From d2c043f2df6cbc096237050f98580b2feda2f918 Mon Sep 17 00:00:00 2001 From: Jeff Johnston Date: May 21 2009 21:10:35 +0000 Subject: - Do not allow directory listings. --- diff --git a/.cvsignore b/.cvsignore index 5e1ca9b..ca4ce2a 100644 --- a/.cvsignore +++ b/.cvsignore @@ -1,2 +1,3 @@ jetty-5.1.12.fedora.zip jetty-5.1.14.fedora.tgz +jetty-5.1.15.fedora.tgz diff --git a/jetty-OSGi-MANIFEST.MF b/jetty-OSGi-MANIFEST.MF index 58fa580..a6163d2 100644 --- a/jetty-OSGi-MANIFEST.MF +++ b/jetty-OSGi-MANIFEST.MF @@ -7,13 +7,13 @@ Import-Package: javax.net.ssl,javax.security.cert,javax.servlet;versio commons.logging;version="[1.0.0,2.0.0)",org.xml.sax,org.xml.sax.helpe rs Bundle-ManifestVersion: 2 -Export-Package: org.mortbay.html;version="5.1.14",org.mortbay.http;ver - sion="5.1.14",org.mortbay.http.ajp;version="5.1.14",org.mortbay.http. - handler;version="5.1.14",org.mortbay.http.nio;version="5.1.14",org.mo - rtbay.jetty;version="5.1.14",org.mortbay.jetty.servlet;version="5.1.1 - 1",org.mortbay.jetty.win32;version="5.1.14",org.mortbay.log;version=" - 5.1.14",org.mortbay.servlet;version="5.1.14",org.mortbay.util;version - ="5.1.14",org.mortbay.xml;version="5.1.14" +Export-Package: org.mortbay.html;version="5.1.15",org.mortbay.http;ver + sion="5.1.15",org.mortbay.http.ajp;version="5.1.15",org.mortbay.http. + handler;version="5.1.15",org.mortbay.http.nio;version="5.1.15",org.mo + rtbay.jetty;version="5.1.15",org.mortbay.jetty.servlet;version="5.1.1 + 5",org.mortbay.jetty.win32;version="5.1.15",org.mortbay.log;version=" + 5.1.15",org.mortbay.servlet;version="5.1.15",org.mortbay.util;version + ="5.1.15",org.mortbay.xml;version="5.1.15" Bundle-Version: 5.1.14.v200806031611 Bundle-SymbolicName: org.mortbay.jetty Bundle-Name: Jetty WebServer diff --git a/jetty-webdefault.patch b/jetty-webdefault.patch new file mode 100644 index 0000000..92379c2 --- /dev/null +++ b/jetty-webdefault.patch @@ -0,0 +1,24 @@ +diff -up ./etc/webdefault.xml.fix ./etc/webdefault.xml +--- ./etc/webdefault.xml.fix 2009-05-20 17:05:52.000000000 -0400 ++++ ./etc/webdefault.xml 2009-05-20 17:06:10.000000000 -0400 +@@ -96,7 +96,7 @@ + + + dirAllowed +- true ++ false + + + putAllowed +diff -up ./src/org/mortbay/jetty/servlet/webdefault.xml.fix ./src/org/mortbay/jetty/servlet/webdefault.xml +--- ./src/org/mortbay/jetty/servlet/webdefault.xml.fix 2009-05-20 17:06:36.000000000 -0400 ++++ ./src/org/mortbay/jetty/servlet/webdefault.xml 2009-05-20 17:06:47.000000000 -0400 +@@ -96,7 +96,7 @@ + + + dirAllowed +- true ++ false + + + putAllowed diff --git a/jetty.spec b/jetty.spec index 9060b71..6b02423 100644 --- a/jetty.spec +++ b/jetty.spec @@ -55,7 +55,7 @@ %define demodir %{jettylibdir}/demo Name: jetty -Version: 5.1.14 +Version: 5.1.15 Release: 3%{?dist} Summary: The Jetty Webserver and Servlet Container @@ -63,14 +63,14 @@ Group: Applications/Internet License: ASL 2.0 URL: http://jetty.mortbay.org/jetty/ # Following source tarball was originally taken from the following location: -# http://www.ibiblio.org/maven/jetty/jetty-5.1.x/jetty-5.1.14.tgz +# http://dist.codehaus.org/jetty/jetty-5.1.x/jetty-5.1.15.tgz # The tarball was modified by removing all jars and BCLA licenses. -# tar -xzf jetty-5.1.14.tgz -# pushd jetty-5.1.14 +# tar -xzf jetty-5.1.15.tgz +# pushd jetty-5.1.15 # find . -name *.jar -exec rm {} \; # rm ./etc/LICENSE.javax.xml.html ./etc/LICENSE.jsse.txt # popd -# tar -czf jetty-5.1.14.fedora.tgz jetty-5.1.14/* +# tar -czf jetty-5.1.15.fedora.tgz jetty-5.1.15/* Source0: %{jettyname}-%{version}.fedora.tgz Source1: jetty.script Source2: jetty.init @@ -80,7 +80,7 @@ Patch0: jetty-extra-j2ee-build_xml.patch Patch1: jetty-PostFileFilter.patch Patch2: jetty-libgcj-bad-serialization.patch Patch3: jetty-TestRFC2616-libgcj-bad-date-parser.patch -Patch4: jetty-CERT438616-CERT237888-CERT21284.patch +Patch4: jetty-webdefault.patch Patch5: jetty-unix.patch BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) @@ -256,7 +256,6 @@ rm src/org/mortbay/util/jmx/MX4JHttpAdaptor.java %patch1 -b .sav %patch2 -b .sav %patch3 -b .sav - %patch4 %patch5 @@ -607,13 +606,19 @@ fi %endif %changelog -* Fri Apr 03 2009 Jeff Johnston 5.1.14-3 +* Thu May 21 2009 Jeff Johnston 5.1.15-3 +- Do not allow directory listings. + +* Tue May 19 2009 Jeff Johnston 5.1.15-2 +- Update OSGI manifest file. + +* Tue May 19 2009 Jeff Johnston 5.1.15-1 +- Upgrade to 5.1.15 source tarball for Fedora. + +* Fri Apr 22 2009 Jeff Johnston 5.1.14-3 - Add %%{libdir} to files list. - Resolves #473585 -* Wed Feb 25 2009 Fedora Release Engineering - 5.1.14-2.10 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild - * Wed Feb 11 2009 Jeff Johnston 5.1.14-1.10 - Rename jettyc back to .jettyrc. - Resolves #485012 diff --git a/sources b/sources index 5d2995d..36eda72 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -04dcaaa5407462cea9c514b7f7aabff7 jetty-5.1.14.fedora.tgz +09d5e3204f5c74efcd3ae9330f92838b jetty-5.1.15.fedora.tgz