2N/A -*- coding: utf-8 -*-
2N/AChanges with Apache 2.5.0
2N/A *) mod_ssl: Don't flush when an EOS is received. Prepares mod_ssl
2N/A to support write completion. [Graham Leggett]
2N/A *) Fix potential rejection of valid MaxMemFree and ThreadStackSize
2N/A *) prefork: Fix long delays when doing a graceful restart.
2N/A PR 54852 [Jim Jagielski, Arkadiusz Miskiewicz <arekm maven pl>]
2N/A *) core: Add parse_errorlog_arg callback to ap_errorlog_provider
2N/A to allow providers to check the ErrorLog argument. [Jan Kaluza]
2N/A *) core: Detect incomplete body in HTTP input filter and return
2N/A APR_INCOMPLETE. PR 55475 [Yann Ylavic <ylavic dev gmail com>]
2N/A *) mod_cgid: Use the servers Timeout for each read from a CGI script,
2N/A allow override with new CGIDRequestTimeout directive. PR43494
2N/A [Eric Covener, Toshikuni Fukaya <toshikuni-fukaya cybozu co jp>]
2N/A *) core: Add missing Reason-Phrase in HTTP response headers.
2N/A PR 54946. [Rainer Jung]
2N/A *) core: ensure any abnormal exit is reported to stderr if it's a tty.
2N/A *) mod_proxy: Added support for unix domain sockets as the
2N/A backend server endpoint [Jim Jagielski, Blaise Tarr
2N/A <blaise tarr gmail com>]
2N/A *) mod_authn_socache: Support optional initialization arguments for
2N/A socache providers. [Chris Darroch]
2N/A *) mod_session: Reset the max-age on session save. PR 47476. [Alexey
2N/A *) mod_session: After parsing the value of the header specified by the
2N/A SessionHeader directive, remove the value from the response. PR 55279.
2N/A *) mod_auth_form: Make sure the optional functions are loaded even when
2N/A the AuthFormProvider isn't specified. [Graham Leggett]
2N/A *) mod_ssl: Improve handling of ephemeral DH and ECDH keys by
2N/A allowing custom parameters to be configured via SSLCertificateFile,
2N/A and by adding standardized DH parameters for 1024/2048/3072/4096 bits.
2N/A Unless custom parameters are configured, the standardized parameters
2N/A are applied based on the certificate's
RSA/DSA key size. [Kaspar Brand]
2N/A *) mod_ssl, configure: Require OpenSSL 0.9.8a or later. [Kaspar Brand]
2N/A *) mod_lua: Let the Inter-VM
get/set functions work with a global
2N/A shared memory pool instead of a per-process pool. [Daniel Gruno]
2N/A *) ldap: Support ldaps when using the Microsoft LDAP SDK.
2N/A PR 54626. [Jean-Frederic Clere]
2N/A *) mod_proxy: Add ap_connection_reusable() for checking if a connection
2N/A is reusable as of this point in processing. [Jeff Trawick]
2N/A *) mod_ssl: drop support for export-grade ciphers with ephemeral RSA
2N/A keys, and unconditionally disable aNULL, eNULL and EXP ciphers
2N/A (not overridable via SSLCipherSuite). [Kaspar Brand]
2N/A *) mod_authnz_ldap: Change default value of AuthLDAPMaxSubGroupDepth to 0
2N/A to avoid performance problems when subgroups aren't in use. [Eric Covener]
2N/A *) mod_syslog: New module implementing syslog ap_error_log provider.
2N/A Previously, this code was part of core, now it's in separate module.
2N/A *) core: Add ap_errorlog_provider to make ErrorLog logging modular. Move
2N/A syslog support from core to new mod_syslog. [Jan Kaluza]
2N/A *) mod_proxy_fcgi: Handle reading protocol data that is split between
2N/A packets. [Jeff Trawick]
2N/A *) mod_proxy_fcgi: Remove 64K limit on encoded length of all envvars.
2N/A An individual envvar with an encoded length of more than 16K will be
2N/A omitted. [Jeff Trawick]
2N/A *) core: draft-ietf-httpbis-p1-messaging-23 corrections regarding
2N/A *) mod_proxy_fcgi: Use apr_socket_timeout_get instead of hard-coded
2N/A 30 seconds timeout. [Jan Kaluza]
2N/A *) WinNT MPM: If ap_run_pre_connection() fails or sets c->aborted, don't
2N/A save the socket for reuse by the next worker as if it were an
2N/A APR_SO_DISCONNECTED socket. Restores 2.2 behavior. [Eric Covener]
2N/A *) mod_cache: Avoid a crash with strcmp() when the hostname is not provided.
2N/A *) mod_lua: Add rudimentary support for WebSocket interaction. This is
2N/A currently request-bound and only supports the WS protocol. [Daniel Gruno]
2N/A *) mod_status, mod_echo: Fix the display of client addresses.
2N/A They were truncated to 31 characters which is not enough for IPv6 addresses.
2N/A PR 54848 [Bernhard Schmidt <berni birkenwald de>]
2N/A *) mod_lua: If the first yield() of a LuaOutputFilter returns a string, it should
2N/A be prefixed to the response as documented. [Eric Covener]
2N/A *) mod_lua: Remove ETAG, Content-Length, and Content-MD5 when a LuaOutputFilter
2N/A is configured without mod_filter. [Eric Covener]
2N/A *) mod_lua: Register LuaOutputFilter scripts as changing the content and
2N/A content-length by default, when run my mod_filter. Previously,
2N/A growing or shrinking a response that started with Content-Length set
2N/A would require mod_filter and FilterProtocol change=yes. [Eric Covnener]
2N/A *) mod_lua: Return a 500 error if a LuaHook* script doesn't return a
2N/A numeric return code. [Eric Covener]
2N/A *) mod_authnz_fcgi: New module to enable FastCGI authorizer
2N/A applications to authenticate
and/or authorize clients.
2N/A routines for FastCGI, based largely on mod_proxy_fcgi.
2N/A *) core: Add ap_log_data(), ap_log_rdata(), etc. for logging buffers.
2N/A *) mod_unique_id: Use output of the PRNG rather than IP address and
2N/A pid, avoiding sleep() call and possible DNS issues at startup,
2N/A plus improving randomness for IPv6-only hosts.
2N/A *) mod_authnz_ldap: Support primitive LDAP servers that do not accept
2N/A filters, such as "SDBM-backed LDAP" on
z/OS, by allowing a special
2N/A filter "none" to be specified in AuthLDAPURL. [Eric Covener]
2N/A *) mod_file_cache: mod_file_cache should be able to serve files that
2N/A haven't had a Content-Type set via
e.g. mod_mime. [Eric Covener]
2N/A *) core: merge AllowEncodedSlashes from the base configuration into
2N/A virtual hosts. [Eric Covener]
2N/A *) AIX: Install DSO's with "cp" instead of "install" in
instdso.sh 2N/A *) mod_ldap: Don't keep retrying if a new LDAP connection times out.
2N/A *) mod_deflate: permit compilation of mod_deflate against a zlib that has
2N/A been configured with -D Z_PREFIX, which redefines the token "deflate".
2N/A previously limited to 64MB. [Jens Låås <jelaas
gmail.com>]
2N/A *) mod_auth_digest: Use the secret when generating nonces in all cases and
2N/A not only when AuthName is used in .htaccess files (this change may cause
2N/A problems if used with round robin load balancers). Don't regenerate the
2N/A secret on graceful restarts. PR 54637 [Stefan Fritsch]
2N/A *) core: Remove apr_brigade_flatten(), buffering and duplicated code
2N/A from the HTTP_IN filter, parse chunks in a single pass with zero copy.
2N/A Reduce memory usage by 48 bytes per request. [Graham Leggett]
2N/A *) core: Stop the HTTP_IN filter from attempting to write error buckets
2N/A to the output filters, which is bogus in the proxy case. Create a
2N/A clean mapping from APR codes to HTTP status codes, and use it where
2N/A needed. [Graham Leggett]
2N/A *) mod_proxy: Ensure network errors detected by the proxy are returned as
2N/A 504 Gateway Timout as opposed to 502 Bad Gateway, in order to be
2N/A compliant with RFC2616 14.9.4 Cache Revalidation and Reload Controls.
2N/A *) mod_dav: mod_dav overrides dav_fs response on PUT failure. PR 35981
2N/A *) core, mod_ssl: Enable the ability for a module to reverse the sense of
2N/A a poll event from a read to a write or vice versa. This is a step on
2N/A the way to allow mod_ssl taking full advantage of the event MPM.
2N/A *) mod_ldap: LDAP connections used for authentication were not respecting
2N/A LDAPConnectionPoolTimeout. PR 54587
2N/A *) core: ap_rgetline_core now pulls from r->proto_input_filters.
2N/A *) mod_proxy_html: process parsed comments immediately.
2N/A Fixes bug where parsed comments may be lost. [Nick Kew]
2N/A *) mod_proxy_html: introduce doctype for HTML 5 [Nick Kew]
2N/A *) mod_proxy_html: fix typo-bug processing "strict" vs "transitional"
2N/A *) core: Add option to add valgrind support. Use it to reduce false positive
2N/A warnings in mod_ssl. [Stefan Fritsch]
2N/A *) mod_authn_file, mod_authn_dbd, mod_authn_dbm, mod_authn_socache:
2N/A Cache the result of the most recent password hash verification for every
2N/A keep-alive connection. This saves some expensive calculations.
2N/A *) http: Remove support for Request-Range header sent by Navigator 2-3 and
2N/A MSIE 3. [Stefan Fritsch]
2N/A *) core, http: Extend HttpProtocol with an option to enforce stricter HTTP
2N/A conformance or to only log the found problems. [Stefan Fritsch]
2N/A *) core: Correctly parse an IPv6 literal host specification in an absolute
2N/A URL in the request line. [Stefan Fritsch]
2N/A *) mod_ssl: Add support for OpenSSL configuration commands [Stephen Henson]
2N/A *) core: Add LogLevelOverride directive that allows to override the
2N/A loglevel for clients from certain IPs. This also works for things
2N/A like the SSL handshake where <If> LogLevel ... </If> is evaluated
2N/A too late. [Stefan Fritsch]
2N/A *) core: Add new directive Warning to issue warnings from a configuration
2N/A file. Both Warning and Error now generate a timestamped log message.
2N/A *) ap_expr: Add SERVER_PROTOCOL_VERSION, ..._MAJOR, and ..._MINOR
2N/A variables. [Stefan Fritsch]
2N/A *) core: New directive RegisterHttpMethod for registering non-standard
2N/A HTTP methods. [Stefan Fritsch]
2N/A *) core: New directive HttpProtocol which allows to disable HTTP/0.9
2N/A support. [Stefan Fritsch]
2N/A *) mod_allowhandlers: New module to forbid specific handlers for specific
2N/A directories. [Stefan Fritsch]
2N/A *) mod_systemd: New module, for integration with systemd on Linux.
2N/A *) WinNT MPM: Store pid and generation for each thread in scoreboard
2N/A to allow tracking of threads from exiting children via mod_status
2N/A or other such mechanisms. [Jeff Trawick]
2N/A - APIs: ap_log_pid(), ap_remove_pid, ap_read_pid()
2N/A - core: the scoreboard (ScoreBoardFile), pid file (PidFile), and
2N/A - mod_cache: thundering herd lock directory
2N/A - mod_lbmethod_heartbeat, mod_heartmonitor: heartbeat storage file
2N/A - mod_ldap: shared memory cache
2N/A - mod_socache_shmcb, mod_socache_dbm: shared memory or dbm for cache
2N/A *) suexec: Add --enable-suexec-capabilites support on Linux, to use
2N/A *) suexec: Add support for logging to syslog as an alternative to logging
2N/A to a file; configure --without-suexec-logfile --with-suexec-syslog.
2N/A *) mod_ssl: Add support for TLS Next Protocol Negotiation. PR 52210.
2N/A *) cross-compile: allow to provide CC_FOR_BUILD so that gen_test_char will
2N/A be compiled by the build compiler instead of the host compiler.
2N/A Also set CC_FOR_BUILD to 'cc' when cross-compilation is detected.
2N/A PR 51257. [Guenter Knauf]
2N/A *) core: In maintainer mode, replace apr_palloc with a version that
2N/A initializes the allocated memory with non-zero values, except if
2N/A AP_DEBUG_NO_ALLOC_POISON is defined. [Stefan Fritsch]
2N/A *) mod_policy: Add a new testing module to help server administrators
2N/A enforce a configurable level of protocol compliance on their
2N/A servers and application servers behind theirs. [Graham Leggett]
2N/A *) mod_firehose: Add a new debugging module able to record traffic
2N/A passing through the server in such a way that connections
and/or 2N/A requests be reconstructed and replayed. [Graham Leggett]
2N/A [Apache 2.5.0-dev includes those bug fixes and changes with the
2N/A Apache
2.4.xx tree as documented below, except as noted.]