CHANGES revision ca8584db70d0ff4d85cbfd912573688c41be27cf
5beae861ede7eba138c7140f195ae77ba3106cbffielding -*- coding: utf-8 -*-
5beae861ede7eba138c7140f195ae77ba3106cbffieldingChanges with Apache 2.5.0
fd2db14d870ff9aa9795841360f6e3d562ad69a2jerenkrantz *) mod_session_dbd: fix a segmentation fault in the function dbd_remove.
5beae861ede7eba138c7140f195ae77ba3106cbffielding PR 53452. [<rebanerebane gmail com>, Reimo Rebane]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) core: New directive RegisterHttpMethod for registering non-standard
50085d81a01f6efbb898397253634837b2b4bddarbowen HTTP methods. [Stefan Fritsch]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) mod_xml2enc: Fix problems with charset conversion altering the
50085d81a01f6efbb898397253634837b2b4bddarbowen Content-Length. [Micha Lenk <micha lenk info>]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) core: New directive HttpProtocol which allows to disable HTTP/0.9
50085d81a01f6efbb898397253634837b2b4bddarbowen support. [Stefan Fritsch]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) mod_allowhandlers: New module to forbid specific handlers for specific
5beae861ede7eba138c7140f195ae77ba3106cbffielding directories. [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) core: Be more correct about rejecting directives that cannot work in <If>
5beae861ede7eba138c7140f195ae77ba3106cbffielding sections. [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) core: Fix directives like LogLevel that need to know if they are invoked
50085d81a01f6efbb898397253634837b2b4bddarbowen at virtual host context or in Directory/Files/Location/If sections to
5beae861ede7eba138c7140f195ae77ba3106cbffielding work properly in If sections that are not in a Directory/Files/Location.
50085d81a01f6efbb898397253634837b2b4bddarbowen [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_cache_disk: Resolve errors while revalidating disk-cached files on
5beae861ede7eba138c7140f195ae77ba3106cbffielding Windows ("...rename tempfile to datafile failed..."). PR 38827
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Eric Covener]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_proxy: Add ability to configure the sticky session separator.
5beae861ede7eba138c7140f195ae77ba3106cbffielding PR 53893. [<inu inusasha de>, Jim Jagielski]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_proxy_ftp: Fix segfaults on IPv4 requests to hosts with DNS AAAA records.
5beae861ede7eba138c7140f195ae77ba3106cbffielding PR 40841. [Andrew Rucker Jones <arjones simultan dyndns org>,
5beae861ede7eba138c7140f195ae77ba3106cbffielding <ast domdv de>, Jim Jagielski]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) ap_expr: Add req_novary function that allows HTTP header lookups
5beae861ede7eba138c7140f195ae77ba3106cbffielding without adding the name to the Vary header. [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_ssl: Change default for SSLCompression to off, as compression
5beae861ede7eba138c7140f195ae77ba3106cbffielding causes security issues in most setups. (The so called "CRIME" attack).
50085d81a01f6efbb898397253634837b2b4bddarbowen [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) syslog logging: Remove stray ", referer" at the end of some messages.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Jeff Trawick]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) configure: Fix processing of --disable-FEATURE for various features.
50085d81a01f6efbb898397253634837b2b4bddarbowen [Jeff Trawick]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) "Iterate" directives: Report an error if no arguments are provided.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Jeff Trawick]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) htpasswd, htdbm: Optionally read passwords from stdin, as more
50085d81a01f6efbb898397253634837b2b4bddarbowen secure alternative to -b. PR 40243. [Adomas Paltanavicius <adomas
5beae861ede7eba138c7140f195ae77ba3106cbffielding paltanavicius gmail com>, Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) htpasswd, htdbm: Add support for bcrypt algorithm (requires
5beae861ede7eba138c7140f195ae77ba3106cbffielding apr-util 1.5 or higher). PR 49288. [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) htpasswd, htdbm: Put full 48bit of entropy into salt, improve
5beae861ede7eba138c7140f195ae77ba3106cbffielding error handling. Add some of htpasswd's improvements to htdbm,
5beae861ede7eba138c7140f195ae77ba3106cbffielding e.g. warn if password is truncated by crypt(). [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) ab: add TLS1.1/TLS1.2 options to -f switch, and adapt output
5beae861ede7eba138c7140f195ae77ba3106cbffielding to more accurately report the negotiated protocol. PR 53916.
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding [Nicolás Pernas Maradei <nico emutex com>, Kaspar Brand]
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding *) mod_systemd: New module, for integration with systemd on Linux.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Jan Kaluza <jkaluza redhat.com>]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) core: ErrorDocument now works for requests without a Host header.
50085d81a01f6efbb898397253634837b2b4bddarbowen PR 48357. [Jeff Trawick]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) --with-module: Fix failure to integrate them into some existing
50085d81a01f6efbb898397253634837b2b4bddarbowen module directories. PR 40097. [Jeff Trawick]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) mod_headers: New params: %l for load averages, %i for an
50085d81a01f6efbb898397253634837b2b4bddarbowen idle percentage rating of httpd, and %b for a busy percentage
50085d81a01f6efbb898397253634837b2b4bddarbowen rating. [Jim Jagielski]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) core: New functions to obtain load parameters: ap_get_sload()
50085d81a01f6efbb898397253634837b2b4bddarbowen and ap_get_loadavg(). [Jim Jagielski]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) mod_cache_socache: New cache implementation backed by mod_socache
50085d81a01f6efbb898397253634837b2b4bddarbowen that replaces mod_mem_cache removed from httpd v2.2. [Graham
50085d81a01f6efbb898397253634837b2b4bddarbowen *) mod_auth_form: Support the expr parser in the
50085d81a01f6efbb898397253634837b2b4bddarbowen AuthFormLoginRequiredLocation, AuthFormLoginSuccessLocation and
50085d81a01f6efbb898397253634837b2b4bddarbowen AuthFormLogoutLocation directives. [Graham Leggett]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) core: Add dirwalk_stat and pre_htaccess hooks, allowing mpm-itk
50085d81a01f6efbb898397253634837b2b4bddarbowen to be used without patches to httpd core. [Jeff Trawick]
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding *) mod_proxy: Allow for persistence of local changes (via the
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding balancer-manager) between graceful and normal restarts.
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding [Jim Jagielski]
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding *) mod_slotmem: New provider function, fgrab(), which forces an
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding allocation of a slot. [Jim Jagielski]
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding *) mod_proxy_balancer: The nonce is only derived from the UUID iff
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding not set via the 'nonce' balancer param. [Jim Jagielski]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_lua: Add LuaInputFilter/LuaOutputFilter for creating content
5beae861ede7eba138c7140f195ae77ba3106cbffielding filters in Lua [Daniel Gruno]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) core: Apply length limit when logging Status header values.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Jeff Trawick, Chris Darroch]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) mod_ssl: Match wildcard SSL certificate names in proxy mode.
5beae861ede7eba138c7140f195ae77ba3106cbffielding PR 53006. [Joe Orton]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) WinNT MPM: Store pid and generation for each thread in scoreboard
5beae861ede7eba138c7140f195ae77ba3106cbffielding to allow tracking of threads from exiting children via mod_status
5beae861ede7eba138c7140f195ae77ba3106cbffielding or other such mechanisms. [Jeff Trawick]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_ssl: Catch missing or mismatched client cert/key pairs with
50085d81a01f6efbb898397253634837b2b4bddarbowen SSLProxyMachineCertificateFile/Path directives. PR 52212.
209d30d974f66f7f62c5888827d4cc0b95de40c0lars [Keith Burdis <keith burdis.org>, Joe Orton]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) mod_lua: Allow scripts handled by the lua-script handler to return
209d30d974f66f7f62c5888827d4cc0b95de40c0lars a status code to the client (such as a 302 or a 500) [Daniel Gruno]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_proxy_ajp: Fix crash in packet dump code when logging
5beae861ede7eba138c7140f195ae77ba3106cbffielding with LogLevel trace7 or trace8. PR 53730. [Rainer Jung]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_cache: Wrong content type and character set when
0729ed19effa96566e715392dd17440bb5a107d6jwoolley mod_cache serves stale content because of a proxy error.
0729ed19effa96566e715392dd17440bb5a107d6jwoolley PR 53539. [Rainer Jung, Ruediger Pluem]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_lua: Decline handling 'lua-script' if the file doesn't exist,
711d4b43c1e5c33611ac1b938cf7b944c3aa77b7jerenkrantz rather than throwing an internal server error. [Daniel Gruno]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_lua: Add functions r:flush and r:sendfile as well as additional
50085d81a01f6efbb898397253634837b2b4bddarbowen request information to the request_rec structure. [Daniel Gruno]
209d30d974f66f7f62c5888827d4cc0b95de40c0lars *) mod_lua: Add a server scope for Lua states, which creates a pool of
209d30d974f66f7f62c5888827d4cc0b95de40c0lars states with managable minimum and maximum size. [Daniel Gruno]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) core: Add post_perdir_config hook.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Steinar Gunderson <sgunderson bigfoot.com>]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) mod_lua: Add new directive, LuaMapHandler, for dynamically mapping
5beae861ede7eba138c7140f195ae77ba3106cbffielding URIs to Lua scripts and functions using regular expressions.
50085d81a01f6efbb898397253634837b2b4bddarbowen [Daniel Gruno]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_lua: Add new directive LuaCodeCache for controlling in-memory
5beae861ede7eba138c7140f195ae77ba3106cbffielding caching of lua scripts. [Daniel Gruno]
50085d81a01f6efbb898397253634837b2b4bddarbowen *) The following now respect DefaultRuntimeDir/DEFAULT_REL_RUNTIMEDIR:
5beae861ede7eba138c7140f195ae77ba3106cbffielding - APIs: ap_log_pid(), ap_remove_pid, ap_read_pid()
ae7bb2d0ddd3b41ced6100e77f6d1ed306774bd5rbowen - core: the scoreboard (ScoreBoardFile), pid file (PidFile), and
5beae861ede7eba138c7140f195ae77ba3106cbffielding mutexes (Mutex)
5beae861ede7eba138c7140f195ae77ba3106cbffielding - mod_cache: thundering herd lock directory
5beae861ede7eba138c7140f195ae77ba3106cbffielding - mod_lbmethod_heartbeat, mod_heartmonitor: heartbeat storage file
5beae861ede7eba138c7140f195ae77ba3106cbffielding - mod_ldap: shared memory cache
5beae861ede7eba138c7140f195ae77ba3106cbffielding - mod_socache_shmcb, mod_socache_dbm: shared memory or dbm for cache
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding [Jeff Trawick]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_ssl: Add RFC 5878 support. [Ben Laurie]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_ssl: Add support for TLS-SRP (Secure Remote Password key exchange
5beae861ede7eba138c7140f195ae77ba3106cbffielding for TLS, RFC 5054). PR 51075. [Quinn Slack <sqs cs stanford edu>,
5beae861ede7eba138c7140f195ae77ba3106cbffielding Christophe Renou, Peter Sylvester]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) core: Make ap_regcomp() return AP_REG_ESPACE if out of memory. Make
50085d81a01f6efbb898397253634837b2b4bddarbowen ap_pregcomp() abort if out of memory. This raises the minimum PCRE
5beae861ede7eba138c7140f195ae77ba3106cbffielding requirement to version 6.0. PR 53284. [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) suexec: Add --enable-suexec-capabilites support on Linux, to use
5beae861ede7eba138c7140f195ae77ba3106cbffielding setuid/setgid capability bits rather than a setuid root binary.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Joe Orton]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) suexec: Add support for logging to syslog as an alternative to logging
c7a58a2e12f7a380fd330a1b5f931ae5d65d308bfielding to a file; configure --without-suexec-logfile --with-suexec-syslog.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Joe Orton]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_ssl: Add support for TLS Next Protocol Negotiation. PR 52210.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Matthew Steele <mdsteele google.com>]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) various modules, rotatelogs: Replace use of apr_file_write() with
5beae861ede7eba138c7140f195ae77ba3106cbffielding apr_file_write_full() to prevent incomplete writes. PR 53131.
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Nicolas Viennot <apache viennot biz>, Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) cross-compile: allow to provide CC_FOR_BUILD so that gen_test_char will
5beae861ede7eba138c7140f195ae77ba3106cbffielding be compiled by the build compiler instead of the host compiler.
5beae861ede7eba138c7140f195ae77ba3106cbffielding Also set CC_FOR_BUILD to 'cc' when cross-compilation is detected.
5beae861ede7eba138c7140f195ae77ba3106cbffielding PR 51257. [Guenter Knauf]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) core: In maintainer mode, replace apr_palloc with a version that
5beae861ede7eba138c7140f195ae77ba3106cbffielding initializes the allocated memory with non-zero values, except if
5beae861ede7eba138c7140f195ae77ba3106cbffielding AP_DEBUG_NO_ALLOC_POISON is defined. [Stefan Fritsch]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_policy: Add a new testing module to help server administrators
5beae861ede7eba138c7140f195ae77ba3106cbffielding enforce a configurable level of protocol compliance on their
50085d81a01f6efbb898397253634837b2b4bddarbowen servers and application servers behind theirs. [Graham Leggett]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_firehose: Add a new debugging module able to record traffic
5beae861ede7eba138c7140f195ae77ba3106cbffielding passing through the server in such a way that connections and/or
5beae861ede7eba138c7140f195ae77ba3106cbffielding requests be reconstructed and replayed. [Graham Leggett]
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_noloris
50085d81a01f6efbb898397253634837b2b4bddarbowen *) Simple MPM
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) mod_serf
5beae861ede7eba138c7140f195ae77ba3106cbffielding [Apache 2.5.0-dev includes those bug fixes and changes with the
5beae861ede7eba138c7140f195ae77ba3106cbffielding Apache 2.4.xx tree as documented below, except as noted.]
5beae861ede7eba138c7140f195ae77ba3106cbffieldingChanges with Apache 2.4.x and later:
5beae861ede7eba138c7140f195ae77ba3106cbffielding *) http://svn.apache.org/viewvc/httpd/httpd/branches/2.4.x/CHANGES?view=markup
5beae861ede7eba138c7140f195ae77ba3106cbffieldingChanges with Apache 2.2.x and later:
50085d81a01f6efbb898397253634837b2b4bddarbowen *) http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/CHANGES?view=markup
50085d81a01f6efbb898397253634837b2b4bddarbowenChanges with Apache 2.0.x and later: