Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to winstone 5.15 to include Jetty 9.4.38.v20210224 #5317

Merged
merged 1 commit into from Mar 1, 2021

Conversation

olamy
Copy link
Member

@olamy olamy commented Feb 27, 2021

Signed-off-by: olivier lamy olamy@apache.org

See JENKINS-XXXXX.

Proposed changelog entries

Proposed upgrade guidelines

N/A

Submitter checklist

  • (If applicable) Jira issue is well described
  • Changelog entries and upgrade guidelines are appropriate for the audience affected by the change (users or developer, depending on the change). Examples
    • Fill-in the Proposed changelog entries section only if there are breaking changes or other changes which may require extra steps from users during the upgrade
  • Appropriate autotests or explanation to why this change has no tests
  • For dependency updates: links to external changelogs and, if possible, full diffs

Desired reviewers

@mention

Maintainer checklist

Before the changes are marked as ready-for-merge:

  • There are at least 2 approvals for the pull request and no outstanding requests for change
  • Conversations in the pull request are over OR it is explicit that a reviewer does not block the change
  • Changelog entries in the PR title and/or Proposed changelog entries are correct
  • Proper changelog labels are set so that the changelog can be generated automatically
  • If the change needs additional upgrade steps from users, upgrade-guide-needed label is set and there is a Proposed upgrade guidelines section in the PR title. (example)
  • If it would make sense to backport the change to LTS, a Jira issue must exist, be a Bug or Improvement, and be labeled as lts-candidate to be considered (see query).

Signed-off-by: olivier lamy <olamy@apache.org>
@daniel-beck
Copy link
Member

Conflicts (in a way) with #5315

@daniel-beck
Copy link
Member

daniel-beck commented Feb 27, 2021

jetty/jetty.project#6001 looks like quite the regression in 9.4.37 fixed by this update.

Edited to add:

Yup. Looks like this is messing with encoded forward slashes, which are legitimately used in some places, including, IIRC, multibranch pipelines (in which child "branch projects" can have forward slashes in the branch name that are then getting encoded this way).

Screenshot

Happens in current master, does not happen in f2b1146 before the Winstone 5.14 update.

@daniel-beck daniel-beck added the regression-fix Pull request that fixes a regression in one of the previous Jenkins releases label Feb 27, 2021
Copy link
Member

@daniel-beck daniel-beck left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval, but ideally #5315 would be integrated and updated here.

Copy link
Member

@oleg-nenashev oleg-nenashev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1.
We may merge it in 24 hours if there is no negative feedback. Please see the merge process documentation for more information about the merge process

@oleg-nenashev oleg-nenashev added ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback bug For changelog: Minor bug. Will be listed after features labels Feb 27, 2021
@oleg-nenashev oleg-nenashev merged commit e77581f into master Mar 1, 2021
@olamy olamy deleted the winstone-5.15 branch March 2, 2021 11:49
@olamy
Copy link
Member Author

olamy commented Mar 3, 2021

@timja should be good to have this cherry-pick in stable-2.277 . To have a fix for CVE CVE-2020-27223 see GHSA-m394-8rww-3jr7
do you need a PR for that?

@timja
Copy link
Member

timja commented Mar 4, 2021

@olamy please do

@p-rog
Copy link

p-rog commented Mar 8, 2021

Are you going to bump winstone to 5.14 or 5.15 in the LTS version?

@MarkEWaite
Copy link
Contributor

Are you going to bump winstone to 5.14 or 5.15 in the LTS version?

#5332 updates it for Jenkins 2.277.1 that will be released Wednesday, March 10, 2021. Included in the 2.277.1 changelog pull request as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug For changelog: Minor bug. Will be listed after features ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback regression-fix Pull request that fixes a regression in one of the previous Jenkins releases
Projects
None yet
6 participants