type
mapping based on file extension in a case insensitive manner. (markt)
Remove duplicate code that converted a Host's appBase attribute to
a canonical file. (markt)
51408: Replace calls to Charset.defaultCharset()
with an explicit reference to the ISO-8859-1 Charset. (markt)
Refactor initialization code to use a single, consistent approach to
determining the Catalina home (binary) and base (instance) directories.
The search order for home is catalina.home system property,
parent of current directory if boootstrap.jar is present and finally
current working directory. The search order for Catalina base is
catalina.base system property falling back to the value for
Catalina home. (markt)
52092: JULI now uses the OneLineFormatter and
AsyncFileHandler by default. (markt)
52558: Refactor CometConnectionManagerValve so
that it does not prevent the session from being serialized in when
running in a cluster. (markt)
52767: Remove reference to MySQL specific autoReconnect
property in JDBCAccessLogValve. (markt)
Make the Mapper type-safe. Hosts, Contexts and Wrappers are no
longer handled as plain objects, instead they keep their type.
Code using the Mapper doesn't need to cast objects returned by
the mapper. (rjung)
Move Manager, Loader and Resources from Container to Context since
Context is the only place they are used. The documentation already
states (and has done for some time) that Context is the only valid
location for these nested components. (markt)
Move the Mapper from the Connector to the Service since the Mapper is
identical for all Connectors of a given Service and it is common for
there to be multiple Connectors for a Service (http, https and ajp).
This means there is now only ever one Mapper per Service rather than
possibly multiple identically configured Mapper objects. (markt)
Remove the per Context Mapper objects and use the Mapper from the
Service. This removes the need to maintain two copies of the mappings
for Servlets and Filters. (markt)
Implement a new Resources implementation that merges Aliases,
VirtualLoader, VirtualDirContext, JAR resources and external
repositories into a single framework rather than a separate one for each
feature. (markt)
URL rewrite valve, similar in functionality to mod_rewrite. (remm)
Port storeconfig functionality, which can persist to server.xml and
context.xml runtime container configuration changes. (remm)
54095: Add support to the Default Servlet for serving
gzipped versions of static resources directly from disk as an
alternative to Tomcat compressing them on each request. Patch by
Philippe Marschall. (markt)
54708: Change the name of the working directory for the ROOT
application (located under $CATALINA_BASE/work by default) from _ to
ROOT. (markt)
Change default configuration so that a change to the global web.xml file
will trigger a reload of all web applications. (markt)
55101: Make BASIC authentication more tolerant of whitespace.
Patch provided by Brian Burch. (markt)
55166: Move JSP descriptor and tag library descriptor schemas
to servlet-api.jar to enable relative references between the schemas to
be correctly resolved. (markt)
Refactor the descriptor parsing code into a separate module that can be
used by both Catalina and Jasper. Includes patches provided by Jeremy
Boynes. (violetagg/markt)
55246: Move TLD scanning to a ServletContainerInitializer
provided by Jasper. Includes removal of TldConfig lifecycle listener and
associated Context properties. (jboynes)
55317: Facilitate weaving by allowing ClassFileTransformer to
be added to WebppClassLoader. Patch by Nick Williams. (markt)
55620: Enable Tomcat to start when either $CATALINA_HOME
and/or $CATALINA_BASE contains a comma character. Prevent Tomcat from
starting when $CATALINA_HOME and/or $CATALINA_BASE contains a semi-colon
on Windows. Prevent Tomcat from starting when $CATALINA_HOME and/or
$CATALINA_BASE contains a colon on Linux/FreeBSD/etc. (markt)
Initialize the JSP runtime in Jasper's initializer to avoid need for a
Jasper-specific lifecycle listener. JasperListener has been
removed. (jboynes)
Change ordering of elements of JMX objects names so components are
grouped more logically in JConsole. Generally, components are now
grouped by Host and then by Context. (markt)
Context listener to allow better EE and framework integration. (remm)
Coyote
Experimental support for SPDY. Includes contributions from Sheldon Shao.
(costin)
The default connector is now the Java NIO connector even when specifying
HTTP/1.1 as protocol (fhanik)
Update default value of pollerThreadCount for the NIO connector. The new
default value will never go above 2 regardless of available processors.
(fhanik)
54010: Remove some unnecessary code (duplicate calls to
configure the scheme as https for AJP requests originally received over
HTTPS). (markt)
Refactor char encoding/decoding using NIO APIs. (remm)
Change the default URIEncoding for all connectors from ISO-8859-1 to
UTF-8. (markt)
Jasper
Simplify API of ErrorDispatcher class by using varargs.
(kkolinko)
Update Jasper to use the new common web.xml parsing code. Includes
patches by Jeremy Boynes. (markt/violetagg)
Create test cases for JspC. Patch by Jeremy Boynes. (markt)
55246: TLD scanning is now performed by JasperInitializer
(a ServletContainerInitializer) removing the need for support within the
Servlet container itself. The scan is now performed only once rather than
in two passes reducing startup time. (jboynes)
55251: Do not allow JspC task to fail silently if the web.xml
or web.xml fragment can not be generated. (markt)
Cluster
Remove unused JvmRouteSessionIDBinderListener and SessionIDMessage.
(kfujino)
Modify method signature in ReplicationValve. Cluster instance is not
necessary to argument of method. (kfujino)
Remove unused expireSessionsOnShutdown attribute in
org.apache.catalina.ha.session.BackupManager. (kfujino)
Web applications
Extend the diagnostic information provided by the Manager web
application to include details of the configured SSL ciphers suites for
each connector. (markt)
48550: Update examples web application to use UTF-8. (markt)
55383: Improve the design and correct the HTML markup of
the documentation web application. Patches provided by Konstantin
Preißer. (markt)
Tribes
Refactor AbstractReplicatedMap to use generics. A key
side-effect of this is that the class now implements
Map<K,V> rather than extends
ConcurrentMap. (markt)
Other
Remove unused, deprecated code. (markt)
Remove static info String and associated getInfo() method where present.
(markt)
(r1353242, r1353410):
Remove Ant tasks jasper2 and jkstatus.
The correct names are jasper and jkupdate.
(kkolinko)
53529: Clean-up the handling of
InterruptedException throughout the code base. (markt)
54899: Provide an initial implementation of NetBeans support.
Patch provided by Brian Burch. (markt)
55166: Move the JSP descriptor and tag library descriptor
schema defintion files from jsp-api.jar to servlet-api.jar so relative
includes between the J2EE, Servlet and JSP schemas are correctly
resolved. (markt)
55372: When starting Tomcat with the jpda option
to enable remote debugging, by default only listen on localhost for
connections from a debugger. Prior to this change, Tomcat listened on
all known addresses. (markt)