The Apache Tomcat Servlet/JSP Container

Apache Tomcat 7

Version 7.0.4, Oct 14 2010
Apache Logo

Links

User Guide

Reference

Apache Tomcat Development

Changelog

Tomcat 7.0.4 (markt)
Catalina
fix 49428: Re-implement the fix for bug 49428 – namespace issues for some Microsoft WebDAV clients. (kkolinko)
fix 49669: Fix memory leak triggered by using the deprecated javax.security.auth.Policy class. (markt)
fix 49922: Don't add filter twice to filter chain if the filter matches more than one URL pattern and/or Servlet name. Patch provided by heyoulin. (markt)
fix 49937: Use an InstanceManager when creating an AsyncListener through the AsyncContext to ensure annotations are processed. Based on a patch by David Jencks. (markt)
fix To avoid NoSuchMethodException, xmlValidation and xmlNamespaceAware are removed from the createStandardHost definition of mbeans-descriptors.xml. (kfujino)
fix 49945: Continue improvements to JMX. Fix a handful of attributes that were showing as Unavailable in JConsole. Patch provided by Chamith Buddhika. (markt)
fix 49952: Allow ServletContainerInitializers to add listeners to a web application. Patch provided by David Jencks. (markt)
fix 49956: Handle case when @Resource annotation uses the full JNDI name for a resource. Based on a patch by Gurkan Erdogdu. (markt)
fix 49557: Correct regression due to Lifecycle refactoring that cleared all work directories (with compiled JSPs and persisted sessions) when Tomcat was stopped. (markt)
fix 49978: Correctly handle the case when a directory expected to be created during web application start is already present. Rather than throwing an exception and failing to start, allow the web application to start normally. (mark)
fix 49987: Fix thread safety issue with population of servlet context initialization parameters. (markt)
fix 49994: As per the Java EE 6 specification, return a new object instance for each JNDI look up of a resource reference. (markt)
fix 50015: Re-factor dynamic servlet security implementation to make extensions, such as JACC implementations, simpler. Patch provided by David Jencks. (markt)
fix 50016: Re-factor isUserInRole() and login()/logout() methods to support JACC implementations and to improve encapsulation. Patch provided by David Jencks. (markt)
update 50017: Code clean-up. No functional change. Patch provided by sebb. (markt)
fix 50027: Avoid NPE on start when a Context is defined in server.xml with one or more JNDI resources. (markt)
fix 50059: JARs should always be searched for static resources even if the web application is marked as meta-data complete. (markt)
fix 500063: Correct regression in fix for 50059 that causes applications marked as meta-data complete to return 404s for all requests. Patch provided by heyoulin. (markt)
fix 50087: Catch ClassFormatErrors when scanning for annotations. (markt)
Coyote
fix 49923: Avoid using negative timeouts during acceptor unlock to ensure APR connector shuts down properly. (mturk)
fix 49972: Fix potential thread safe issue when formatting dates for use in HTTP headers. (markt)
fix 50003: Set not maxThreads but minSpareThreads to corePoolSize, if AbstractEndpoint.setMinSpareThreads is called. (kfujino)
fix 50044: Fix issue when using comet where socket remained in long poll after the comet request has ended. (markt)
fix 50054: Correctly handle the setting of minSpareThreads in AJP connector. (kfujino)
fix 50072: Fix issues when using a non-blocking read for the request line with the NIO connector that could result in the request line being mis-read. (markt)
Jasper
fix 49986: Fix thread safety issue for JSP reload. (timw)
fix 49998: Make jsp:root detection work with single quoted attributes as well. (timw)
fix Correctly handle the setting of primitve bean values via expression language. (markt)
fix Don't swallow exceptions when processing TLD files and handle the case when there is no web.xml file. (markt)
fix 50066: Fix building of recursive tag files when the file depends on a JAR file. Patch provided by Sylvain Laurent. (markt)
fix 50078: Fix threading problem in EL caches. Patch provided by Takayoshi Kimura. (markt)
add Make EL cache sizes configurable. (markt)
Web applications
fix Apply filters to default home page so copyright year is correctly displayed. (markt)
Other
fix 50013: Correctly package classes from org.apache.tomcat.util.file and add the tomcat-util.jar to the class path for the Ant tasks. Based on a patch provided by Sylvain Laurent. (markt)
Tomcat 7.0.3 (markt)not released
Catalina
fix 48644: Review all instances of catching Throwable and re-throw where appropriate. (markt)
update Allow glob patterns in the jarsToSkip configuration and add some debug logging to the jar scanner. (rjung)
fix 48738: Workaround a couple of long standing JDK bugs to enable GZIP compressed output streams to be flushed. Based on a patch provided by Jiong Wang. (markt)
fix 49195: Don't report an error when shutting down a Windows service for a Tomcat instance that has a disabled shutdown port. (markt)
fix 49209: Prevent possible AccessControlException during undeployment when running with a security manager. Patch provided by Sylvain Laurent. (markt)
fix 49657: Handle CGI executables with spaces in the path. (markt)
fix 49667: Ensure that using the JDBC driver memory leak prevention code does not cause a one of the memory leaks it is meant to avoid. (markt)
fix 49670: Restore SSO functionality that was broken by Lifecycle refactoring. (markt)
fix 49698: Allow a listener to complete an asynchronous request if it times out. (markt)
fix 49714: The annotation process of Jar doesn't influence distributable element of web.xml. (kfujino)
fix 49721: Alls JAR in a web application should be searched for resources, not just those with a web-fragment.xml that is going to be processed. (markt)
fix 49728: Improve PID file handling when another process is managing the PID file and Tomcat does not have write access. (markt)
fix 49730: Fix a race condition in StandardThreadExector that can cause requests to experience large delays. Patch provided by Sylvain Laurent. (markt)
fix 49749: Single sign on cookies should have httpOnly flag set using same rules as session cookies. (markt)
fix 49750: Align WebappClassLoader.validate() implementation with Javadoc and ensure that javax.servlet.* classes can not be loaded by a WebappClassLoader instance. Patch provided by pid. (markt)
fix 49757: Correct some generics warnings. Based on a patch provided by Gábor. (markt)
fix Provide 100 Continue responses at appropriate points during FORM authentication if client indicates that they are expected. (markt)
fix 49779: Improve handling of POST requests and FORM authentication, particularly when the user agent responds to the 302 response by repeating the POST request including a request body. Any request body provided at this point is now swallowed. (markt)
fix CSRF prevention filter did not correctly handle URLs that used anchors. (markt)
fix Fix memory leak on web application stopped caused by failed to de-register the web application's Servlets with the MBean server. (markt)
update More tweaks to the Lifecycle refactoring to ensure that when a component is being destroyed, the destroy method is only called once on each child component. (markt)
update 48967: Replace strings "catalina.base" and "catalina.home" by globally defined constants. Patch provided by Marc Guillemot. (rjung)
fix Keep the MBean names for web applications consistent between Tomcat 6 and Tomcat 7. (markt)
fix 49856: Add an executorName attribute to Connectors so it is possible to trace ThreadPool to Connector to Executor via the JMX interface. (markt)
fix 49865: Tomcat failed to start if catalina.properties was not present. (markt)
fix 49876: Fix the generics warnings in the copied Apache Jakarta BCEL code. Based on a patch by Gábor. (markt)
fix 49883: Ensure that the CombinedRealm and LockOutRealm return a name for use in log messages rather than throwing an UnsupportedOperationException. (markt)
fix 49884: Fix occassional NullPointerException on async complete(). This resulted in a major refactoring of the async implementation to address a number of threading issues. (markt)
fix Update the version numbers in ServerInfo defaults to Tomcat 7.0.x. (markt)
fix 49892: Correct JNDI name for method resource injections. Based on a patch by Gurkan Erdogdu. (markt)
fix Ensure that Context elements defined in server.xml use any configClass setting specified in the parent Host element. (markt)
fix GSOC 2010. Enable the creation of Services, Engines, Connectors, Hosts and Contexts via JMX from a minimal server.xml that contains only a Server element. Based on a patch by Chamith Buddhika. (markt)
fix 49909: Fix a regression introduced with the fix for 47950 that prevented JSTL classes being loaded. (markt)
fix 49915: Make error more obvious, particularly when accessed via JConsole, if StandardServer.storeConfig() is called when there is no StoreConfig implementation present. (markt)
fix 50018: Fix some minor Javadoc errors in Jasper source. Based on a patch by sebb. (timw)
fix 50021: Correct a regression in the fix for 46844 that may have caused additional problems during a failure at start up. (markt)
fix 50026: Prevent serving of resources from WEB-INF and META-INF directories when DefaultServlet or WebdavServlet is mapped to a sub-path of the context. This changes DefaultServlet to always serve resources with paths relative to the root of the context regardless of where it is mapped, which is a breaking change for current servlet-mappings that map the default servlet to a subpath. (timw)
Coyote
update Wait for the connectors to exit before closing them down. (mturk)
add Follow up to 48545. Make JSSE connectors more tolerant of a incorrect trust store password. (markt)
fix Fix some edge cases in the NIO connector when handling requests that are not received all at the same time and the socket needs to be returned to the poller. (markt)
update Further work to reduce the code duplication in the HTTP connectors. (markt)
fix Make sure acceptor threads are stopped when the connector is stopped. (markt)
fix Make sure async timeout thread is stopped when the connector is stopped. (markt)
fix 49625: Ensure Vary header is set if response may be compressed rather than only setting it if it is compressed. (markt)
fix 49802: Re-factor connector pause, stop and destroy methods so that calling any of those methods has the expected results. (markt)
update Various refactorings to reduce code duplication and unnecessary code in the connectors. (markt)
fix 49860: Add support for trailing headers in chunked HTTP requests. (markt)
Jasper
fix 49665: Provide better information including JSP file name and location when a missing file is detected during TLD handling. Patch provided by Ted Leung. (markt)
fix 49726: Specifying a default content type via a JSP property group should not prevent a page from setting some other content type. (markt)
fix 49799: The new omit attribute for jsp:attribute elements now supports the use of expressions and expression language. (markt)
fix 49916: Switch to using an initialisation parameter to pass JSP file information from Catalina to Jasper. This simplifies the Catalina code as well as making it easier for Geronimo and others to integrate Jasper. Patch provided by David Jencks. (markt)
fix 49985: Fix thread safety issue in EL parser. (markt)
Cluster
fix Remove domainReplication attribute from ClusterManager. If you send session to only same domain, use DomainFilterInterceptor. (kfujino)
fix Add Null check when CHANGE_SESSION_ID message received. (kfujino)
fix Add support for LAST_ACCESS_AT_START system property to DeltaSession. (kfujino)
fix Avoid a NPE in the DeltaManager when a parallel request invalidates the session before the current request has a chance to send the replication message. (markt)
fix 49905: Prevent memory leak when using asynchronous session replication. (markt)
fix 49924: When non-primary node changes into a primary node, make sure isPrimarySession is changed to true. (kfujino)
Web applications
fix Correct the class name of the default JAR scanner in the documentation web application. (rjung)
fix 49585: Update JSVC documentation to reflect new packaging of Commons Daemon. (markt)
update Update the Servlet, JSP and EL Javadoc links to link to the specifications and the relevant part of the Java EE 6 Javadoc. (markt)
fix Update a few places in the docs where the Manager documentation referred to the old role name of manager rather than than the new manager-script. (markt)
Extras
fix 49861: Don't log RMI ports formatted with commas for the JMX remote listener. (markt)
Other
fix Correct the user names created by the Windows installer for the Manager and Host Manager applications. (mturk)
fix Correct the Eclipse compiler dependency in the Jasper POM. (markt)
add Extend Checkstyle validation checks to check import order. (markt)
fix 49758: Fix generics warnings exposed by a fix in Eclipse 3.6. Patch provided by sebb. (markt)
update Update commons pool to 1.5.5. (markt)
update 49955: Improvement and correction of Building Tomcat guide. Based on a patch from Wesley Acheson. (timw)
Tomcat 7.0.2 (markt)beta, 2010-08-11
Catalina
fix Fix regression that prevented running with a security manager enabled. (markt)
Web applications
fix Correct Javadoc errors. (markt)
add Provide Javadoc for Servlet 3.0 API, JSP 2.2 API and EL 2.2 API. (markt)
fix Remove second copy of RUNNING.txt from the full-docs distribution. Some unpacking utilities can't handle multiple copies of a file with the same name in a directory. (markt)
Other
add Extend Checkstyle validation checks to check for tabs in nearly all text files. (markt)
update Update Commons Daemon from 1.0.2 to 1.0.3.(markt)
update Update Eclipse JDT Core Batch Compiler (ecj.jar) from 3.5.1 to 3.6. (markt)
Tomcat 7.0.1 (markt)not released
Catalina
fix GSOC 2010. Continue work to align MBean descriptors with reality. Patch provided by Chamith Buddhika. (markt)
fix When running under a security manager, enforce package access and package definition restrictions defined in the catalina.properties file. (markt)
fix When using a Loader configured with searchExternalFirst="true" failure to find the class in an external repository should not prevent searching of the local repositories. (markt)
add Add entryPoint support to the CSRF prevention filter. (markt)
fix 48297: Correctly initialise handler chain for web services resources. (markt)
add 48960: Add a new option to the SSI Servlet and SSI Filter to allow the disabling of the exec command. This is now disabled by default. Based on a patch by Yair Lenga. (markt)
add 48998, 49617: Add the ExpiresFilter, a port of the httpd mod_expires module. Patch provided by Cyrille Le Clerc. (markt)
fix 49030: When initializing/starting/stopping connectors and one of them fails, do not ignore the others. (markt/kkolinko)
fix 49128: Don't swallow exceptions unnecessarily in WebappClassLoader.start(). (markt)
fix 49182: Align comments in setclasspath.[sh|bat] with behaviour. Based on a patch provided by sebb. (markt)
fix 49230: Enhance JRE leak prevention listener with protection for the keep-alive thread started by sun.net.www.http.HttpClient. Based on a patch provided by Rob Kooper. (markt)
fix 49414: When reporting threads that may have triggered a memory leak on web application stop, attempt to differentiate between request processing threads and threads started by the application. (markt)
fix 49428: Add a work-around for the known namespace issues for some Microsoft WebDAV clients. Patch provided by Panagiotis Astithas. (markt)
add Add support for *.jar pattern in VirtualWebappLoader. (kkolinko)
add Use a LockOutRealm in the default configuration to prevent attempts to guess user passwords by brute-force. (markt)
add 49478: Add support for user specified character sets to the AddDefaultCharsetFilter. Based on a patch by Felix Schumacher. (markt)
fix 49503: Make sure connectors bind to their associated ports sufficiently early to allow jsvc and the org.apache.catalina.startup.EXIT_ON_INIT_FAILURE system property to operate correctly. (markt)
fix 49525: Ensure cookies for the ROOT context have a path of / rather than an empty string. (markt)
fix 49528, 49567: Ensure that AsyncContext.isAsyncStarted() returns the correct value after AsyncContext.start() and that if AsyncContext.complete() is called on a separate thread that it is handled correctly. (markt)
fix 49530: Contexts and Servlets not stopped when Tomcat is shut down. (markt)
fix 49536: If no ROOT context is deployed, ensure a 404 rather than a 200 is returned for requests that don't map to any other context. (markt)
add Additional debug logging in StandardContext to provide information on Manager selection. (markt)
fix 49550: Supress deprecation warning where deprecated code is required to be used. No functional change. Patch provided by Sebb. (markt)
fix 49551: Allow default context.xml location to be specified using an absolute path. (markt)
add Improve logging of unhandled exceptions in servlets by including the path of the context where the error occurred. (markt)
add Include session ID in error message logged when trying to set an attribute on an invalid session. (markt)
fix Improve the CSRF protection filter by using SecureRandom rather than Random to generate nonces. Also make the implementation class used user configurable. (markt)
fix Avoid NullPointerException, when copyXML=true and META-INF/context.xml does not exist. (kfujino)
fix 49598: When session is changed and the session cookie is replaced, ensure that the new Set-Cookie header overwrites the old Set-Cookie header. (markt)
fix Create a thread to trigger asynchronous timeouts when using the BIO connector, change the default timeout to 10s (was infinite) and make the default timeout configurable using the asyncTimeout attribute on the connector. (pero/markt)
fix 49600: Make exceptions returned by the ProxyDirContext consistent for resources that weren't found by checking the DirContext or the cache. Test case based on a patch provided by Marc Guillemot. (markt)
fix 49613: Improve performance when using SSL for applications that make multiple class to Request.getAttributeNames(). Patch provided by Sampo Savolainen. (markt)
fix Handle the edge cases where resources packaged in JARs have names that start with a single quote character or a double quote character. (markt)
fix Correct copy and paste typo in web.xml parsing rules that mixed up local-ejb-ref and resource-env-ref. (markt)
update Refactor session managers to remove unused code and to reduce code duplication. Also, all session managers used for session replication now extend org.apache.catalina.ha.session.ClusterManagerBase. (markt)
Jasper
update Remove references to Jikes since it does not support Java 6. (markt)
fix Correct over zealous type checking for EL in attributes that broke the use of JSF converters. (markt)
fix Correct algorithm used to identify correct method to use when a MethodExpressions is used in EL. (markt)
fix 49217: Ensure that identifiers used in EL meet the requirements of the Java Language Specification. (markt)
add Improve logging of JSP exceptions by including JSP snippet (if enabled) rather than just the root cause in the host log. (markt)
fix 49555: Correctly handled Tag Libraries where functions are defined in static inner classes. (markt)
Cluster
fix 49127: Don't swallow exceptions unnecessarily in SimpleTcpReplicationManager.startInternal(). (markt)
fix 49407: Change the BackupManager so it is consistent with DeltaManager and reports both primary and backup sessions when active sessions are requested. (markt)
fix 49445: When session ID is changed after authentication, ensure the DeltaManager replicates the change in ID to the other nodes in the cluster. (kfujino)
Web applications
fix 49112: Update the ROOT web application's index page. Patch provided by pid. (markt)
fix 49213: Add the permissions necessary to enable the Manager application to operate currently when running with a security manager. (markt)
fix 49436: Correct documented default for readonly attribute of the UserDatabase component. (markt)
fix 49475: Use new role name for manager application access on the ROOT web application's index page. (markt)
fix 49476: CSRF protection was preventing access to the session expiration features. Also switch the manager application to the generic CSRF protection filter. (markt)
fix Better handle failure to create directories required for new hosts in the Host Manager application. (markt)
fix Switch the Host Manager application to the generic CSRF protection for the HTML interface and prevent started hosts from being started and stopped hosts from being stopped. (markt)
fix 49518: Fix typo in extras documentation. (markt)
fix 49522: Fix regression due to change of name for MBeans for naming resources that broke the complete server status page in the manager application. Note these MBeans now have a new name. (markt)
fix 49570: When using the example compression filter, set the Vary header on compressed responses. (markt)
add Add redirects for the root of the manager and host-manager web applications that redirect users to the html interface rather than returning a 404. (markt)
add Provide the HTML Manager application with the ability to differentiate between primary, backup and proxy sessions. Note that proxy sessions are only shown if enabled in web.xml. (markt)
Other
fix 49130: Better describe the core package in the Windows installer, making it clear that the service will be installed. Patch provided by sebb. (markt)
add Re-factor unit tests to enable them to be run once with each of the HTTP connector implementations (BIO, NIO and APR/native). (markt)
add 49268: Add the necessary plumbing to include CheckStyle in the build process. Start with no checks. Additional checks will be added as they are agreed. (markt)
update Updated to Ant 1.8.1. The build now requires a minimum of Ant 1.8.x. (markt)
update Update the re-packaged version of commons-fileupload from 1.2.1 to 1.2.2. The layout of re-packaged version was also restored to the original commons-fileupload layout to make merging of future updates easier. (markt)
update Update the re-packaged version of Jakarta BCEL from trunk revision 880760 to trunk revision 978831. (markt)
Tomcat 7.0.0 (markt)beta, 2010-06-29
Catalina
update Update Servlet support to the Servlet 3.0 specification. (all)
update Improve and document VirtualWebappLoader. (rjung)
add 43642: Add prestartminSpareThreads attribute for Executor. (jfclere)
update Switch from AnnotationProcessor to InstanceManager. Patch provided by David Jecks with modifications by Remy. (remm/fhanik)
update r620845 and r669119. Make shutdown address configurable. (jfclere)
fix r651977 Add some missing control checks to ThreadWithAttributes. (markt)
add r677640 Add a startup class that does not require any configuration files. (costin)
fix r700532 Log if temporary file operations within the CGI servlet fail. Make sure header Reader is closed on failure. (markt)
fix r708541 Delete references to DefaultContext which was removed in 6.0.x. (markt)
add r709018 Initial implementation of an asynchronous file handler for JULI. (fhanik)
fix Give session thisAccessedTime and lastAccessedTime clear semantics. (rjung)
add Expose thisAccessedTime via Session interface. (rjung)
add Provide a log format for JULI that provides the same information as the default but on a single line. (markt)
add r723889 Provide the ability to configure the Executor job queue size and a timeout for adding jobs to the queue. (fhanik)
add Add support for aliases to StandardContext. This allows content from other directories and/or WAR files to be mapped to paths within the context. (markt)
update Provide clearer definition of Lifecycle interface, particularly start and stop, and align components that implement Lifecycle with this definition. (markt)
add 48662: Provide a new option to control the copying of context XML descriptors from web applications to the host's xmlBase. Copying of XMl descriptors is now disabled by default. (markt)
fix Move comet classes from the org.apache.catalina package to the org.apache.catalina.comet package to allow comet to work under a security manager. (markt)
Coyote
update Port SSLInsecureRenegotiation from mod_ssl. This requires to use tomcat-native 1.2.21 that have option to detect this support from OpenSSL library. (mturk)
update Allow bigger AJP packets also for request bodies and responses using the packetSize attribute of the Connector. (rjung)
updater703017 Make Java socket options consistent between NIO and JIO connector. Expose all the socket options available on java.net.Socket (fhanik)
fix 46051: The writer returned by getWriter() now conforms to the PrintWriter specification and uses platform dependent line endings rather than always using \r\n. (markt)
update Use tc-native 1.2.x which is based on APR 1.3.3+ (mturk)
update r724239 NIO connector now always uses an Executor. (fhanik)
update r724393 Implement keepAliveCount for NIO connector in a thread safe manner. (fhanik)
update r724849 Implement keep alive timeout for NIO connector. (fhanik)
Jasper
update Update JSP support to the JSP 2.2 specification. (markt)
update Update EL support to the EL 2.2 specification. (markt)
update r787978 Use "1.6" as the default value for compilerSourceVM and compilerTargetVM options of Jasper. (kkolinko)
add 48358: Add support for limiting the number of JSPs that are loaded at any one time. Based on a patch by Isabel Drost. (markt)
add 48689: Access TLD files through a new JarResource interface to make extending Jasper simpler, particularly in OSGi environments. Patch provided by Jarek Gawor. (markt)
High Availability
add Add support for UDP and secure communication to tribes. (fhanik)
add Add versioning to the tribes communication protocol to support future developments. (fhanik)
add Add a demo on how to use the payload. (fhanik)
add Started to add JMX support to the cluster implementation. (markt)
fix r609778 Minor fixes to the throughput interceptor and the NIO receiver. (fhanik)
fix r630234 Additional checks for the NIO receiver. (fhanik)
update r671650 Improve error message when multicast is not enabled. (fhanik)
Web applications
update r631321 Update changelog to support the <rev> element in the documentation. (fhanik)
add A number of additional roles were added to the Manager and Host Manager applications to separate out permissions for the HTML interface, the text interface and the JMX proxy. (markt)
add CSRF protection was added to the Manager and Host Manager applications. (markt)
add List array elements in the JMX proxy output of the Manager application. (rjung)
Extras
add A new JmxRemoteLifecycleListener that can be used to fix the ports used for remote JMX connections, eg when using JConsole. (markt)
Other
fix Numerous code clean-up changes including the use of generics and removing unused imports, fields, parameters and methods. (markt)
fix All deprecated internal code has been removed. Warning: If you have custom components for a previous Tomcat version that extend internal Tomcat classes and override deprecated methods it is highly likely that they will no longer work. (markt)
update Parameterize version number throughout build scripts and source. (rjung)

Copyright © 1999-2010, Apache Software Foundation