Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fresh solr 2.9.2 oss #766

Open
wants to merge 58 commits into
base: develop-2.9
Choose a base branch
from

Commits on Jun 21, 2018

  1. grab-solr: stop all unsafety

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    7d64c5d View commit details
    Browse the repository at this point in the history
  2. solr build script changes

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    982efef View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    a42e861 View commit details
    Browse the repository at this point in the history
  4. tools: use sha512

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    ba2aad5 View commit details
    Browse the repository at this point in the history
  5. Fix solr startup

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    0107b1d View commit details
    Browse the repository at this point in the history
  6. minor yz_solr_proc fixes

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    bd2adca View commit details
    Browse the repository at this point in the history
  7. maven/idea files

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    681d671 View commit details
    Browse the repository at this point in the history
  8. ant build.xml for java files

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    251f7e5 View commit details
    Browse the repository at this point in the history
  9. fix SimpleQueryExample

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    963363b View commit details
    Browse the repository at this point in the history
  10. Configuration menu
    Copy the full SHA
    9df8638 View commit details
    Browse the repository at this point in the history
  11. Configuration menu
    Copy the full SHA
    49a6d49 View commit details
    Browse the repository at this point in the history
  12. Configuration menu
    Copy the full SHA
    16e6197 View commit details
    Browse the repository at this point in the history
  13. Configuration menu
    Copy the full SHA
    0fae1b0 View commit details
    Browse the repository at this point in the history
  14. fix solr logging

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    0833513 View commit details
    Browse the repository at this point in the history
  15. Configuration menu
    Copy the full SHA
    67516c7 View commit details
    Browse the repository at this point in the history
  16. fix jetty configuration

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    f4d7652 View commit details
    Browse the repository at this point in the history
  17. Configuration menu
    Copy the full SHA
    f07af4a View commit details
    Browse the repository at this point in the history
  18. Configuration menu
    Copy the full SHA
    4925e24 View commit details
    Browse the repository at this point in the history
  19. fix solr version in build.xml

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    091498d View commit details
    Browse the repository at this point in the history
  20. make love not war

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    05f0bdf View commit details
    Browse the repository at this point in the history
  21. make sure custom jars exist

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    ffdafce View commit details
    Browse the repository at this point in the history
  22. precompiled jars

    llelf committed Jun 21, 2018
    Configuration menu
    Copy the full SHA
    f533136 View commit details
    Browse the repository at this point in the history

Commits on Jul 2, 2018

  1. yz_schema: allow v1.6

    llelf committed Jul 2, 2018
    Configuration menu
    Copy the full SHA
    2c8d746 View commit details
    Browse the repository at this point in the history

Commits on Jul 9, 2018

  1. grab-solr: download solr from archives

    7.4 came ⇒ 7.3.1 disappeared everywhere!
    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    88c5231 View commit details
    Browse the repository at this point in the history
  2. minor java code changes

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    5418cd5 View commit details
    Browse the repository at this point in the history
  3. trivial Monitor.java change

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    8acbbaf View commit details
    Browse the repository at this point in the history
  4. modernize SimpleQueryExample

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    871ec25 View commit details
    Browse the repository at this point in the history
  5. SIMPLE rename back

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    1f15141 View commit details
    Browse the repository at this point in the history
  6. java changes stash

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    e93feb5 View commit details
    Browse the repository at this point in the history
  7. Configuration menu
    Copy the full SHA
    22d8a41 View commit details
    Browse the repository at this point in the history
  8. Configuration menu
    Copy the full SHA
    de5cb6b View commit details
    Browse the repository at this point in the history
  9. Configuration menu
    Copy the full SHA
    d4f4925 View commit details
    Browse the repository at this point in the history
  10. Configuration menu
    Copy the full SHA
    dd4cb0b View commit details
    Browse the repository at this point in the history
  11. Revert "set yz.lib.dir correctly (XXX needed?)"

    This reverts commit 0fb1d04d1cbd410d6ec7cb6373fdbcb51f4a96f2.
    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    9cbd665 View commit details
    Browse the repository at this point in the history
  12. kill outdated java options

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    682ebee View commit details
    Browse the repository at this point in the history
  13. Configuration menu
    Copy the full SHA
    3027082 View commit details
    Browse the repository at this point in the history
  14. tooling

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    0834ca4 View commit details
    Browse the repository at this point in the history
  15. don't use fancy xml in jetty configs (todo: actually DO use it)

    this is from a bug-hunt (which was in a entirely different place)
    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    d568288 View commit details
    Browse the repository at this point in the history
  16. add (java) package-info

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    5936eb3 View commit details
    Browse the repository at this point in the history
  17. tools: remove bashisms

    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    110c517 View commit details
    Browse the repository at this point in the history
  18. Configuration menu
    Copy the full SHA
    4bc15b4 View commit details
    Browse the repository at this point in the history
  19. Configuration menu
    Copy the full SHA
    77fc2a9 View commit details
    Browse the repository at this point in the history
  20. tooling minor changes

    copy-jars
    llelf committed Jul 9, 2018
    Configuration menu
    Copy the full SHA
    d8b48d0 View commit details
    Browse the repository at this point in the history

Commits on Jul 10, 2018

  1. preliminary EntropyClient

    llelf committed Jul 10, 2018
    Configuration menu
    Copy the full SHA
    f82c552 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    c3ad477 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    56f062f View commit details
    Browse the repository at this point in the history
  4. tooling

    llelf committed Jul 10, 2018
    Configuration menu
    Copy the full SHA
    119e30f View commit details
    Browse the repository at this point in the history

Commits on Jul 20, 2018

  1. Configuration menu
    Copy the full SHA
    f686b9d View commit details
    Browse the repository at this point in the history
  2. “bump” version

    llelf committed Jul 20, 2018
    Configuration menu
    Copy the full SHA
    6c789d7 View commit details
    Browse the repository at this point in the history

Commits on Aug 6, 2018

  1. Configuration menu
    Copy the full SHA
    cf698d1 View commit details
    Browse the repository at this point in the history

Commits on Jan 8, 2019

  1. pass indent=false to solr

    llelf committed Jan 8, 2019
    Configuration menu
    Copy the full SHA
    9a934e5 View commit details
    Browse the repository at this point in the history

Commits on Mar 7, 2019

  1. [sec] yz xml extractor: prevent XXE attack

    XML External Entity attack
    
    1. if HTTP API is exposed:
    
      - read any file on the system — via /search/extract, the error message leaks
        file content;
    
      - send HTTP «GET /» request to any host — by PUT/POSTing text/xml document,
        or via /search/extract.  This is also likely riak DoS if the host is
        attacker-controlled.
    
    2. if PB API is exposed
    
      - send HTTP «GET /» request to any host — by PUT/POST, see above.
    
    Example request:
    
    <?xml version="1.0"?>
    <!DOCTYPE meow [
      <!ENTITY xxe2 SYSTEM "/etc/passwd">
      <!ENTITY xxe1 SYSTEM "http://host/ping-me">
    ]>
    <meow>&xxe1;</meow>
    llelf committed Mar 7, 2019
    Configuration menu
    Copy the full SHA
    f57ff77 View commit details
    Browse the repository at this point in the history
  2. [sec] http search: get rid of ‘yz-fprof’ header handling

    It doesn't check user-provided path in any way.
    This allows overriding any file on the system with riak permissions.
    llelf committed Mar 7, 2019
    Configuration menu
    Copy the full SHA
    8fc7727 View commit details
    Browse the repository at this point in the history
  3. Merge branch 'sec1' into fresh-solr

    Security fixes
    
    1. if HTTP API is exposed:
    
      - read any file on the system — via /search/extract, the error message leaks
        file content;
    
      - send HTTP «GET /» request to any host — by PUT/POSTing text/xml document,
        or via /search/extract.  This is also likely riak DoS if the host is
        attacker-controlled.
    
    2. if PB API is exposed:
    
      - send HTTP «GET /» request to any host — by PUT/POST, see above.
    
    3. if HTTP API is exposed:
    
      - override (with garbage) any file on the system with riak permissions.
    llelf committed Mar 7, 2019
    Configuration menu
    Copy the full SHA
    fdeffe7 View commit details
    Browse the repository at this point in the history

Commits on Jan 21, 2020

  1. Merge tag 'riak_kv-2.9.0p6' into fresh-solr+2.9.0p6

    Steven Joseph committed Jan 21, 2020
    Configuration menu
    Copy the full SHA
    f6d2238 View commit details
    Browse the repository at this point in the history

Commits on Jan 23, 2020

  1. fix: update test case for cuttlefish

    Steven Joseph committed Jan 23, 2020
    Configuration menu
    Copy the full SHA
    7988a2f View commit details
    Browse the repository at this point in the history

Commits on Feb 23, 2020

  1. Merge branch 'fresh-solr-2.9.0p6' into fresh-solr-2.9.1

    Steven Joseph committed Feb 23, 2020
    Configuration menu
    Copy the full SHA
    95a1bef View commit details
    Browse the repository at this point in the history

Commits on Apr 22, 2020

  1. fix: solr jvm opts test

    Steven Joseph committed Apr 22, 2020
    Configuration menu
    Copy the full SHA
    47894d5 View commit details
    Browse the repository at this point in the history