[JBoss JIRA] (JBDS-3562) Prepare for 9.0.1 (9.0.0 with patched EAP 6.4.0 BZ1281963 / CVE-2015-7501)
by Nick Boldt (JIRA)
[ https://issues.jboss.org/browse/JBDS-3562?page=com.atlassian.jira.plugin.... ]
Nick Boldt commented on JBDS-3562:
----------------------------------
I know it's not required, but you told me to use https://devstudio.redhat.com/9.0/stable/updates/ and that URL contains Central. And the Integration Stack stuff too.
(You may recall a year ago when it was decided that having separate URLs for all the JBDS stuff created unnecessary cruft in Preferences > Update > Available Software Sites.)
So, it got dragged into the build's reactor, and we ended up with a newer gson.
> Prepare for 9.0.1 (9.0.0 with patched EAP 6.4.0 BZ1281963 / CVE-2015-7501)
> --------------------------------------------------------------------------
>
> Key: JBDS-3562
> URL: https://issues.jboss.org/browse/JBDS-3562
> Project: Developer Studio (JBoss Developer Studio)
> Issue Type: Bug
> Components: build
> Affects Versions: 9.0.0.CVE-2015-7501-GA
> Reporter: Nick Boldt
> Assignee: Nick Boldt
> Fix For: 9.0.0.CVE-2015-7501-GA
>
> Attachments: 900GAvs901GA_B6.p2diff.txt, JBDS900GA-respin_diffs__EAP640-BZ1281963.png, JBDS900GA-respin_diffs__EAP640patched-looks-the-same-as-EAP640.png, JBDS900GA-respin_diffs__EAP640patched-looks-the-same-as-EAP640__002.png, JBDS900GA-respin_diffs__google.gson_JBDSTPvsJBDSCentralTP.png, JBDS900GA-respin_diffs__google.gson_JBDSTPvsJBDSCentralTP_210_refs.png, JBDS900GA-respin_diffs__google.gson_JBDSTPvsJBDSCentralTP_224_refs.png, JBDS900GA-respin_diffs__o.e.jst.plugins.manifest.mf.png, JBDS900GA-respin_diffs__p2director.manifest.mf.png, JBDS900GA-respin_diffs__plugins_including_gson2.1.0vs.2.2.4.png, JBDS900GA-respin_diffs__readme.txt.png
>
>
> Tracker JIRA to house things to do to prepare for 9.0.1 / 9.1.0 branches & builds.
> Because JBDS 9.0.0 includes the compromised version of
> apache.commons.collections (JBDS-3560, JBDS-3561), we need to at some point respin it, which
> will include:
> a) updated JBT/JBDS target platforms 4.50.1.* and 4.51.1.*
> b) repin of JBDS update sites and installer jars
> To that end, I've created the following new branches:
> https://github.com/jbosstools/jbosstools-target-platforms/commits/4.50.1.x
> https://github.com/jbosstools/jbosstools-target-platforms/commits/4.51.1.x
> And I've bumped the version of the target platforms in the 4.50.x and
> 4.51.x branches to 4.50.2.Beta1-SNAPSHOT and 4.51.2.Beta1-SNAPSHOT,
> respectively.
> JBDS is now at version 9.1.0 in the 4.3.x branch and 9.0.1 in the
> 4.3.1.x branch.
> https://github.com/jbdevstudio/jbdevstudio-product/commits/jbosstools-4.3...
> (new, 9.0.1)
> https://github.com/jbdevstudio/jbdevstudio-product/commits/jbosstools-4.3.x
> (updated to 9.1.0)
> So, now we just need to ensure that the correct BUILD_ALIAS (CR1 for
> 9.0.1, Beta1 for 9.1.0) and target platforms are used.
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBDS-3562) Prepare for 9.0.1 (9.0.0 with patched EAP 6.4.0 BZ1281963 / CVE-2015-7501)
by Denis Golovin (JIRA)
[ https://issues.jboss.org/browse/JBDS-3562?page=com.atlassian.jira.plugin.... ]
Denis Golovin commented on JBDS-3562:
-------------------------------------
Central is not required to rebuild installer, you should use just stable jbds p2 repo and disable to in build, so it would have no chance to pick up anything outside of what was used to build installer.
> Prepare for 9.0.1 (9.0.0 with patched EAP 6.4.0 BZ1281963 / CVE-2015-7501)
> --------------------------------------------------------------------------
>
> Key: JBDS-3562
> URL: https://issues.jboss.org/browse/JBDS-3562
> Project: Developer Studio (JBoss Developer Studio)
> Issue Type: Bug
> Components: build
> Affects Versions: 9.0.0.CVE-2015-7501-GA
> Reporter: Nick Boldt
> Assignee: Nick Boldt
> Fix For: 9.0.0.CVE-2015-7501-GA
>
> Attachments: 900GAvs901GA_B6.p2diff.txt, JBDS900GA-respin_diffs__EAP640-BZ1281963.png, JBDS900GA-respin_diffs__EAP640patched-looks-the-same-as-EAP640.png, JBDS900GA-respin_diffs__EAP640patched-looks-the-same-as-EAP640__002.png, JBDS900GA-respin_diffs__google.gson_JBDSTPvsJBDSCentralTP.png, JBDS900GA-respin_diffs__google.gson_JBDSTPvsJBDSCentralTP_210_refs.png, JBDS900GA-respin_diffs__google.gson_JBDSTPvsJBDSCentralTP_224_refs.png, JBDS900GA-respin_diffs__o.e.jst.plugins.manifest.mf.png, JBDS900GA-respin_diffs__p2director.manifest.mf.png, JBDS900GA-respin_diffs__plugins_including_gson2.1.0vs.2.2.4.png, JBDS900GA-respin_diffs__readme.txt.png
>
>
> Tracker JIRA to house things to do to prepare for 9.0.1 / 9.1.0 branches & builds.
> Because JBDS 9.0.0 includes the compromised version of
> apache.commons.collections (JBDS-3560, JBDS-3561), we need to at some point respin it, which
> will include:
> a) updated JBT/JBDS target platforms 4.50.1.* and 4.51.1.*
> b) repin of JBDS update sites and installer jars
> To that end, I've created the following new branches:
> https://github.com/jbosstools/jbosstools-target-platforms/commits/4.50.1.x
> https://github.com/jbosstools/jbosstools-target-platforms/commits/4.51.1.x
> And I've bumped the version of the target platforms in the 4.50.x and
> 4.51.x branches to 4.50.2.Beta1-SNAPSHOT and 4.51.2.Beta1-SNAPSHOT,
> respectively.
> JBDS is now at version 9.1.0 in the 4.3.x branch and 9.0.1 in the
> 4.3.1.x branch.
> https://github.com/jbdevstudio/jbdevstudio-product/commits/jbosstools-4.3...
> (new, 9.0.1)
> https://github.com/jbdevstudio/jbdevstudio-product/commits/jbosstools-4.3.x
> (updated to 9.1.0)
> So, now we just need to ensure that the correct BUILD_ALIAS (CR1 for
> 9.0.1, Beta1 for 9.1.0) and target platforms are used.
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBIDE-21192) jboss-runtimes are still not scanned
by Rob Stryker (JIRA)
[ https://issues.jboss.org/browse/JBIDE-21192?page=com.atlassian.jira.plugi... ]
Rob Stryker resolved JBIDE-21192.
---------------------------------
Resolution: Done
https://github.com/jbosstools/jbosstools-base/commit/b495a62ef0414738f735...
It currently does add jboss-runtimes as a path to scan on every startup. However, you are correct, it does NOT do this if the folder doesn't exist on first startup.
The fix is to ensure it adds the RuntimePath to be scanned regardless of whether the jboss-runtimes folder actually exists at the first startup or not. The path will be invalid if the folder doesn't exist, but there's no other harm or damage, as it's already defensively coded to ignore paths that don't exist.
It does seem a bit weird to add a path to be scanned when the path doesn't exist, but the alternatives (re-adding the path even if a user intentionally removed it? trying to figure out if it was added in the past and removed and customize logic to POSSIBLY add it?) all seem more complicated, and possibly confusing to the user; very voodoo magical. Adding the invalid path is the most logical.
> jboss-runtimes are still not scanned
> -------------------------------------
>
> Key: JBIDE-21192
> URL: https://issues.jboss.org/browse/JBIDE-21192
> Project: Tools (JBoss Tools)
> Issue Type: Bug
> Components: runtime-detection
> Reporter: Max Rydahl Andersen
> Assignee: Rob Stryker
> Fix For: 4.3.1.Beta1
>
>
> JBDS-2515 requested that ~/jboss-runtimes would be scanned but seem to have ended up being to only add this on new workspaces and *only* if the location exist when creating the new workspace.
> I found no way to have restore defaults or any way to actually have the scan happen.
> Why are we not always adding ~/jboss-runtimes to the list of locations to scan no matter if the location exists or not ?
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBIDE-21192) jboss-runtimes are still not scanned
by Rob Stryker (JIRA)
[ https://issues.jboss.org/browse/JBIDE-21192?page=com.atlassian.jira.plugi... ]
Rob Stryker updated JBIDE-21192:
--------------------------------
Fix Version/s: 4.4.0.Alpha1
> jboss-runtimes are still not scanned
> -------------------------------------
>
> Key: JBIDE-21192
> URL: https://issues.jboss.org/browse/JBIDE-21192
> Project: Tools (JBoss Tools)
> Issue Type: Bug
> Components: runtime-detection
> Reporter: Max Rydahl Andersen
> Assignee: Rob Stryker
> Fix For: 4.3.1.Beta1, 4.4.0.Alpha1
>
>
> JBDS-2515 requested that ~/jboss-runtimes would be scanned but seem to have ended up being to only add this on new workspaces and *only* if the location exist when creating the new workspace.
> I found no way to have restore defaults or any way to actually have the scan happen.
> Why are we not always adding ~/jboss-runtimes to the list of locations to scan no matter if the location exists or not ?
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months
[JBoss JIRA] (JBIDE-21194) Result from adbinfo on windows has different syntax
by Rob Stryker (JIRA)
[ https://issues.jboss.org/browse/JBIDE-21194?page=com.atlassian.jira.plugi... ]
Rob Stryker resolved JBIDE-21194.
---------------------------------
Resolution: Done
pushed to master and maintenance.
> Result from adbinfo on windows has different syntax
> ---------------------------------------------------
>
> Key: JBIDE-21194
> URL: https://issues.jboss.org/browse/JBIDE-21194
> Project: Tools (JBoss Tools)
> Issue Type: Sub-task
> Components: openshift, server
> Affects Versions: 4.3.0.Beta1
> Reporter: Rob Stryker
> Assignee: Rob Stryker
> Fix For: 4.3.1.Beta1, 4.4.0.Alpha1
>
>
> The result from adbinfo on linux is:
> {code}
> export key=value
> {code}
> The result on Windows is:
> {code}
> setx key value
> {code}
> The adbinfo runner needs to be aware of this difference and react accordingly when creating the openshift connection.
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
10 years, 4 months