CHANGES revision b9aa9ca00496f67eb755d67764775ff23ac7eb03
6f3e57ac9d0b054c3169579f3422080b8ba10105mx -*- coding: utf-8 -*-
47693af92e50a1ad81825eb01b7157a211269613mxChanges with Apache 2.3.6
47693af92e50a1ad81825eb01b7157a211269613mx *) SECURITY: CVE-2009-3555 (cve.mitre.org)
47693af92e50a1ad81825eb01b7157a211269613mx mod_ssl: Comprehensive fix of the TLS renegotiation prefix injection
47693af92e50a1ad81825eb01b7157a211269613mx attack when compiled against OpenSSL version 0.9.8m or later. Introduces
47693af92e50a1ad81825eb01b7157a211269613mx the 'SSLInsecureRenegotiation' directive to reopen this vulnerability
47693af92e50a1ad81825eb01b7157a211269613mx and offer unsafe legacy renegotiation with clients which do not yet
47693af92e50a1ad81825eb01b7157a211269613mx support the new secure renegotiation protocol, RFC 5746.
47693af92e50a1ad81825eb01b7157a211269613mx [Joe Orton, and with thanks to the OpenSSL Team]
47693af92e50a1ad81825eb01b7157a211269613mx *) SECURITY: CVE-2009-3555 (cve.mitre.org)
47693af92e50a1ad81825eb01b7157a211269613mx mod_ssl: A partial fix for the TLS renegotiation prefix injection attack
47693af92e50a1ad81825eb01b7157a211269613mx by rejecting any client-initiated renegotiations. Forcibly disable
47693af92e50a1ad81825eb01b7157a211269613mx keepalive for the connection if there is any buffered data readable. Any
47693af92e50a1ad81825eb01b7157a211269613mx configuration which requires renegotiation for per-directory/location
47693af92e50a1ad81825eb01b7157a211269613mx access control is still vulnerable, unless using OpenSSL >= 0.9.8l.
47693af92e50a1ad81825eb01b7157a211269613mx [Joe Orton, Ruediger Pluem, Hartmut Keil <Hartmut.Keil adnovum.ch>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) SECURITY: CVE-2010-0408 (cve.mitre.org)
6f3e57ac9d0b054c3169579f3422080b8ba10105mx mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent
47693af92e50a1ad81825eb01b7157a211269613mx when request headers indicate a request body is incoming; not a case of
47693af92e50a1ad81825eb01b7157a211269613mx HTTP_INTERNAL_SERVER_ERROR. [Niku Toivola <niku.toivola sulake.com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) SECURITY: CVE-2010-0425 (cve.mitre.org)
6f3e57ac9d0b054c3169579f3422080b8ba10105mx mod_isapi: Do not unload an isapi .dll module until the request
6f3e57ac9d0b054c3169579f3422080b8ba10105mx processing is completed, avoiding orphaned callback pointers.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Brett Gervasoni <brettg senseofsecurity.com>, Jeff Trawick]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ldap: LDAP caching was suppressed (and ldap-status handler returns
6f3e57ac9d0b054c3169579f3422080b8ba10105mx title page only) when any mod_ldap directives were used in VirtualHost
6f3e57ac9d0b054c3169579f3422080b8ba10105mx context. [Eric Covener]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_disk_cache: Decline the opportunity to cache if the response is
6f3e57ac9d0b054c3169579f3422080b8ba10105mx a 206 Partial Content. This stops a reverse proxied partial response
6f3e57ac9d0b054c3169579f3422080b8ba10105mx from becoming cached, and then being served in subsequent responses.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_deflate: avoid the risk of forwarding data before headers are set.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 49369 [Matthew Steele <mdsteele google.com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_authnz_ldap: Ensure nested groups are checked when the
6f3e57ac9d0b054c3169579f3422080b8ba10105mx top-level group doesn't have any direct non-group members
6f3e57ac9d0b054c3169579f3422080b8ba10105mx of attributes in AuthLDAPGroupAttribute. [Eric Covener]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_authnz_ldap: Search or Comparison during authorization phase
6f3e57ac9d0b054c3169579f3422080b8ba10105mx can use the credentials from the authentication phase
6f3e57ac9d0b054c3169579f3422080b8ba10105mx (AuthLDAPSearchAsUSer,AuthLDAPCompareAsUser).
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 48340 [Domenico Rotiroti, Eric Covener]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_authnz_ldap: Allow the initial DN search during authentication
6f3e57ac9d0b054c3169579f3422080b8ba10105mx to use the HTTP username/pass instead of an anonymous or hard-coded
6f3e57ac9d0b054c3169579f3422080b8ba10105mx LDAP id (AuthLDAPInitialBindAsUser, AuthLDAPInitialBindPattern).
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Eric Covener]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_authnz_ldap: Publish requested LDAP data with an AUTHORIZE_ prefix
6f3e57ac9d0b054c3169579f3422080b8ba10105mx when this module is used for authorization. See AuthLDAPAuthorizePrefix.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 45584 [Eric Covener]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) apxs -q: Stop filtering out ':' characters from the reported values.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 45343. [Bill Cole]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) prefork MPM: Run cleanups for final request when process exits gracefully.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 43857. [Tom Donovan]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) ab: fix number of requests sent by ab when keepalive is enabled. PR 48497.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Bryn Dole <dole blekko.com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Log an error for failures to read a chunk-size, and return 408 instead of
6f3e57ac9d0b054c3169579f3422080b8ba10105mx 413 when this is due to a read timeout. This change also fixes some cases
6f3e57ac9d0b054c3169579f3422080b8ba10105mx of two error documents being sent in the response for the same scenario.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Eric Covener] PR49167
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy_balancer: Add new directive BalancerNonce to allow admin
6f3e57ac9d0b054c3169579f3422080b8ba10105mx to control/set the nonce used in the balancer-manager application.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Jim Jagielski]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy_connect: Support port ranges in AllowConnect. PR 23673.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Proxy balancer: support setting error status according to HTTP response
6f3e57ac9d0b054c3169579f3422080b8ba10105mx code from a backend. PR 48939. [Daniel Ruggeri <DRuggeri primary.net>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) htcacheclean: Introduce the ability to clean specific URLs from the
6f3e57ac9d0b054c3169579f3422080b8ba10105mx cache, if provided as an optional parameter on the command line.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) core: Introduce the IncludeStrict directive, which explicitly fails
6f3e57ac9d0b054c3169579f3422080b8ba10105mx server startup if no files or directories match a wildcard path.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) htcacheclean: Report additional statistics about entries deleted.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 48944. [Mark Drayton mark markdrayton.info]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Introduce SSLFIPS directive to support OpenSSL FIPS_mode; permits all
6f3e57ac9d0b054c3169579f3422080b8ba10105mx builds of mod_ssl to use 'SSLFIPS off' for portability, but the proper
6f3e57ac9d0b054c3169579f3422080b8ba10105mx build of openssl is required for 'SSLFIPS on'. PR 46270.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Dr Stephen Henson <steve openssl.org>, William Rowe]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy_http: Log the port of the remote server in various messages.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 48812. [Igor Galić <i galic brainsware org>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_reqtimeout: Do not wrongly enforce timeouts for mod_proxy's backend
6f3e57ac9d0b054c3169579f3422080b8ba10105mx connections and other protocol handlers (like mod_ftp). [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy_ajp: Really regard the operation a success, when the client
6f3e57ac9d0b054c3169579f3422080b8ba10105mx aborted the connection. In addition adjust the log message if the client
6f3e57ac9d0b054c3169579f3422080b8ba10105mx aborted the connection. [Ruediger Pluem]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ssl: Add the 'SSLInsecureRenegotiation' directive, which
6f3e57ac9d0b054c3169579f3422080b8ba10105mx allows insecure renegotiation with clients which do not yet
6f3e57ac9d0b054c3169579f3422080b8ba10105mx support the secure renegotiation protocol. [Joe Orton]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ssl: Fix a potential I/O hang if a long list of trusted CAs
6f3e57ac9d0b054c3169579f3422080b8ba10105mx is configured for client cert auth. PR 46952. [Joe Orton]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) core: Only log a 408 if it is no keepalive timeout. PR 39785
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Ruediger Pluem, Mark Montague <markmont umich.edu>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) support/rotatelogs: Add -L option to create a link to the current
6f3e57ac9d0b054c3169579f3422080b8ba10105mx log file. PR 48761 [<lyndon orthanc.ca>, Dan Poirier]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ldap: Update LDAPTrustedClientCert to consistently be a per-directory
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj setting only, matching most of the documentation and examples.
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj PR 46541 [Paul Reder, Eric Covener]
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj *) mod_ldap: LDAPTrustedClientCert now accepts CA_DER/CA_BASE64 argument
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj types previously allowed only in LDAPTrustedGlobalCert. [Eric Covener]
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj *) mod_negotiation: Preserve query string over multiviews negotiation.
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj This buglet was fixed for type maps in 2.2.6, but the same issue
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj affected multiviews and was overlooked.
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj PR 33112 [Joergen Thomsen <apache jth.net>]
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj *) mod_ldap: Eliminate a potential crash with multiple LDAPTrustedClientCert
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj when some are not password-protected. [Eric Covener]
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj *) Fix startup segfault when the Mutex directive is used but no loaded
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj modules use httpd mutexes. PR 48787. [Jeff Trawick]
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj *) Proxy: get the headers right in a HEAD request with
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj ProxyErrorOverride, by checking for an overridden error
02d51d0d625c185ad277d9ad1ddf34b06f78b9b4jj before not after going into a catch-all code path.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 41646. [Nick Kew, Stuart Children]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) support/rotatelogs: Support the simplest log rotation case, log
6f3e57ac9d0b054c3169579f3422080b8ba10105mx truncation. Useful when the log is being processed in real time
6f3e57ac9d0b054c3169579f3422080b8ba10105mx using a command like tail. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) support/htcacheclean: Teach it how to write a pid file (modelled on
6f3e57ac9d0b054c3169579f3422080b8ba10105mx httpd's writing of a pid file) so that it becomes possible to run
6f3e57ac9d0b054c3169579f3422080b8ba10105mx more than one instance of htcacheclean on the same machine.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Log command line on startup, so there's a record of command line
6f3e57ac9d0b054c3169579f3422080b8ba10105mx arguments like -f. PR 48752. [Dan Poirier]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Introduce mod_reflector, a handler capable of reflecting POSTed
6f3e57ac9d0b054c3169579f3422080b8ba10105mx request bodies back within the response through the output filter
6f3e57ac9d0b054c3169579f3422080b8ba10105mx stack. Can be used to turn an output filter into a web service.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy_http: Make sure that when an ErrorDocument is served
6f3e57ac9d0b054c3169579f3422080b8ba10105mx from a reverse proxied URL, that the subrequest respects the status
6f3e57ac9d0b054c3169579f3422080b8ba10105mx of the original request. This brings the behaviour of proxy_handler
6f3e57ac9d0b054c3169579f3422080b8ba10105mx in line with default_handler. PR 47106. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Support wildcards in both the directory and file components of
6f3e57ac9d0b054c3169579f3422080b8ba10105mx the path specified by the Include directive. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy, mod_proxy_http: Support remote https proxies
6f3e57ac9d0b054c3169579f3422080b8ba10105mx by using HTTP CONNECT. PR 19188.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Philippe Dutrueux <lilas evidian.com>, Rainer Jung]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) apxs: Fix -A and -a options to ignore whitespace in httpd.conf
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Philip M. Gollucci]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) worker: Don't report server has reached MaxClients until it has.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Add message when server gets within MinSpareThreads of MaxClients.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 46996. [Dan Poirier]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_session: Session expiry was being initialised, but not updated
6f3e57ac9d0b054c3169579f3422080b8ba10105mx on each session save, resulting in timed out sessions when there
6f3e57ac9d0b054c3169579f3422080b8ba10105mx should not have been. Fixed. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_log_config: Add the R option to log the handler used within the
6f3e57ac9d0b054c3169579f3422080b8ba10105mx request. [Christian Folini <christian.folini netnea com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_include: Allow fine control over the removal of Last-Modified and
6f3e57ac9d0b054c3169579f3422080b8ba10105mx ETag headers within the INCLUDES filter, making it possible to cache
6f3e57ac9d0b054c3169579f3422080b8ba10105mx responses if desired. Fix the default value of the SSIAccessEnable
6f3e57ac9d0b054c3169579f3422080b8ba10105mx directive. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Add new UnDefine directive to undefine a variable. PR 35350.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Make ap_pregsub(), used by AliasMatch and friends, use the same syntax
6f3e57ac9d0b054c3169579f3422080b8ba10105mx for regex backreferences as mod_rewrite and mod_include: Remove the use
6f3e57ac9d0b054c3169579f3422080b8ba10105mx of '&' as an alias for '$0' and allow to escape any character with a
6f3e57ac9d0b054c3169579f3422080b8ba10105mx backslash. PR 48351. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_authnz_ldap: If AuthLDAPCharsetConfig is set, also convert the
6f3e57ac9d0b054c3169579f3422080b8ba10105mx password to UTF-8. PR 45318.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Johannes Müller <joh_m gmx.de>, Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) ab: Fix calculation of requests per second in HTML output. PR 48594.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_authnz_ldap: Failures to map a username to a DN, or to check a user
6f3e57ac9d0b054c3169579f3422080b8ba10105mx password now result in an informational level log entry instead of
6f3e57ac9d0b054c3169579f3422080b8ba10105mx warning level. [Eric Covener]
6f3e57ac9d0b054c3169579f3422080b8ba10105mxChanges with Apache 2.3.5
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) SECURITY: CVE-2010-0434 (cve.mitre.org)
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Ensure each subrequest has a shallow copy of headers_in so that the
6f3e57ac9d0b054c3169579f3422080b8ba10105mx parent request headers are not corrupted. Eliminates a problematic
6f3e57ac9d0b054c3169579f3422080b8ba10105mx optimization in the case of no request body. PR 48359
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Jake Scott, William Rowe, Ruediger Pluem]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Turn static function get_server_name_for_url() into public
6f3e57ac9d0b054c3169579f3422080b8ba10105mx ap_get_server_name_for_url() and use it where appropriate. This
6f3e57ac9d0b054c3169579f3422080b8ba10105mx fixes mod_rewrite generating invalid URLs for redirects to IPv6
6f3e57ac9d0b054c3169579f3422080b8ba10105mx literal addresses. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ldap: Introduce new config option LDAPTimeout to set the timeout
6f3e57ac9d0b054c3169579f3422080b8ba10105mx for LDAP operations like bind and search. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy, mod_proxy_ftp: Move ProxyFtpDirCharset from mod_proxy to
6f3e57ac9d0b054c3169579f3422080b8ba10105mx mod_proxy_ftp. [Takashi Sato]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy, mod_proxy_connect: Move AllowCONNECT from mod_proxy to
6f3e57ac9d0b054c3169579f3422080b8ba10105mx mod_proxy_connect. [Takashi Sato]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_cache: Do an exact match of the keys defined by
6f3e57ac9d0b054c3169579f3422080b8ba10105mx CacheIgnoreURLSessionIdentifiers against the querystring instead of
6f3e57ac9d0b054c3169579f3422080b8ba10105mx a partial match. PR 48401.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Dodou Wang <wangdong.08 gmail.com>, Ruediger Pluem]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy_balancer: Fix crash in balancer-manager. [Rainer Jung]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Core HTTP: disable keepalive when the Client has sent
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Expect: 100-continue
6f3e57ac9d0b054c3169579f3422080b8ba10105mx but we respond directly with a non-100 response.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Keepalive here led to data from clients continuing being treated as
6f3e57ac9d0b054c3169579f3422080b8ba10105mx a new request.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 47087 [Nick Kew]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Core: reject NULLs in request line or request headers.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 43039 [Nick Kew]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Core: (re)-introduce -T commandline option to suppress documentroot
6f3e57ac9d0b054c3169579f3422080b8ba10105mx check at startup.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 41887 [Jan van den Berg <janvdberg gmail.com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_autoindex: support XHTML as equivalent to HTML in IndexOptions,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx ScanHTMLTitles, ReadmeName, HeaderName
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 48416 [Dmitry Bakshaev <dab18 izhnet.ru>, Nick Kew]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Proxy: Fix ProxyPassReverse with relative URL
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Derived (slightly erroneously) from PR 38864 [Nick Kew]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_headers: align Header Edit with Header Set when used on Content-Type
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_headers: Enable multi-match-and-replace edit option
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 47066 [Nick Kew]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_filter: enable it to act on non-200 responses.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 48377 [Nick Kew]
6f3e57ac9d0b054c3169579f3422080b8ba10105mxChanges with Apache 2.3.4
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Replace AcceptMutex, LockFile, RewriteLock, SSLMutex, SSLStaplingMutex,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx and WatchdogMutexPath with a single Mutex directive. Add APIs to
6f3e57ac9d0b054c3169579f3422080b8ba10105mx simplify setup and user customization of APR proc and global mutexes.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx (See util_mutex.h.) Build-time setting DEFAULT_LOCKFILE is no longer
6f3e57ac9d0b054c3169579f3422080b8ba10105mx respected; set DEFAULT_REL_RUNTIMEDIR instead. [Jeff Trawick]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) http_core: KeepAlive no longer accepts other than On|Off.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Takashi Sato]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav: Remove errno from dav_error interface. Calls to dav_new_error()
6f3e57ac9d0b054c3169579f3422080b8ba10105mx and dav_new_error_tag() must be adjusted to add an apr_status_t parameter.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Jeff Trawick]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_authnz_ldap: Add AuthLDAPBindAuthoritative to allow Authentication to
6f3e57ac9d0b054c3169579f3422080b8ba10105mx try other providers in the case of an LDAP bind failure.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 46608 [Justin Erenkrantz, Joe Schaefer, Tony Stevenson]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Build: fix --with-module to work as documented
6f3e57ac9d0b054c3169579f3422080b8ba10105mxChanges with Apache 2.3.3
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) SECURITY: CVE-2009-3095 (cve.mitre.org)
6f3e57ac9d0b054c3169579f3422080b8ba10105mx mod_proxy_ftp: sanity check authn credentials.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch <sf fritsch.de>, Joe Orton]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) SECURITY: CVE-2009-3094 (cve.mitre.org)
6f3e57ac9d0b054c3169579f3422080b8ba10105mx mod_proxy_ftp: NULL pointer dereference on error paths.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch <sf fritsch.de>, Joe Orton]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ssl: enable support for ECC keys and ECDH ciphers. Tested against
6f3e57ac9d0b054c3169579f3422080b8ba10105mx OpenSSL 1.0.0b3. [Vipul Gupta <vipul.gupta sun.com>, Sander Temme]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav: Include uri when logging a PUT error due to connection abort.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 38149. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav: Return 409 instead of 500 for a LOCK request if the parent
6f3e57ac9d0b054c3169579f3422080b8ba10105mx resource does not exist or is not a collection. PR 43465. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav_fs: Return 409 instead of 500 for Litmus test case copy_nodestcoll
6f3e57ac9d0b054c3169579f3422080b8ba10105mx (a COPY request where the parent of the destination resource does not
6f3e57ac9d0b054c3169579f3422080b8ba10105mx exist). PR 39299. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav_fs: Don't delete the whole file if a PUT with content-range failed.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 42896. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav_fs: Make PUT create files atomically and no longer destroy the
6f3e57ac9d0b054c3169579f3422080b8ba10105mx old file if the transfer aborted. PR 39815. [Paul Querna, Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav_fs: Remove inode keyed locking as this conflicts with atomically
6f3e57ac9d0b054c3169579f3422080b8ba10105mx creating files. On systems with inode numbers, this is a format change of
6f3e57ac9d0b054c3169579f3422080b8ba10105mx the DavLockDB. The old DavLockDB must be deleted on upgrade.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_log_config: Make ${cookie}C correctly match whole cookie names
6f3e57ac9d0b054c3169579f3422080b8ba10105mx instead of substrings. PR 28037. [Dan Franklin <dan dan-franklin.com>,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) vhost: A purely-numeric Host: header should not be treated as a port.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 44979 [Nick Kew]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ldap: Avoid 500 errors with "Unable to set LDAP_OPT_REFHOPLIMIT option to 5"
6f3e57ac9d0b054c3169579f3422080b8ba10105mx when built against openldap by using SDK LDAP_OPT_REFHOPLIMIT defaults unless
6f3e57ac9d0b054c3169579f3422080b8ba10105mx LDAPReferralHopLimit is explicitly configured.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Eric Covener]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_charset_lite: Honor 'CharsetOptions NoImplicitAdd'.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Eric Covener]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ssl: Add support for OCSP Stapling. PR 43822.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Dr Stephen Henson <shenson oss-institute.org>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_socache_shmcb: Allow parens in file name if cache size is given.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Fixes SSLSessionCache directive mis-parsing parens in pathname.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 47945. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) htpasswd: Improve out of disk space handling. PR 30877. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) htpasswd: Use MD5 hash by default on all platforms. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_sed: Reduce memory consumption when processing very long lines.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) ab: Fix segfault in case the argument for -n is a very large number.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 47178. [Philipp Hagemeister <oss phihag.de>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Allow ProxyPreserveHost to work in <Proxy> sections. PR 34901.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) configure: Fix THREADED_MPMS so that mod_cgid is enabled again
6f3e57ac9d0b054c3169579f3422080b8ba10105mx for worker MPM. [Takashi Sato]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav: Provide a mechanism to obtain the request_rec and pathname
6f3e57ac9d0b054c3169579f3422080b8ba10105mx from the dav_resource. [Jari Urpalainen <jari.urpalainen nokia.com>,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Brian France <brian brianfrance.com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) Build: Use install instead of cp if available on installing
6f3e57ac9d0b054c3169579f3422080b8ba10105mx modules to avoid segmentation fault. PR 47951. [hirose31 gmail.com]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_cache: correctly consider s-maxage in cacheability
6f3e57ac9d0b054c3169579f3422080b8ba10105mx decisions. [Dan Poirier]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_logio/core: Report more accurate byte counts in mod_status if
6f3e57ac9d0b054c3169579f3422080b8ba10105mx mod_logio is loaded. PR 25656. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ldap: If LDAPSharedCacheSize is too small, try harder to purge
6f3e57ac9d0b054c3169579f3422080b8ba10105mx some cache entries and log a warning. Also increase the default
6f3e57ac9d0b054c3169579f3422080b8ba10105mx LDAPSharedCacheSize to 500000. This is a more realistic size suitable
6f3e57ac9d0b054c3169579f3422080b8ba10105mx for the default values of 1024 for LdapCacheEntries/LdapOpCacheEntries.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 46749. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_rewrite: Make sure that a hostname:port isn't fully qualified if
6f3e57ac9d0b054c3169579f3422080b8ba10105mx the request is a CONNECT request. [Bill Zajac <billz consultla.com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_cache: Teach CacheEnable and CacheDisable to work from within a
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Location section, in line with how ProxyPass works. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_reqtimeout: New module to set timeouts and minimum data rates for
6f3e57ac9d0b054c3169579f3422080b8ba10105mx receiving requests from the client. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) core: Fix potential memory leaks by making sure to not destroy
6f3e57ac9d0b054c3169579f3422080b8ba10105mx bucket brigades that have been created by earlier filters.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) core, mod_deflate, mod_sed: Reduce memory usage by reusing bucket
6f3e57ac9d0b054c3169579f3422080b8ba10105mx brigades in several places. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_cache: Fix uri_meets_conditions() so that CacheEnable will
6f3e57ac9d0b054c3169579f3422080b8ba10105mx match by scheme, or by a wildcarded hostname. PR 40169
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Peter Grandi <pg_asf asf.for.sabi.co.uk>, Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) suxec: Allow to log an error if exec fails by setting FD_CLOEXEC
6f3e57ac9d0b054c3169579f3422080b8ba10105mx on the log file instead of closing it. PR 10744. [Nicolas Rachinsky]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_mime: Make RemoveType override the info from TypesConfig.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 38330. [Stefan Fritsch]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_cache: Introduce the option to run the cache from within the
6f3e57ac9d0b054c3169579f3422080b8ba10105mx normal request handler, and to allow fine grained control over
6f3e57ac9d0b054c3169579f3422080b8ba10105mx where in the filter chain content is cached. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) core: Treat timeout reading request as 408 error, not 400.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Log 408 errors in access log as was done in Apache 1.3.x.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR 39785 [Nobutaka Mantani <nobutaka nobutaka.org>,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Stefan Fritsch <sf fritsch.de>, Dan Poirier]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ssl: Reintroduce SSL_CLIENT_S_DN, SSL_CLIENT_I_DN, SSL_SERVER_S_DN,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx SSL_SERVER_I_DN back to the environment variables to be set by mod_ssl.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_disk_cache: don't cache incomplete responses, per RFC 2616, 13.8.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR15866. [Dan Poirier]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) ab: ab segfaults in verbose mode on https sites
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR46393. [Ryan Niebur]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav: Allow other modules to become providers and add resource types
6f3e57ac9d0b054c3169579f3422080b8ba10105mx to the DAV response. [Jari Urpalainen <jari.urpalainen nokia.com>,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Brian France <brian brianfrance.com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_dav: Allow other modules to add things to the DAV or Allow headers
6f3e57ac9d0b054c3169579f3422080b8ba10105mx of an OPTIONS request. [Jari Urpalainen <jari.urpalainen nokia.com>,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Brian France <brian brianfrance.com>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) core: Lower memory usage of core output filter.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx [Stefan Fritsch <sf sfritsch.de>]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_mime: Detect invalid use of MultiviewsMatch inside Location and
6f3e57ac9d0b054c3169579f3422080b8ba10105mx LocationMatch sections. PR47754. [Dan Poirier]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_request: Make sure the KeptBodySize directive rejects values
6f3e57ac9d0b054c3169579f3422080b8ba10105mx that aren't valid numbers. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_session_crypto: Sanity check should the potentially encrypted
6f3e57ac9d0b054c3169579f3422080b8ba10105mx session cookie be too short. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_session.c: Prevent a segfault when session is added but not
6f3e57ac9d0b054c3169579f3422080b8ba10105mx configured. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) htcacheclean: 19 ways to fail, 1 error message. Fixed. [Graham Leggett]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_auth_digest: Fail server start when nonce count checking
6f3e57ac9d0b054c3169579f3422080b8ba10105mx is configured without shared memory, or md5-sess algorithm is
6f3e57ac9d0b054c3169579f3422080b8ba10105mx configured. [Dan Poirier]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_proxy_connect: The connect method doesn't work if the client is
6f3e57ac9d0b054c3169579f3422080b8ba10105mx connecting to the apache proxy through an ssl socket. Fixed.
6f3e57ac9d0b054c3169579f3422080b8ba10105mx PR29744. [Brad Boyer, Mark Cave-Ayland, Julian Gilbey, Fabrice Durand,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx David Gence, Tim Dodge, Per Gunnar Hans, Emmanuel Elango,
6f3e57ac9d0b054c3169579f3422080b8ba10105mx Kevin Croft, Rudolf Cardinal]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_ssl: The error message when SSLCertificateFile is missing should
6f3e57ac9d0b054c3169579f3422080b8ba10105mx at least give the name or position of the problematic virtual host
6f3e57ac9d0b054c3169579f3422080b8ba10105mx definition. [Stefan Fritsch sf sfritsch.de]
6f3e57ac9d0b054c3169579f3422080b8ba10105mx *) mod_auth_digest: Fix null pointer when qop=none. [Dan Poirier]
*) Add support for HTTP PUT to ab. [Jeff Barnes <jbarnesweb yahoo.com>]
PR 46971 [evanc nortel.com]
[Stefan Fritsch <sf sfritsch.de>]
for a file is missing. PR 47682 [Peter Poeml <poeml suse.de>]
*) SECURITY: CVE-2009-1890 (cve.mitre.org)
*) SECURITY: CVE-2009-1191 (cve.mitre.org)
by the client. PR 33098 [ Stefan Fritsch <sf sfritsch.de>]
PR 42175 [Jim Radford <radford blackbean.org>]
type. PR 45107. [Michael Ströder <michael stroeder.com>,
PR 44020 [HÃ¥kon Stordahl <hakon stordahl.org>]
CGI process. PR 47335 [Kornél Pál <kornelpal gmail.com>]
PR 46942 [Dan Poirier <poirier pobox.com>]
PR 44729 [Sönke Tesch <st kino-fahrplan.de>, Jim Jagielski]
PR 47177 [Carlos Garcia Braschi <cgbraschi gmail.com>]
PR 45082 [Vitaly Polonetsky <m_vitaly topixoft.com>]
[Marko Kevac <mkevac gmail.com>]
as A/UX, Next, and Tandem. [Jeff Trawick]
directory listing. PR 46789 [Dan Poirier <poirier pobox.com>]
of module state across unload/load. [Jeff Trawick]
[Dan Poirier <poirier pobox.com>]
[Geoff Keating <geoffk apple.com>]
with kqueue (BSD/OS X) and excessive CPU with event ports (Solaris).
a media type has not been configured via mime.types, AddType,
[Ryan Phillips <ryan-apache trolocsis.com>]
[<tlhackque yahoo.com>]
*) prefork: Fix child process hang during graceful restart/stop in
*) core/utils: Enhance ap_escape_html API to support escaping non-ASCII chars
PR 45529 [Bob Ionescu <bobsiegen googlemail.com>]
times out before returning status line/headers.
PR 39332 [Masaoki Kobayashi <masaoki techfirm.co.jp>]
[Theo Schlossnagle <jesus omniti.com>, Paul Querna]
modules/proxy/balancers [Jim Jagielski]
privileges and Unix user/group IDs [Nick Kew]
logic replicate 2.2.x authz logic, and replace <Satisfy*>, Reject,
*) unixd: turn existing code into a module, and turn the set user/group
Suggested By André Warnier <aw ice-sa.com> [Eric Covener]
*) mod_ssl: Send Content-Type application/ocsp-request for POST requests to
OSCP responders. PR 46014 [Dr Stephen Henson <steve openssl.org>]
*) Export and install the mod_rewrite.h header to ensure the optional
*) New module mod_sed: filter Request/Response bodies through sed
null value. [David Shane Holden <dpejesh apache.org>]
*) ab: Make ab.c compile on VC6. PR 45024 [Ruediger Pluem]
*) configure: Don't reject libtool 2.x
overwritten. PR 44262 [Michał Grzędzicki <lazy iq.pl>]
PR 44799 [Christian Wenz <christian wenz.org>]
both inside and outside the location/directory sections, as
form request with the type of application/x-www-form-urlencoded.
*) mod_authz_dbd: When redirecting after successful login/logout per
PR 44560 [Anders Kaseorg <anders kaseorg.com>]
mod_cache et.al. to trap the results of the redirect.
PR 34607. [Kaspar Brand <asfbugz velox.ch>]. A test configuration
can be created with test/make_sni.sh [Dirk-Willem van Gulik].
*) ApacheMonitor.exe: Introduce --kill argument for use by the
*) mod_ldap, mod_authnzldap: Add support for nested groups (i.e. the ability
[David Jones <oscaremma gmail.com>]
[David M. Lee <dmlee crossroads.com>]
[Niklas Edmundsson <nikke acc.umu.se>]
[Stijn Hoop <stijn sandcat.nl>]
[Niklas Edmundsson <nikke acc.umu.se>]
final name. [Davi Arnaut <davi haxent.com.br>]
[Markus Schiegl <ms schiegl.com>]
*) Remove incorrect comments from scoreboard.h regarding conditional
[Chris Darroch <chrisd pearsoncmg.com>]
in ap_init_scoreboard(). [Chris Darroch <chrisd pearsoncmg.com>]
[Chris Darroch <chrisd pearsoncmg.com>]
and 'Reject' to mod_authz_core. The new directives introduce 'AND/OR'
*) mod_authz_dbd: SQL authz with Login/Session support [Nick Kew]
Apache 2.2.xx tree as documented, and except as noted, below.]
Changes with Apache 2.2.x and later:
Changes with Apache 2.0.x and later:
Changes with Apache 1.3.x and later: