modules/enterprise/server/appserver/pom.xml | 11 ++++++++++ modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml | 11 ++++++++++ pom.xml | 2 - 3 files changed, 23 insertions(+), 1 deletion(-)
New commits: commit 4fa9f082b2e011b3bde9defe1021248148c4ad40 Author: Simeon Pinder spinder@fulliautomatix.conchfritter.com Date: Tue Jul 23 15:02:09 2013 -0400
[BZ 984649] fix module metadata.
diff --git a/modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml b/modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml index 145e3af..82ff294 100644 --- a/modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml +++ b/modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml @@ -290,7 +290,7 @@ <delete file="${jboss.home}/modules/system/layers/base/org/jgroups/main/jgroups-${jgroups.initial.version}.jar.index" /> <!-- Update the module metadata to the patched version --> <replace file="${jboss.home}/modules/system/layers/base/org/jgroups/main/module.xml" - token="jgroups-${jgroups.initial.version}.jar" value="${jgroups.patch.version}"/> + token="jgroups-${jgroups.initial.version}.jar" value="jgroups-${jgroups.patch.version}.jar"/> <!-- Copy in patched version --> <copy file="${settings.localRepository}/org/jgroups/jgroups/${jgroups.patch.version}/jgroups-${jgroups.patch.version}.jar" toDir="${jboss.home}/modules/system/layers/base/org/jgroups/main" verbose="true"/>
commit 8203c669b3b3ba5ed5c3ef27f051220da93ea868 Author: Simeon Pinder spinder@fulliautomatix.conchfritter.com Date: Tue Jul 23 13:37:32 2013 -0400
Upgrading richfaces to latest patched version.
diff --git a/pom.xml b/pom.xml index 3662bc7..f909033 100644 --- a/pom.xml +++ b/pom.xml @@ -135,7 +135,7 @@ <postgresql.version>9.2-1002.jdbc4</postgresql.version> <h2.version>1.2.139</h2.version> <jtds.version>1.2.2</jtds.version> - <richfaces.version>3.3.3.Final</richfaces.version> + <richfaces.version>3.3.4.Final</richfaces.version> <jline.version>0.9.94</jline.version> <sigar.version>1.6.5.132-5</sigar.version> <sigar.zip.version>1.6.5</sigar.zip.version>
commit caeb7a5c832334b74f76a265c8028a5697152dda Author: Simeon Pinder spinder@fulliautomatix.conchfritter.com Date: Tue Jul 23 12:28:52 2013 -0400
[BZ 984649] update jgroups usage to latest patched version.
diff --git a/modules/enterprise/server/appserver/pom.xml b/modules/enterprise/server/appserver/pom.xml index 0a61138..f1a4c7b 100644 --- a/modules/enterprise/server/appserver/pom.xml +++ b/modules/enterprise/server/appserver/pom.xml @@ -19,6 +19,8 @@
<properties> <rhq.dev.data.dir>${rhq.rootDir}/rhq-data</rhq.dev.data.dir> + <jgroups.initial.version>3.2.7.Final</jgroups.initial.version> + <jgroups.patch.version>3.2.10.Final</jgroups.patch.version> </properties>
<dependencies> @@ -72,6 +74,13 @@ <groupId>org.codehaus.groovy</groupId> <artifactId>groovy-all</artifactId> </dependency> + + <!-- Pull down the patched version of JGroups. See CVE 2013-4112 and BZ 984365 --> + <dependency> + <groupId>org.jgroups</groupId> + <artifactId>jgroups</artifactId> + <version>${jgroups.patch.version}</version> + </dependency> </dependencies>
<build> @@ -157,6 +166,8 @@ <property name="rhq.server.http.port" value="${rhq.server.http.port}" /> <property name="rhq.server.https.port" value="${rhq.server.https.port}" /> <property name="rhq.sync.endpoint-address" value="${rhq.sync.endpoint-address}" /> + <property name="jgroups.initial.version" value="${jgroups.initial.version}" /> + <property name="jgroups.patch.version" value="${jgroups.patch.version}" /> </ant> </target> </configuration> diff --git a/modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml b/modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml index a81b6cd..145e3af 100644 --- a/modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml +++ b/modules/enterprise/server/appserver/src/main/scripts/rhq-container.build.xml @@ -283,6 +283,17 @@ </resources> </module> ]]></echo> + + <echo>Updating JGroups module component for EAP to ${jgroups.patch.version}</echo> + <!-- Remove the unpatched version --> + <delete file="${jboss.home}/modules/system/layers/base/org/jgroups/main/jgroups-${jgroups.initial.version}.jar" /> + <delete file="${jboss.home}/modules/system/layers/base/org/jgroups/main/jgroups-${jgroups.initial.version}.jar.index" /> + <!-- Update the module metadata to the patched version --> + <replace file="${jboss.home}/modules/system/layers/base/org/jgroups/main/module.xml" + token="jgroups-${jgroups.initial.version}.jar" value="${jgroups.patch.version}"/> + <!-- Copy in patched version --> + <copy file="${settings.localRepository}/org/jgroups/jgroups/${jgroups.patch.version}/jgroups-${jgroups.patch.version}.jar" + toDir="${jboss.home}/modules/system/layers/base/org/jgroups/main" verbose="true"/>
<echo>Generate SSL key for RHQ server - 128-bit key that expires in 20 years</echo> <property name="jboss.conf.dir" location="${jboss.home}/standalone/configuration" />
rhq-commits@lists.fedorahosted.org