CHANGES revision df46ff21c57d00f6addccaaf9b1484f2b56b8577
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder -*- coding: utf-8 -*-
25cc5fbba63f84b47e389af749f55abbbde71c8cChristian MaederChanges with Apache 2.3.2
25cc5fbba63f84b47e389af749f55abbbde71c8cChristian Maeder[ When backported to 2.2.x, remove entry from this file ]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian MaederChanges with Apache 2.3.1
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) ap_slotmem: Add in new slot-based memory access API impl., including
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder 2 providers (mod_sharedmem and mod_plainmem) [Jim Jagielski,
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder Jean-Frederic Clere, Brian Akins <brian.akins turner.com>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_include: support generating non-ASCII characters as entities in SSI
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 25202 [Nick Kew]
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder *) core/utils: Enhance ap_escape_html API to support escaping non-ASCII chars
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder PR 25202 [Nick Kew]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) mod_rewrite: fix "B" flag breakage by reverting r5589343
76712faeb5ffeb3ff704404a34f2b8d284aa92bcChristian Maeder PR 45529 [Bob Ionescu <bobsiegen googlemail.com>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) CGI: return 504 (Gateway timeout) rather than 500 when a script
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder times out before returning status line/headers.
d67a33b40578beef2e255a274f89bb9c34aaf056Christian Maeder PR 42190 [Nick Kew]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) mod_cgid: fix segfault problem on solaris.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 39332 [Masaoki Kobayashi <masaoki techfirm.co.jp>]
c55a0f77be7e88d3620b419ec8961f4379a586e3Klaus Luettich *) mod_proxy_scgi: Added. [André Malo]
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder *) mod_cache: Introduce 'no-cache' per-request environment variable
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder to prevent the saving of an otherwise cacheable response.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Eric Covener]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_rewrite: Introduce DiscardPathInfo|DPI flag to stop the troublesome
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder way that per-directory rewrites append the previous notion of PATH_INFO
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder to each substitution before evaluating subsequent rules.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR38642 [Eric Covener]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_cgid: Do not add an empty argument when calling the CGI script.
b0294d73dcefc502ddaa13e18b46103a5916971fTill Mossakowski PR 46380 [Ruediger Pluem]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) scoreboard: Remove unused sb_type from process_score.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Torsten Foertsch <torsten.foertsch gmx.net>, Chris Darroch]
ed9207cf24e96b0d6f59985822054ae28cb69b2eChristian Maeder *) mod_ssl: Add SSLRenegBufferSize directive to allow changing the
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder size of the buffer used for the request-body where necessary
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder during a per-dir renegotiation. PR 39243. [Joe Orton]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_proxy_fdpass: New module to pass a client connection over to a separate
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder process that is reading from a unix daemon socket.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_ssl: Improve environment variable extraction to be more
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder efficient and to correctly handle DNs with duplicate tags.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 45975. [Joe Orton]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) Remove the obsolete serial attribute from the RPM spec file. Compile
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder against the external pcre. Add missing binaries fcgistarter, and
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder mod_socache* and mod_session*. [Graham Leggett]
ce50fe187cdae64e75e510daafb78156280bdb91Christian MaederChanges with Apache 2.3.0
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers *) mod_ratelimit: New module to do bandwidth rate limiting. [Paul Querna]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) Remove X-Pad header which was added as a work around to a bug in
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder Netscape 2.x to 4.0b2. [Takashi Sato <takashi lans-tv.com>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) Add DTrace Statically Defined Tracing (SDT) probes.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Theo Schlossnagle <jesus omniti.com>, Paul Querna]
ebe517300051f765f2ed856a789dd5613d681ab0Klaus Luettich *) mod_proxy_balancer: Move all load balancing implementations
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers as individual, self-contained mod_proxy submodules under
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) Rename APIs to include ap_ prefix:
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder find_child_by_pid -> ap_find_child_by_pid
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder suck_in_APR -> ap_suck_in_APR
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder sys_privileges_handlers -> ap_sys_privileges_handlers
ce50fe187cdae64e75e510daafb78156280bdb91Christian Maeder unixd_accept -> ap_unixd_accept
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder unixd_config -> ap_unixd_config
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder unixd_killpg -> ap_unixd_killpg
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder unixd_set_global_mutex_perms -> ap_unixd_set_global_mutex_perms
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder unixd_set_proc_mutex_perms -> ap_unixd_set_proc_mutex_perms
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers unixd_set_rlimit -> ap_unixd_set_rlimit
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers [Paul Querna]
5d4038657f6a63e131f5804af2f7957b69e15a43Klaus Luettich *) core: When the ap_http_header_filter processes an error bucket, cleanup
5d4038657f6a63e131f5804af2f7957b69e15a43Klaus Luettich the passed brigade before returning AP_FILTER_ERROR down the filter
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder chain. This unambiguously ensures the same error bucket isn't revisited
c432483b64662e8db604a58758cd18ea7fa65659Christian Maeder [Ruediger Pluem]
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder *) mod_lbmethod_heartbeat: New module to load balance mod_proxy workers
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder based on heartbeats. [Paul Querna]
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder *) mod_heartmonitor: New module to collect heartbeats, and write out a file
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder so that other modules can load balance traffic as needed. [Paul Querna]
8659594bb40eb5f3da5439692f0908300947191eSonja Gröning *) mod_heartbeat: New module to generate multicast heartbeats to know if a
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder server is online. [Paul Querna]
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning *) core: Error responses set by filters were being coerced into 500 errors,
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning sometimes appended to the original error response. Log entry of:
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning 'Handler for (null) returned invalid result code -3'
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning [Eric Covener]
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder *) mod_buffer: Honour the flush bucket and flush the buffer in the
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers input filter. Make sure that metadata buckets are written to
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder the buffer, not to the final brigade. [Graham Leggett]
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder *) mod_buffer: Optimise the buffering of heap buckets when the heap
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder buckets stay exactly APR_BUCKET_BUFF_SIZE long. [Graham Leggett,
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers Ruediger Pluem]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_buffer: Optional support for buffering of the input and output
327a9b9bf44b6e33f71fee7526dc1c0035251591Christian Maeder filter stacks. Can collapse many small buckets into fewer larger
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder buckets, and prevents excessively small chunks being sent over
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder the wire. [Graham Leggett]
0e012772df2ce0dc7e8f0fe3acf458c2871dcfbcChristian Maeder *) mod_privileges: new module to make httpd on Solaris privileges-aware
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder and to enable different virtualhosts to run with different
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder privileges and Unix user/group IDs [Nick Kew]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) authn/z: Remove mod_authn_default and mod_authz_default.
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder [Chris Darroch]
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder *) authz: Fix handling of authz configurations, make default authz
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers logic replicate 2.2.x authz logic, and replace <Satisfy*>, Reject,
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder and AuthzMergeRules directives with Match, <Match*>, and AuthzMerge
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder directives. [Chris Darroch]
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder *) mod_authn_core: Prevent crash when provider alias created to
88c800932dd7053322501ea2039d9f234be6866cKlaus Luettich provider which is not yet registered. [Chris Darroch]
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder *) mod_authn_core: Add AuthType of None to support disabling
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder authentication. [Chris Darroch]
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder *) core: Allow <Limit> and <LimitExcept> directives to nest, and
fa21fba9ceb1ddf7b3efd54731a12ed8750191d8Christian Maeder constrain their use to conform with that of other access control
fa21fba9ceb1ddf7b3efd54731a12ed8750191d8Christian Maeder and authorization directives. [Chris Darroch]
ed9207cf24e96b0d6f59985822054ae28cb69b2eChristian Maeder *) unixd: turn existing code into a module, and turn the set user/group
ed9207cf24e96b0d6f59985822054ae28cb69b2eChristian Maeder and chroot into a child_init function. [Nick Kew]
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder *) core: Add ap_timeout_parameter_parse to public API. [Ruediger Pluem]
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder *) mod_dir: Support "DirectoryIndex disabled"
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder Suggested By André Warnier <aw ice-sa.com> [Eric Covener]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_ssl: Send Content-Type application/ocsp-request for POST requests to
f29371d8bd5a232c974e736b06d0d8a655d320fbKlaus Luettich OSCP responders. PR 46014 [Dr Stephen Henson <steve openssl.org>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) Export and install the mod_rewrite.h header to ensure the optional
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder rewrite_mapfunc_t and ap_register_rewrite_mapfunc functions are
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder available to third party modules. [Graham Leggett]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_authnz_ldap: don't return NULL-valued environment variables to
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder other modules. PR 39045 [Francois Pesce <francois.pesce gmail.com>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) Don't adjust case in pathname components that are not of interest
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder to mod_mime. Fixes mod_negotiation's use of such components.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 43250 [Basant Kumar Kukreja <basant.kukreja sun.com>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) Be tolerant in what you accept - accept slightly broken
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder status lines from a backend provide they include a valid status code.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 44995 [Rainer Jung <rainer.jung kippdata.de>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) New module mod_sed: filter Request/Response bodies through sed
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Basant Kumar Kukreja <basant.kukreja sun.com>]
ef67402074be14deb95e4ff564737d5593144130Klaus Luettich *) mod_auth_form: Make sure that basic authentication is correctly
ef67402074be14deb95e4ff564737d5593144130Klaus Luettich faked directly after login. [Graham Leggett]
ef67402074be14deb95e4ff564737d5593144130Klaus Luettich *) mod_session_cookie, mod_session_dbd: Make sure cookies are set both
19933e754a6a244efca3b63184fb191668e08931Klaus Luettich within the output headers and error output headers, so that the
75cda7e5b890d050d560d970af244a183f28328fKlaus Luettich session is maintained across redirects. [Graham Leggett]
02a42d9fbc41445bac7e93a3df810a531f14e1a0Christian Maeder *) mod_auth_form: Make sure the logged in user is populated correctly
ef67402074be14deb95e4ff564737d5593144130Klaus Luettich after a form login. Fixes a missing REMOTE_USER variable directly
1323eba62fc519b068f5aaec4f9d2be05ffabea9Klaus Luettich following a login. [Graham Leggett]
1323eba62fc519b068f5aaec4f9d2be05ffabea9Klaus Luettich *) mod_session_cookie: Make sure that cookie attributes are correctly
725a68ec81cba9b8aa8647bebfb5baa449803e7eKlaus Luettich included in the blank cookie when cookies are removed. This fixes an
d579f5b263e6c73d466c265f2fbfd45b0e69ca64Klaus Luettich inability to log out when using mod_auth_form. [Graham Leggett]
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder *) mod_autoindex: add configuration option to insert string
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder in HTML HEAD. [Nick Kew]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) mod_session: Prevent a segfault when a CGI script sets a cookie with a
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder null value. [David Shane Holden <dpejesh apache.org>]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) mod_headers: Prevent Header edit from processing only the first header
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder of possibly multiple headers with the same name and deleting the
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder remaining ones. PR 45333. [Ruediger Pluem]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) mod_rewrite: Preserve the query string with [proxy,noescape]. PR 45247
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder [Tom Donovan]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) core, authn/z: Determine registered authn/z providers directly in
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder ap_setup_auth_internal(), which allows optional functions that just
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder wrapped ap_list_provider_names() to be removed from authn/z modules.
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder [Chris Darroch]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) authn/z: Convert common provider version strings to macros.
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder [Chris Darroch]
02a42d9fbc41445bac7e93a3df810a531f14e1a0Christian Maeder *) ab: Make ab.c compile on VC6. PR 45024 [Ruediger Pluem]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) configure: Don't reject libtool 2.x
ac43fa22d2d3f91a17674ac164cba3cf39a17795Klaus Luettich PR 44817 [Arfrever Frehtes Taifersar Arahesis <Arfrever.FTA gmail.com>]
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers *) core: When testing for slash-terminated configuration paths in
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder ap_location_walk(), don't look past the start of an empty string
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers such as that created by a <Location ""> directive.
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder [Chris Darroch]
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers *) core, mod_proxy: If a kept_body is present, it becomes safe for
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder subrequests to support message bodies. Make sure that safety
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder checks within the core and within the proxy are not triggered
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder when kept_body is present. This makes it possible to embed
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder proxied POST requests within mod_include. [Graham Leggett]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) mod_auth_form: Make sure the input filter stack is properly set
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder up before reading the login form. Make sure the kept body filter
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder is correctly inserted to ensure the body can be read a second
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers time safely should the authn be successful. [Graham Leggett,
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers Ruediger Pluem]
ac43fa22d2d3f91a17674ac164cba3cf39a17795Klaus Luettich *) mod_request: Insert the KEPT_BODY filter via the insert_filter
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers hook instead of during fixups. Add a safety check to ensure the
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers filters cannot be inserted more than once. [Graham Leggett,
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers Ruediger Pluem]
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers *) core: Do not allow Options ALL if not all options are allowed to be
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers overwritten. PR 44262 [Michał Grzędzicki <lazy iq.pl>]
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers *) ap_cache_cacheable_headers_out() will (now) always
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers merge an error heaeders _before_ clearing them and _before_
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers merging in the actual entity headers and doing normal
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers hop-by-hop cleansing. [Dirk-Willem van Gulik].
ba0ec5e897ef99d420c8c14c2374e0f32b7043dbKlaus Luettich *) cache: retire ap_cache_cacheable_hdrs_out() which was used
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers for both in- and out-put headers; and replace it by a single
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder ap_cache_cacheable_headers() wrapped in a in- and out-put
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder specific ap_cache_cacheable_headers_in()/out(). The latter
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder which will also merge error and ensure content-type. To keep
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder cache modules consistent with ease. This API change bumps
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder up the minor MM by one [Dirk-Willem van Gulik].
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder *) mod_rewrite: Allow Cookie option to set secure and HttpOnly flags.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 44799 [Christian Wenz <christian wenz.org>]
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder *) Move the KeptBodySize directive, kept_body filters and the
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder ap_parse_request_body function out of the http module and into a
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers new module called mod_request, reducing the size of the core.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Graham Leggett]
d67a33b40578beef2e255a274f89bb9c34aaf056Christian Maeder *) mod_dbd: Handle integer configuration directive parameters with a
d67a33b40578beef2e255a274f89bb9c34aaf056Christian Maeder dedicated function.
26f228bf3a3fea810223396e5794c217a79a8d5bChristian Maeder *) Change the directives within the mod_session* modules to be valid
d67a33b40578beef2e255a274f89bb9c34aaf056Christian Maeder both inside and outside the location/directory sections, as
26f228bf3a3fea810223396e5794c217a79a8d5bChristian Maeder suggested by wrowe. [Graham Leggett]
ba904a15082557e939db689fcfba0c68c9a4f740Christian Maeder *) mod_auth_form: Add a module capable of allowing end users to log
ba904a15082557e939db689fcfba0c68c9a4f740Christian Maeder in using an HTML form, storing the credentials within mod_session.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Graham Leggett]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) Add a function to the http filters that is able to parse an HTML
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder form request with the type of application/x-www-form-urlencoded.
26f228bf3a3fea810223396e5794c217a79a8d5bChristian Maeder [Graham Leggett]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_session_crypto: Initialise SSL in the post config hook.
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder [Ruediger Pluem, Graham Leggett]
75cda7e5b890d050d560d970af244a183f28328fKlaus Luettich *) mod_session_dbd: Add a session implementation capable of storing
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder session information in a SQL database via the dbd interface. Useful
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder for sites where session privacy is important. [Graham Leggett]
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder *) mod_session_crypto: Add a session encoding implementation capable
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder of encrypting and decrypting sessions wherever they may be stored.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder Introduces a level of privacy when sessions are stored on the
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder browser. [Graham Leggett]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_session_cookie: Add a session implementation capable of storing
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder session information within cookies on the browser. Useful for high
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning volume sites where server bound sessions are too resource intensive.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Graham Leggett]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_session: Add a generic session interface to unify the different
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder attempts at saving persistent sessions across requests.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Graham Leggett]
470ca7a2797069ae4b27c34c1b71419f67be1f84Christian Maeder *) core, authn/z: Avoid calling access control hooks for internal requests
470ca7a2797069ae4b27c34c1b71419f67be1f84Christian Maeder with configurations which match those of initial request. Revert to
470ca7a2797069ae4b27c34c1b71419f67be1f84Christian Maeder original behaviour (call access control hooks for internal requests
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder with URIs different from initial request) if any access control hooks or
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder providers are not registered as permitting this optimization.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder Introduce wrappers for access control hook and provider registration
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder which can accept additional mode and flag data. [Chris Darroch]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) Introduced ap_expr API for expression evaluation.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder This is adapted from mod_include, which is the first module
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder to use the new API.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_authz_dbd: When redirecting after successful login/logout per
ce50fe187cdae64e75e510daafb78156280bdb91Christian Maeder AuthzDBDRedirectQuery, do not report authorization failure, and use
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder first row returned by database query instead of last row.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Chris Darroch]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_ldap: Correctly return all requested attribute values
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder when some attributes have a null value.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 44560 [Anders Kaseorg <anders kaseorg.com>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) core: check symlink ownership if both FollowSymlinks and
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder SymlinksIfOwnerMatch are set [Nick Kew]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) core: fix origin checking in SymlinksIfOwnerMatch
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 36783 [Robert L Mathews <rob-apache.org.bugs tigertech.net>]
327a9b9bf44b6e33f71fee7526dc1c0035251591Christian Maeder *) Activate mod_cache, mod_file_cache and mod_disc_cache as part of the
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder 'most' set for '--enable-modules' and '--enable-shared-mods'. Include
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder mod_mem_cache in 'all' as well. [Dirk-Willem van Gulik]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) Also install mod_so.h, mod_rewrite.h and mod_cache.h; as these
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder contain public function declarations which are useful for
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder third party module authors. PR 42431 [Dirk-Willem van Gulik].
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_dir, mod_negotiation: pass the output filter information
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder to newly created sub requests; as these are later on used
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder as true requests with an internal redirect. This allows for
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder mod_cache et.al. to trap the results of the redirect.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Dirk-Willem van Gulik, Ruediger Pluem]
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers *) mod_ldap: Add support (taking advantage of the new APR capability)
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers for ldap rebind callback while chasing referrals. This allows direct
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers searches on LDAP servers (in particular MS Active Directory 2003+)
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers using referrals without the use of the global catalog.
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers PRs 26538, 40268, and 42557 [Paul J. Reder]
c55a0f77be7e88d3620b419ec8961f4379a586e3Klaus Luettich *) mod_ssl: Added server name indication support (SNI, RFC 4366).
c55a0f77be7e88d3620b419ec8961f4379a586e3Klaus Luettich PR 34607. [Kaspar Brand <asfbugz velox.ch>]. A test configuration
c55a0f77be7e88d3620b419ec8961f4379a586e3Klaus Luettich can be created with test/make_sni.sh [Dirk-Willem van Gulik].
5d4038657f6a63e131f5804af2f7957b69e15a43Klaus Luettich *) ApacheMonitor.exe: Introduce --kill argument for use by the
5d4038657f6a63e131f5804af2f7957b69e15a43Klaus Luettich installer. This will permit the installation tool to remove
5d4038657f6a63e131f5804af2f7957b69e15a43Klaus Luettich all running instances before attempting to remove the .exe.
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers [William Rowe]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_ssl: Add support for OCSP validation of client certificates.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 41123. [Marc Stern <marc.stern approach.be>, Joe Orton]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_serf: New module for Reverse Proxying. [Paul Querna]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) core: Add the option to keep aside a request body up to a certain
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder size that would otherwise be discarded, to be consumed by filters
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder such as mod_include. When enabled for a directory, POST requests
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder to shtml files can be passed through to embedded scripts as POST
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder requests, rather being downgraded to GET requests. [Graham Leggett]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_ssl: Fix TLS upgrade (RFC 2817) support. PR 41231. [Joe Orton]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) scoreboard: Correctly declare ap_time_process_request.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 43789 [Tom Donovan <Tom.Donovan acm.org>]
efa8f9db01f64e2c719c201e4037743caefae045Klaus Luettich *) core; scoreboard: ap_get_scoreboard_worker(sbh) now takes the sbh member
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder from the connection rec, ap_get_scoreboard_worker(proc, thread) will now
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder provide the unusual legacy lookup. [William Rowe]
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder *) mpm winnt: fix null pointer dereference
d67a33b40578beef2e255a274f89bb9c34aaf056Christian Maeder PR 42572 [Davi Arnaut]
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder *) mod_authnz_ldap, mod_authn_dbd: Tidy up the code to expose authn
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers parameters to the environment. Improve portability to
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder EBCDIC machines by using apr_toupper(). [Martin Kraemer]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_ldap, mod_authnzldap: Add support for nested groups (i.e. the ability
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder to authorize an authenticated user via a "require ldap-group X" directive
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder where the user is not in group X, but is in a subgroup contained in X.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder PR 42891 [Paul J. Reder]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_ssl: Add support for caching SSL Sessions in memcached. [Paul Querna]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_ldap: Fix the search limit parameter to ldap_search_ext_s()
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder for SDKs that define LDAP_NO_LIMIT to something other than -1.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [David Jones <oscaremma gmail.com>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) apxs: Enhance -q flag to print all known variables and their values
1a6464613c59e35072b90ca296ae402cbe956144Christian Maeder when invoked without variable name(s).
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [William Rowe, Sander Temme]
1a6464613c59e35072b90ca296ae402cbe956144Christian Maeder *) apxs: Eliminate run-time check for mod_so. PR 40653.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [David M. Lee <dmlee crossroads.com>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) beos MPM: Create pmain pool and run modules' child_init hooks when
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder entering ap_mpm_run(), then destroy pmain when exiting ap_mpm_run().
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder [Chris Darroch]
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder *) netware MPM: Destroy pmain pool when exiting ap_mpm_run() so that
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder cleanups registered in modules' child_init hooks are performed.
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers [Chris Darroch]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) mod_dbd: Stash DBD connections in request_config of initial request
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder only, or else sub-requests and internal redirections may cause
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers entire DBD pool to be stashed in a single HTTP request. [Chris Darroch]
f29371d8bd5a232c974e736b06d0d8a655d320fbKlaus Luettich *) Fix issue which could cause error messages to be written to access logs
f29371d8bd5a232c974e736b06d0d8a655d320fbKlaus Luettich on Win32. PR 40476. [Tom Donovan <Tom.Donovan acm.org>]
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder *) The LockFile directive, which specifies the location of
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder the accept() mutex lockfile, is deprecated. Instead, the
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder AcceptMutex directive now takes an optional lockfile
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder location parameter, ala SSLMutex. [Jim Jagielski]
88c800932dd7053322501ea2039d9f234be6866cKlaus Luettich *) mod_authn_dbd: Export any additional columns queried in the SQL select
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder into the environment with the name AUTHENTICATE_<COLUMN>. This brings
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder mod_authn_dbd behaviour in line with mod_authnz_ldap. [Graham Leggett]
[Niklas Edmundsson <nikke acc.umu.se>]
[Stijn Hoop <stijn sandcat.nl>]
[Niklas Edmundsson <nikke acc.umu.se>]
final name. [Davi Arnaut <davi haxent.com.br>]
[Markus Schiegl <ms schiegl.com>]
*) Remove incorrect comments from scoreboard.h regarding conditional
[Chris Darroch <chrisd pearsoncmg.com>]
in ap_init_scoreboard(). [Chris Darroch <chrisd pearsoncmg.com>]
[Chris Darroch <chrisd pearsoncmg.com>]
and 'Reject' to mod_authz_core. The new directives introduce 'AND/OR'
*) mod_authz_dbd: SQL authz with Login/Session support [Nick Kew]
Apache 2.2.xx tree as documented, and except as noted, below.]
Changes with Apache 2.2.x and later:
Changes with Apache 2.0.x and later:
Changes with Apache 1.3.x and later: