CHANGES revision f2386b627177c7a80d38fed6ec0aed3c086909c1
f743002678eb67b99bbc29fee116b65d9530fec0wrowe -*- coding: utf-8 -*-
a34684a59b60a4173c25035d0c627ef17e6dc215rpluemChanges with Apache 2.3.6
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic *) SECURITY: CVE-2009-3555 (cve.mitre.org)
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic mod_ssl: Comprehensive fix of the TLS renegotiation prefix injection
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic attack when compiled against OpenSSL version 0.9.8m or later. Introduces
4da61833a1cbbca94094f9653fd970582b97a72etrawick the 'SSLInsecureRenegotiation' directive to reopen this vulnerability
4da61833a1cbbca94094f9653fd970582b97a72etrawick and offer unsafe legacy renegotiation with clients which do not yet
4da61833a1cbbca94094f9653fd970582b97a72etrawick support the new secure renegotiation protocol, RFC 5746.
4da61833a1cbbca94094f9653fd970582b97a72etrawick [Joe Orton, and with thanks to the OpenSSL Team]
4789804be088bcd86ae637a29cdb7fda25169521jailletc *) SECURITY: CVE-2009-3555 (cve.mitre.org)
4789804be088bcd86ae637a29cdb7fda25169521jailletc mod_ssl: A partial fix for the TLS renegotiation prefix injection attack
4789804be088bcd86ae637a29cdb7fda25169521jailletc by rejecting any client-initiated renegotiations. Forcibly disable
4789804be088bcd86ae637a29cdb7fda25169521jailletc keepalive for the connection if there is any buffered data readable. Any
e50c3026198fd496f183cda4c32a202925476778covener configuration which requires renegotiation for per-directory/location
e50c3026198fd496f183cda4c32a202925476778covener access control is still vulnerable, unless using OpenSSL >= 0.9.8l.
e50c3026198fd496f183cda4c32a202925476778covener [Joe Orton, Ruediger Pluem, Hartmut Keil <Hartmut.Keil adnovum.ch>]
5b88c8507d5ef6d0c4cfbc78230294968175b638minfrin *) SECURITY: CVE-2010-0408 (cve.mitre.org)
6c3b9cebb551140fbb25d58bae08b539b3802133ylavic mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent
6c3b9cebb551140fbb25d58bae08b539b3802133ylavic when request headers indicate a request body is incoming; not a case of
6c3b9cebb551140fbb25d58bae08b539b3802133ylavic HTTP_INTERNAL_SERVER_ERROR. [Niku Toivola <niku.toivola sulake.com>]
4f29b65ab4b547ad5dbe506e2d0ff5d12ead9247ylavic *) SECURITY: CVE-2010-0425 (cve.mitre.org)
0a0df13b7f1f4f1a74fe295253d89ca3911b301aylavic mod_isapi: Do not unload an isapi .dll module until the request
0a0df13b7f1f4f1a74fe295253d89ca3911b301aylavic processing is completed, avoiding orphaned callback pointers.
0a0df13b7f1f4f1a74fe295253d89ca3911b301aylavic [Brett Gervasoni <brettg senseofsecurity.com>, Jeff Trawick]
69301145375a889e7e37caf7cc7321ac0f91801erpluem *) mod_ldap: LDAP caching is suppressed (and ldap-status handler returns
69301145375a889e7e37caf7cc7321ac0f91801erpluem title page only) when any mod_ldap directives are used in VirtualHost
69301145375a889e7e37caf7cc7321ac0f91801erpluem context. [Eric Covener]
506bfe33206b2fece40ef25f695af39dd4130facjkaluza *) mod_disk_cache: Decline the opportunity to cache if the response is
506bfe33206b2fece40ef25f695af39dd4130facjkaluza a 206 Partial Content. This stops a reverse proxied partial response
506bfe33206b2fece40ef25f695af39dd4130facjkaluza from becoming cached, and then being served in subsequent responses.
d58a848a016d401b965111e50ef829e1641f7834minfrin [Graham Leggett]
d58a848a016d401b965111e50ef829e1641f7834minfrin *) mod_deflate: avoid the risk of forwarding data before headers are set.
2e6f4d654c96c98b761fb012fd25c5d5b1558c44sf PR 49369 [Matthew Steele <mdsteele google.com>]
2e6f4d654c96c98b761fb012fd25c5d5b1558c44sf *) mod_authnz_ldap: Ensure nested groups are checked when the
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic top-level group doesn't have any direct non-group members
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic of attributes in AuthLDAPGroupAttribute. [Eric Covener]
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic *) mod_authnz_ldap: Search or Comparison during authorization phase
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic can use the credentials from the authentication phase
e8bd80a4bb88199d2f9a24a50345688e52d9c116ylavic (AuthLDAPSearchAsUSer,AuthLDAPCompareAsUser).
e8bd80a4bb88199d2f9a24a50345688e52d9c116ylavic PR 48340 [Domenico Rotiroti, Eric Covener]
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic *) mod_authnz_ldap: Allow the initial DN search during authentication
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic to use the HTTP username/pass instead of an anonymous or hard-coded
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic LDAP id (AuthLDAPInitialBindAsUser, AuthLDAPInitialBindPattern).
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic [Eric Covener]
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic *) mod_authnz_ldap: Publish requested LDAP data with an AUTHORIZE_ prefix
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic when this module is used for authorization. See AuthLDAPAuthorizePrefix.
d7205b1a86c51c27b71a2c458dc453fd53a261c1covener PR 45584 [Eric Covener]
d7205b1a86c51c27b71a2c458dc453fd53a261c1covener *) apxs -q: Stop filtering out ':' characters from the reported values.
d7205b1a86c51c27b71a2c458dc453fd53a261c1covener PR 45343. [Bill Cole]
44ff304057225e944e220e981d434a046d14cf06covener *) prefork MPM: Run cleanups for final request when process exits gracefully.
44ff304057225e944e220e981d434a046d14cf06covener PR 43857. [Tom Donovan]
44ff304057225e944e220e981d434a046d14cf06covener *) ab: fix number of requests sent by ab when keepalive is enabled. PR 48497.
5d1ba75b8794925e67591c209085a49279791de9covener [Bryn Dole <dole blekko.com>]
5d1ba75b8794925e67591c209085a49279791de9covener *) Log an error for failures to read a chunk-size, and return 408 instead of
032982212dbcc7c3cce95bf89c503bb56e185ac7kbrand 413 when this is due to a read timeout. This change also fixes some cases
032982212dbcc7c3cce95bf89c503bb56e185ac7kbrand of two error documents being sent in the response for the same scenario.
032982212dbcc7c3cce95bf89c503bb56e185ac7kbrand [Eric Covener] PR49167
caad2986f81ab263f7af41467dd622dc9add17f3ylavic *) mod_proxy_balancer: Add new directive BalancerNonce to allow admin
caad2986f81ab263f7af41467dd622dc9add17f3ylavic to control/set the nonce used in the balancer-manager application.
caad2986f81ab263f7af41467dd622dc9add17f3ylavic [Jim Jagielski]
45a10d38e6051fd7bdf9d742aaae633d97ff02abjailletc *) mod_proxy_connect: Support port ranges in AllowConnect. PR 23673.
f7317ff316c2b141feea31bddb74d5d3fa1584edjorton [Stefan Fritsch]
2165214331e4afafca4048f66f303d0253d7b001covener *) Proxy balancer: support setting error status according to HTTP response
a34684a59b60a4173c25035d0c627ef17e6dc215rpluem code from a backend. PR 48939. [Daniel Ruggeri <DRuggeri primary.net>]
1e2d421a36999d292042a5539971070d54aa6c63ylavic *) htcacheclean: Introduce the ability to clean specific URLs from the
1e2d421a36999d292042a5539971070d54aa6c63ylavic cache, if provided as an optional parameter on the command line.
1e2d421a36999d292042a5539971070d54aa6c63ylavic [Graham Leggett]
fa7ed98b9dc94c5845cf845aea0a44ecacd290c9humbedooh *) core: Introduce the IncludeStrict directive, which explicitly fails
fa7ed98b9dc94c5845cf845aea0a44ecacd290c9humbedooh server startup if no files or directories match a wildcard path.
0b67eb8568cd58bb77082703951679b42cf098actrawick [Graham Leggett]
0b67eb8568cd58bb77082703951679b42cf098actrawick *) htcacheclean: Report additional statistics about entries deleted.
0b67eb8568cd58bb77082703951679b42cf098actrawick PR 48944. [Mark Drayton mark markdrayton.info]
fb1985a97912b25ec6564c73e610a31e5fc6e25fcovener *) Introduce SSLFIPS directive to support OpenSSL FIPS_mode; permits all
09c87c777bed1655621bb20e1c46cb6b1a63279dcovener builds of mod_ssl to use 'SSLFIPS off' for portability, but the proper
6502b7b32f980cc2093bb3ebce37e5e4dc68fba4ylavic build of openssl is required for 'SSLFIPS on'. PR 46270.
6502b7b32f980cc2093bb3ebce37e5e4dc68fba4ylavic [Dr Stephen Henson <steve openssl.org>, William Rowe]
c1a63b8fad09c419c1a64f75993feb8a343a6801ylavic *) mod_proxy_http: Log the port of the remote server in various messages.
c1a63b8fad09c419c1a64f75993feb8a343a6801ylavic PR 48812. [Igor Galić <i galic brainsware org>]
e6b4bd1113567627ab6bb6c6a7105e1e01a7d889jailletc *) mod_reqtimeout: Do not wrongly enforce timeouts for mod_proxy's backend
e6b4bd1113567627ab6bb6c6a7105e1e01a7d889jailletc connections and other protocol handlers (like mod_ftp). [Stefan Fritsch]
e466c40e1801982602ee0200c9e8b61cc148742djailletc *) mod_proxy_ajp: Really regard the operation a success, when the client
457468b82e59d01eba00dd9d0817309c8f5e414ejim aborted the connection. In addition adjust the log message if the client
457468b82e59d01eba00dd9d0817309c8f5e414ejim aborted the connection. [Ruediger Pluem]
04983e3bd1754764eec7d6bb772fe3b0bf391771jorton *) mod_ssl: Add the 'SSLInsecureRenegotiation' directive, which
04983e3bd1754764eec7d6bb772fe3b0bf391771jorton allows insecure renegotiation with clients which do not yet
15890c9306ba98f6fc243e15a3c4778ddc7d773erpluem support the secure renegotiation protocol. [Joe Orton]
15660979a30d251681463de2e0584853890082accovener *) mod_ssl: Fix a potential I/O hang if a long list of trusted CAs
49dacedb6c387b786b7911082ff35121a45f414bcovener is configured for client cert auth. PR 46952. [Joe Orton]
cfd9415521847b2f9394fad04fb701cfb955f503rjung *) core: Only log a 408 if it is no keepalive timeout. PR 39785
cfd9415521847b2f9394fad04fb701cfb955f503rjung [Ruediger Pluem, Mark Montague <markmont umich.edu>]
28c31fb73c1264bd1d0ff932573677030b024c7dwrowe *) support/rotatelogs: Add -L option to create a link to the current
28c31fb73c1264bd1d0ff932573677030b024c7dwrowe log file. PR 48761 [<lyndon orthanc.ca>, Dan Poirier]
28c31fb73c1264bd1d0ff932573677030b024c7dwrowe *) mod_ldap: Update LDAPTrustedClientCert to consistently be a per-directory
28c31fb73c1264bd1d0ff932573677030b024c7dwrowe setting only, matching most of the documentation and examples.
8491e0600f69b0405e156ea8a419653c065c645bcovener PR 46541 [Paul Reder, Eric Covener]
63b9f1f5880391261705f696d7d65507bbe9ace3covener *) mod_ldap: LDAPTrustedClientCert now accepts CA_DER/CA_BASE64 argument
63b9f1f5880391261705f696d7d65507bbe9ace3covener types previously allowed only in LDAPTrustedGlobalCert. [Eric Covener]
49dacedb6c387b786b7911082ff35121a45f414bcovener *) mod_negotiation: Preserve query string over multiviews negotiation.
49dacedb6c387b786b7911082ff35121a45f414bcovener This buglet was fixed for type maps in 2.2.6, but the same issue
49dacedb6c387b786b7911082ff35121a45f414bcovener affected multiviews and was overlooked.
3c990331fc6702119e4f5b8ba9eae3021aea5265jim PR 33112 [Joergen Thomsen <apache jth.net>]
3c990331fc6702119e4f5b8ba9eae3021aea5265jim *) mod_ldap: Eliminate a potential crash with multiple LDAPTrustedClientCert
3c990331fc6702119e4f5b8ba9eae3021aea5265jim when some are not password-protected. [Eric Covener]
fc42512879dd0504532f52fe5d0d0383dda96a1eniq *) Fix startup segfault when the Mutex directive is used but no loaded
fc42512879dd0504532f52fe5d0d0383dda96a1eniq modules use httpd mutexes. PR 48787. [Jeff Trawick]
0451df5dc50fa5d8b3e07d92ee6a92e36a1181a5niq *) Proxy: get the headers right in a HEAD request with
0451df5dc50fa5d8b3e07d92ee6a92e36a1181a5niq ProxyErrorOverride, by checking for an overridden error
da0442c0440caef34706e2c2f3af05cb65921cc0jailletc before not after going into a catch-all code path.
983528026996668ea295be95aedb9c7a346af470ylavic PR 41646. [Nick Kew, Stuart Children]
da0442c0440caef34706e2c2f3af05cb65921cc0jailletc *) support/rotatelogs: Support the simplest log rotation case, log
06b8f183140c8e02e0974e938a05078b511d1603covener truncation. Useful when the log is being processed in real time
06b8f183140c8e02e0974e938a05078b511d1603covener using a command like tail. [Graham Leggett]
15890c9306ba98f6fc243e15a3c4778ddc7d773erpluem *) support/htcacheclean: Teach it how to write a pid file (modelled on
259878293a997ff49f5ddfc53d3739cbdc25444ecovener httpd's writing of a pid file) so that it becomes possible to run
259878293a997ff49f5ddfc53d3739cbdc25444ecovener more than one instance of htcacheclean on the same machine.
259878293a997ff49f5ddfc53d3739cbdc25444ecovener [Graham Leggett]
15890c9306ba98f6fc243e15a3c4778ddc7d773erpluem *) Log command line on startup, so there's a record of command line
b54b024c06a19926832d77d40ba35ad8c41e4d3dminfrin arguments like -f. PR 48752. [Dan Poirier]
b54b024c06a19926832d77d40ba35ad8c41e4d3dminfrin *) Introduce mod_reflector, a handler capable of reflecting POSTed
65967d05f839dbf27cf91d91fa79585eeae19660minfrin request bodies back within the response through the output filter
65967d05f839dbf27cf91d91fa79585eeae19660minfrin stack. Can be used to turn an output filter into a web service.
65967d05f839dbf27cf91d91fa79585eeae19660minfrin [Graham Leggett]
8152945ae46857b170cb227e79bb799f4fc7710dminfrin *) mod_proxy_http: Make sure that when an ErrorDocument is served
8152945ae46857b170cb227e79bb799f4fc7710dminfrin from a reverse proxied URL, that the subrequest respects the status
8152945ae46857b170cb227e79bb799f4fc7710dminfrin of the original request. This brings the behaviour of proxy_handler
8152945ae46857b170cb227e79bb799f4fc7710dminfrin in line with default_handler. PR 47106. [Graham Leggett]
75f5c2db254c0167a0e396254460de09b775d203trawick *) Support wildcards in both the directory and file components of
75f5c2db254c0167a0e396254460de09b775d203trawick the path specified by the Include directive. [Graham Leggett]
4f0358189bfa57b8e75bd6b94db264302a8f336amrumph *) mod_proxy, mod_proxy_http: Support remote https proxies
4f0358189bfa57b8e75bd6b94db264302a8f336amrumph by using HTTP CONNECT. PR 19188.
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick [Philippe Dutrueux <lilas evidian.com>, Rainer Jung]
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick *) apxs: Fix -A and -a options to ignore whitespace in httpd.conf
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick [Philip M. Gollucci]
54d750a84a175d8e338880514d440773eb986b50covener *) worker: Don't report server has reached MaxClients until it has.
54d750a84a175d8e338880514d440773eb986b50covener Add message when server gets within MinSpareThreads of MaxClients.
54d750a84a175d8e338880514d440773eb986b50covener PR 46996. [Dan Poirier]
54d750a84a175d8e338880514d440773eb986b50covener *) mod_session: Session expiry was being initialised, but not updated
54d750a84a175d8e338880514d440773eb986b50covener on each session save, resulting in timed out sessions when there
54d750a84a175d8e338880514d440773eb986b50covener should not have been. Fixed. [Graham Leggett]
54d750a84a175d8e338880514d440773eb986b50covener *) mod_log_config: Add the R option to log the handler used within the
54d750a84a175d8e338880514d440773eb986b50covener request. [Christian Folini <christian.folini netnea com>]
4e30ef014533a7e93c92d88306291f5e49c9692ftrawick *) mod_include: Allow fine control over the removal of Last-Modified and
83b50288fa7d306324bba68832011ea08f5c7832covener ETag headers within the INCLUDES filter, making it possible to cache
5f066f496cd9f20a2a701255bc67d44e7cb46daetrawick responses if desired. Fix the default value of the SSIAccessEnable
5f066f496cd9f20a2a701255bc67d44e7cb46daetrawick directive. [Graham Leggett]
2e15620d724fb8e3a5be183b917359a2fd6e9468covener *) Add new UnDefine directive to undefine a variable. PR 35350.
2e15620d724fb8e3a5be183b917359a2fd6e9468covener [Stefan Fritsch]
2e15620d724fb8e3a5be183b917359a2fd6e9468covener *) Make ap_pregsub(), used by AliasMatch and friends, use the same syntax
1b988c41ee505962781d110a3e4c2c90f1ea0aa4covener for regex backreferences as mod_rewrite and mod_include: Remove the use
1b988c41ee505962781d110a3e4c2c90f1ea0aa4covener of '&' as an alias for '$0' and allow to escape any character with a
1b988c41ee505962781d110a3e4c2c90f1ea0aa4covener backslash. PR 48351. [Stefan Fritsch]
b8efdc95bec9cf089aa1be0bfd07d46aa1137a7acovener *) mod_authnz_ldap: If AuthLDAPCharsetConfig is set, also convert the
b8efdc95bec9cf089aa1be0bfd07d46aa1137a7acovener password to UTF-8. PR 45318.
b8efdc95bec9cf089aa1be0bfd07d46aa1137a7acovener [Johannes Müller <joh_m gmx.de>, Stefan Fritsch]
f06e7c4b1bce6b6491e5de0b7998d3f5696b293dchrisd *) ab: Fix calculation of requests per second in HTML output. PR 48594.
f06e7c4b1bce6b6491e5de0b7998d3f5696b293dchrisd [Stefan Fritsch]
179565be4043d7e5f9161aa75271fa0a001866d9covener *) mod_authnz_ldap: Failures to map a username to a DN, or to check a user
179565be4043d7e5f9161aa75271fa0a001866d9covener password now result in an informational level log entry instead of
111436a32ba1254291e4883292fb116d15fe8f64covener warning level. [Eric Covener]
fce4949fb0b309a5744afcd503c6ed2d35621ee2covenerChanges with Apache 2.3.5
fce4949fb0b309a5744afcd503c6ed2d35621ee2covener *) SECURITY: CVE-2010-0434 (cve.mitre.org)
7b7430e701e9a31ce809da7c220bb8dfcf68c86etrawick Ensure each subrequest has a shallow copy of headers_in so that the
7b7430e701e9a31ce809da7c220bb8dfcf68c86etrawick parent request headers are not corrupted. Eliminates a problematic
7b7430e701e9a31ce809da7c220bb8dfcf68c86etrawick optimization in the case of no request body. PR 48359
ccc20788c1e5fc973f36df634399c89acb70deaejerenkrantz [Jake Scott, William Rowe, Ruediger Pluem]
ccc20788c1e5fc973f36df634399c89acb70deaejerenkrantz *) Turn static function get_server_name_for_url() into public
273e512f20f262e5e2aa8e0e83371d1929fb76adjkaluza ap_get_server_name_for_url() and use it where appropriate. This
273e512f20f262e5e2aa8e0e83371d1929fb76adjkaluza fixes mod_rewrite generating invalid URLs for redirects to IPv6
273e512f20f262e5e2aa8e0e83371d1929fb76adjkaluza literal addresses. [Stefan Fritsch]
fe83f60b41477b14a37edcfcd1f7f5c5a1ebfe44minfrin *) mod_ldap: Introduce new config option LDAPTimeout to set the timeout
fe83f60b41477b14a37edcfcd1f7f5c5a1ebfe44minfrin for LDAP operations like bind and search. [Stefan Fritsch]
993d1261a278d7322bccef219101220b7b4fb8c5jkaluza *) mod_proxy, mod_proxy_ftp: Move ProxyFtpDirCharset from mod_proxy to
993d1261a278d7322bccef219101220b7b4fb8c5jkaluza mod_proxy_ftp. [Takashi Sato]
ba050a6f942b9fa0e81ed73437588005c569655ccovener *) mod_proxy, mod_proxy_connect: Move AllowCONNECT from mod_proxy to
ba050a6f942b9fa0e81ed73437588005c569655ccovener mod_proxy_connect. [Takashi Sato]
ba050a6f942b9fa0e81ed73437588005c569655ccovener *) mod_cache: Do an exact match of the keys defined by
135ddda3a989215d2bedbcf1529bfb269c3eda23niq CacheIgnoreURLSessionIdentifiers against the querystring instead of
135ddda3a989215d2bedbcf1529bfb269c3eda23niq a partial match. PR 48401.
135ddda3a989215d2bedbcf1529bfb269c3eda23niq [Dodou Wang <wangdong.08 gmail.com>, Ruediger Pluem]
001a44c352f89c9ec332ffd3e0a6927dcd19432chumbedooh *) mod_proxy_balancer: Fix crash in balancer-manager. [Rainer Jung]
efe780dcf13b2b95effabf897d694d8f23feac74trawick *) Core HTTP: disable keepalive when the Client has sent
793214f67dede32edfd9ee96c664ead04d175cbbjfclere Expect: 100-continue
cc5a4a08dc9783fcbc52ce86f11e01c281a43810minfrin but we respond directly with a non-100 response.
9b0076ddd1103e5fa9c1f9bafde4b06ce244fbaecovener Keepalive here led to data from clients continuing being treated as
9b0076ddd1103e5fa9c1f9bafde4b06ce244fbaecovener a new request.
9b0076ddd1103e5fa9c1f9bafde4b06ce244fbaecovener PR 47087 [Nick Kew]
249d09d51808cb7981af99762c3b3736ca126cd5jkaluza *) Core: reject NULLs in request line or request headers.
249d09d51808cb7981af99762c3b3736ca126cd5jkaluza PR 43039 [Nick Kew]
56589be3d7a3e9343370df240010c6928cc78b39jkaluza *) Core: (re)-introduce -T commandline option to suppress documentroot
56589be3d7a3e9343370df240010c6928cc78b39jkaluza check at startup.
56589be3d7a3e9343370df240010c6928cc78b39jkaluza PR 41887 [Jan van den Berg <janvdberg gmail.com>]
77ca16c5676da23155311e13cee61e7eaba9fa3ejailletc *) mod_autoindex: support XHTML as equivalent to HTML in IndexOptions,
77ca16c5676da23155311e13cee61e7eaba9fa3ejailletc ScanHTMLTitles, ReadmeName, HeaderName
77ca16c5676da23155311e13cee61e7eaba9fa3ejailletc PR 48416 [Dmitry Bakshaev <dab18 izhnet.ru>, Nick Kew]
f87299dab99bc04b51a6b8cad51b6795db862c0atrawick *) Proxy: Fix ProxyPassReverse with relative URL
f87299dab99bc04b51a6b8cad51b6795db862c0atrawick Derived (slightly erroneously) from PR 38864 [Nick Kew]
4d12805e6c18253040223ea637acd6b3b3c18f60jorton *) mod_headers: align Header Edit with Header Set when used on Content-Type
4d12805e6c18253040223ea637acd6b3b3c18f60jorton PR 48422 [Cyril Bonté <cyril.bonte free.fr>, Nick Kew>]
85eacfc96a04547ef25aabbc06440039715084c2jorton *) mod_headers: Enable multi-match-and-replace edit option
e5d909f2b06bd880fb3675cd49363df981caa631trawick PR 47066 [Nick Kew]
a4df2cd1e1391575a327c2a90ba4315f805a0a78covener *) mod_filter: enable it to act on non-200 responses.
a4df2cd1e1391575a327c2a90ba4315f805a0a78covener PR 48377 [Nick Kew]
cb666b29f81df1d11d65002250153353568021fccovenerChanges with Apache 2.3.4
6a80c3c6f4b8ea7ba5e89402b8b779b09ce020e0covener *) Replace AcceptMutex, LockFile, RewriteLock, SSLMutex, SSLStaplingMutex,
1c2cab00d988fc48cbe59032cf76cc0bab20d6f7covener and WatchdogMutexPath with a single Mutex directive. Add APIs to
6a80c3c6f4b8ea7ba5e89402b8b779b09ce020e0covener simplify setup and user customization of APR proc and global mutexes.
75a230a728338d84dcfe81edd375352f34de22d0covener (See util_mutex.h.) Build-time setting DEFAULT_LOCKFILE is no longer
75a230a728338d84dcfe81edd375352f34de22d0covener respected; set DEFAULT_REL_RUNTIMEDIR instead. [Jeff Trawick]
1f50dc34ae069adeed20b2986e5ffdefa5c410e0covener *) http_core: KeepAlive no longer accepts other than On|Off.
1f50dc34ae069adeed20b2986e5ffdefa5c410e0covener [Takashi Sato]
63a5ea80bddcc84a462e40f402b4f330e0e05411covener *) mod_dav: Remove errno from dav_error interface. Calls to dav_new_error()
63a5ea80bddcc84a462e40f402b4f330e0e05411covener and dav_new_error_tag() must be adjusted to add an apr_status_t parameter.
63a5ea80bddcc84a462e40f402b4f330e0e05411covener [Jeff Trawick]
65a4e663b82f8bce28ac22ab2edfd7502de36998sf *) mod_authnz_ldap: Add AuthLDAPBindAuthoritative to allow Authentication to
65a4e663b82f8bce28ac22ab2edfd7502de36998sf try other providers in the case of an LDAP bind failure.
65a4e663b82f8bce28ac22ab2edfd7502de36998sf PR 46608 [Justin Erenkrantz, Joe Schaefer, Tony Stevenson]
c7de1955eb0eaeabf7042902476397692672d549sf *) Build: fix --with-module to work as documented
74e7f6c55fd67b10cb400b3f6d1dc718a303d944minfrinChanges with Apache 2.3.3
a511a29faf2ff7ead3b67680154a624effb31aafminfrin *) SECURITY: CVE-2009-3095 (cve.mitre.org)
a511a29faf2ff7ead3b67680154a624effb31aafminfrin mod_proxy_ftp: sanity check authn credentials.
a511a29faf2ff7ead3b67680154a624effb31aafminfrin [Stefan Fritsch <sf fritsch.de>, Joe Orton]
a511a29faf2ff7ead3b67680154a624effb31aafminfrin *) SECURITY: CVE-2009-3094 (cve.mitre.org)
63921358ef93fcb41bc71d9894221ba3d7fbb87bminfrin mod_proxy_ftp: NULL pointer dereference on error paths.
63921358ef93fcb41bc71d9894221ba3d7fbb87bminfrin [Stefan Fritsch <sf fritsch.de>, Joe Orton]
63921358ef93fcb41bc71d9894221ba3d7fbb87bminfrin *) mod_ssl: enable support for ECC keys and ECDH ciphers. Tested against
deec48c67d4786bc77112ffbf3a4e70b931097edminfrin OpenSSL 1.0.0b3. [Vipul Gupta <vipul.gupta sun.com>, Sander Temme]
6d601599d3d65df0410eae6e573e75b2dbfb1fb4minfrin *) mod_dav: Include uri when logging a PUT error due to connection abort.
6d601599d3d65df0410eae6e573e75b2dbfb1fb4minfrin PR 38149. [Stefan Fritsch]
684e0cfc200f66287a93bbd1708d1dd8a92a7eefcovener *) mod_dav: Return 409 instead of 500 for a LOCK request if the parent
684e0cfc200f66287a93bbd1708d1dd8a92a7eefcovener resource does not exist or is not a collection. PR 43465. [Stefan Fritsch]
05a5a9c3e16f21566e1b61f4bd68025ce1b741ccjoes *) mod_dav_fs: Return 409 instead of 500 for Litmus test case copy_nodestcoll
05a5a9c3e16f21566e1b61f4bd68025ce1b741ccjoes (a COPY request where the parent of the destination resource does not
ef82e8fa164e0a1f8b813f7deb6b7ead96018c94niq exist). PR 39299. [Stefan Fritsch]
ef82e8fa164e0a1f8b813f7deb6b7ead96018c94niq *) mod_dav_fs: Don't delete the whole file if a PUT with content-range failed.
ef82e8fa164e0a1f8b813f7deb6b7ead96018c94niq PR 42896. [Stefan Fritsch]
ef82e8fa164e0a1f8b813f7deb6b7ead96018c94niq *) mod_dav_fs: Make PUT create files atomically and no longer destroy the
ef82e8fa164e0a1f8b813f7deb6b7ead96018c94niq old file if the transfer aborted. PR 39815. [Paul Querna, Stefan Fritsch]
413ee814748f37be168ff12407fa6dba0ceeabe6trawick *) mod_dav_fs: Remove inode keyed locking as this conflicts with atomically
c12917da693bae4028a1d5a5e8224bceed8c739dsf creating files. On systems with inode numbers, this is a format change of
c12917da693bae4028a1d5a5e8224bceed8c739dsf the DavLockDB. The old DavLockDB must be deleted on upgrade.
eafcc0ebf263d0ba69855b6e10958c4c1a2361bdsf [Stefan Fritsch]
eafcc0ebf263d0ba69855b6e10958c4c1a2361bdsf *) mod_log_config: Make ${cookie}C correctly match whole cookie names
eafcc0ebf263d0ba69855b6e10958c4c1a2361bdsf instead of substrings. PR 28037. [Dan Franklin <dan dan-franklin.com>,
eafcc0ebf263d0ba69855b6e10958c4c1a2361bdsf Stefan Fritsch]
d7ffd2da16d58b1a0de212e4d56f7aebb72bef26sf *) vhost: A purely-numeric Host: header should not be treated as a port.
d7ffd2da16d58b1a0de212e4d56f7aebb72bef26sf PR 44979 [Nick Kew]
4576c1a9ef54cd1e5555ee07d016a7f559f80338sf *) mod_ldap: Avoid 500 errors with "Unable to set LDAP_OPT_REFHOPLIMIT option to 5"
4576c1a9ef54cd1e5555ee07d016a7f559f80338sf when built against openldap by using SDK LDAP_OPT_REFHOPLIMIT defaults unless
9811aed12bbc71783d2e544ccb5fecd193843eadsf LDAPReferralHopLimit is explicitly configured.
9811aed12bbc71783d2e544ccb5fecd193843eadsf [Eric Covener]
88fac54d9d64f85bbdab5d7010816f4377f95bd7rjung *) mod_charset_lite: Honor 'CharsetOptions NoImplicitAdd'.
88fac54d9d64f85bbdab5d7010816f4377f95bd7rjung [Eric Covener]
bd3f5647b96d378d9c75c954e3f13582af32c643sf *) mod_ssl: Add support for OCSP Stapling. PR 43822.
bd3f5647b96d378d9c75c954e3f13582af32c643sf [Dr Stephen Henson <shenson oss-institute.org>]
bd3f5647b96d378d9c75c954e3f13582af32c643sf *) mod_socache_shmcb: Allow parens in file name if cache size is given.
2a7beea91d46beb41f043a84eaad060047ee04aafabien Fixes SSLSessionCache directive mis-parsing parens in pathname.
2a7beea91d46beb41f043a84eaad060047ee04aafabien PR 47945. [Stefan Fritsch]
2a7beea91d46beb41f043a84eaad060047ee04aafabien *) htpasswd: Improve out of disk space handling. PR 30877. [Stefan Fritsch]
584a85dd4047e38d3ed3a29b6662fcc9d100ae4csf *) htpasswd: Use MD5 hash by default on all platforms. [Stefan Fritsch]
f21e9e3d0bfb7a507ecc5bc963f2159d693503d1sf *) mod_sed: Reduce memory consumption when processing very long lines.
f6b9c755a0b793e8a3a3aebd327ca20a86478117sf *) ab: Fix segfault in case the argument for -n is a very large number.
f6b9c755a0b793e8a3a3aebd327ca20a86478117sf PR 47178. [Philipp Hagemeister <oss phihag.de>]
132ee6ac1c26d6e8953836316ba50734eefab47bsf *) Allow ProxyPreserveHost to work in <Proxy> sections. PR 34901.
132ee6ac1c26d6e8953836316ba50734eefab47bsf [Stefan Fritsch]
85eacfc96a04547ef25aabbc06440039715084c2jorton *) configure: Fix THREADED_MPMS so that mod_cgid is enabled again
85eacfc96a04547ef25aabbc06440039715084c2jorton for worker MPM. [Takashi Sato]
536d2e7cd1fdec1255b8c3bdf41fdc714c506a54trawick *) mod_dav: Provide a mechanism to obtain the request_rec and pathname
536d2e7cd1fdec1255b8c3bdf41fdc714c506a54trawick from the dav_resource. [Jari Urpalainen <jari.urpalainen nokia.com>,
536d2e7cd1fdec1255b8c3bdf41fdc714c506a54trawick Brian France <brian brianfrance.com>]
79c5787b92ac5f0e1cc82393816c77a006399316trawick *) Build: Use install instead of cp if available on installing
79c5787b92ac5f0e1cc82393816c77a006399316trawick modules to avoid segmentation fault. PR 47951. [hirose31 gmail.com]
79c5787b92ac5f0e1cc82393816c77a006399316trawick *) mod_cache: correctly consider s-maxage in cacheability
c967bf3bc89e8aa60dbd30d9da388e448ddc1cc4trawick decisions. [Dan Poirier]
79c5787b92ac5f0e1cc82393816c77a006399316trawick *) mod_logio/core: Report more accurate byte counts in mod_status if
79c5787b92ac5f0e1cc82393816c77a006399316trawick mod_logio is loaded. PR 25656. [Stefan Fritsch]
79c5787b92ac5f0e1cc82393816c77a006399316trawick *) mod_ldap: If LDAPSharedCacheSize is too small, try harder to purge
7b395e4e878c28a4784919cfd2e704ddd14a3390jorton some cache entries and log a warning. Also increase the default
7b395e4e878c28a4784919cfd2e704ddd14a3390jorton LDAPSharedCacheSize to 500000. This is a more realistic size suitable
7b395e4e878c28a4784919cfd2e704ddd14a3390jorton for the default values of 1024 for LdapCacheEntries/LdapOpCacheEntries.
7b395e4e878c28a4784919cfd2e704ddd14a3390jorton PR 46749. [Stefan Fritsch]
536e48c08d674acac5d44929318f2ad928edc361jorton *) mod_rewrite: Make sure that a hostname:port isn't fully qualified if
e81785da447b469da66f218b3f0244aab507958djorton the request is a CONNECT request. [Bill Zajac <billz consultla.com>]
3e4e54d4e3fc0123c63d57aa84ac7ad7a8c73ff8jorton *) mod_cache: Teach CacheEnable and CacheDisable to work from within a
3e4e54d4e3fc0123c63d57aa84ac7ad7a8c73ff8jorton Location section, in line with how ProxyPass works. [Graham Leggett]
53e9b27aba029b18be814df40bcf6f0428771d1efuankg *) mod_reqtimeout: New module to set timeouts and minimum data rates for
53e9b27aba029b18be814df40bcf6f0428771d1efuankg receiving requests from the client. [Stefan Fritsch]
53e9b27aba029b18be814df40bcf6f0428771d1efuankg *) core: Fix potential memory leaks by making sure to not destroy
53e9b27aba029b18be814df40bcf6f0428771d1efuankg bucket brigades that have been created by earlier filters.
6bb524f1895f30265a1431afc460977d391cb36bsf [Stefan Fritsch]
ca61ccd0c306c2c72df153688ba1b49f3eceed80sf *) core, mod_deflate, mod_sed: Reduce memory usage by reusing bucket
6bb524f1895f30265a1431afc460977d391cb36bsf brigades in several places. [Stefan Fritsch]
e6dd71992459d05a676b98b7963423dc5dc1e24aminfrin *) mod_cache: Fix uri_meets_conditions() so that CacheEnable will
e6dd71992459d05a676b98b7963423dc5dc1e24aminfrin match by scheme, or by a wildcarded hostname. PR 40169
e6dd71992459d05a676b98b7963423dc5dc1e24aminfrin [Peter Grandi <pg_asf asf.for.sabi.co.uk>, Graham Leggett]
23f1535d6a60817d2846bac0aea230ea475d7dccminfrin *) suxec: Allow to log an error if exec fails by setting FD_CLOEXEC
23f1535d6a60817d2846bac0aea230ea475d7dccminfrin on the log file instead of closing it. PR 10744. [Nicolas Rachinsky]
ec7520b24cd80d34d82bbcaca153cbb23cc04bc0rjung *) mod_mime: Make RemoveType override the info from TypesConfig.
ec7520b24cd80d34d82bbcaca153cbb23cc04bc0rjung PR 38330. [Stefan Fritsch]
ec7520b24cd80d34d82bbcaca153cbb23cc04bc0rjung *) mod_cache: Introduce the option to run the cache from within the
ec7520b24cd80d34d82bbcaca153cbb23cc04bc0rjung normal request handler, and to allow fine grained control over
ec7520b24cd80d34d82bbcaca153cbb23cc04bc0rjung where in the filter chain content is cached. [Graham Leggett]
ec7520b24cd80d34d82bbcaca153cbb23cc04bc0rjung *) core: Treat timeout reading request as 408 error, not 400.
6249dfa569d3b4f1f539665b979a80c6e335d93etrawick Log 408 errors in access log as was done in Apache 1.3.x.
6249dfa569d3b4f1f539665b979a80c6e335d93etrawick PR 39785 [Nobutaka Mantani <nobutaka nobutaka.org>,
0827cb14e550f6f65018431c22c2c913631c8f25kbrand Stefan Fritsch <sf fritsch.de>, Dan Poirier]
ae600ca541efc686b34f8b1f21bd3d0741d37674covener *) mod_ssl: Reintroduce SSL_CLIENT_S_DN, SSL_CLIENT_I_DN, SSL_SERVER_S_DN,
6249dfa569d3b4f1f539665b979a80c6e335d93etrawick SSL_SERVER_I_DN back to the environment variables to be set by mod_ssl.
cfa64348224b66dd1c9979b809406c4d15b1c137fielding *) mod_disk_cache: don't cache incomplete responses, per RFC 2616, 13.8.
74499a117b3b2cd9666715a14f90c0e5d1a4ee8ajim PR15866. [Dan Poirier]
74499a117b3b2cd9666715a14f90c0e5d1a4ee8ajim *) ab: ab segfaults in verbose mode on https sites
cfa64348224b66dd1c9979b809406c4d15b1c137fielding PR46393. [Ryan Niebur]
cfa64348224b66dd1c9979b809406c4d15b1c137fielding *) mod_dav: Allow other modules to become providers and add resource types
Brian France <brian brianfrance.com>]
Brian France <brian brianfrance.com>]
[Stefan Fritsch <sf sfritsch.de>]
*) mod_session.c: Prevent a segfault when session is added but not
definition. [Stefan Fritsch sf sfritsch.de]
*) Add support for HTTP PUT to ab. [Jeff Barnes <jbarnesweb yahoo.com>]
PR 46971 [evanc nortel.com]
[Stefan Fritsch <sf sfritsch.de>]
for a file is missing. PR 47682 [Peter Poeml <poeml suse.de>]
*) SECURITY: CVE-2009-1890 (cve.mitre.org)
*) SECURITY: CVE-2009-1191 (cve.mitre.org)
by the client. PR 33098 [ Stefan Fritsch <sf sfritsch.de>]
PR 42175 [Jim Radford <radford blackbean.org>]
type. PR 45107. [Michael Ströder <michael stroeder.com>,
PR 44020 [HÃ¥kon Stordahl <hakon stordahl.org>]
CGI process. PR 47335 [Kornél Pál <kornelpal gmail.com>]
PR 46942 [Dan Poirier <poirier pobox.com>]
PR 44729 [Sönke Tesch <st kino-fahrplan.de>, Jim Jagielski]
PR 47177 [Carlos Garcia Braschi <cgbraschi gmail.com>]
PR 45082 [Vitaly Polonetsky <m_vitaly topixoft.com>]
[Marko Kevac <mkevac gmail.com>]
as A/UX, Next, and Tandem. [Jeff Trawick]
directory listing. PR 46789 [Dan Poirier <poirier pobox.com>]
of module state across unload/load. [Jeff Trawick]
[Dan Poirier <poirier pobox.com>]
[Geoff Keating <geoffk apple.com>]
with kqueue (BSD/OS X) and excessive CPU with event ports (Solaris).
a media type has not been configured via mime.types, AddType,
[Ryan Phillips <ryan-apache trolocsis.com>]
[<tlhackque yahoo.com>]
*) prefork: Fix child process hang during graceful restart/stop in
*) core/utils: Enhance ap_escape_html API to support escaping non-ASCII chars
PR 45529 [Bob Ionescu <bobsiegen googlemail.com>]
times out before returning status line/headers.
PR 39332 [Masaoki Kobayashi <masaoki techfirm.co.jp>]
[Theo Schlossnagle <jesus omniti.com>, Paul Querna]
modules/proxy/balancers [Jim Jagielski]
privileges and Unix user/group IDs [Nick Kew]
logic replicate 2.2.x authz logic, and replace <Satisfy*>, Reject,
*) unixd: turn existing code into a module, and turn the set user/group
Suggested By André Warnier <aw ice-sa.com> [Eric Covener]
*) mod_ssl: Send Content-Type application/ocsp-request for POST requests to
OSCP responders. PR 46014 [Dr Stephen Henson <steve openssl.org>]
*) Export and install the mod_rewrite.h header to ensure the optional
*) New module mod_sed: filter Request/Response bodies through sed
null value. [David Shane Holden <dpejesh apache.org>]
*) ab: Make ab.c compile on VC6. PR 45024 [Ruediger Pluem]
*) configure: Don't reject libtool 2.x
overwritten. PR 44262 [Michał Grzędzicki <lazy iq.pl>]
PR 44799 [Christian Wenz <christian wenz.org>]
both inside and outside the location/directory sections, as
form request with the type of application/x-www-form-urlencoded.
*) mod_authz_dbd: When redirecting after successful login/logout per
PR 44560 [Anders Kaseorg <anders kaseorg.com>]
mod_cache et.al. to trap the results of the redirect.
PR 34607. [Kaspar Brand <asfbugz velox.ch>]. A test configuration
can be created with test/make_sni.sh [Dirk-Willem van Gulik].
*) ApacheMonitor.exe: Introduce --kill argument for use by the
*) mod_ldap, mod_authnzldap: Add support for nested groups (i.e. the ability
[David Jones <oscaremma gmail.com>]
[David M. Lee <dmlee crossroads.com>]
[Niklas Edmundsson <nikke acc.umu.se>]
[Stijn Hoop <stijn sandcat.nl>]
[Niklas Edmundsson <nikke acc.umu.se>]
final name. [Davi Arnaut <davi haxent.com.br>]
[Markus Schiegl <ms schiegl.com>]
*) Remove incorrect comments from scoreboard.h regarding conditional
[Chris Darroch <chrisd pearsoncmg.com>]
in ap_init_scoreboard(). [Chris Darroch <chrisd pearsoncmg.com>]
[Chris Darroch <chrisd pearsoncmg.com>]
and 'Reject' to mod_authz_core. The new directives introduce 'AND/OR'
*) mod_authz_dbd: SQL authz with Login/Session support [Nick Kew]
Apache 2.2.xx tree as documented, and except as noted, below.]
Changes with Apache 2.2.x and later:
Changes with Apache 2.0.x and later:
Changes with Apache 1.3.x and later: