jetty-websocket-servlet-9.4.58-150200.3.37.1<>,@ iip9|Cu'q7e9GIe-63LrȄ_0kù[cg$8y}tIז MJ, }'4|*2_,I].{ ,3d@,0 v8έPj:z6ߗc{N7mhY0x e`8Pu HVVT-)JF5>$h?$Xd! / V 17@T ^ h | A H\u}(89:IF G 0H DI XX `Y p\ ] ^!"b!c"Bd"e"f"l"u"v# w#x#y#z#$$ $$TCjetty-websocket-servlet9.4.58150200.3.37.1The websocket-servlet module for Jetty%{extdesc} The websocket-servlet module for Jetty.iih04-ch1ddSUSE Linux Enterprise 15SUSE LLC Apache-2.0 OR EPL-1.0https://www.suse.com/Unspecifiedhttps://www.eclipse.org/jetty/linuxnoarchOL A큤A큤iiiiiiiiiiae861811862ffde4695ac332a9bf408d33fe2368f2273401f2a310d3e531e0a1d8ec8012491bcc3b6be7adfa38f902947d971b18aa2a6da8f8bde8d67ac48ad3b94aefe4bb38790a3c11d89feca2e83647294724320bd3e6d0eb510e7bbeddf3rootrootrootrootrootrootrootrootrootrootjetty-websocket-9.4.58-150200.3.37.1.src.rpmjetty-websocket-servletmvn(org.eclipse.jetty.websocket:websocket-servlet)mvn(org.eclipse.jetty.websocket:websocket-servlet:pom:)osgi(org.eclipse.jetty.websocket.servlet)@ @@@    java-headlessjavapackages-filesystemmvn(javax.servlet:javax.servlet-api)mvn(org.eclipse.jetty.websocket:websocket-api)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.89.4.58.v202508143.0.4-14.6.0-14.0-15.2-14.14.1h[h4WgY@ee'd^@djb@bBb9@an@`i@`@`f@`KW_@_^@^]߶]Xfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comrpm@fthiessen.defstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.comfstrba@suse.com- Upgrade to version 9.4.58.v20250814 * Changes + #13461 - 9.4.x HTTP2Session cleanups - Addresses CVE-2025-5115, bsc#1244252 + #13261 - Improve handling of failed HTTP/2 requests + #461 - Move ServletTester to the test source directory- Upgrade to version 9.4.57.v20241219 * Security fixes: + CVE-2024-6763, bsc#1231652: the HttpURI class does insufficient validation on the authority segment of a URI + CVE-2024-13009, bsc#1243271: Gzip Request Body Buffer Corruption * Changes: + #12268 - IteratingCallback may iterate too much when process() returns Action.IDLE + #12648 - Backport improved handling of bad Gzip content (and Gzip Exceptions) + #12532 - Backport of deprecation of UserInfo on URI (in violation of RFC2616 spec)- Upgrade to version 9.4.56.v20240826 * Security fixes: + CVE-2024-8184, bsc#1231651, ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks * Changes: + #12201 backport ThreadLimitHandler improvements from Jetty 12 + #11938 - Updating URL refs from eclipse.org/jetty and eclipse.dev/jetty to jetty.org (including XML dtd references) + #10805 - Jetty response with an invalid HTTP2 packet if the client set the hpack table size as 0- Upgrade to version 9.4.54.v20240208 * Security fixes + CVE-2024-22201, bsc#1220437: HTTP/2 connection not closed after idle timeout when TCP congested * Other changes + #1256 DoSFilter leaks USER_AUTH entries + #11389 Strip default ports on ws/wss scheme uris too- Upgrade to version 9.4.53.v20231009 * Fixes of 9.4.53.v20231009 + CVE-2023-44487, bsc#1216169 + CVE-2023-36478, bsc#1216162 + #10679 - backport HTTP/2 rate control from Jetty 10.0.x + #10573 - backport hpack improvements from Jetty 10.0.x + #10546 - backport jetty-http Huffman encoders/decoders from Jetty 10.0.x * Fixes of 9.4.52.v20230823 + #10352 - Jetty accepts "+" prefixed value in Content-Length (CVE-2023-40167, bsc#1215417) + #10337 - SizeLimitHandler does not enforce 0 responseLimit + #10169 - make sure that a ServiceLoader is retrieved before iterating + #10066 - Allow SAXParserFactory or SAXParser to be configured in Jetty's XmlParser class - Allows for GHSA-58qw-p7qm-5rvh workaround + #9887 - Deprecate CGI Servlet (CVE-2023-36479, bsc#1215415) + #9716 - Deprecate PushSessionCacheFilter + #9660 - OpenId Revoked authentication allows one request (CVE-2023-41900, bsc#1215416) + #9476 - onCompleteFailure called multiple times- Reproducible builds: use SOURCE_DATE_EPOCH for timestamp- Update to version 9.4.51.v20230217 * Fixes of 9.4.49.v20220914: + #8578 - getRequestURL can append "null" if getRequestURI is unspecified in an authority-form request-target + #8493 - Review HTTP client feature setRemoveIdleDestinations * Fixes of 9.4.50.v20221201: + #8774 - Added SizeLimitHandler + #8678 - Jetty client is not responding to GO_AWAY packet received from (Jetty) Server and continue to send traffic on same connection * Fixes of 9.4.51.v20230217: + #9352 - Update / Fix CookieCutter + #9345 - Backport Multipart Fix for CVE-2023-26048, bsc#1210620 + #9352 - Backport Cookie Parsing Fix for CVE-2023-26049, bsc#1210621- Upgrade to version 9.4.48.v20220622 * Fixes + #8184 - All suffix globs except first fail to match if path has "." character in prefix section + #8145 - RegexPathSpec backport of optional group name/info lookup if regex fails + #8088 - Add option to configure exitVm on ShutdownMonitor from System properties + #8067 - Wall time usage in DoSFilter RateTracker results in false positive alert + #8014 - Review HttpRequest URI construction (Resolves CVE-2022-2047, bsc#1201317) + #7976 - Add TRANSFER_ENCODING violation for MultiPart RFC7578 parser + #7947 - Improved PathSpec handling for servletName & pathInfo + #7935 - Review HTTP/2 error handling (Resolves CVE-2022-2048, bsc#1201316) + #7918 - PathMappings.asPathSpec does not allow root ServletPathSpec + #7863 - Default servlet drops first accept-encoding header if there is more than one. + #7858 - GZipHandler does not play nice with other handlers in HandlerCollection + #7837 - Fix StatisticsHandler in the case a Handler throws exception + #7809 - Jetty 9.4.x 7801 duplicate set session cookies + #7748 - Allow overriding of url-pattern mapping in ServletContextHandler to allow for regex or uri-template matching- Upgrade to version 9.4.46.v20220328 * Changes + Option --write-module-graph produces wrong .dot file + ArrayTrie getBest fails to match the empty string entry in certain cases + Interrupt flag is not always cleared in between requests + Gzip compression not working for multipart/form-data when added to the allowed list using addIncludedMimeTypes. + Miconfigured headerCacheSize in can result in IllegalArgumentException + HttpServletResponse.encodeURL not working for URLs starting with ../- Build with java source and target levels 8 - Fix javadoc generation on JDK >= 13- Make importing of package sun.misc optional since not all jdk versions export it- Update to version 9.4.43.v20210629 * Fix: bsc#1188438, CVE-2021-34429 * Changes: + Improve alias checking in PathResource + java.nio.ReadOnlyBufferException + Deprecate support for UTF16 encoding in URIs + Update to spifly 1.3.3 + Update to asm 9.1- Update to version 9.4.42.v20210604 * Fix: bsc#1187117, CVE-2021-28169- Update to version 9.4.40.v20210413 * Fix: bsc#1184367, CVE-2021-28165 - jetty server high CPU when client send data length > 17408 * Fix: bsc#1184368, CVE-2021-28164 - Normalize ambiguous URIs * Fix: bsc#1184366, CVE-2021-28163 - Exclude webapps directory from deployment scan * Improve handling of unconsumed content * Jetty start.jar always reports jetty.tag.version as master * HttpConnection.getBytesIn() incorrect for requests with chunked content * SslConnection compacting- Upgrade to upstream version 9.4.38.v20210224 * Fixes bsc#1182898, CVE-2020-27223- Upgrade to upstream version 9.4.35.v20201120 * Fixes bsc#1179727, CVE-2020-27218- Upgrade to upstream version 9.4.30.v20200611- Upgrade to upstream version 9.4.27.v20200227- Removed patch: * jetty-annotations-asm6.patch + not needed when building against ASM7- Initial packaging of the websocket submodules of jetty 9.4.22.v20191022h04-ch1d 17730379849.4.58-150200.3.37.19.4.58.v202508149.4.58.v202508149.4.58jettywebsocket-servlet.jarjetty-websocket-websocket-servlet.xmljettywebsocket-servlet.pom/usr/share/java//usr/share/java/jetty//usr/share/maven-metadata//usr/share/maven-poms//usr/share/maven-poms/jetty/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:43078/SUSE_SLE-15-SP2_Update/a8f464d19a81ea1de0a5be8421554026-jetty-minimal.SUSE_SLE-15-SP2_Update:jetty-websocketdrpmxz5noarch-suse-linuxdirectoryASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract Zip archive data, at least v2.0 to extract)XML 1.0 document, ASCII textPPPRRRR+?Za/*XL0_utf-8c2ce09349374a72d1ad83abb83c7fadd0d77e10596f6771176196bc3409db483? 7zXZ !t/$%Z]"k%'lJYyNF?56#{1Xox ُt4w/71.ߤstΝE*6WDR0/ =ʕj(!UN?wpF4ʸcLbQnD VYR3`^EH@jGg^ɔ씞Z#s@[|cmaꙊ6VwU\jޣ]^ M (;) z/z_yV.u׼%gjډ"Y)f-/\QICuv伙HFU"^C7kkjqBs=>!/])8n{iUDEY4.#aU@fMGm\!sQScڋxscbmG$<ϋgr6^٪v8E@6M G_dW`y7 ZBaU rDGЛh:[Qx,1X,!9Bn&nL0&nfŬZ VA%tFqE_]^RLI/QN۶┴$wJQG-X8 })U%0DO/N|L+H_%*|)sQw1SRg_OZ@|}l]S]%R8c^/jD>#o#؉wV1oFMXLcpQ%Q)\s2|%yo*<-X,vZwa6~R6UJ2J~^:8طŷ>==iN\Q^bSNJwn"%tgkCGj416fG^WgLߗYZyi@1aU)QuxXJ}:VlfYI ͡PB=1b'wv0"rS)_lWmN|$ lK#1J٧$VlҺQ`sDa JD#4A>njg E f8~$X QmFb+^$_c+]eU@3eZoiQ_W:b|+&"ެ,-ʪ<4QXB`SXM'aD1:{_WAl"~رT'u aXc1@K՗3%]Bv#7 &;ٜ\>{LJ|~zhjv72{\9岓C{\4>"{nO̒*5-i6o 6@Le}+C  :ǽWj, pR]mҁ))c x6S>@_20S<%dO| t &pqڥv{h&fT3cLnsaL{MM'@_I+`EٖQj^zƠRBF(%~X;C|R/Ľ;gP`3\-ʩڂdnڝ66b`QƏЂPՠr+`0R(ρ_:.8y~j麤>(F=Q,KRUcw] y!ۨ9iE@߷Ⱥ|FI̬7l*]}lI?Om~׋@z<3\`!;;tAmq ҄V0` @nkhGT =ų$mxuݺA%PchOM{P d{2dkǃAĔxto)#7&l͆a3ܰ4\Њ]XI"_Zz[GB9aBKj9Gll_~:2ћtQ&ԭ/!%4|9DUNoұS NjnPmUWmx\,>/. `LS9a\dA9آgvѠ ݜwi/2_(e& B NYdFvn(V!'+=Bsnªwwܳ6t>" ,qRA`+:ޯz8J~қH/ۢ <Ս,W7Mȶo_SwgD3Q/0ԓʹ&^]6=E@a7#]2g;&0d ssUM"Adh !a#АuD<}!,-"`SCd5nvʹ+*bGBXͬ6ՐUt5`2*R@mޟJB[۩^!ͣh7C.AEuiTÄ12qaoC 's~Ű~kJ5qd3{me!7ZJueRE6M&&$Y 2;4;{;sU |g˄vo#) $S|~ L-.6>L+bձZz8rCZ֙e۷Řf3N302{mV4RKwjZdm3L? g޼E+l[I")X3V y3edvG<1{}TmI׼NYuqȁ\VQeJ>c_L>쭤1_G<ȐN~=Us;c4!]{w= &ڡ0J3kn֭R3gWvo}压*Nz a(xl 580JSm; /`by M<7M!&OJ+n}'E.BՔԉZ#m?2ac F?s%a/ dtSO(kJ՛6;cdդ`_L6{},uV6Z{~Cگ~[>vZp ω&8%0]=I(Fqi}ǟGam Q"y1/Q1KGLpooYyti]X=.g5SOۺ>ػ@, ײaQ *)[45%D''\<~T0S'$5L#CSA`aIRnMw`R揼GE|f>nҳ1mz5Rf=%(iq;U2hZ 8_0D^R֫?qk${Cؤc, ^hӮzz2SPf퓛s3W-6mC[H#v ˚`&ҸrnBJ|E/FN=y/sF|M1P]KJOWwSmWT>[en(P5-LӺa7%$M $К7|ց1Ƭ f'|}%2_Oơ!cl|j~Kq-QapD\=3qR,Ue;VS}WOAZL7$?bO~AacBL%sm}sq`r[ue)7afY"~X,˕; m@#.ypJP o\`O7AR1AӪ1r㴦:sF0m*APnf؄n8y\zێ9oTlKuErcͨ e@n H;P-4d'qʩg:$'?NȾnu^Ҏ/SXI(ܡc^fXnO3 ,:$ugz3G9y7W9b-l@["?PlgG\yJ565rOh6UFXתcǨ!{k 5_(F)Mō2,d~ I4SL[aWbX\h O.@\= T)TFbi$r!n#o`NIḽ̌]qw3c_PBE`[JD: +F5q 4fzD/y˨,s7R]-W ǦDBu'4\D\aqA[]J QתpI%%/YauVSciѪ,EkFȱ3'2p`K{i-f &X G*:ȘN >K] هu.T<xV Di:&z;9%~1Fl;(2"bPSXzK+1 S9tHo{ACghKanA~8~ m/ "޳G]ƌ%~|Lk{$Zgۼ6k솙4pgWG8kwʂ>8hAvtƨ}cMLz8pq7GcҊ|pk?׃yp׽+^2)#U/7BR F% ~Vc֛Б'% of;W ^]Օ\cDp!VP]~Ҭ[W]<[( ~‡ BRuxK 1Њ|q/ou:Q=B6#5#gX&QW~7/RbK##>2-sDKTN0XߞTui9lIڞuxdݡ$i/:K3RxBյbnA'/H YZ