0.155
-------
MAMETesters Bugs Fixed
----------------------
- 01007: [Sound] (simpsons.c) simpsons: Some in-game samples such as
"maggie" and "that's my sister mister" sound bad. (Alex Jackson)
- 05705: [DIP/Input] (segas18.c) ddcrew: Player 3 buttons not working (Osso)
- 05700: [Graphics] (terracre.c) amazon, amatelas: lag/desync between
sprites and background (Alex Jackson)
- 03395: [Sound] (nmk16.c) macross2: Music emulation is not 100% perfect
(a balance issue) (trap15)
- 02422: [Sound] (nmk16.c) mustang: Sound communication might be incorrectly
implemented. (trap15)
- 02417: [Sound] (nmk16.c) NMK004 sound CPU is just (imperfectly) simulated
for now. (trap15)
- 01117: [Graphics] (nmk16.c) macross2: After some versions, I noticed a different
gfx overlap priority between hugest ships and weapon pickups in Macross2. (trap15)
- 05493: [Crash/Freeze] (itgambl2.c) All sets in itgambl2.c: Crash before OK
(Olivier Galibert)
- 05697: [DIP/Input] (flyball.c) All sets in flyball.c: Controls for Batter and
Pitcher are intertwined (hap)
- 05693: [Graphics] (ddragon3.c) wwfwfest: Wrestler Entrance does not show graphics
(hap)
- 05689: [Misc.] (williams.c) All sets in williams.c: Utility panel buttons not
working correctly compared to real game
- 05683: [Interface] SDL-based: -watchdog command not operable in SDLMAME (R. Belmont)
- 05681: [Crash/Freeze] SDL-based: Most Laserdisc CHD games either do not boot or
have other issues (R. Belmont)
- 05688: [Crash/Freeze] (psikyo4.c) hgkairak, hotgm4ev, hotgmck, hotgmck3, hotgmcki:
MAME crashes when enabling flip screen in psikyo4 games (Osso)
- 02124: [Graphics] (namconb1.c) nebulray, nebulrayj: Nebulas Ray is missing a rotation
effect in the first level (Phil Bennett)
- 05686: [Documentation] (model2.c) vcopa: missing relationship (Tafoid)
- 05685: [Documentation] (alg.c) maddog22: maddog22 is missing relationship with other
maddog2 sets (JWallace)
- 05676: [Sound] (eolith.c) candy: Loss of in-game sound (Wilbert Pol)
- 05675: [Color/Palette] (highvdeo.c) newmcard, record: Palette problems (David Haywood)
- 05666: [Crash/Freeze] (cswat.c) cswat: AddressSanitizer: heap-buffer-overflow with
-aviwrite (hap)
- 05350: [Core] Systems using M6809 with M6809_HOLD_LINE: CWAI doesn't acknowledge
interrupts while polling for them (hap)
- 05629: [Color/Palette] hangplt, hangpltu, thrilld: Voodoo 3D graphics have no palette
(Phil Bennett)
- 05637: [Crash/Freeze] (vegas.c) gauntdl, gauntdl24: Emulation hangs after initialization
(Phil Bennett)
- 05638: [Crash/Freeze] (seattle.c) vaportrx, vaportrxp: Emulation hangs during INIT
(Phil Bennett)
- 05636: [Sound] (vegas.c) gauntleg, gauntdl, carnevil and clones: Missing streaming
BGM/Sounds during gameplay (Phil Bennett)
- 05634: [Crash/Freeze] (tasman.c) All sets in tasman.c: [debug] Assertion in Debug
(Alex Jackson)
- 05644: [Graphics] (homerun.c) ganjaja: Line glitches at top of screen (hap)
- 05631: [Crash/Freeze] mquake.c, upscope.c: Crash shortly after start (Osso)
- 05633: [Crash/Freeze] (pcxt.c) tetriskr: [debug] Crash in Debug at start (crazyc)
- 00386: [Graphics] (battlera.c) battlera, bldwolf, bldwolfj: Sprites in the same player
where the black box with text that appears sometimes are printed in front of them.
(David Haywood)
- 00385: [Graphics] (battlera.c) battlera: When you are fighting against the first final
boss, you can see it even if it is under the water. (David Haywood)
Source Changes
--------------
-tourvis.c: Added version 5.3 BIOS to the Tourvision driver. [system11]
-m68kmake.c: change overlapping memcpy() to memmove() [Casper Ti. Vector]
-Changed set mpoker and driver to mgames. Also description from
Multi-Poker to Match Games accordingly with the official flyer.
http://flyers.arcade-museum.com/?page=thumbs&db=videodb&id=6500 In
fact, these are skill instead of poker games. Also added way more
documentation and some cosmetic fixes. [Roberto Fresca]
-Unknown Pac-Man gambling game: Rename and redefine the inputs to match
the behavior of both games. Added complete instructions to play the
stealth gambling game. [Roberto Fresca]
-Unknown Pac-Man gambling game: Added proper sound support. Rearranged
some inputs and hooked extra port. Found some DIP switches. Added
technical notes and instructions. Cleaned up the whole driver.
[Roberto Fresca]
-k053246_k053247_k055673.c: Make 8-bit-per-pixel ROM readback work;
hook up ROM readback properly in rungun.c; hook up registers properly
in tasman.c (sprite ROM tests pass now, still doesn't draw anything)
[Alex Jackson]
-fm2612: fixed missing dac channel on savestate load
[dink (FB Alpha project)]
-Added decryption support for Music Ball [Andreas Naive]
-speedbal.c: Give Music Ball it's own correct Bonus dipswitch settings.
Add dipswitch locations to Speed Ball & Music Ball. [Brian Troha]
-improve Funny Strip / Puck People protection simulation [iq_132]
-tatsumi.c: Fixed Cycle Warriors (set 1) hangs at boot. [MASH]
-k005289: fix off-by-one frequency; adds missing detune effect to
nemesis BGM [Alex Jackson]
-floppy: Handle half and quarter tracks [O. Galibert]
-williams.c - Added missing video board PROM to Joust 2 [Joe Magiera]
-flopimg: don't trash a bunch of memory when loading legacy floppies.
[R. Belmont]
-gcpinbal.c: Added PCB layout for Grand Cross Pinball
[Brian Troha, system11]
-ssv.c: Add PCB for the Storm Blade game rom board.
[Brian Troha, ShouTime]
-Laserdisc titles added and reorganised to include dumps from other
sources. ALG titles in particular have been heavily reorganised
[Dragon's Lair Project, J. Wallace]
-taito_b.c: Verified clock speeds for the East Technology's ET910000A
PCB used by Sel Feena and Ryu Jin. [system11]
-namconb1.c - Improved interrupt handling, fixing raster-effects (used
by nebulray and machbrkr) and nebulray test mode. [Phil Bennett]
-Implemented the Namco Custom 116 palette and raster IRQ controller as
a device, and hooked it up to the namcos1, namconb1 and namcofl
drivers [Alex Jackson]
-digfx.c: Make some members protected instead of private to be less
fascistic and more consistent with other device_interfaces. [Alex Jackson]
-SDL: update manpages [Cesare Falco]
-Allow use of external SQLite3 [Cesare Falco]
-coinmvga.c driver: Minor cleanup, new set added, and changed game
descriptions. [Roberto Fresca]
-msm5832: day of week is 0-6, not 1-7 [R. Belmont]
-galaxian.c: redumped atlantis2. [system11]
-Preliminary IGS029 protection simulation for mgcs: [Luca Elia]
fixes sound, dips and crash at game start.
-bwidow.c - Various changes: [Phil Bennett]
* Added address decoder PROMs to Gravitar and clones.
* Renamed ROMs to include correct part numbers and locations.
* Renamed set gravp to gravitar1.
-centiped.c - Various changes: [Phil Bennett]
* Made centtime the parent (this is actually revision 4)
* Renamed ROMs to include correct part numbers and locations.
* Added sync PROM to Warlords
-fuukifg2.c: Correct clock speeds for the Susume! Mile Smile / Go Go!
Mile Smile and Gyakuten!! Puzzle Bancho sets. [system11]
-added decryption for Gundam Wing: Endless Duel (SNES bootleg) [iq_132]
-floppy: Don't infloop in set_write_splice when there's no floppy
(fixes MT5672) [O. Galibert]
-mips3drc: Throw badcop exceptions on COP1 accesses while the COP1
status bit is not enabled [MarathonMan]
-segaybd.c: Give the new Power Drift (Japan, Link Version) it's own
correct dipswitch settings. [Brian Troha]
-ymf278b: Use the memory system to access wavetable data. This should
make it possible to hook up RAM as well as ROM to the device, e.g. for
computer sound cards in MESS. [Alex Jackson]
-psikyo4: Improve and clean up wavetable ROM banking. The mask ROM
tests in hotgm4ev and hotgmcki pass now. loderndf still fails for
unknown reasons. Miscellaneous cleanups as well. [Alex Jackson]
-mfi_dsk: Fix leaks [O. Galibert]
-SDL: fall through to the baseline Win32 implementations for file,
socket, and pty/named pipe I/O. [R. Belmont]
-SDL: init timebase the first time it's needed on Windows, Mac, and
OS/2 targets. [R. Belmont]
-Fixed sprite DMA for Raiden 2, bullets are now visible
[Angelo Salese, Olivier Galibert]
-SDL: remove dead code from SDL2 renderer, fix laserdisc crash with
SDL2 -video accel rendering. [R. Belmont]
-replace rom in ryukendna set [system11]
-SDL: link properly on OS X for SDL2. [R. Belmont]
-SDL: Use the same screen selection method for SDL2 as Windows.
[R. Belmont]
-Various pinballs working (see list below) [Robbbert]
-Sound for Atari pinball machines [Robbbert]
-gtia.c: converted to be a device. [Fabio Priuli]
-hikaru: add mask dumps for podrace [Cah4e3]
-voodoo.c, vooddefs.h: Added support for writes to trexInit1 register,
to return TMU configuration data. [Peter Ferrie]
-antic.c: converted to be a device. [Fabio Priuli]
-SDL: Allow -sound dsound on SDL Windows builds. [R. Belmont]
-Removed legacy_cpu_device. [Wilbert Pol]
-Added proper NMK004 internal rom [trap15]
-Hooked up support for NMK004 internal rom in MAME, replacing Nicola's
old simulation code [trap15, David Haywood]
-Fixed TLCS90 16-bit timers & support NMI in the core [trap15]
-Various tweaks and improvements in nmk16.c (timings, sound balance,
etc.): [trap15, David Haywood]
* US AAF Mustang now has sound / music for the first time
* Much better sound / music in the following games Bio-ship Paladin,
Vandyke, Black Heart, Acrobat Mission, Koutetsu Yousai Strahl, Thunder
Dragon, Hacha Mecha Fighter, Super Spacefortress Macross, GunNail
-SDL: use Windows OSD's font-selection semantics for SDL Windows
builds. [R. Belmont]
-softlist: fixed inconsistent -listsoftware output. [phulshof]
-ui: fixed crash when loading floppies with no parent software from
softlist (only via internal File Manager, though) [Fabio Priuli]
-added generic cartslot / ROM socket slot device, which offers basic
allocation and access handlers, and converted a few drivers to use
this instead of code from cartslot.c [Fabio Priuli]
-softlist: restored the support for loading games from compatible
softlists (like gbcolor games in gameboy, and viceversa, msx1 carts in
msx2, etc.) by using the syntax mess system -media list:gamename You
can now for instance use again "mess gbcolor -cart gameboy:sml" to
play "Super Mario Land" with the custom palettes of the Game Boy
Color. [Fabio Priuli]
-NS8250 Fixes [smf]
* Loopback: tx goes high and data is clocked at the
correct rate instead of appearing instantly Modem status register:
don't lose track of external signals when starting, resetting,
switching loopback off, writing to register Handshaking: active low
for consistency (RS232 port now defaults handshaking lines high and
serial mouse dtr/rts handling has been adjusted).
-Memory system and Namco improvements: [Alex Jackson]
* Explicit regions in address maps (AM_REGION) are now looked up
relative to the device rather than as siblings when in an internal
address map (similar to devices and shared pointers) Besides being
more orthogonal than before, this allows internal ROMs of MCUs and
similar devices to be hooked up in a nicer and more foolproof way.
Updated the m37710 and m5074x (m6502 derivative) to take advantage of
this.
* Divided the M37702/M37710 into specific models, with each model having
its own internal address map containing the correct amounts of
internal RAM and ROM.
* M37702 MCUs found on various Namco PCBs are now all unique devices and
have their respective internal ROMs loaded as device ROMs.
-namcops2: Documentation fixes [Guru]
-addrmap.c: Only install the default device address map if the owner
didn't provide one [Alex Jackson]
-8250: call interrupt callback after clearing internal interrupt state
when resetting [smf]
-added workaround to build with XCode 6.0.1 out-of-the-box
[Oliver Stöneberg]
-wd_fdc: Hopefully fix reading sectors with DDAM [lowen, O. Galibert]
-Moved protection vectors from hachamfb to hachamf, making the latter
to work properly too [Angelo Salese]
-web: allow pasting in text. [Firehawke]
-Gundam Wing: Endless Duel updates: [Peter Ferrie]
* added additional shared memory block
* added protection handlers
* corrected reset vector
* worked around bad startup
Game now boots but doesn't coin up.
-fix compile on MSVC 2012 & 2013 [Peter Ferrie]
-snesb.c: Add coin/DSW inputs to Gundam Wing, game is now playable.
[stephh]
-s4.c : fixed sound, 4 games marked as working (Flash,Stellar
Wars,TriZone,TimeWarp)
-snesb: Set up dip switches for Gundam Wing. [stephh]
-peplus.c: Various fixes, all sets should be working now. [BrianT]
-WebUI: clean up and fixed HTML compliance. [Firehawke]
-added makefile variable OPENMP to enable usage of OpenMP (includes
vconv support of -fopenmp) [Oliver Stöneberg]
-blktiger priority fixes [Mamesick]
-dragrace.c: Added tachometer outputs. [Comboman]
-Handcrafted PAL for actual Varth US PCB. [Palindrome]
-awboard: add "offset protection" used by some carts. samsptk and
kofxi boot now. [R. Belmont, MetalliC]
-model3: Rewrote 2D tilemap rendering. [Ville Linde]
-Rewrite k053260 sound device [Alex Jackson]
-Make cheat initialization debugger message more verbose. [Pugsy]
-make the orlegend111t set work [iq_132]
-chqflag.c: improve k007232 volume/pan controls, still largely
guesswork [Alex Jackson]
-wecleman.c: add missing k007232 volume callback [Alex Jackson]
-naomi.c:
* M2-type cartridges 4/8MB mode mapping documentation/code
[MetalliC, rtw]
* F355 protection key, small docs update/corrections [MetalliC]
* Atomiswave controller type register [MetalliC]
* Added InitialD Ver3 Cycraft PIC key [anonymous, MetalliC]
-eepromuser.c: Added Support for MSM16911 Serial eeprom [Felipe Sanches]
-mb88xx.c: Added support for Fujitsu M88201-202 MCU [Felipe Sanches]
-model3: New 3D renderer + various fixes (still heavily WIP) [Ville Linde]
-Beatmania IIDX Twinkle hardware: The IDE DMA is now hooked up, but the
sound board isn't running well enough yet for it to make a difference.
Hooked up the FDC37665GT and HLE the XVD701 and the 68k sound board
responses to get most of the games booting. There is no sound and the
games all fail with a hdd error when you start a stage. Beatmania IIDX
with DDR 2nd Club Version wants the GQ863 hard disk. [smf]
-Beatmania IIDX Twinkle hardware: beatmania IIDX Substream with DDR 2nd
Club Version 2 wants the harddisk from beatmania IIDX Substream. Added
missing 3rd & 6th style CD images & replaced 5th style images. [smf]
-upd7220: add Bresenham arc and complete char drawing [Carl]
-m68000: add missing item to save state [Alex Jackson]
- Converted battlera.c driver to use real PCE video code, fixing several
longstanding bugs (present since driver was added in 0.37b2 era)
[David Haywood]
- Reorganized ST0016 code, detangling several drivers, and fixing a some
missing video features used by gostop [David Haywood]
- Refactored legionna.c COP code to use new Raiden II implementation
fixing several bugs along the way [David Haywood]
- Tweaked Raiden II collision detection based on user feedback citing
specific bullet patterns and expected hitbox sizes [David Haywood]
- Added note about tharrier Dipswitches being likely read via the
protection device (not yet hooked up) [David Haywood]
- Fix girls 4,5,6 in the 'popbingo' bonus rounds [David Haywood]
- Fix what appears to be bad sound ROM banking in sandscrp
[Dink, David Haywood]
2014-10-26 meld 3.12.1
======================
Fixes:
* Work around change colours not displaying on GTK+ 3.14 (Kai Willadsen)
* Fix missing cache opcodes in some circumstances (Kai Willadsen)
* Fix text view expansion when resizing patch dialog (Kai Willadsen)
* Build fix to always include C locale when LINGUAS is set (Kai Willadsen)
Translations:
* Rafael Ferreira (pt_BR)
* Мирослав Николић (sr, sr@latin)
- Better handling of empty %platform% in Util::filepathReplaceReservedStrings
- Fixed setting filepath for language packs
* I forgot to set the filepath for language packs which caused some problems
- Added support for caching game details
* --update-cache creates and updates the cache.
* --use-cache enables loading game details from cache.
* --cache-valid specifies how long cached game details are considered valid
- Fixed login issue
* Regex in Downloader::HTTP_Login matched wrong auth url after GOG
made some changes to website
The following bugs have been fixed since version 4.2.10:
- bug #4562 [security] XSS in debug SQL output
- bug #4563 [security] XSS in monitor query analyzer
openpyxl is a pure python reader and writer of Excel OpenXML files.
It was born from lack of existing library to read/write natively from
Python the new Office Open XML format. All kudos to the PHPExcel team
as openpyxl is a Python port of PHPExcel http://www.phpexcel.net/
Update to version 2.2
Version 2.2
-----------
- Updated zoneinfo to 2013h
- fuzzy_with_tokens parse addon from Christopher Corley
- Bug with LANG=C fixed by Mike Gilbert
Version 2.1
-----------
- New maintainer
- Dateutil now works on Python 2.6, 2.7 and 3.2 from same codebase (with
- six)
- #704047: Ismael Carnales' patch for a new time format
- Small bug fixes, thanks for reporters!
Changelog:
r350 2014-10-12 1.15.1895.102 - r323 2014-08-24 1.15.1869.102
You can check out Mozc r350 as follows.
gclient sync --revision=350
Summary of changes between 1.15.1869.102 (r323) and 1.15.1895.102 (r350).
Build related changes:
Android build is now tested with NDK r10b only
Ubuntu 14.04 is now experimentally supported as a build environment. See mozc/docker/ubuntu14.04/Dockerfile.
Fixed issues:
FIX: Partial suggestion for numbers are not annotated by <部分確定> ( Issue 250 )
FIX: Meaningless candidates are displayed on the Start Screen in Windows 8 and later ( Issue 249 )
Commit summary:
r350: Use StringPiece to avoid unnecessary instantiation of std::string
r349: Introduce Util::ConcatStrings to reduce string copy
r348: Do not make the destructor virtual unless it is necessary part 2
r347: Do nothing if the key string passed to the converter is empty
r346: Fix Year 2038 Problem in UserHistoryStorage
r345: Do not make the destructor virtual unless it is necessary
r344: Add supportedOS GUID for Windows 10
r343: Use apt command instead of apt-get command in Ubuntu 14.04
r342: Tidy up UserHistoryPredictor::InsertHistory
r341: Reorder logical AND conditions just for readability
r340: Remove a redundant length check
r339: Roll jsoncpp 4b687640cbc197e8:11086dd6a7eba042
r338: Roll gyp r1972:r1987
r337: Roll breakpad r1354:r1374
r336: Use Util::EndsWith when appropriate
r335: Stop unnecessarily using uint64 variable for uint32 data part 2
r334: Stop unnecessarily using uint64 variable for uint32 data
r333: Fix a typo in a test name
r332: Fix style violations in header include guards
r331: Propagate information of partial suggestion in the number rewriter
r330: Add an all-in-one Dockerfile to build Mozc for Android and Linux desktop (Ubuntu 14.04 edition)
r329: Disable ITfFnSearchCandidateProvider until ITfIntegratableCandidateListUIElement is implemented
r328: Use Android NDK r10b in the reference build environment part 2
r327: Use Android NDK r10b in the reference build environment
r326: Make sure to use correct 'NM' and 'READELF' in cross build
r325: Roll gyp r1958:r1971
r324: Update copyright year notice in the about dialog
r323: Update line number attributes in Qt message files
r318 2014-08-17 1.15.1868.102 - r307 2014-08-03 1.15.1857.102
You can check out Mozc r318 as follows.
gclient sync --revision=318
Summary of changes between 1.15.1868.102 (r318) and 1.15.1857.102 (r307).
Build related changes:
Visual C++ 2013 is now supported to build Mozc binaries. ( Issue 244 )
Fixed issues:
FIX: Support Visual C++ 2013 ( Issue 244 )
FIX: 'Set input mode to X' commands do not work while input mode is set to "Direct Input" ( Issue 246 )
FIX: Remove shortcut keys for Japanese IME for intra IME mode switching (Issue chromium:310698)
Commit summary:
r318: Fix a typo in a build rule for OS X
r317: Introduce a new keymap for Chromium OS device
r316: Move GetDefaultKeyMap from keymap::KeyMapManager to config::ConfigHandler
r315: Support 'Set input mode to X' in DirectInput mode on Linux, NaCl and Android
r314: Enable Ninja's console pool feature for 'ant' tasks in Android build
r313: Suppress build time message for the clean build log, especially when being built with Ninja
r312: Update symbol dictionary
r311: Roll protobuf r489:r512
r310: Include Visual C++ 2013 merge modules when necessary
r309: Use the workaroud for KB 813540 only for Visual C++ 2010
r308: Remove an unnesesary blank line
r307: Roll WTL r460:r587 part 2
r303 2014-08-03 1.15.1856.102 - r282 2014-07-20 1.15.1835.102
You can check out Mozc r303 as follows.
gclient sync --revision=303
Summary of changes between 1.15.1856.102 (r303) and 1.15.1835.102 (r282).
Build related changes:
Android build is now tested with NDK r10 only
OS X 10.5/10.6 are no longer supported as the target platform. ( Issue 242 )
OS X build now uses libc++ instead of libstdc++.
Fixed issues:
FIX: mozc.el should conform Emacs Lisp library header conventions ( Issue 213 )
FIX: GetMachPortName fails on OS X 10.10 Yosemite ( Issue 241 )
FIX: Discontinue the support of OS X 10.5/10.6 ( Issue 242 )
Commit summary:
r303: Remove an unnecessary directry search rule
r302: Switch to libc++ for better C++11 support
r301: Change the minimum supported OS X version to 10.7
r300: Rely on predictable Mach port name for OS X
r299: Change the group ID of the installed files from admin(80) to wheel(0) for Mac OS X
r298: Fix missing copyright notice and license notice at the top of the file
r297: Simplify build rules for Mac
r296: Use Android NDK r10
r295: Remove unused function in auto-generated code
r294: Fix code signing error on Mac OS X Marveriks
r293: Remove a workaround against copy-on-write implementation of std::string
r292: Use C++11 auto keyword
r291: Roll WTL r460:r587
r290: Roll protobuf r463:r488
r289: Roll jsoncpp ea0797351fbabd3e:3a0c4fcc82d25d18
r288: Roll gyp r1949:r1957
r287: Roll gtest r682:r692 and gmock r472:r485
r286: Roll breakpad r1239:r1353
r285: Better conforms to the emacs library standard
r284: Adds autoload magic comments
r283: Use more appropriate and descriptive constant for OK/Cancel dialog
r282: Include twelvekeys_toggle_flick_alphabet_scenario.txt in the test scenario list
* Fix name for vcsh_clean. Closes: #766655
* Add darcs grep command using ack-grep. Thanks, Paul Wise.
* Add a clean command. Thanks, Paul Wise. Closes: #702685
* Fix breakage introduced by --minimal patch.
* Deal with abs_path change in new version of perl, now it returns undefined
when the directory does not exist.
* Added --minimal mode. Closes: #694031 Thanks, Paul Wise.
* Use libio-pty-easy-perl when available when captuting command output
(for --minimal or -jN), so that programs that output color to terminals
will be colorized. This is only a recommends as it will fall back to
the old method. Thanks, Paul Wise.
Changelog:
Tomcat 7.0.56 Released, 2014-10-06
The Apache Tomcat Project is proud to announce the release of version 7.0.56 of Apache Tomcat. This release contains a number of bug fixes and improvements compared to version 7.0.55. The notable changes since 7.0.55 include:
Update the Java WebSocket support to version 1.1 of the Java WebSocket specification.
Add support for the WebSocket permessage-deflate extension.
Changelog:
What's new in 1.565.3 (2014/10/01)
Plugin code can be downloaded by anyone with Overall/Read (SECURITY-155)
Stored passwords can be read out from build with parameters page (SECURITY-138)
Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2 as included with Jenkins (SECURITY-149)
Unauthenticated users can make Jenkins behind Apache unresponsive (SECURITY-87)
Users with limited Job/Configure can replace other jobs they have no access to (if they know the name) (SECURITY-128)
CLI calls are causing file descriptor leaks. (issue 23248)
Users with limited Job/Configure can change the kind of job via CLI, getting access to denied job types (SECURITY-127)
Test result trend breaks lazy-loading (issue 23945)
Unable to kill a job which is running (issue 17667)
XSS weakness in load-statistics (SECURITY-143)
Job is removed from ListView after rename (issue 23893)
set-build-result and set-build-parameter do insufficient checks (issue 24080)
Missing no-sniff header (SECURITY-122)
Directory traversal (SECURITY-131)
"incompatible InnerClasses attribute" error in IBM J9 VM (issue 22525)
Arbitrary file system write via DiskFileItem deserialization (SECURITY-159)
Missing SecureFlag cookie (SECURITY-120)
Prevent (private security realm) usernames from being guessed (SECURITY-79 redux!) (SECURITY-110)
Deadlock in OldDataMonitor (issue 24358)
RemoteInvocationHandler.RPCRequest allows invoking any method on an exported object event those not exposed by the exported interface (SECURITY-150)
What's new in 1.565.2 (2014/09/03)
Jenkins needs to check whether the war's directory is writeable before offering to upgrade (issue 23683)
AbstractLazyLoadRunMap.iterator() calls .all() (issue 18065)
Jenkins no longer kills running processes after job fails (issue 22641)
HTTP error 405 when trying to restart ssh host (issue 23094)
Run.delete (from LogRotator) failing with "...looks to have already been deleted" (issue 22395)
file name encoding broken in zip archives (issue 20663)
Kill win32 processes from win64 JVMs (issue 23410)
What's new in 1.565.1 (2014/07/30)
Queue.maintain does disk I/O via PeepholePermalink.resolve (issue 22822)
“Form too large” errors submitting view configurations with many jobs (issue 20327)
NPE on plugin install (issue 20031)
Link to the console output missing in popup when log >200Kb (issue 14264)
Parameters: NPE in canTake() procedures may kill all executors (issue 15094)
NPE from AbstractBuild$AbstractBuildExecution.run (issue 23277)
broken ProjectNamingStrategy Extension (issue 23127)
Move DecoratedLauncher from the custom-tools plugin to the Jenkins Core (issue 19454)
hudson.Launcher:ProcStarter::envs() may throw NPE (issue 20559)
Resource leak in hudson.model.FileParameterValue (issue 22693)
ReverseBuildTrigger.threshold not consistently saved (issue 23191)
AccessRestriction on SecurityListener methods (issue 23417)
After deleting folder, get 404 (issue 23375)
email-ext plugin doesn't handle tokens when slave has gone offline: IAE from AbstractProject.getEnvironment (issue 23517)
Jenkins cannot restart Windows service (issue 22685)
Rules for showing/hiding SCMTrigger.pollingThreadCount option are broken (issue 22934)
What's new in 1.554.3 (2014/06/30)
Queue.maintain does disk I/O via PeepholePermalink.resolve (issue 22822)
Non-recursive ListViews unnecessarily call owner.getAllItems in getItems (issue 22720)
SSH slave connections die after the slave outputs 4MB of stderr, usually during findbugs analysis (issue 22938)
Jenkins cannot restart Windows service (issue 22685)
What's new in 1.554.2 (2014/05/30)
Don't ask for confirmation when it doesn't make any sense (issue 21720)
On a configure screen that has multiple groups of radio buttons, clicking the apply button clears all but the last radio group selection (issue 22570)
Optimize creation of relative links to jobs (issue 18364)
Jenkins asks for confirmation before leaving edited 'View Configuration' page (issue 20597)
OutOfOrderBuildMonitor fails to correct builds with duplicate number (issue 22631)
Computer does not exist returns NPE (issue 21999)
Last build of project reloaded when project asked for later build (issue 22681)
After clicking 'Apply' at least once, 'Save' opens a new window (issue 20245)
hetero-radio should work with multiple instances of the same ui (issue 22583)
Cannot submit configuration after removing groovy step (issue 22582)
No autocompletion and NullPointerException when using 'Copy Existing Job' (issue 22142)
What's new in 1.554.1 (2014/04/30)
NPE if trying to install a plugin from the update center and either the update source or the plugin contains a '.' in its name (issue 22080)
Download update center from master by default (issue 19081)
OutOfMemory due to unbounded storage in OldDataMonitor (issue 19544)
Very slow resource loading from UberClassLoader (issue 21579)
Jetty exploding war to /tmp is a bad idea (issue 22442)
Performance issue with search box (issue 21969)
ArrayIndexOutOfBoundsException during Jenkins.doConfigSubmit; need XStream 1.4.6 (issue 18537)
NullPointerException when trying to mark slave temporarily offline (issue 21875)
Build queue is not filtered after progress updated (issue 20500)
copy-job permission checks wrong (issue 22262)
What's new in 1.532.3 (2014/04/11)
Replace description in error dialog instead of appending (issue 21457)
NPE from xstream.core.JVM.isOpenJDK (issue 21183)
WorkspaceCleanupThread does not handle folders (issue 21023)
Copy Artifact's fingerprinting creates second hudson.tasks.Fingerprinter_-FingerprintAction section with just the artifacts copied (issue 17606)
/login offers link to /opensearch.xml which anonymous users cannot retrieve (issue 21254)
Miscellaneous exceptions in config.xml can prevent entire job from loading (issue 21024)
Jobs named "." can be created, but not built, configured, accessed, ... (issue 21639)
DirectoryBrowserSupport.buildChildPaths does quadratic number of calls to check whether entries are directories (issue 21780)
ZIP file download generates corrupt zip file (issue 20345)
Update credentials plugin to 1.9.4 (issue 21820)
Apply button does not work in IE Compat View (issue 19826)
Deadlock while parallel deletion/rename of jobs (issue 19446)
What's new in 1.532.2 (2014/02/14)
CannotResolveClassException breaks loading of entire containing folder, not just one job (issue 20951)
Default markup formatter permits offsite-bound forms (SECURITY-88)
Using jenkins-cli connecting to HTTPS port fails due to hostname mismatch in certificate (issue 12629)
ApiTokenFilter does not check that the user actually exists (SECURITY-89)
HTTP two-way remoting does not work (jenkins-cli.jar without JNLP) (issue 20128)
Slave launcher fails after NoClassDefFoundError: Could not initialize class jenkins.model.Jenkins$MasterComputer (issue 19453)
StreamCorruptedException (issue 8856)
UI Redressing/ClickJacking (SECURITY-80)
Fail to run 'groovysh' in CLI due to insufficient permission (issue 17929)
Loading projects too slow because of File.isDirectory calls (issue 21078)
HTML metacharacters not escaped in log messages (issue 20800)
Channel's executorService's pool should have a name (issue 19004)
ListView.expand throws ClassCastException: … cannot be cast to hudson.model.TopLevelItem (issue 20415)
Stored XSS (SECURITY-74)
Session Fixation (SECURITY-75)
/heapDump offered to anyone with ADMINISTER (SECURITY-73)
Username Guessing/Enumeration (SECURITY-79)
RingBufferLogHandler throws ArrayIndexOutOfBoundsException after int-overflow (issue 9120)
Iframe Injection (SECURITY-76)
Reflected XSS in Cookie (SECURITY-77)
l:breakable mishandles HTML metacharacters (issue 20928)
Start JNLP slave ignores jar-cache flag (issue 20093)
Stored passwords can be read out from UIs with password fields (SECURITY-93)
Too many open files upon HTTP listener init or shutdown (issue 14336)
Extension point for secure users of Api (issue 16936)
'Apply' error screens don't work (issue 20772)
Workspaces seem to be removed prematurely on concurrent jobs (issue 10615)
Job creators are able to edit or destroy the system configuration via the CLI (SECURITY-108)
Disable\Delete "Remember me on this computer" check box in login screen (issue 15757)
SECURITY-55 fails if downstream project not visible (SECURITY-109)
Builds disappear some time after renaming job (issue 18678)
Use RunAction2 from TestResultAction (issue 18410)
java.lang.NoClassDefFoundError: sun/net/www/protocol/jar/JarURLConnection (issue 20163)
Remote code execution via xstream deserialization in XML API (SECURITY-105)
Jenkins on winstone vulnerable to session hijacking (SECURITY-106)
Jenkins allows anonymous access if the Authorization Strategy can't be loaded (SECURITY-107)
you cannot use the cli without giving Overall read to Anonymous (issue 8815)
Highlights from release notes:
* Touchscreen gestures support (Carlos Garnacho)
* Improved color management compatibility (pdknsk)
* Improved Exif GPS tag handling (Felix Riemann)
* Image background layer uses GdkRGBA to avoid color conversion from
GdkColor and principally allow transparent backgrounds (Felix Riemann)
* Make several actions available over D-Bus (Ryan Lortie, Felix Riemann)
* Replace several deprecated APIs (Felix Riemann)
* Many new and updated translations
* Many bug fixes
For full details see:
https://git.gnome.org/browse/eog/tree/NEWS?id=3.14.1