0N/A -*- coding: utf-8 -*-
0N/A mod_negotiation: Escape filenames in variant list to prevent an
0N/A possible XSS for a site where untrusted users can upload files to
0N/A a location with MultiViews enabled. [Niels Heinen <heinenn
google.com>]
0N/A *) mod_lua: Change prototype of vm_construct, to work around gcc bug which
0N/A causes a segfault. PR 52779. [Dick Snippe <Dick Snippe tech omroep nl>]
0N/A *) mod_ssl: If exiting during initialization because of a fatal error,
0N/A log a message to the main error log pointing to the appropriate
0N/A virtual host error log. [Stefan Fritsch]
0N/A *) mod_ldap: Treat the "server unavailable" condition as a transient
2362N/A *) mod_ssl: Add support for TLS-SRP (Secure Remote Password key exchange
2362N/A for TLS, RFC 5054). PR 51075. [Quinn Slack <sqs cs stanford edu>,
2362N/A Christophe Renou, Peter Sylvester]
0N/A *) htdbm, htpasswd: Don't crash if crypt() fails (
e.g. with FIPS enabled).
0N/A *) mod_ssl: Add new directive SSLCompression to disable TLS-level
0N/A compression. PR 53219. [Björn Jacke <bjoern j3e de>, Stefan Fritsch]
0N/A *) core: Make ap_regcomp() return AP_REG_ESPACE if out of memory. Make
0N/A ap_pregcomp() abort if out of memory. This raises the minimum PCRE
0N/A requirement to version 6.0. PR 53284. [Stefan Fritsch]
0N/A *) mpm_event: Fix handling of MaxConnectionsPerChild. [Stefan Fritsch]
0N/A *) suexec: Add --enable-suexec-capabilites support on Linux, to use
0N/A *) suexec: Add support for logging to syslog as an alternative to logging
0N/A to a file; configure --without-suexec-logfile --with-suexec-syslog.
0N/A *) mod_proxy_ajp: Reduce memory usage in case of many keep-alive requests on
0N/A one connection. PR 52275. [Naohiro Ooiwa <naohiro ooiwa miraclelinux com>]
0N/A *) mod_proxy: Use the the same hostname for SNI as for the HTTP request when
0N/A forwarding to SSL backends. PR 53134.
0N/A *) mod_ssl: Add support for TLS Next Protocol Negotiation. PR 52210.
0N/A *) mod_so: If a filename without slashes is specified for LoadFile or
0N/A LoadModule and the file cannot be found in the server root directory,
0N/A try to use the standard dlopen() search path. [Stefan Fritsch]
0N/A *) various modules, rotatelogs: Replace use of apr_file_write() with
0N/A apr_file_write_full() to prevent incomplete writes. PR 53131.
0N/A [Nicolas Viennot <apache viennot biz>, Stefan Fritsch]
0N/A *) cross-compile: allow to provide CC_FOR_BUILD so that gen_test_char will
0N/A be compiled by the build compiler instead of the host compiler.
0N/A Also set CC_FOR_BUILD to 'cc' when cross-compilation is detected.
0N/A PR 51257. [Guenter Knauf]
0N/A *) mod_authz_core: Fix parsing of Require arguments in <AuthzProviderAlias>.
0N/A PR 53048. [Stefan Fritsch]
0N/A *) core: Fix error handling in ap_scan_script_header_err_brigade() if there
0N/A is no EOS bucket in the brigade. Fixes segfault with mod_proxy_fcgi.
0N/A PR 48272. [Stefan Fritsch]
0N/A *) mod_proxy_fcgi: If there is an error reading the headers from the
0N/A backend, send an error to the client. PR 52879. [Stefan Fritsch]
0N/A *) mod_rewrite: Fix RewriteCond integer checks to be parsed correctly.
0N/A *) Fix MPM DSO load failure on AIX. [Jeff Trawick]
0N/A *) core: Add the port number to the vhost's name in the scoreboard.
0N/A *) mpm_event: Don't do a blocking write when starting a lingering close
0N/A from the listener thread. PR 52229. [Stefan Fritsch]
0N/A *) core: In maintainer mode, replace apr_palloc with a version that
0N/A initializes the allocated memory with non-zero values, except if
0N/A AP_DEBUG_NO_ALLOC_POISON is defined. [Stefan Fritsch]
0N/A *) mod_authnz_ldap: Don't try a potentially expensive nested groups
0N/A search before exhausting all AuthLDAPGroupAttribute checks on the
0N/A current group. PR52464 [Eric Covener]
0N/A *) mod_policy: Add a new testing module to help server administrators
0N/A enforce a configurable level of protocol compliance on their
0N/A servers and application servers behind theirs. [Graham Leggett]
0N/A *) mod_firehose: Add a new debugging module able to record traffic
0N/A passing through the server in such a way that connections
and/or 0N/A requests be reconstructed and replayed. [Graham Leggett]
0N/A [Apache 2.5.0-dev includes those bug fixes and changes with the
0N/A Apache
2.4.xx tree as documented below, except as noted.]
Changes with Apache
2.2.x and later:
Changes with Apache
2.0.x and later: