JBoss Enterprise Application Platform 7.0 Update 01 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 7 have been discontinued and replaced with updates delivered on a repeating schedule, targeting a new release every 6 weeks.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

For more information see the following Red Hat Knowledgebase articles: Maintenance Release Changes in EAP 6.2+ and Updated Patch Management with EAP 6.2+

This update includes fixes for the following security related issues:

IDComponentSummary
CVE-2016-2141ClusteringAdd authorization checks by default on JGroups message receipt

This update includes the following bug fixes or changes:
IDComponentSummary
Content from issues.jboss.org is not included.JBEAP-2946ActiveMQException on subscriber during failback on replication
Content from issues.jboss.org is not included.JBEAP-4242ActiveMQFix LargeMessage replication through LargeMessage.copy (Redistribution, Divert and DLQ transfer)
Content from issues.jboss.org is not included.JBEAP-3998ActiveMQLive does not become active after failback in colocated replicated toplogy
Content from issues.jboss.org is not included.JBEAP-4225ActiveMQPossible lost message over Failover/Failback using regular JMS Transactions
Content from issues.jboss.org is not included.JBEAP-3468ActiveMQSetting of non-existing factory class to connector service can cause ActiveMQ crash
Content from issues.jboss.org is not included.JBEAP-4659ClusteringBackported https://issues.jboss.org/browse/JGRP-2033 to 3.6 branch - UNICAST2, FlowControl
Content from issues.jboss.org is not included.JBEAP-4654ClusteringGroupRequest: moved checkCompletion() into lock scope
Content from issues.jboss.org is not included.JBEAP-4646ClusteringInfinispanSessionManager#getLocalSessions should only return sessions with current node locality
Content from issues.jboss.org is not included.JBEAP-4660ClusteringJGRP-2035 Revert "pmd:UseProperClassLoader - Use Proper Class Loader"
Content from issues.jboss.org is not included.JBEAP-4662ClusteringMerge remote-tracking branch 'origin/3.6' into 3.6: purge Thread.currentThread().getContextClassLoader();
Content from issues.jboss.org is not included.JBEAP-4655ClusteringNot blocking forever if wait_time_ms == 0
Content from issues.jboss.org is not included.JBEAP-4661ClusteringParseInitialHosts now returns an empty list if prop is null
Content from issues.jboss.org is not included.JBEAP-4657ClusteringReplaced Util.object{To,From}Buffer() with Util.streamableToBuffer()
Content from issues.jboss.org is not included.JBEAP-4656ClusteringRequest.setListener() now returns NotifyingFuture instead of Request
Content from issues.jboss.org is not included.JBEAP-4658ClusteringTOA logs too much at DEBUG level
Content from issues.jboss.org is not included.JBEAP-4386Clusteringsession.invalidate() behavior not conform Servlet specification in HA profile
Content from issues.jboss.org is not included.JBEAP-4574Domain ManagementEAP 7 with management leaks small portions of memory when delay between requests is large resulting in management becoming unavailable after several days.
Content from issues.jboss.org is not included.JBEAP-4370Domain ManagementMissing services for outbound socket bindings on the HC
Content from issues.jboss.org is not included.JBEAP-3603Domain ManagementWeb console authentication when LDAP is used as credentials store doesn't accept passwords with non-ascii characters
Content from issues.jboss.org is not included.JBEAP-4434Domain Managementcan't start server with configuration file from EAP 6.4.7 (and above)
Content from issues.jboss.org is not included.JBEAP-3114EJBDeadlock in EJB client
Content from issues.jboss.org is not included.JBEAP-4167EJBServer is unable to invoke @Timeout method after 10 methods are called on Asynchronous bean on IBM JDK
Content from issues.jboss.org is not included.JBEAP-3708HibernateHHH-10563: Significant String use/duplication associated with subselect fetch
Content from issues.jboss.org is not included.JBEAP-3811JCADifficult to identify datasource with wrong credentials if security-domain is used
Content from issues.jboss.org is not included.JBEAP-2895JCASpecial logging for jta=false data sources
Content from issues.jboss.org is not included.JBEAP-3944JCAlist driven ExceptionSorter, StaleConnectionChecker
Content from issues.jboss.org is not included.JBEAP-4588JMSWeb Console - Messaging - Broadcast should allow to add optional field if there is other required field other than Name
Content from issues.jboss.org is not included.JBEAP-4389JMXSAR deployer uses wrong MBean class to resolve source Method for property injection
Content from issues.jboss.org is not included.JBEAP-4101LoggingLogContexts are not removed for ear subdeployments
Content from issues.jboss.org is not included.JBEAP-2058Maven RepositoryPOM files in EAP 7.0 Maven repository fails to validate: resteasy artifacts
Content from issues.jboss.org is not included.JBEAP-2057Maven RepositoryPOM files in EAP 7.0 Maven repository fails to validate: jackson & resteasy artifacts
Content from issues.jboss.org is not included.JBEAP-4542Patchingageout-history does not report failures
Content from issues.jboss.org is not included.JBEAP-2669Patchinginstalling CP over one-off fails if the modules patched by the one-off are not patched in the CP
Content from issues.jboss.org is not included.JBEAP-4708RESTCannot remove property from ClientWebTarget
Content from issues.jboss.org is not included.JBEAP-4707RESTContainerRequestContext setRequestUri doesn't clear previous query parameters
Content from issues.jboss.org is not included.JBEAP-4694RESTDocs: Section 26.1. Exception Mappers needs correction
Content from issues.jboss.org is not included.JBEAP-4692RESTEnhance javadoc for deprecated classes/interfaces/methods/etc
Content from issues.jboss.org is not included.JBEAP-4693RESTFormUrlEncodedProvider ignores charset parameter
Content from issues.jboss.org is not included.JBEAP-4710RESTInstances built from org.jboss.resteasy.client.jaxrs.internal.ClientWebTarget must inherit of a snaphot of the parent configuration
Content from issues.jboss.org is not included.JBEAP-4699RESTIssues with moving from deprecated RestEasy client code to new implementation
Content from issues.jboss.org is not included.JBEAP-4703RESTJAX-RS component must not be registered more than once on javax.ws.rs.core.Configurable instances
Content from issues.jboss.org is not included.JBEAP-4712RESTNewCookieHeaderDelegate throws if NewCookie value is null
Content from issues.jboss.org is not included.JBEAP-4697RESTNo error is thrown if the same class is present in both Application.getClasses() and Application.getSingletons()
Content from issues.jboss.org is not included.JBEAP-4696RESTOAuth 2.0 AuthenticationServerValve fails for user passwords containing colon character
Content from issues.jboss.org is not included.JBEAP-4695RESTOpposite behaviour of AsyncResponse.setTimeout with <= 0 values.
Content from issues.jboss.org is not included.JBEAP-2847RESTRESTEasy should have some Provider to produce primitive types without @Produces annotation
Content from issues.jboss.org is not included.JBEAP-4719RESTRegisterBuiltin globbles up stack traces
Content from issues.jboss.org is not included.JBEAP-2446RESTResponseObjectTest failing when using ProxyBuilder
Content from issues.jboss.org is not included.JBEAP-4705RESTResteasy processes If-Modified-Since header even when If-None-Match header is present
Content from issues.jboss.org is not included.JBEAP-3567RESTResteasy uses cdi-api 1.1 (or 1.0) which is not in sync with cdi-api 1.2 used in EAP
Content from issues.jboss.org is not included.JBEAP-1047RESTResteasy yaml provider - ReaderException: Failed to decode Yaml
Content from issues.jboss.org is not included.JBEAP-3197RESTResteasyClientProxy class should be deprecated
Content from issues.jboss.org is not included.JBEAP-4706RESTResteasyProviderFactory.registerProviderInstance does not always take priority into account
Content from issues.jboss.org is not included.JBEAP-4709RESTSupport Java generic wildcard types
Content from issues.jboss.org is not included.JBEAP-4700RESTSupport for polymorphic sub-resource locators - "casting" client proxies
Content from issues.jboss.org is not included.JBEAP-4701RESTUnable to find contextual data of type: javax.ws.rs.container.ResourceInfo when using ReadListener
Content from issues.jboss.org is not included.JBEAP-4698RESTUriInfo#getPath() is missing trailing slash
Content from issues.jboss.org is not included.JBEAP-4711RESTUriInfo.getQueryParameters() should return an immutable map
Content from issues.jboss.org is not included.JBEAP-4713RESTWildcardType support to org.jboss.resteasy.util.Types
Content from issues.jboss.org is not included.JBEAP-1610RPMNo eap7 conf file in /etc/<srvc_name>/<srvc_name>.conf
Content from issues.jboss.org is not included.JBEAP-3097RemotingToo many invocations to a remote EJB from multiple threads cause infinite wait
Content from issues.jboss.org is not included.JBEAP-3812SecurityFlagging of invalid login credential for datasource is inconsistent - No SecurityContext set when creating subject
Content from issues.jboss.org is not included.JBEAP-4562SecurityPicketLink's Partition Manager fails due to several permission failures when running with Security Manager enabled
Content from issues.jboss.org is not included.JBEAP-4060SecurityPrevent inserting malicious assertion
Content from issues.jboss.org is not included.JBEAP-4625ServerDeadlock during server start
Content from issues.jboss.org is not included.JBEAP-3044ServerEditing of default deployment scanner's relative-to attribute can cause server crash
Content from issues.jboss.org is not included.JBEAP-4624Transactionsorg.infinispan.transaction.xa.GlobalTransaction objects are not cleared properly
Content from issues.jboss.org is not included.JBEAP-5079Web (Undertow)Allow file system watch to be disabled in PathResourceManager
Content from issues.jboss.org is not included.JBEAP-4820Web (Undertow)ArrayIndexOutOfBoundsException when calling to addExchangeCompleteListener
Content from issues.jboss.org is not included.JBEAP-4816Web (Undertow)Enabling PerMessageDeflateHandshake creates corrupt message when message size is > 300K range
Content from issues.jboss.org is not included.JBEAP-4844Web (Undertow)Error detection for when exchange is resumed and dispatched is wrong
Content from issues.jboss.org is not included.JBEAP-4814Web (Undertow)NPE in io.undertow.server.Connectors.terminateResponse
Content from issues.jboss.org is not included.JBEAP-4819Web (Undertow)NullPointerException :: UT005018: Exception invoking close listener
Content from issues.jboss.org is not included.JBEAP-4822Web (Undertow)Potential race when resuming writes in AbstractFramedStreamSinkChannel
Content from issues.jboss.org is not included.JBEAP-4334Web (Undertow)Predicate handlers that run before the servlet initial handler can't set servlet request attributes
Content from issues.jboss.org is not included.JBEAP-4813Web (Undertow)Protocol name for HTTP/2 connections is reported as HTTP/1.1
Content from issues.jboss.org is not included.JBEAP-4824Web (Undertow)Randomly ServerSentEventConnection$SseWriteListener.handleEvent goes into an infinite loop
Content from issues.jboss.org is not included.JBEAP-4848Web (Undertow)Undertow does not call the init() method of servlets that implements SingleThreadModel even when load-on-startup is set
Content from issues.jboss.org is not included.JBEAP-4436Web (Undertow)Undertow mod_cluster proxy: AjpClientConnection: XNIO001007: java.lang.NullPointerException
Content from issues.jboss.org is not included.JBEAP-4817Web (Undertow)Wildfly 10 (& 9) websocket producing massive logs on websocket error (async send only)
Content from issues.jboss.org is not included.JBEAP-3277Web (Undertow)[WebToUndertow] Migrating access log valve results always in migration warning
Content from issues.jboss.org is not included.JBEAP-4256Web (Undertow)add trace logging to the SSO code in undertow
Content from issues.jboss.org is not included.JBEAP-4255Web (Undertow)add trace logging to the security constraint processing in wildfly/undertow
Content from issues.jboss.org is not included.JBEAP-4818Web (Undertow)java.lang.NumberFormatException when extracting X-Forwarded-Port in ProxyPeerAddressHandler
Content from issues.jboss.org is not included.JBEAP-4815Web (Undertow)mod_cluster does not advertise immediatly on startup, but waits for advertise_frequency
Content from issues.jboss.org is not included.JBEAP-4845Web (Undertow)receiveFullBytes callbacks may not be called on error with some protocols
Content from issues.jboss.org is not included.JBEAP-4093Web ConsoleApostrophes are not correctly displayed for French localization
Content from issues.jboss.org is not included.JBEAP-3898Web ConsoleBroken path text in deployment view
Content from issues.jboss.org is not included.JBEAP-3607Web ConsoleCaching breaks subsystem filtering in domain mode.
Content from issues.jboss.org is not included.JBEAP-3145Web ConsoleClosing of WSDL host expression resolver popup closes host interfaces application detail as well
Content from issues.jboss.org is not included.JBEAP-1382Web ConsoleConfusing error when reloading server
Content from issues.jboss.org is not included.JBEAP-4236Web ConsoleDeployment preview info doesn't change when disabled
Content from issues.jboss.org is not included.JBEAP-1949Web ConsoleEAP tour window doesnt respect window sizes
Content from issues.jboss.org is not included.JBEAP-3916Web ConsoleGraph Failure Origin does not show any values in Runtime screen of Transactions
Content from issues.jboss.org is not included.JBEAP-5078Web ConsoleHAL does not allow to manage different patching streams
Content from issues.jboss.org is not included.JBEAP-4902Web ConsoleImpossible to add server in domain using web console
Content from issues.jboss.org is not included.JBEAP-3394Web ConsoleIn application detail Back link always leads to first level of subsystem navigation
Content from issues.jboss.org is not included.JBEAP-3846Web ConsoleIn management model tool optional attributes are sometimes marked as required
Content from issues.jboss.org is not included.JBEAP-3940Web ConsoleIt is not possible to add deployment scanner in web console
Content from issues.jboss.org is not included.JBEAP-3032Web ConsoleIt should be possible to set relative-to when adding deployment scanner in web console
Content from issues.jboss.org is not included.JBEAP-4791Web ConsoleIt's not possible to add SAML handler with nonempty class-name attribute using web console
Content from issues.jboss.org is not included.JBEAP-4535Web ConsoleMessages and user elements in top right corner of web console aren't vertically aligned
Content from issues.jboss.org is not included.JBEAP-2323Web ConsoleMissing Button Borders on Deployment Configuration Screen
Content from issues.jboss.org is not included.JBEAP-4428Web ConsoleMissing favicon in web console
Content from issues.jboss.org is not included.JBEAP-4094Web ConsoleNon-functioning Korean localization option in web console
Content from issues.jboss.org is not included.JBEAP-4509Web ConsoleOld type of url in template for Microsoft SQLServer datasource in datasource wizard
Content from issues.jboss.org is not included.JBEAP-4051Web ConsolePatch Management doesn't show the "Latest Applied Patch" correctly.
Content from issues.jboss.org is not included.JBEAP-4894Web ConsolePatch management page is missing pending restart state info
Content from issues.jboss.org is not included.JBEAP-2137Web ConsolePlease remove empty option from Batch subsystem thread pool keepalive unit dropdown.
Content from issues.jboss.org is not included.JBEAP-3899Web ConsoleSimplify returning to upper level after going too deep in nested tree in management model view
Content from issues.jboss.org is not included.JBEAP-4534Web ConsoleTypo in heading of step 1/4 of Create XA Datasource wizard
Content from issues.jboss.org is not included.JBEAP-4806Web ConsoleUnable to create EJB3 bean pool with derive-size 'none'
Content from issues.jboss.org is not included.JBEAP-4839Web ConsoleUnable to undefine auth-method attribute of IIOP subsystem using web console
Content from issues.jboss.org is not included.JBEAP-4796Web ConsoleUnable to unset (in
Content from issues.jboss.org is not included.JBEAP-3923Web ConsoleVersion information dialog shows HAL version n/a
Content from issues.jboss.org is not included.JBEAP-4532Web ConsoleWeb Console - Messaging - Rename Connections to Cluster Connections in Messaging Clustering and provide more attributes
Content from issues.jboss.org is not included.JBEAP-2553Web ConsoleWeb Console is not centered in Internet Explorer 11
Content from issues.jboss.org is not included.JBEAP-4688Web ConsoleWeb/HTTP - Undertow connectors metrics doesn't work in domain

Note: This update should only be applied to installer or zip-based installations.

To apply this update using the CLI on Unix-based systems, run the following command from JBOSS_HOME:

bin/jboss-cli.sh "patch apply path/to/jboss-eap-7.0.1-patch.zip"

To apply this update using the CLI on Windows-based systems, run the following command from JBOSS_HOME:

bin\jboss-cli.bat "patch apply path\to\jboss-eap-7.0.1-patch.zip"

These commands will apply the update to the installation that contains the CLI script. Other scenarios and use of the management console are covered in the This content is not included.JBoss EAP 7.0 Patching And Upgrading Guide

Category
Components
Article Type