STATUS revision 01c8bf02cc8e1165981d792de7b383b1f70d3401
0N/AAPACHE 2.0 STATUS: -*-text-*-
797N/ALast modified at [$Date: 2002/05/23 21:35:08 $]
0N/A
0N/ARelease:
0N/A
0N/A 2.0.37 : in development.
553N/A 2.0.36 : released May 6, 2002 as GA.
0N/A 2.0.35 : released April 5, 2002 as GA.
553N/A 2.0.34 : tagged March 26, 2002.
0N/A 2.0.33 : tagged March 6, 2002. not released.
0N/A 2.0.32 : released Feburary 16, 2002 as beta.
0N/A 2.0.31 : rolled Feburary 1, 2002. not released.
0N/A 2.0.30 : tagged January 8, 2002. not rolled.
0N/A 2.0.29 : tagged November 27, 2001. not rolled.
0N/A 2.0.28 : released November 13, 2001 as beta.
0N/A 2.0.27 : rolled November 6, 2001
0N/A 2.0.26 : tagged October 16, 2001. not rolled.
0N/A 2.0.25 : rolled August 29, 2001
0N/A 2.0.24 : rolled August 18, 2001
0N/A 2.0.23 : rolled August 9, 2001
553N/A 2.0.22 : rolled July 29, 2001
553N/A 2.0.21 : rolled July 20, 2001
553N/A 2.0.20 : rolled July 8, 2001
0N/A 2.0.19 : rolled June 27, 2001
0N/A 2.0.18 : rolled May 18, 2001
0N/A 2.0.17 : rolled April 17, 2001
0N/A 2.0.16 : rolled April 4, 2001
0N/A 2.0.15 : rolled March 21, 2001
0N/A 2.0.14 : rolled March 7, 2001
0N/A 2.0a9 : released December 12, 2000
415N/A 2.0a8 : released November 20, 2000
415N/A 2.0a7 : released October 8, 2000
415N/A 2.0a6 : released August 18, 2000
0N/A 2.0a5 : released August 4, 2000
415N/A 2.0a4 : released June 7, 2000
415N/A 2.0a3 : released April 28, 2000
415N/A 2.0a2 : released March 31, 2000
415N/A 2.0a1 : released March 10, 2000
415N/A
415N/APlease consult the following STATUS files for information
415N/Aon related projects:
415N/A
415N/A * srclib/apr/STATUS
415N/A * srclib/apr-util/STATUS
415N/A * docs/STATUS
415N/A
415N/A
574N/ACURRENT RELEASE NOTES:
415N/A
415N/A * 37 status: Cliff proposes that 2.0.37 be tagged on Saturday, May 25,
580N/A with the aim of releasing by Friday, May 31, and volunteers to RM.
415N/A
415N/ARELEASE SHOWSTOPPERS:
415N/A
415N/A * Worker MPM deadlocks
415N/A
415N/A * for 2.0.37: decide if the MMN bump was warranted
0N/A
0N/ACURRENT VOTES:
0N/A
415N/A * Should we always build [support*] binaries statically unless otherwise
415N/A indicated?
415N/A Message-ID: <20020129210006.B23512@Lithium.MeepZor.Com>
0N/A
0N/A +1: Ken, *wrowe [they are PITAs on OSX]
0N/A -1: Justin, Ian
415N/A
415N/A * If the parent process dies, should the remaining child processes
0N/A "gracefully" self-terminate. Or maybe we should make it a runtime
0N/A option, or have a concept of 2 parent processes (one being a
0N/A "hot spare").
0N/A See: Message-ID: <3C58232C.FE91F19F@Golux.Com>
0N/A
0N/A Self-destruct: Ken, Martin
0N/A Not self-destruct: BrianP, Ian, Cliff, BillS
415N/A Make it runtime configurable: Aaron, Jim, Justin
711N/A Have 2 parents: +1: Jim
711N/A -1: Justin, wrowe [for 2.0]
711N/A +0: Martin (while standing by, could it do
711N/A something useful?)
711N/A
711N/A * Make the worker MPM the default MPM for threaded Unix boxes.
711N/A +1: Justin, Ian, Cliff, BillS
711N/A +0: BrianP, Aaron (mutex contention is looking better with the
711N/A latest code, let's continue tuning and testing)
711N/A -0: Lars
0N/A
0N/A * Change the default config so that we add a ServerToken Minimal
0N/A to the config. Possibly go one step further and add a option
711N/A to just report '2.0' instead of '2.0.x'
711N/A +1: IanH, BrianP
415N/A -1: Greg, Cliff, Justin
0N/A I use the default response all the time to verify that a
0N/A module is present and at the proper version. This information
0N/A is also very handy for the module surveys, to determine what
0N/A modules are out there and in prevalent use (see
0N/A securityspace.com; frickin' JServ is still increasing in
0N/A numbers!). Security conscious people can change this on their
0N/A own, when required. Removing the information doesn't remove
0N/A any future vulnerabilities. Assuming that a vulnerability
0N/A occurred, I highly doubt that somebody would actually bother
0N/A to *test* the version reported in the response before
415N/A attempting to use the vulnerability, so trying to hide the
0N/A information isn't all that useful.
0N/A
0N/ARELEASE NON-SHOWSTOPPERS BUT WOULD BE REAL NICE TO WRAP THESE UP:
0N/A * Get mod_cache/mod_mem_cache out of experimental (still some
0N/A work items left to complete)
0N/A
0N/A * The 2.0.36 worker MPM graceless shutdown changes work but are
0N/A a bit clunky on some platforms; eg, on Linux, the loop to
0N/A join each worker thread seems to hang, and the parent ends up
0N/A killing off the child with SIGKILL. But at least it shuts down.
0N/A
0N/A * --enable-mods-shared="foo1 foo2" is busted on Darwin. Pier
0N/A posted a patch (Message-ID: <B8DBBE8D.575A%pier@betaversion.org>).
0N/A
415N/A * We do not properly substitute the prefix-variables in the configuration
415N/A scripts or generated-configs. (i.e. if sysconfdir is etc,
0N/A httpd-std.conf points to conf.)
0N/A
0N/A * If any request gets through ap_process_request_internal() and is
0N/A scheduled to be served by the core handler, without a flag that this
0N/A r->filename was tested by dir/file_walk, we need to 500 at the very
0N/A end of the ap_process_request_internal() processing so sub_req-esters
0N/A know this request cannot be run. This provides authors of older
0N/A modules better compatibility, while still improving the security and
0N/A robustness of 2.0.
0N/A
0N/A Status: still need to decide where this goes, OtherBill comments...
415N/A Message-ID: <065701c14526$495203b0$96c0b0d0@roweclan.net>
0N/A [Deleted comments regarding the ap_run_handler phase, as irrelevant
0N/A as BillS points out that "common case will be caught in
0N/A default_handler already (with the r->finfo.filetype == 0 check)"
711N/A and the issue is detecting this -before- we try to run the req.]
711N/A
415N/A gregames says: can this happen somehow without a broken module
415N/A being involved? If not, why waste cycles trying to defend against
0N/A potential broken modules? It seems futile.
0N/A wrowe counters: no, it shouldn't happen unless the module is broken.
415N/A But the right answer is to fail the request up-front in dir/file
415N/A walk if the path was entirely invalid; and we can't do that either
415N/A or we break modules that are unwilling to hook map_to_storage.
415N/A
415N/A * Rewrite core_output_filter. It is nearly impossible to support
0N/A it with predictable results as it is implemented now.
0N/A
0N/A * With AP_MODE_EXHAUSTIVE in the core, it is finally clear to me
415N/A how the Perchild MPM should be re-written. It hasn't worked
0N/A correctly since filters were added because it wasn't possible to
415N/A get the content that had already been written and the socket at
415N/A the same time. This mode lets us do that, so the MPM can be
415N/A fixed.
415N/A
0N/A * htpasswd blindly processes the file you give it, and does no
0N/A sanity checking before totally corrupting whatever file it was
0N/A you thought you had. It should check the input file and bail
0N/A if it finds non-comment lines that do not contain exactly 1
0N/A ':' character.
0N/A Message-ID: <20020217150457.A31632@clove.org>
0N/A
415N/A * Can a static httpd be built reliably?
0N/A Message-ID: <20020207142751.T31582@clove.org>
415N/A
415N/A * [Ken] Test suite failures:
415N/A o worker is also failing some of the 'cgi' subtests
415N/A (see <URL:http://Source-Zone.Org/Apache/regression/>):
0N/A Justin says: "Worker should be fine and passes httpd-test here.
0N/A If you can provide evidence that it can be reproduced
0N/A outside of httpd-test, then it's a showstopper. I
0N/A think it's a perl or a httpd-test problem."
0N/A Not a showstopper: Justin
0N/A
0N/A * Usage of APR_BRIGADE_NORMALIZE in core_input_filter should be
0N/A removed if possible.
0N/A Message-ID: <Pine.LNX.4.33.0201202232430.318-100000@deepthought.cs.virginia.edu>
0N/A
0N/A * There is a bug in how we sort some hooks, at least the pre-config
0N/A hook. The first time we call the hooks, they are in the correct
0N/A order, but the second time, we don't sort them correctly. Currently,
0N/A the modules/http/config.m4 file has been renamed to
0N/A modules/http/config2.m4 to work around this problem, it should moved
0N/A back when this is fixed. rbb
0N/A Justin says: "Is this really a showstopper? This has been here
0N/A forever. What's wrong? Does this have to do with
0N/A autoconf or m4?"
0N/A Not a showstopper: Justin, BrianP, trawick, gregames
0N/A
0N/A * The Add...Filter and Set...Filter directives do not allow the
0N/A administrator to order filters, beyond the order of filename (mime)
0N/A extensions. It isn't clear if Set...Filter(s) should be inserted
0N/A before or after the Add...Filter(s) which are ordered by sequence of
0N/A filename extensions. At minimum, some sort of +-[0-10] syntax seems
0N/A like the quickest fix for a 2.0 gold release.
415N/A Justin says: "Could we delay this for a point release or 2.1?"
0N/A Not a showstopper: justin, wrowe, trawick, stoddard, Jim, Ian, Aaron,
415N/A gregames
0N/A
0N/A * Get perchild to work on platforms other than Linux. This
0N/A will require a portable mechanism to pass data and file/socket
0N/A descriptors between vhost child groups. An API was proposed
0N/A on dev@apr:
0N/A Message-ID: <20020111115006.K1529@clove.org>
0N/A
0N/A * Try to get libtool inter-library dependency code working on AIX.
0N/A Message-ID: <cm3n10lx555.fsf@rdu163-40-092.nc.rr.com>
0N/A
0N/A Justin says: If we get it working on AIX, we can enable this
0N/A on all platforms and clean up our build system
0N/A somewhat.
0N/A Jeff says: I thought I tested a patch for you sometime in
0N/A January that you were going to commit within a few
0N/A days.
0N/A
0N/A * Handling of %2f in URIs. Currently both 1.3 and 2.0
0N/A completely disallow %2f in the request URI path (see
0N/A ap_unescape_url() in util.c). It's permitted and passed
0N/A through in the query string, however. Roy says the
0N/A original reason for disallowing it, from five years ago,
0N/A was to protect CGI scripts that applied PATH_INFO to
0N/A a filesystem location and which might be tricked by
0N/A ..%2f..%2f(...). We *should* allow path-info of the
0N/A form 'http://foo.com/index.cgi/path/to/path%2finfo'.
0N/A Since we've revamped a lot of our processing of path
0N/A segments, it would be nice to allow this, or at least
0N/A allow it conditionally with a directive.
0N/A
415N/A * FreeBSD, threads, and worker MPM. All seems to work fine
415N/A if you only have one worker process with many threads. Add
0N/A a second worker process and the accept lock seems to be
0N/A lost. This might be an APR issue with how it deals with
0N/A the child_init hook (i.e. the fcntl lock needs to be resynced).
0N/A More examination and analysis is required.
0N/A Status: This has also been reported on Cygwin.
0N/A Message-ID: <3C2CC514.8EF3BED1@wapme-systems.de> (cygnus)
0N/A
0N/A Justin says: So, FreeBSD-CURRENT and Cywin have the same
0N/A problem. Yum. If another platform has this
415N/A with worker, this becomes a showstopper.
415N/A Aaron says: I spent some time disecting this and have come to
0N/A the conclusion that it is not a problem in the worker MPM
0N/A (or at least, it is not isolated to a problem in worker).
0N/A I'll list some of the problems I'm seeing in case someone
0N/A else wants to pick up where I've left off:
0N/A - Delivery of just about any signal to one of the child
0N/A processes will send it into an infinite loop as well.
0N/A - Even though the parent is spinning out of control,
0N/A at first the child or children will appear to work
0N/A properly. At times it is possible to get it into a state,
0N/A however, where a request will hang until another concurrent
0N/A request "kicks" the first, at which point the second will
0N/A hang. My theory is that this has to do with the
0N/A pthread_cond_*() implementation in FreeBSD, but it's still
0N/A possible that it is in APR.
0N/A
0N/A Justin adds: Oh, FreeBSD threads are implemented entirely with
0N/A select()/poll()/longjmp(). Welcome to the nightmare.
0N/A So, that means a ktrace output also has the thread
0N/A scheduling internals in it (since it is all the same to
0N/A the kernel). Which makes it hard to distinguish between
0N/A our select() calls and their select() calls.
415N/A *bangs head on wall repeatedly* But, some of the libc_r
415N/A files have a DBG_MSG #define. This is moderately helpful
0N/A when used with -DNO_DETACH. The kernel scheduler isn't
415N/A waking up the threads on a select(). Yum. And, I bet
0N/A those decrementing select calls have to do with the
415N/A scheduler. Time to brush up on our OS fundamentals.
415N/A
415N/A * There is increasing demand from module writers for an API
0N/A that will allow them to control the server � la apachectl.
0N/A Reasons include sole-function servers that need to die if
0N/A an external dependency (e.g., a database) fails, et cetera.
0N/A Perhaps something in the (ever more abused) scoreboard?
0N/A rbb: I don't believe the scoreboard is the correct mechanism
0N/A for this. We already have a pipe that goes between parent
0N/A and child for graceful shutdown events, along with an API that
415N/A can be used to send a message down that pipe. In threaded MPMs,
0N/A it is easy enough to make that one pipe be used for graceful
0N/A and graceless events, and it is also easy to open that pipe
0N/A to both parent and child for writing. Then we just need to
0N/A figure out how to do graceless on non-threaded MPMs.
415N/A
415N/A * Allow the DocumentRoot directive within <Location > scopes? This
0N/A allows the beloved (crusty) Alias /foo/ /somepath/foo/ followed
0N/A by a <Directory /somepath/foo> to become simply
0N/A <Location /foo/> DocumentRoot /somefile/foo (IMHO a bit more legible
415N/A and in-your-face.) DocumentRoot unset would be accepted [and would
415N/A not permit content to be served, only virtual resources such as
0N/A server-info or server-status.
0N/A This proposed change would _not_ depricate Alias.
415N/A
0N/A * Win32: Rotatelogs sometimes is not terminated when Apache
0N/A goes down hard. FirstBill was looking at possibly tracking the
0N/A child's-child processes in the parent process.
0N/A OtherBill asks, wasn't this fixed?
0N/A stoddard: Not fixed. Shared scoreboard might offer a good
0N/A way for the parent to keep track of 'other child' processes
0N/A and whack them if the child goes down.
0N/A Other thoughts on walking the process chain using the NT kernel
0N/A have also been proposed on APR.
415N/A
0N/A * Win32: Add a simple hold console open patch (wait for close or
415N/A the ESC key, with a nice message) if the server died a bad
0N/A death (non-zero exit code) in console mode.
0N/A Resolution: bring forward same ugly hacks from 1.3.13-.20
0N/A
0N/A * Port of mod_ssl to Apache 2.0:
0N/A
0N/A The current porting state is summarized in modules/ssl/README. The
415N/A remaining work includes:
415N/A (1) stablizing/optimizing the SSL filter logic
0N/A (2) Enabling SSL extentions
0N/A (3) Trying to seperate the https filter logic from mod_ssl -
0N/A This is to facilitate other modules that wish to use the https
0N/A filter or the mod_ssl logic or both as required.
0N/A
0N/A * Eliminate unnecessary creation of pipes in mod_cgid
0N/A
0N/A * Combine log_child and piped_log_spawn. Clean up http_log.c.
0N/A Common logging API.
0N/A
0N/A * Document mod_file_cache.
0N/A
0N/A * Platforms that do not support fork (primarily Win32 and AS/400)
0N/A Architect start-up code that avoids initializing all the modules
0N/A in the parent process on platforms that do not support fork.
0N/A
0N/A * Win32: Migrate the MPM over to use APR thread/process calls. This
415N/A would eliminate some code in the Win32 branch that essentially
415N/A duplicates what is in APR.
0N/A
0N/A * There are still a number of places in the code where we are
415N/A losing error status (i.e. throwing away the error returned by a
0N/A system call and replacing it with a generic error code)
0N/A
0N/A * Mass vhosting version of suEXEC.
0N/A
415N/A * All DBMs suffer from confusion in support/dbmmanage (perl script) since
0N/A the dbmmanage employs the first-matched dbm format. This is not
415N/A necessarily the library that Apache was built with. Aught to
415N/A rewrite dbmmanage upon installation to bin/ with the proper library
0N/A for predictable mod_auth_dbm administration.
0N/A Questions; htdbm exists, time to kill dbmmanage, or does it remain
0N/A useful as a perl dbm management example? If we keep it,
0N/A do we address the issue above?
0N/A
0N/A * Integrate mod_dav.
0N/A Some additional items remaining:
0N/A - case_preserved_filename stuff
0N/A (use the new canonical name stuff?)
0N/A - find a new home for ap_text(_header)
0N/A - is it possible to remove the DAV: namespace stuff from util_xml?
415N/A
0N/A * ap_core_translate() and its use by mod_mmap_static and mod_file_cache
0N/A are a bit wonky. The function should probably be exposed as a utility
0N/A function (such as ap_translate_url2fs() or ap_validate_fs_url() or
415N/A something). Another approach would be a new hook phase after
0N/A "translate" which would allow the module to munge what the
415N/A translation has decided to do.
0N/A Status: Greg +1 (volunteers), Ryan +1
0N/A
415N/A * Explore use of a post-config hook for the code in http_main.c which
0N/A calls ap_fixup_virutal_hosts(), ap_fini_vhost_config(), and
0N/A ap_sort_hooks() [to reduce the logic in main()]
0N/A
0N/A * read the config tree just once, and process N times (as necessary)
415N/A
0N/A * (possibly) use UUIDs in mod_unique_id and/or mod_usertrack
0N/A
0N/A * (possibly) port the bug fix for PR 6942 (segv when LoadModule is put
415N/A into a VirtualHost container) to 2.0.
415N/A
415N/A * shift stuff to mod_core.h
0N/A
415N/A * callers of ap_run_create_request() should check the return value
0N/A for failure (Doug volunteers)
415N/A
0N/A * Win32: Get Apache working on Windows 95/98. The following work
0N/A (at least) needs to be done:
0N/A - Document warning that OSR2 is required (for Crypt functions, in
0N/A rand.c, at least.) This could be resolved with an SSL library, or
415N/A randomization in APR itself.
415N/A - Bring the Win9xConHook.dll from 1.3 into 2.0 (no sense till it
415N/A actually works) and add in a splash of Win9x service code.
415N/A
415N/A * In order to use a DSO version of mod_ssl we have to link with
415N/A -lssl and -lcrypto. A workaround is in place right now where the
415N/A entire EXTRA_LIBS macro is being appended to the objects list, but
0N/A this is a hack. We should either revamp the APACHE_CHECK_SSL_TOOLKIT
0N/A autoconf function or come up with some other autoconf checks to
0N/A search for libssl and libcrypto and properly add them to mod_ssl's
0N/A link flags.
0N/A
0N/A * Fix the worker MPM to use POD to kill child processes instead
0N/A of ap_os_killpg, regardless of how they should die. (Ryan Bloom)
0N/A
0N/A * Scoreboard structures could be changed in the future such that
415N/A proper alignment is not maintained, leading to segfaults on
415N/A some systems. Cliff posted a patch to deal with this issue but
415N/A later recanted. See this message to dev@apr.apache.org:
0N/A Message-ID: <Pine.LNX.4.44.0203011354090.16457-200000@deepthought
0N/A .cs.virginia.edu>
415N/A
0N/AEXPERIMENTAL MODULES:
0N/A Experimental modules should eventually be be promoted to fully supported
0N/A status or removed from the repository entirely (ie, the
0N/A 'experiment' failed). This section tracks what needs to happen to
0N/A get the modules promoted to fully supported status.
0N/A
0N/A mod_cache/mod_mem_cache/mod_disk_cache:
415N/A * mod_cache: handle cache_control: no_cache "field_name" to enable
711N/A cacheing the response w/o header "field_name"
0N/A See RFC2616 section 14.9.1
0N/A
0N/A * mod_cache: CacheEnable/CacheDisable should accept regular expressions.
0N/A
0N/A * mod_cache: Fix dependency on ATOMIC operators. Need
0N/A APR_HAS_ATOMIC_* feature macros.
0N/A
0N/A * mod_disk_cache: Implement garbage collection
0N/A
0N/A * mod_mem_cache/mod_disk_cache: Need to be able to query cache
0N/A status (num of entries, cache object properties, etc.).
0N/A mod_status could be extended to query optional hooks defined
0N/A by modules for the purpose of reporting module status.
0N/A mod_cache (et. al.) could define optional hooks that are called
711N/A to collect status. Status should be queryable by
711N/A HTTP or SNMP?
0N/A
0N/A * mod_mem_cache: garbage collection. One strategy is to simply
415N/A remove stale entries as we attempt to serve them. Another
415N/A strategy is to kick off a GC thread that traverses the cache
0N/A and preemptively remove stale entries. How to manage a
0N/A cache that is full? Do LRU GC? Other? Bueller?
0N/A
0N/A * mod_mem_cache/mod_disk_cache: Complete implementing config
0N/A directives.
415N/A
415N/A * Sample config for mod_cache/mod_mem_cache/mod_disk_cache for
711N/A inclusion into httpd.conf.
0N/A
0N/A * mod_cache/mod_mem_cache/mod_disk_cache: Documentation.
415N/A
415N/APRs that have been suspended forever waiting for someone to
415N/Aput them into 'the next release':
0N/A
0N/A * PR#76: general
0N/A missing call to "setlocale();"
0N/A Status:
415N/A
0N/A * PR#78: mod_include
0N/A Additional status for XBitHack directive
0N/A Status:
0N/A
415N/A * PR#362: mod_proxy
415N/A Mod_proxy doesn't allow change of error pages
415N/A Status:
415N/A
0N/A * PR#370: mod_env
0N/A Modified PATH environemnt variable is not passed, instead
0N/A system's is used
0N/A Status:
0N/A
0N/A * PR#440: mod_proxy
415N/A Proxy doesn't deliver documents if not connected
415N/A Status:
0N/A
0N/A * PR#534: mod_proxy
0N/A proxy converts ~name to %7Ename when name starts with a dot (.)
0N/A Status:
415N/A
415N/A * PR#537: mod_access
415N/A mod_access syntax allows hosts that should be restricted
415N/A Status:
0N/A
415N/A * PR#557: mod_auth-any
415N/A ~UserHome directories are not honored in absolute pathname
0N/A requests (.htaccess)
0N/A Status:
0N/A
0N/A * PR#612: mod_proxy
0N/A Proxy FTP Authentication Fails
415N/A Status:
711N/A
711N/A * PR#623: mod_include
415N/A A smarter "Last Modified" value for SSI documents (see PR number 600)
0N/A Status:
0N/A
415N/A * PR#628: config
415N/A Request of "Options SymLinksIfGroupMatch"
415N/A Status:
415N/A
415N/A * PR#700: mod_proxy
0N/A Proxy doesn't do links right for OpenVMS files through ftp:
0N/A Status:
0N/A
415N/A * PR#759: mod_imap
415N/A imap should read <MAP><AREA>*</MAP> too!
415N/A Status:
0N/A
0N/A * PR#793: general
0N/A RLimitCPU and RLimitMEM don't apply to all children like they should
0N/A Status:
0N/A
0N/A * PR#921: suexec
0N/A Uses cwd before filling it in, doesn't use syslog
415N/A Status:
415N/A
415N/A * PR#922: config
415N/A it is useful to allow specifiction that root-owned symlinks
415N/A should always be followed
415N/A Status:
415N/A
415N/A * PR#980: mod_proxy
415N/A Controlling Access to Remote Proxies would be nice...
415N/A Status:
415N/A
415N/A * PR#994: mod_proxy
415N/A Adding authentication "on the fly" through the proxy module
415N/A Status:
415N/A
415N/A * PR#1004: apache-api
415N/A request_config field in request_rec is moderately bogus
415N/A Status:
415N/A
415N/A * PR#1028: other
415N/A DoS attacks involving memory consumption
415N/A Status:
415N/A
415N/A * PR#1050: mod_log-any
415N/A Logging of virtual server to error_log as well
415N/A Status:
415N/A
415N/A * PR#1085: mod_proxy
415N/A ProxyRemote make a dead cycle.
415N/A Status:
415N/A
415N/A * PR#1117: mod_auth-any
415N/A Using NIS passwd.byname dbm files with AuthDBMUserFile
415N/A Status:
415N/A
415N/A * PR#1120: suexec
415N/A suexec does not parse arguments to #exec cmd
0N/A Status:
415N/A
415N/A * PR#1145: mod_include
415N/A Allow for Last-Modified: without resorting to XBitHack
0N/A Status:
0N/A
0N/A * PR#1158: apache-api
0N/A improvements to child spawning API
0N/A Status:
415N/A
415N/A * PR#1166: mod_proxy
0N/A ``nph-'' not honored (no buffering) for ProxyRemote mapping
0N/A Status:
0N/A
415N/A * PR#1176: mod_cgi
0N/A Apache cannot handle continuation line in headers
415N/A Status:
415N/A
415N/A * PR#1191: general
415N/A setlogin() is not called, causing problems with e.g. identd
415N/A Status:
415N/A
415N/A * PR#1204: general
415N/A regerror() exists, use it
415N/A Status:
415N/A
415N/A * PR#1233: apache-api
415N/A there is no way to keep per-connection per-module state
415N/A Status:
415N/A
415N/A * PR#1263: mod_autoexec
415N/A Add frame-safe anchor attribute to mod_autoindex links
415N/A Status:
0N/A
415N/A * PR#1268: suexec
0N/A CGI scripts running as Apache user: security (suexec etc.)
415N/A Status:
415N/A
415N/A * PR#1285: suexec
415N/A Error messages could be easier to spot in cgi.log file for suexec.c
415N/A Status:
415N/A
415N/A * PR#1287: mod_access
415N/A add allow,deny/deny,allow warning to mod_access
415N/A Status:
415N/A
415N/A * PR#1290: mod_proxy
415N/A Need to know "hit-rate" on proxy cache
415N/A Status:
415N/A
415N/A * PR#1358: mod_log-any
415N/A Selective url-encode of log fields (or maybe a pseudo
415N/A log_rewrite module?)
415N/A Status:
415N/A
415N/A * PR#1383: mod_headers
415N/A I make mod_headers to modify request headers as well as
415N/A response ones.
415N/A Status:
415N/A
415N/A * PR#1532: mod_proxy
415N/A Proxy transfer logging
415N/A Status:
415N/A
415N/A * PR#1547: mod_proxy
415N/A No HTTP_X_FORWARDED_FOR set...
415N/A Status:
415N/A
415N/A * PR#1567: mod_proxy
0N/A ProxyRemote proxy requests fail authentication by firewall
415N/A Status:
0N/A
0N/A * PR#1582: mod_rewrite
0N/A mod_rewrite forms REQUEST_URI different than mod_cgi does
415N/A Status:
415N/A
0N/A * PR#1677: mod_headers
0N/A mod_headers should allow mod_log_config-style formats in
0N/A header values
0N/A Status:
0N/A
0N/A * PR#1702: mod_proxy
415N/A mod_proxy to support persistent conns?
415N/A Status:
0N/A
0N/A * PR#1803: mod_include
415N/A patches to mod_include to allow for file tests
574N/A Status:
415N/A
415N/A * PR#1809: mod_auth-any
415N/A Suggestion for improving authentication modules and core source
415N/A code, problem with 401 and ErrorDocument
415N/A Status:
415N/A
415N/A * PR#1878: mod_proxy
415N/A listing of proxy cache content
415N/A Status:
415N/A
415N/A * PR#1905: suexec
415N/A Allow modules to set user:group for execution.
0N/A Status:
0N/A
0N/A * PR#2024: apache-api
0N/A adding auth_why to conn_rec
0N/A Status:
0N/A
0N/A * PR#2073: mod_log-any
0N/A pipelined connections are not logged correctly
0N/A Status:
0N/A
0N/A * PR#2074: mod_rewrite
0N/A mod_rewrite doesn't pass Proxy Throughput on internal subrequests
0N/A Status:
0N/A
0N/A * PR#2113: config
0N/A HTTP Server Rebuild Line Needs Changing for the better
0N/A Status:
0N/A
0N/A * PR#2138: mod_status
0N/A mod_status always displays 256 possible connection slots
0N/A Status:
0N/A
0N/A * PR#2221: documentation
0N/A Make online documentation search link back to my installation
0N/A Status:
0N/A
0N/A * PR#2284: general
0N/A Can not POST to ErrorDocument - Apache/1.3b6
0N/A Status:
0N/A
0N/A * PR#2314: mod_proxy
0N/A patterns in ProxyRemote
0N/A Status:
0N/A
0N/A * PR#2343: mod_status
0N/A Status module averages are for entire uptime
415N/A Status:
* PR#2360: suexec
suexec for general access of user content?
Status:
* PR#2396: general
Proposal for TimeZone directive
Status:
* PR#2415: mod_info
/server-info doesn't check for the virtual host to list the info
Status:
* PR#2421: config
problem specifying ndbm library for build ?with autoconfigure
Status:
* PR#2431: general
A small addition to rotatelogs.c to improve program functionality.
Status:
* PR#2446: config
AllowOverride FileInfo is too coarse
Status:
* PR#2460: mod_cgi
TimeOut applies to output of CGI scripts
Status:
* PR#2512: mod_access
&lt;IfDenied&gt; directive wanted
Status:
* PR#2573: suexec
CGI's for general use still have to be run as another user
with suExec
Status:
* PR#2648: general
Cache file names in Proxy module
Status:
* PR#2760: config
[PATCH] User/Group for <Directory> and <Location> i.e. not only
in global and <Virtual>.
Status:
* PR#2763: general
mailto tags and bundling bug report script
Status:
* PR#2785: os-aix
Support for System Resource Controller
Status:
* PR#2793: protocol
When will Apache support P3P? Any Plans?
Status:
* PR#2873: config
Feedback/Comment on APACI
Status:
* PR#2889: general
Inclusion of RPM spec file in CVS/distributions
Status:
* PR#2906: general
Propose that Apache recommend $UNIQUE_ID for all "session id"
algorithms
Status:
* PR#2907: config
suggestion: power up your Include directive :)
Status:
* PR#3018: general
cannot limit some HTTP methods
Status:
* PR#3143: apache-api
No module specific data hook for per-connection data
Status:
* PR#3191: mod_negotiation
no way to set global quality-of-source (qs) coneg values
with multiviews
Status:
* PR#3568: mod_proxy
Accessing URL through proxy server corrupts data.
Status:
* PR#3605: mod_proxy
Some anonymous FTP URLs ask for authentication
Status:
* PR#3677: general
New ErrorDocumentMatch directive
Status:
* PR#4241: config
Need to be able to override shebang line to make CGI scripts
more portable.
Status:
* PR#4244: config
"Files" and "FilesMatch" regexp does not recognize bang as
negation operator
Status:
* PR#4448: mod_log-any
Please allow CGI env variables (QUERY_STRING, ...) to be logged
with %{}e
Status:
* PR#4459: mod_include
Suggestion for better handling of Last-modified headers
Status:
* PR#4490: mod_cgi
mod_cgi prevents handling of OPTIONS requests
Status:
* PR#5713: os-windows
[PATCH] install as win32 service with domain account
Status: Cannot accept password-as-arg, we should prompt the
user when -k install/-k config with a user argument.
* PR#5993: general
AllowOverride should have a 'CheckNone' and 'AllowNone' argument
instead of only 'None'
Status:
Other bugs that need fixing:
* ap_discard_request should be converted to use the bucket API
directly rather than waste cycles copying buffers with the old API.
* MaxRequestsPerChild measures connections, not requests.
Until someone has a better way, we'll probably just rename it
"MaxConnectionsPerChild".
* Regex containers don't work in an intutive way
Status: No one has come up with an efficient way to fix this
behavior. Dean has suggested getting rid of regex containers
completely.
OtherBill suggests: We at least seem to agree on eliminating
the <Container ~ foo> forms, and using only
<ContainerMatch foo> semantics.
* SIGSEGV on Linux (glibc 2.1.2) isn't caught properly by a
sigwaiting thread. We need to work around this, perhaps unless
there is hope soon for a fixed glibc.
* orig_ct in the byterange/multipart handling may not be
needed. Apache 1.3 just never stashed "multipart" into
r->content_type. We should probably follow suit since the
byterange stuff doesn't want the rest of the code to see the
multipart content-type; the other code should still think it is
dealing with the <orig_ct> stuff.
Status: Greg volunteers to investigate (esp. since he was most
likely the one to break it :-)
Binaries (2.0.35):
Platform Avail. Volunteer
------------------------------------------------------------------
AIX 4.3.3 Bill Stoddard
Mandrake 8.1 no Ryan Bloom
FreeBSD 4.1 yes Ryan Bloom
i386-unknown-freebsd4.5 yes Aaron Bannert
OS X 10.1.3/Darwin 5.3 yes Jim Jagielski
Solaris 8.x/sparc yes Jim Jagielski
i686-pc-linux-gnu-rh70 yes Aaron Bannert
i686-pc-linux-gnu-rh72 yes Aaron Bannert
i386-pc-solaris2.8 yes Aaron Bannert
powerpc-unknown-linux-gnu yes Graham Leggett
NetWare yes Brad Nicholes
Win32-x86 yes William Rowe
Other features that need writing:
* Finish infrastructure in core for async MPMs
Status: post 2.0
* TODO in source -- just do an egrep on "TODO" and see what's there
Available Patches:
* Martin Sojka <msojka@gmx.de>'s patch to add error reporting for failed
htpasswd actions due to a full /tmp volume (other programs may have
similar problems?)
PR: 6475
Status:
* Mike Abbott's <mja@trudge.engr.sgi.com> patches to improve
performance
Status: These were written for 1.3, and are awaiting a port to
2.0
* Jim Winstead's <jimw@trainedmonkey.com> patch to add CookieDomain and
other small mod_usertrack features
* Dan Rench's <drench@xnet.com> patch to add allow the errmsg and timefmt
of SSI's to be modified in the config file. Patch is available in
PR6193
Open issues:
* Which MPMs will be included with Apache 2.0?