6
by tony mancill
* Team upload. |
1 |
tomcat7 (7.0.19-1) unstable; urgency=high (security) |
2 |
||
3 |
* Team upload. |
|
4 |
* New upstream release. |
|
5 |
- Includes fix for CVE-2011-2526 (Closes: #634992) |
|
6 |
* Remove patch for CVE-2011-2204 (included upstream). |
|
7 |
||
8 |
-- tony mancill <tmancill@debian.org> Mon, 25 Jul 2011 22:58:33 -0700 |
|
9 |
||
5
by tony mancill
* Team upload. |
10 |
tomcat7 (7.0.16-3) unstable; urgency=low |
11 |
||
12 |
* Team upload. |
|
13 |
* Correct Suggests: for libtcnative-1 (tomcat-native) |
|
14 |
* Add patch for CVE-2011-2204 (Closes: #632882) |
|
15 |
||
16 |
-- tony mancill <tmancill@debian.org> Wed, 06 Jul 2011 21:55:39 -0700 |
|
17 |
||
4
by tony mancill
Restore tomcat-juli.jar link in /usr/share/tomcat7/bin. |
18 |
tomcat7 (7.0.16-2) unstable; urgency=low |
19 |
||
20 |
* Restore tomcat-juli.jar link in /usr/share/tomcat7/bin. |
|
21 |
Thank you to Kristof Csillag for the bug report. (Closes: #631667) |
|
22 |
||
23 |
-- tony mancill <tmancill@debian.org> Sun, 26 Jun 2011 08:13:33 -0700 |
|
24 |
||
3
by tony mancill, Miguel Landaeta, tony mancill
[ Miguel Landaeta ] |
25 |
tomcat7 (7.0.16-1) unstable; urgency=low |
26 |
||
27 |
[ Miguel Landaeta ] |
|
28 |
* New upstream release. |
|
29 |
* Add missing deps and symlinks for commons-pool ands commons-dbcp jars. |
|
30 |
||
31 |
[ tony mancill ] |
|
32 |
* Add logrotate file for catalina.out. |
|
33 |
* Add build-arch target to debian/rules. |
|
34 |
||
35 |
-- tony mancill <tmancill@debian.org> Thu, 23 Jun 2011 20:26:29 -0700 |
|
36 |
||
2
by tony mancill
* Team upload. |
37 |
tomcat7 (7.0.14-1) unstable; urgency=low |
38 |
||
39 |
* Team upload. |
|
40 |
* New upstream release. |
|
41 |
Thank you to Ernesto Hernández-Novich for providing the basis of |
|
42 |
this packaging. |
|
43 |
||
44 |
-- tony mancill <tmancill@debian.org> Tue, 17 May 2011 21:10:22 -0700 |
|
45 |
||
46 |
tomcat6 (6.0.32-4) UNRELEASED; urgency=low |
|
47 |
||
48 |
* Team upload. |
|
49 |
* Add Italian debconf translation. |
|
50 |
Thanks to Dario Santamaria (Closes: #624376) |
|
51 |
||
52 |
-- tony mancill <tmancill@debian.org> Thu, 28 Apr 2011 20:17:30 -0700 |
|
53 |
||
54 |
tomcat6 (6.0.32-3) unstable; urgency=low |
|
55 |
||
56 |
* Team upload. |
|
57 |
* Include upstream patch for ASF Bugzilla - Bug 50700 |
|
58 |
(Context parameters are being overridden with parameters from the |
|
59 |
web application deployment descriptor) (Closes: #623242) |
|
60 |
||
61 |
-- tony mancill <tmancill@debian.org> Mon, 18 Apr 2011 20:38:29 -0700 |
|
62 |
||
63 |
tomcat6 (6.0.32-2) unstable; urgency=low |
|
64 |
||
65 |
* Team upload. |
|
66 |
||
67 |
[ tony mancill ] |
|
68 |
* Patch debian/tomcat6-instance-create (LP: #707405) |
|
69 |
tomcat6-instance-create should accept -1 as the value of -c option |
|
70 |
as per http://tomcat.apache.org/tomcat-6.0-doc/config/server.html |
|
71 |
Thanks to Dave Walker. (Closes: #617553) |
|
72 |
* Move tomcat6-instance-create manpage from section 2 to section 8. |
|
73 |
Thanks to brian m. carlson (Closes: #607682) |
|
74 |
* Add tomcat6-extras package. |
|
75 |
Currently includes only catalina-jmx-remote.jar (Closes: #614333) |
|
76 |
||
77 |
[ Thierry Carrez ] |
|
78 |
* debian/tomcat6-instance-create: Eclipse can now be configured to use a |
|
79 |
user instance of tomcat6 using tomcat6-instance-create without any |
|
80 |
additional work. Patch from Abhinav Upadhyay (Closes: #551091, LP: #297675) |
|
81 |
||
82 |
-- tony mancill <tmancill@debian.org> Sun, 03 Apr 2011 21:16:08 -0700 |
|
83 |
||
84 |
tomcat6 (6.0.32-1) unstable; urgency=low |
|
85 |
||
86 |
* Team upload. |
|
87 |
* New upstream release |
|
88 |
* Remove following patches applied upstream: |
|
89 |
CVE-2010-4172, CVE-2011-0534, CVE-2010-3718, CVE-2011-0013, |
|
90 |
0009-allow-empty-PID-file.patch |
|
91 |
* Adjust 0004-split-deploy-webapps-target-from-deploy-target.patch |
|
92 |
||
93 |
-- tony mancill <tmancill@debian.org> Tue, 15 Feb 2011 22:41:42 -0800 |
|
94 |
||
95 |
tomcat6 (6.0.28-10) unstable; urgency=medium |
|
96 |
||
97 |
* Team upload. |
|
98 |
* Add Portuguese/Brazilian debconf translation. |
|
99 |
Thanks to José de Figueiredo (Closes: #608527) |
|
100 |
* Add patches for CVE-2011-0534, CVE-2010-3718, CVE-2011-0013 |
|
101 |
(Closes: #612257) |
|
102 |
||
103 |
-- tony mancill <tmancill@debian.org> Wed, 09 Feb 2011 21:49:33 -0800 |
|
104 |
||
105 |
tomcat6 (6.0.28-9) unstable; urgency=medium |
|
106 |
||
107 |
* Team upload. |
|
108 |
* Update URL for manager application in README.Debian |
|
109 |
Thanks to Ernesto Ongaro (Closes: #606170) |
|
110 |
* Add patch for CVE-2010-4172. (Closes: #606388) |
|
111 |
||
112 |
-- tony mancill <tmancill@debian.org> Thu, 09 Dec 2010 22:52:08 -0800 |
|
113 |
||
114 |
tomcat6 (6.0.28-8) unstable; urgency=low |
|
115 |
||
116 |
* Team upload. |
|
117 |
||
118 |
[ Thierry Carrez (ttx) ] |
|
119 |
* Do not fail to purge if /etc/tomcat6 was manually removed (LP: #648619) |
|
120 |
* Add missing -p option in start-stop-daemon when starting tomcat6 to avoid |
|
121 |
failing to start due to /bin/bash running (LP: #632554) |
|
122 |
* Fix build failure (missing TraXLiaison class) by adding ant-nodeps |
|
123 |
to the classpath. |
|
124 |
||
125 |
[ tony mancill ] |
|
126 |
* Use debconf to determine tomcat6 user and group to delete upon purge. |
|
127 |
Thanks to Misha Koshelev. (Closes: #599458) |
|
128 |
* Add tomcat-native to Suggests: for tomcat6 binary package. |
|
129 |
Thanks to Eddy Petrisor (Closes: #600590) |
|
130 |
* Add Danish debconf template translation. |
|
131 |
Thanks to Joe Dalton (Closes: #605070) |
|
132 |
* Actually add the Czech debconf template translation. |
|
133 |
Thanks this time to Christian PERRIER (Closes: #597863) |
|
134 |
||
135 |
-- tony mancill <tmancill@debian.org> Sat, 04 Dec 2010 17:20:11 -0800 |
|
136 |
||
137 |
tomcat6 (6.0.28-7) unstable; urgency=low |
|
138 |
||
139 |
* Team upload. |
|
140 |
* Add Czech debconf template translation. |
|
141 |
Thanks to Michal Simunek. (Closes: #597863) |
|
142 |
* Add Spanish debconf template translation. |
|
143 |
Thanks to Javier Fernández-Sanguino (Closes: #599230) |
|
144 |
* Modify postinst to handle JAVA_OPTS strings containing the '/' |
|
145 |
character. This was causing upgrade failures for users. |
|
146 |
(Closes: #597814) |
|
147 |
||
148 |
-- tony mancill <tmancill@debian.org> Wed, 06 Oct 2010 14:40:19 -0700 |
|
149 |
||
150 |
tomcat6 (6.0.28-6) unstable; urgency=low |
|
151 |
||
152 |
* Team upload. |
|
153 |
* Add Japanese debconf template translation. |
|
154 |
Thanks to Hideki Yamane. (Closes: #595460) |
|
155 |
* Add Russian debconf template translation. |
|
156 |
Thanks to Yuri Kozlov. (Closes: #592627) |
|
157 |
* Add Portuguese debconf template translation. |
|
158 |
Thanks to Américo Monteiro. (Closes: #592655) |
|
159 |
* Add Swedish debconf template translation. |
|
160 |
Thanks to Martin Bagge. (Closes: #593676) |
|
161 |
* Add German debconf template translation. |
|
162 |
Thanks to Holger Wansing. (Closes: #593200) |
|
163 |
||
164 |
-- tony mancill <tmancill@debian.org> Fri, 17 Sep 2010 21:30:27 -0700 |
|
165 |
||
166 |
tomcat6 (6.0.28-5) unstable; urgency=low |
|
167 |
||
168 |
* Team upload. |
|
169 |
||
170 |
[Thierry Carrez (ttx)] |
|
171 |
* Check for group existence to avoid postinst failure (LP: #611721) |
|
172 |
||
173 |
[tony mancill] |
|
174 |
* Add French debconf template translation. |
|
175 |
Thanks to Steve Petruzzello. (Closes: #594313) |
|
176 |
||
177 |
-- tony mancill <tmancill@debian.org> Thu, 02 Sep 2010 21:49:08 -0700 |
|
178 |
||
179 |
tomcat6 (6.0.28-4) unstable; urgency=medium |
|
180 |
||
181 |
* Ignore most errors during purge. (Closes: #591867) |
|
182 |
* Add po-debconf support. |
|
183 |
||
184 |
-- Torsten Werner <twerner@debian.org> Fri, 06 Aug 2010 04:08:40 +0200 |
|
185 |
||
186 |
tomcat6 (6.0.28-3) unstable; urgency=low |
|
187 |
||
188 |
* UNRELEASED |
|
189 |
* Fix filename of /etc/tomcat6/tomcat-users in README.Debian. Thanks to |
|
190 |
Olivier Berger. (Closes: #590085) |
|
191 |
||
192 |
-- Torsten Werner <twerner@debian.org> Fri, 23 Jul 2010 23:36:49 +0200 |
|
193 |
||
194 |
tomcat6 (6.0.28-2) unstable; urgency=low |
|
195 |
||
196 |
* Add debconf questions for user, group and Java options. |
|
197 |
* Use ucf to install /etc/default/tomcat6 from a template |
|
198 |
* Drop CATALINA_BASE and CATALINA_HOME from /etc/default/tomcat6 since we |
|
199 |
shouldn't encourage users to change those anyway |
|
200 |
||
201 |
-- Thierry Carrez <thierry.carrez@ubuntu.com> Tue, 20 Jul 2010 14:36:48 +0200 |
|
202 |
||
203 |
tomcat6 (6.0.28-1) unstable; urgency=low |
|
204 |
||
205 |
[ Niels Thykier ] |
|
206 |
* Removed depends on JREs for the library packages. It is no longer |
|
207 |
required by the policy. |
|
208 |
||
209 |
[ Torsten Werner ] |
|
210 |
* New upstream release (Closes: #588813) |
|
211 |
- Fixes CVE-2010-2227: DoS and information disclosure |
|
212 |
* Remove 2 patches that were backports to 6.0.26. |
|
213 |
||
214 |
-- Torsten Werner <twerner@debian.org> Mon, 19 Jul 2010 18:22:52 +0200 |
|
215 |
||
216 |
tomcat6 (6.0.26-5) unstable; urgency=medium |
|
217 |
||
218 |
* Convert patches to dep3 format. |
|
219 |
* Backport security fix from trunk to fix CVE-2010-1157. (Closes: #587447) |
|
220 |
* Set urgency to medium due to the security fix. |
|
221 |
||
222 |
-- Torsten Werner <twerner@debian.org> Mon, 28 Jun 2010 21:41:31 +0200 |
|
223 |
||
224 |
tomcat6 (6.0.26-4) unstable; urgency=low |
|
225 |
||
226 |
[ Thierry Carrez ] |
|
227 |
* Fix issues preventing from running Tomcat6 with a security manager: |
|
228 |
- debian/tomcat6.init: Remove duplicate securitymanager options. |
|
229 |
- debian/patches/catalina-sh-security-manager.patch: Use the right |
|
230 |
location for the security.policy file in catalina.sh. |
|
231 |
- Closes: #585379, LP: #591802. Thanks to Jeff Turner for the original |
|
232 |
patches and to Adam Guthrie for the Lucid debdiff. |
|
233 |
* Allow binding to any interface when using authbind, rather than only allow |
|
234 |
binding to all (LP: #594989) |
|
235 |
* Force backgrounding of catalina.sh in start-stop-daemon, to allow the init |
|
236 |
script to be started through ssh -t (LP: #588481) |
|
237 |
||
238 |
[ Torsten Werner ] |
|
239 |
* Remove Paul from Uploaders list. |
|
240 |
||
241 |
-- Thierry Carrez <thierry.carrez@ubuntu.com> Thu, 24 Jun 2010 15:55:10 +0200 |
|
242 |
||
243 |
tomcat6 (6.0.26-3) unstable; urgency=low |
|
244 |
||
245 |
[ Marcus Better ] |
|
246 |
* Apply upstream fix for deadlock in WebappClassLoader. (Closes: #583896) |
|
247 |
||
248 |
[ Thierry Carrez ] |
|
249 |
* debian/tomcat6.{install,postinst}: Do not store the default root webapp |
|
250 |
in /usr/share/tomcat6/webapps as it increases confusion on what this |
|
251 |
directory contains (and its relation with /var/lib/tomcat6/webapps). |
|
252 |
Store it inside /usr/share/tomcat6-root instead (LP: #575303). |
|
253 |
||
254 |
-- Marcus Better <marcus@better.se> Mon, 31 May 2010 15:50:57 +0200 |
|
255 |
||
256 |
tomcat6 (6.0.26-2) unstable; urgency=low |
|
257 |
||
258 |
* debian/tomcat6.{postinst,prerm}: Respect TOMCAT6_USER and TOMCAT6_GROUP |
|
259 |
as defined in /etc/default/tomcat6 when setting directory permissions and |
|
260 |
authbind configuration (Closes: #581018, LP: #557300) |
|
261 |
* debian/tomcat6.postinst: Use group "tomcat6" instead of "adm" for |
|
262 |
permissions in /var/lib/tomcat6, so that group "adm" doesn't get write |
|
263 |
permissions over /var/lib/tomcat6/webapps (LP: #569118) |
|
264 |
||
265 |
-- Thierry Carrez <thierry.carrez@ubuntu.com> Fri, 21 May 2010 13:51:15 +0200 |
|
266 |
||
267 |
tomcat6 (6.0.26-1) unstable; urgency=low |
|
268 |
||
269 |
* New upstream version |
|
270 |
* Apply patch from Mark Scott to fix |
|
271 |
tomcat6-instance-create which failed when multiple commandline |
|
272 |
options are provided, fix creation of FULLPATH (Closes: #575580) |
|
273 |
||
274 |
-- Ludovic Claude <ludovic.claude@laposte.net> Wed, 21 Apr 2010 23:07:09 +0100 |
|
275 |
||
276 |
tomcat6 (6.0.24-5) unstable; urgency=low |
|
277 |
||
278 |
* Added optimised garbage collection options to tomcat6's default options. |
|
279 |
Thanks to Aaron J. Zirbes and Thierry Carrez for research and the patch. |
|
280 |
(Closes: LP: #541520) |
|
281 |
* Updated the changelog to mention closed CVE's in the 6.0.24-1 release. |
|
282 |
* Applied patch from Arto Jantunen fixing an issue with cleaning up the |
|
283 |
pid-file. (Closes: #574084) |
|
284 |
||
285 |
-- Niels Thykier <niels@thykier.net> Thu, 25 Mar 2010 23:45:32 +0100 |
|
286 |
||
287 |
tomcat6 (6.0.24-4) unstable; urgency=low |
|
288 |
||
289 |
* debian/tomcat6.postrm: fix removal of Tomcat (Closes: #567548) |
|
290 |
* Set UTF-8 as default character encoding - Patch by Thomas Koch |
|
291 |
(Closes: #573539) |
|
292 |
||
293 |
-- Ludovic Claude <ludovic.claude@laposte.net> Thu, 11 Mar 2010 23:45:34 +0100 |
|
294 |
||
295 |
tomcat6 (6.0.24-3) unstable; urgency=medium |
|
296 |
||
297 |
* Set the major, minor and build versions when calling Ant |
|
298 |
(Closes: LP: #495505) |
|
299 |
* Rebuild with a more recent version of maven-repo-helper which puts |
|
300 |
the javax jars at the correct location in the Maven repository. |
|
301 |
Fixes several FTBFS in other packages. |
|
302 |
||
303 |
-- Ludovic Claude <ludovic.claude@laposte.net> Wed, 03 Mar 2010 00:10:15 +0100 |
|
304 |
||
305 |
tomcat6 (6.0.24-2) unstable; urgency=low |
|
306 |
||
307 |
* Fix missing symlinks to tomcat-coyote.jar and |
|
308 |
catalina-tribes.jar causing NoClassDefFoundException |
|
309 |
at startup (last minute packaging change, sorry) |
|
310 |
(Closes: #570220) |
|
311 |
* tomcat6-admin, tomcat6-examples and tomcat6-docs now depend on |
|
312 |
tomcat6-common instead of tomcat6, this allow users to install |
|
313 |
those packages without requiring tomcat6 and its automatic startup scripts |
|
314 |
being present. tomcat-users can be installed instead and allow full |
|
315 |
control over when Tomcat is started or stopped. |
|
316 |
||
317 |
-- Ludovic Claude <ludovic.claude@laposte.net> Wed, 17 Feb 2010 22:59:21 +0100 |
|
318 |
||
319 |
tomcat6 (6.0.24-1) unstable; urgency=low |
|
320 |
||
321 |
[ Ludovic Claude ] |
|
322 |
* New upstream version |
|
323 |
- Fixes Directory traversal vulnerability (CVE-2009-2693,CVE-2009-2902) |
|
324 |
- Fixes Autodeployment vulnerability (CVE-2009-2901) |
|
325 |
* Update the POM files for the new version of Tomcat |
|
326 |
* Bump up Standards-Version to 3.8.4 |
|
327 |
* Refresh patches deploy-webapps-build-xml.patch and var_loaders.patch |
|
328 |
* Remove patch fix_context_name.patch as it has been applied upstream |
|
329 |
* Fix the installation of servlet-api-2.5.jar: the jar |
|
330 |
goes to /usr/share/java as in older versions (6.0.20-2) |
|
331 |
and links to the jar are added to /usr/share/maven-repo |
|
332 |
* Moved NEWS.Debian into README.Debian |
|
333 |
* Add a link from /usr/share/doc/tomcat6-common/README.Debian to |
|
334 |
/usr/share/doc/tomcat6/README.Debian to include a minimum of |
|
335 |
documentation in the tomcat6 package and add some useful notes. |
|
336 |
(Closes: #563937, #563939) |
|
337 |
* Remove poms from the Debian packaging, use upstream pom files |
|
338 |
||
339 |
[ Jason Brittain ] |
|
340 |
* Fixed a bug in the init script: When a start fails, the PID file was |
|
341 |
being left in place. Now the init script makes sure it is deleted. |
|
342 |
* Fixed a packaging bug that results in the ROOT webapp not being properly |
|
343 |
installed after an uninstall, then a reinstall. |
|
344 |
* control: Corrected a couple of comments (no functional change). |
|
345 |
||
346 |
-- Ludovic Claude <ludovic.claude@laposte.net> Tue, 09 Feb 2010 23:06:51 +0100 |
|
347 |
||
348 |
tomcat6 (6.0.20-dfsg1-2) unstable; urgency=low |
|
349 |
||
350 |
* JSVC is no longer used by the package. Instead, the init script invokes |
|
351 |
the stock catalina.sh script. |
|
352 |
* Authbind is now the standard method for binding Tomcat to ports lower |
|
353 |
than 1024 (when using IPv4). |
|
354 |
* The security manager now defaults to the disabled state, and is commented |
|
355 |
that way in /etc/default/tomcat6. |
|
356 |
* Reliable restarts are now implemented in the init script. |
|
357 |
(Closes: #561559) |
|
358 |
* Tomcat now sends STDOUT and STDERR to its usual, stock log file |
|
359 |
CATALINA_BASE/logs/catalina.out (/var/log/tomcat6/catalina.out in this |
|
360 |
package's case. |
|
361 |
||
362 |
-- Jason Brittain <jason.brittain@mulesoft.com> Wed, 27 Jan 2010 01:08:57 +0000 |
|
363 |
||
364 |
tomcat6 (6.0.20-dfsg1-1) unstable; urgency=low |
|
365 |
||
366 |
* Fix debian/orig-tar.sh to exclude binary only standard.jar and jstl.jar. |
|
367 |
(Closes: #528119) |
|
368 |
* Upload a cleaned tarball. |
|
369 |
* Add ${misc:Depends} in debian/control. |
|
370 |
||
371 |
-- Torsten Werner <twerner@debian.org> Sat, 23 Jan 2010 19:40:38 +0100 |
|
372 |
||
373 |
tomcat6 (6.0.20-9) unstable; urgency=low |
|
374 |
||
375 |
* Fix spelling issues. |
|
376 |
* Always set JSVC_CLASSPATH to a default value in init. |
|
377 |
||
378 |
-- Niels Thykier <niels@thykier.net> Sat, 19 Dec 2009 19:11:33 +0100 |
|
379 |
||
380 |
tomcat6 (6.0.20-8) unstable; urgency=low |
|
381 |
||
382 |
* Corrected some spelling mistakes in debian/control. |
|
383 |
(Closes: #557377, #557378) |
|
384 |
* Added patches to install the OSGi metadata in some of the jars. |
|
385 |
(Closes: #558176) |
|
386 |
* Updated 03catalina.policy to allow "setContextClassLoader". |
|
387 |
- Fixes a problem where Sun's JVM would fail to generate log-files. |
|
388 |
(Closes: LP: #410379) |
|
389 |
* Updated /etc/default/tomcat6: |
|
390 |
- Clarified that JAVA_OPTS are passed to jscv and not the JVM. |
|
391 |
- Updated the JSP_COMPILER to javac (jikes is not in Debian anymore). |
|
392 |
(Closes: LP: #440685) |
|
393 |
* Use default-jdk and default-jre-headless instead of openjdk in |
|
394 |
(Build-)Depends. |
|
395 |
* Added more alternatives for java implementations to the Depends of |
|
396 |
libservlet2.5-java. |
|
397 |
* Exposed JSVC_CLASSPATH to the configuration file. |
|
398 |
(Closes: LP: #475457) |
|
399 |
* Updated description so it no longer refers to non-existent package. |
|
400 |
(Closes: #559475) |
|
401 |
* Used "set -e" in postinst and postrm instead of passing "-e" to sh |
|
402 |
in the #!-line. |
|
403 |
* Changed to 3.0 (quilt) source format. |
|
404 |
||
405 |
-- Niels Thykier <niels@thykier.net> Mon, 07 Dec 2009 21:17:55 +0100 |
|
406 |
||
407 |
tomcat6 (6.0.20-7) unstable; urgency=low |
|
408 |
||
409 |
* New patch fix_context_name.patch: |
|
410 |
- Allow Service name != Engine name. Regression in fix for 42707. |
|
411 |
Fix https://issues.apache.org/bugzilla/show_bug.cgi?id=47316 |
|
412 |
- This has been fixed in trunk and will be in 6.0.21 |
|
413 |
* Register libservlet2.5-java-doc API with doc-base |
|
414 |
* Fix short description of tomcat6-docs by using "documentation" suffix |
|
415 |
||
416 |
-- Damien Raude-Morvan <drazzib@debian.org> Sat, 10 Oct 2009 21:41:55 +0200 |
|
417 |
||
418 |
tomcat6 (6.0.20-6) unstable; urgency=low |
|
419 |
||
420 |
[ Ludovic Claude ] |
|
421 |
* tomcat6.postinst: set the ownership of files in /etc/tomcat6/ |
|
422 |
to root:tomcat6, to prevent an attacker running inside a tomcat6 |
|
423 |
instance to change the tomcat configuration |
|
424 |
* debian/policy/02debian.policy: grant access to |
|
425 |
/usr/share/maven-repo/ as it is a valid source of Debian JARs. |
|
426 |
(Closes: #545674) |
|
427 |
* Bump up Standards-Version to 3.8.3 |
|
428 |
- add debian/README.source that describes the quilt patch system. |
|
429 |
* debian/control: Add Conflicts on libtomcat6-java with old versions |
|
430 |
of tomcat6-common (Closes: #542397) |
|
431 |
||
432 |
[ Michael Koch ] |
|
433 |
* Replace dh_clean -k by dh_prep. |
|
434 |
* Added Ludovic and myself to Uploaders. |
|
435 |
* Build-Depends on debhelper >= 7. |
|
436 |
||
437 |
-- Michael Koch <konqueror@gmx.de> Fri, 25 Sep 2009 07:14:07 +0200 |
|
438 |
||
439 |
tomcat6 (6.0.20-5) unstable; urgency=low |
|
440 |
||
441 |
* Fix jsp-api dependency in the Maven descriptors. |
|
442 |
* Put tomcat-juli.jar in /usr/share/java instead of juli.jar. |
|
443 |
This fixes a broken link which prevented tomcat to start |
|
444 |
when logging is turned on, and restores the file layout |
|
445 |
defined in 6.0.20-2. |
|
446 |
* Restore links to the jars in usr/share/tomcat6/lib |
|
447 |
* Change watch to download fresh sources from SVN. |
|
448 |
Should fix wrong encoding in tomcat-i18n-fr/es.jar in the next upstream |
|
449 |
version. (Closes: #522067) |
|
450 |
* Update ownership for files in /etc/tomcat6 and /var/lib/tomcat6/webapps. |
|
451 |
The new owner is tomcat6:adm (Closes: #532284) |
|
452 |
* Add additional directories for the common, server and shared classloader. |
|
453 |
Directories are also compatible with Alfresco's packaging done for |
|
454 |
Ubuntu. (Closes: #521318) |
|
455 |
* Update checksum in postrm script to reflect changes |
|
456 |
in the new upstream webapp |
|
457 |
* postrm removes the extra directories created in /var/lib/tomcat6 |
|
458 |
to hold shared and common classes or jars. |
|
459 |
* Added commented out default options for enabling debug mode. |
|
460 |
(Closes: LP: #375493) |
|
461 |
||
462 |
-- Ludovic Claude <ludovic.claude@laposte.net> Wed, 05 Aug 2009 00:56:59 +0100 |
|
463 |
||
464 |
tomcat6 (6.0.20-4) experimental; urgency=low |
|
465 |
||
466 |
* Fix init script: |
|
467 |
- Change Provides: tomcat6. (Closes: #532286) |
|
468 |
- Check for /etc/default/rcS before sourcing it. |
|
469 |
* Update Standards-Version: 3.8.2 (no changes). |
|
470 |
||
471 |
-- Torsten Werner <twerner@debian.org> Thu, 16 Jul 2009 23:36:32 +0200 |
|
472 |
||
473 |
tomcat6 (6.0.20-3) experimental; urgency=low |
|
474 |
||
475 |
* Add the Maven POM to the package |
|
476 |
* Add a Build-Depends-Indep dependency on maven-repo-helper |
|
477 |
* Use mh_installpom and mh_installjar to install the POM and the jar to the |
|
478 |
Maven repository |
|
479 |
||
480 |
-- Ludovic Claude <ludovic.claude@laposte.net> Tue, 14 Jul 2009 14:17:27 +0100 |
|
481 |
||
482 |
tomcat6 (6.0.20-2) unstable; urgency=low |
|
483 |
||
484 |
* Expose tomcat-juli.jar as a library in /usr/share/java |
|
485 |
as it is a dependency of jasper which is used also by jetty |
|
486 |
||
487 |
-- Ludovic Claude <ludovic.claude@laposte.net> Mon, 15 Jun 2009 13:33:13 +0100 |
|
488 |
||
489 |
tomcat6 (6.0.20-1) unstable; urgency=low |
|
490 |
||
491 |
* new upstream release (Closes: #531873) |
|
492 |
* Remove patch tcnative-ipv6-fix-43327.patch that has been applied upstream. |
|
493 |
* Refresh other patches. |
|
494 |
||
495 |
-- Torsten Werner <twerner@debian.org> Fri, 05 Jun 2009 23:38:44 +0200 |
|
496 |
||
497 |
tomcat6 (6.0.18-dfsg1-1) unstable; urgency=low |
|
498 |
||
499 |
[ Torsten Werner ] |
|
500 |
* Remove jstl.jar and standard.jar from orig tarball because it comes without |
|
501 |
source code. (Closes: #528119) |
|
502 |
||
503 |
[ Marcus Better ] |
|
504 |
* Let the init script exit silently if the package is |
|
505 |
uninstalled. (Closes: #529301) |
|
506 |
||
507 |
-- Torsten Werner <twerner@debian.org> Tue, 19 May 2009 21:23:18 +0200 |
|
508 |
||
509 |
tomcat6 (6.0.18-4) unstable; urgency=low |
|
510 |
||
511 |
* Add patch tcnative-ipv6-fix-43327.patch provided by Thierry Carrez. |
|
512 |
(Closes: #527033) |
|
513 |
* Change Section: java (from web). |
|
514 |
* Bump up Standards-Version: 3.8.1 (no changes). |
|
515 |
* Remove redundant Depends: ant because we depend on ant-optional. |
|
516 |
||
517 |
-- Torsten Werner <twerner@debian.org> Sun, 10 May 2009 19:41:40 +0200 |
|
518 |
||
519 |
tomcat6 (6.0.18-3) unstable; urgency=low |
|
520 |
||
521 |
* Remove unneeded dirs and symlinks; thanks to Thierry Carrez. (Closes: |
|
522 |
#517857)
|
|
523 |
* Improve the long description of all binary packages. (Closes: #518140) |
|
524 |
||
525 |
-- Torsten Werner <twerner@debian.org> Wed, 04 Mar 2009 21:58:41 +0100 |
|
526 |
||
527 |
tomcat6 (6.0.18-2) unstable; urgency=low |
|
528 |
||
529 |
* upload to unstable |
|
530 |
||
531 |
-- Torsten Werner <twerner@debian.org> Sat, 21 Feb 2009 11:31:20 +0100 |
|
532 |
||
533 |
tomcat6 (6.0.18-1) experimental; urgency=low |
|
534 |
||
535 |
* Merge changes from Ubuntu. Thanks to the Ubuntu developers we are shipping |
|
536 |
a full Tomcat 6.0 server stack now. (Closes: #494674) |
|
537 |
* Add myself to Uploaders. |
|
538 |
* Switch to openjdk-6 which is not the default in Debian. |
|
539 |
||
540 |
-- Torsten Werner <twerner@debian.org> Sat, 07 Feb 2009 17:02:57 +0100 |
|
541 |
||
542 |
tomcat6 (6.0.18-0ubuntu5) jaunty; urgency=low |
|
543 |
||
544 |
[ Thierry Carrez ] |
|
545 |
* Removed tomcat6-[admin,docs,examples].post[inst,rm] and let Tomcat webapp |
|
546 |
autodeployment features handle application load/unload (LP: #302914) |
|
547 |
* tomcat6-instance-create, tomcat6-instance-create.1, control: |
|
548 |
Allow to change the HTTP port, control port and shutdown word on the |
|
549 |
tomcat6-instance-create command line (LP: #300691). |
|
550 |
||
551 |
[ Mathias Gug] |
|
552 |
* debian/tomcat6-instance-create: move directoryname from an option to |
|
553 |
an argument. |
|
554 |
* debian/tomcat6-instance-create.1: some updates to the man page. |
|
555 |
* debian/control: update maintainer field to Ubuntu Core Developers now that |
|
556 |
tomcat6 is in main. |
|
557 |
||
558 |
-- Mathias Gug <mathiaz@ubuntu.com> Wed, 07 Jan 2009 18:44:39 -0500 |
|
559 |
||
560 |
tomcat6 (6.0.18-0ubuntu4) jaunty; urgency=low |
|
561 |
||
562 |
* tomcat6.init, tomcat6.postinst, tomcat6.dirs, tomcat6.default, |
|
563 |
README.debian: Use /tmp/tomcat6-temp instead of /var/lib/tomcat6/temp as |
|
564 |
the JVM temporary directory and clean it at each restart (LP: #287452) |
|
565 |
* policy/04webapps.policy: add rules to allow usage of java.io.tmpdir |
|
566 |
* tomcat6.init, rules: Do not use TearDown, as this results in |
|
567 |
LifecycleListener callbacks in webapps being bypassed (LP: #299436) |
|
568 |
* rules: Compile at Java 1.5 level to allow usage of Java 5 JREs |
|
569 |
(LP: #286427) |
|
570 |
* control, rules, libservlet2.5-java-doc.install, |
|
571 |
libservlet2.5-java-doc.links: New libservlet2.5-java-doc package ships |
|
572 |
missing Servlet/JSP API documentation (LP: #279645) |
|
573 |
* patches/use-commons-dbcp.patch: Change default DBCP factory class |
|
574 |
to org.apache.commons.dbcp.BasicDataSourceFactory (LP: #283852) |
|
575 |
* tomcat6.dirs, tomcat6.postinst, default_root/index.html: Create |
|
576 |
Catalina/localhost in /etc/tomcat6 and make it writeable by the tomcat6 |
|
577 |
group, so that autodeploy and admin webapps work as expected (LP: #294277) |
|
578 |
* patches/disable-apr-loading.patch: Disable APR library loading until we |
|
579 |
properly provide it. |
|
580 |
* patches/disable-ajp-connector: Do not load AJP13 connector by default |
|
581 |
(LP: #300697) |
|
582 |
* rules: minor fixes to prevent build being called twice. |
|
583 |
||
584 |
-- Thierry Carrez <thierry.carrez@ubuntu.com> Thu, 27 Nov 2008 12:47:42 +0000 |
|
585 |
||
586 |
tomcat6 (6.0.18-0ubuntu3) intrepid; urgency=low |
|
587 |
||
588 |
* debian/tomcat6.postinst: |
|
589 |
- Make /var/lib/tomcat6/temp writeable by the tomcat6 user (LP: #287126) |
|
590 |
- Make /var/lib/tomcat6/webapps writeable by tomcat6 group (LP: #287447) |
|
591 |
* debian/tomcat6.init: make status return nonzero if tomcat6 is not running |
|
592 |
(fixes LP: #288218) |
|
593 |
||
594 |
-- Thierry Carrez <thierry.carrez@ubuntu.com> Thu, 23 Oct 2008 18:19:15 +0200 |
|
595 |
||
596 |
tomcat6 (6.0.18-0ubuntu2) intrepid; urgency=low |
|
597 |
||
598 |
* debian/rules: call dh_installinit with --error-handler so that install |
|
599 |
doesn't fail if Tomcat cannot be started during configure (LP: #274365) |
|
600 |
||
601 |
-- Thierry Carrez <thierry.carrez@ubuntu.com> Mon, 06 Oct 2008 13:55:21 +0200 |
|
602 |
||
603 |
tomcat6 (6.0.18-0ubuntu1) intrepid; urgency=low |
|
604 |
||
605 |
* New upstream version (LP: #260016) |
|
606 |
- Fixes CVE-2008-2938: Directory traversal vulnerability (LP: #256802) |
|
607 |
- Fixes CVE-2008-2370: Information disclosure vulnerability (LP: #256922) |
|
608 |
- Fixes CVE-2008-1232: XSS through sendError vulnerability (LP: #256926) |
|
609 |
* Dropped CVE-2008-1947.patch (fix is shipped in this upstream release) |
|
610 |
* control: Improve short descriptions for the binary packages |
|
611 |
* copyright: Added link to /usr/share/common-licenses/Apache-2.0 |
|
612 |
* control: To pull the right JRE, libtomcat6-java now depends on |
|
613 |
default-jre-headless | java6-runtime-headless |
|
614 |
||
615 |
-- Thierry Carrez <thierry.carrez@ubuntu.com> Fri, 22 Aug 2008 09:15:11 +0200 |
|
616 |
||
617 |
tomcat6 (6.0.16-1ubuntu1) intrepid; urgency=low |
|
618 |
||
619 |
* Adding full Tomcat 6 server stack support (LP: #256052) |
|
620 |
- tomcat6 handles the system instance (/var/lib/tomcat6) |
|
621 |
- tomcat6-user allows users to create their own private instances |
|
622 |
- tomcat6-common installs common files in /usr/share/tomcat6 |
|
623 |
- libtomcat6-java installs Tomcat 6 java libs in /usr/share/java |
|
624 |
- tomcat6-docs installs the documentation webapp |
|
625 |
- tomcat6-examples installs the examples webapp |
|
626 |
- tomcat6-admin installs the manager and host-manager webapps |
|
627 |
* Other key differences with the tomcat5.5 packages: |
|
628 |
- default-jdk build support |
|
629 |
- OpenJDK-6 JRE runtime support |
|
630 |
- tomcat6 installs a minimal ROOT webapp |
|
631 |
- new webapp locations follow Debian webapp policy |
|
632 |
- webapps restart tomcat6 in postrm rather than in prerm |
|
633 |
- added a doc-base entry |
|
634 |
- use standard upstream server.xml |
|
635 |
- initscript: try to check if Tomcat is really running before returning OK |
|
636 |
- removed transitional configuration migration code |
|
637 |
- autogenerate policy in /var/cache/tomcat6 rather than /etc/tomcat6 |
|
638 |
- logging.properties is customized to remove -webapps-related lines |
|
639 |
- initscript: implement TearDown spec |
|
640 |
* CVE-2008-1947 fix (cross-site-scripting issue in host-manager webapp) |
|
641 |
||
642 |
-- Thierry Carrez <thierry.carrez@ubuntu.com> Fri, 08 Aug 2008 15:37:48 +0200 |
|
643 |
||
644 |
tomcat6 (6.0.16-1) unstable; urgency=low |
|
645 |
||
646 |
* Initial release. |
|
647 |
(Closes: #480964). |
|
648 |
||
649 |
-- Paul Cager <paul-debian@home.paulcager.org> Mon, 12 May 2008 23:04:49 +0000 |