Skip to content

Commit 8e8f074

Browse files
authored
Enforce HTTP/1.1 for internal component JdkHttpClient (#2521)
Signed-off-by: Viet Nguyen Duc <[email protected]>
1 parent 170f936 commit 8e8f074

File tree

14 files changed

+54
-0
lines changed

14 files changed

+54
-0
lines changed

.github/workflows/build-ffmpeg.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,9 @@ on:
44
push:
55
paths:
66
- '.ffmpeg/Dockerfile'
7+
pull_request:
8+
paths:
9+
- '.ffmpeg/Dockerfile'
710
workflow_dispatch:
811
inputs:
912
release:

Base/Dockerfile

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -130,6 +130,8 @@ RUN --mount=type=secret,id=SEL_PASSWD \
130130
org.seleniumhq.selenium:selenium-session-map-jdbc:${MVN_SELENIUM_VERSION} \
131131
org.postgresql:postgresql:${POSTGRESQL_VERSION} \
132132
org.seleniumhq.selenium:selenium-session-map-redis:${MVN_SELENIUM_VERSION} \
133+
# Patch specific version for CVEs in the dependencies
134+
io.lettuce:lettuce-core:6.5.1.RELEASE \
133135
> /external_jars/.classpath_session_map.txt \
134136
&& chmod 664 /external_jars/.classpath_session_map.txt ; \
135137
fi \
@@ -185,6 +187,7 @@ ENV SE_BIND_HOST=false \
185187
SE_STRUCTURED_LOGS=false \
186188
SE_ENABLE_TRACING=true \
187189
SE_ENABLE_TLS=false \
190+
SE_JAVA_HTTPCLIENT_VERSION="HTTP_1_1" \
188191
SE_JAVA_SSL_TRUST_STORE="/opt/selenium/secrets/server.jks" \
189192
SE_JAVA_SSL_TRUST_STORE_PASSWORD="/opt/selenium/secrets/server.pass" \
190193
SE_JAVA_DISABLE_HOSTNAME_VERIFICATION=true \

Distributor/start-selenium-grid-distributor.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -179,6 +179,10 @@ else
179179
echo "Tracing is disabled"
180180
fi
181181

182+
if [ -n "${SE_JAVA_HTTPCLIENT_VERSION}" ]; then
183+
SE_JAVA_OPTS="$SE_JAVA_OPTS -Dwebdriver.httpclient.version=${SE_JAVA_HTTPCLIENT_VERSION}"
184+
fi
185+
182186
java ${JAVA_OPTS:-$SE_JAVA_OPTS} \
183187
-jar /opt/selenium/selenium-server.jar \
184188
${EXTRA_LIBS} \

EventBus/start-selenium-grid-eventbus.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -109,6 +109,10 @@ else
109109
echo "Tracing is disabled"
110110
fi
111111

112+
if [ -n "${SE_JAVA_HTTPCLIENT_VERSION}" ]; then
113+
SE_JAVA_OPTS="$SE_JAVA_OPTS -Dwebdriver.httpclient.version=${SE_JAVA_HTTPCLIENT_VERSION}"
114+
fi
115+
112116
java ${JAVA_OPTS:-$SE_JAVA_OPTS} \
113117
-jar /opt/selenium/selenium-server.jar \
114118
${EXTRA_LIBS} event-bus \

Hub/start-selenium-grid-hub.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -159,6 +159,10 @@ else
159159
echo "Tracing is disabled"
160160
fi
161161

162+
if [ -n "${SE_JAVA_HTTPCLIENT_VERSION}" ]; then
163+
SE_JAVA_OPTS="$SE_JAVA_OPTS -Dwebdriver.httpclient.version=${SE_JAVA_HTTPCLIENT_VERSION}"
164+
fi
165+
162166
java ${JAVA_OPTS:-$SE_JAVA_OPTS} \
163167
-jar /opt/selenium/selenium-server.jar \
164168
${EXTRA_LIBS} \

NodeBase/start-selenium-node.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -171,6 +171,10 @@ CHROME_DRIVER_PATH_PROPERTY=-Dwebdriver.chrome.driver=/usr/bin/chromedriver
171171
EDGE_DRIVER_PATH_PROPERTY=-Dwebdriver.edge.driver=/usr/bin/msedgedriver
172172
GECKO_DRIVER_PATH_PROPERTY=-Dwebdriver.gecko.driver=/usr/bin/geckodriver
173173

174+
if [ -n "${SE_JAVA_HTTPCLIENT_VERSION}" ]; then
175+
SE_JAVA_OPTS="$SE_JAVA_OPTS -Dwebdriver.httpclient.version=${SE_JAVA_HTTPCLIENT_VERSION}"
176+
fi
177+
174178
java ${JAVA_OPTS:-$SE_JAVA_OPTS} \
175179
${CHROME_DRIVER_PATH_PROPERTY} \
176180
${EDGE_DRIVER_PATH_PROPERTY} \

NodeDocker/start-selenium-grid-docker.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -119,6 +119,10 @@ else
119119
echo "Tracing is disabled"
120120
fi
121121

122+
if [ -n "${SE_JAVA_HTTPCLIENT_VERSION}" ]; then
123+
SE_JAVA_OPTS="$SE_JAVA_OPTS -Dwebdriver.httpclient.version=${SE_JAVA_HTTPCLIENT_VERSION}"
124+
fi
125+
122126
java ${JAVA_OPTS:-$SE_JAVA_OPTS} \
123127
-jar /opt/selenium/selenium-server.jar \
124128
${EXTRA_LIBS} node \

NodeFirefox/Dockerfile

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,9 @@ RUN apt-get update -qqy && \
5858
fi \
5959
# Download the language pack for Firefox
6060
&& /opt/bin/get_lang_package.sh \
61+
# Do one more upgrade to fix possible CVEs from Firefox dependencies
62+
&& apt-get update -qqy \
63+
&& apt-get upgrade -yq \
6164
&& rm -rf /var/lib/apt/lists/* /var/cache/apt/*
6265

6366
#============

Router/start-selenium-grid-router.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -160,6 +160,10 @@ else
160160
echo "Tracing is disabled"
161161
fi
162162

163+
if [ -n "${SE_JAVA_HTTPCLIENT_VERSION}" ]; then
164+
SE_JAVA_OPTS="$SE_JAVA_OPTS -Dwebdriver.httpclient.version=${SE_JAVA_HTTPCLIENT_VERSION}"
165+
fi
166+
163167
java ${JAVA_OPTS:-$SE_JAVA_OPTS} \
164168
-jar /opt/selenium/selenium-server.jar \
165169
${EXTRA_LIBS} router \

SessionQueue/start-selenium-grid-session-queue.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,10 @@ else
113113
echo "Tracing is disabled"
114114
fi
115115

116+
if [ -n "${SE_JAVA_HTTPCLIENT_VERSION}" ]; then
117+
SE_JAVA_OPTS="$SE_JAVA_OPTS -Dwebdriver.httpclient.version=${SE_JAVA_HTTPCLIENT_VERSION}"
118+
fi
119+
116120
java ${JAVA_OPTS:-$SE_JAVA_OPTS} \
117121
-jar /opt/selenium/selenium-server.jar \
118122
${EXTRA_LIBS} sessionqueue \

0 commit comments

Comments
 (0)