]>
git.ipfire.org Git - thirdparty/apache/httpd.git/log
William A. Rowe Jr [Fri, 9 Sep 2011 13:05:38 +0000 (13:05 +0000)]
Looks great, thanks Jeff!
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167145 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Fri, 9 Sep 2011 11:02:41 +0000 (11:02 +0000)]
try to herd some cats
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167091 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Thu, 5 May 2011 13:36:58 +0000 (13:36 +0000)]
Add BSD-specific note about core dumping. (Via mi+apache aldan.algebra.com)
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1099788 13f79535 -47bb-0310-9956-
ffa450edef68
Roy T. Fielding [Tue, 3 May 2011 20:15:58 +0000 (20:15 +0000)]
sync with trunk
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1099227 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Fri, 8 Apr 2011 14:44:02 +0000 (14:44 +0000)]
hernan gonzalez <hgonzalez gmail.com> points out that the USER_AGENT
strings were probably more accurate with the leading ^ anchor.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1090280 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Fri, 8 Apr 2011 14:32:17 +0000 (14:32 +0000)]
Remove unnecessary anchors in various rewrite examples. Rebuilding other
changes.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1090270 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Tue, 5 Apr 2011 01:53:21 +0000 (01:53 +0000)]
Fixed sysinclude; removed tab.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1088846 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Sun, 20 Mar 2011 21:43:55 +0000 (21:43 +0000)]
Drop obscure 1.3 change backrefs
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1083581 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 20 Mar 2011 18:58:27 +0000 (18:58 +0000)]
Removed dav_get_limit_xml_body() from mod_dav.h.
This was a forgotten prototype hanging around for close
to 11 years where no code for existed (see r85816);
now removed from all branches per wrowe's permission.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1083536 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 2 Mar 2011 22:24:36 +0000 (22:24 +0000)]
Commented NetWare build debug output which breaks make 3.82.
(backport from r789553).
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1076438 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Sun, 16 Jan 2011 16:01:53 +0000 (16:01 +0000)]
Rebuilds changes to mod_autoindex.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1059593 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Sun, 16 Jan 2011 15:58:58 +0000 (15:58 +0000)]
Merges changes from trunk as per tid50417
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1059591 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Mon, 3 Jan 2011 15:37:41 +0000 (15:37 +0000)]
Update copyright year.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1054656 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Mon, 3 Jan 2011 13:02:48 +0000 (13:02 +0000)]
Update copyright to 2011
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1054602 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sat, 25 Dec 2010 13:30:01 +0000 (13:30 +0000)]
Removed define obsolete since r96478.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1052780 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sat, 25 Dec 2010 12:56:07 +0000 (12:56 +0000)]
Removed define obsolete since r93260.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1052778 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sat, 25 Dec 2010 12:51:49 +0000 (12:51 +0000)]
Removed define obsolete since r93260.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1052777 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 21 Dec 2010 00:39:44 +0000 (00:39 +0000)]
Need ZLIB_DLL to build correctly for zlib.dll consumed by openssl and deflate
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1051345 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Sat, 18 Dec 2010 03:19:16 +0000 (03:19 +0000)]
new localized message
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1050577 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 21:18:56 +0000 (21:18 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044724 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 21:04:16 +0000 (21:04 +0000)]
grammar fixes
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044720 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 21:02:57 +0000 (21:02 +0000)]
merge translation from trunk
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044719 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 20:38:47 +0000 (20:38 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044712 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 20:31:19 +0000 (20:31 +0000)]
add localized not-yet-translated messages
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044706 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 00:36:46 +0000 (00:36 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044555 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 00:31:23 +0000 (00:31 +0000)]
update metafiles
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044554 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 00:20:22 +0000 (00:20 +0000)]
merge directive output changes from 2.2
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044550 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Thu, 9 Dec 2010 14:31:18 +0000 (14:31 +0000)]
Typo correction, from Eduardo Tompson Pereira
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1043976 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Fri, 3 Dec 2010 15:08:09 +0000 (15:08 +0000)]
update transformations.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1041852 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Fri, 3 Dec 2010 15:07:41 +0000 (15:07 +0000)]
update for sync with English doc.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1041850 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Mon, 22 Nov 2010 21:07:31 +0000 (21:07 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1037890 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Fri, 12 Nov 2010 21:54:51 +0000 (21:54 +0000)]
s/mycompany.com/example.com/g
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1034582 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 6 Nov 2010 13:48:17 +0000 (13:48 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1032054 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Fri, 29 Oct 2010 15:28:49 +0000 (15:28 +0000)]
Merge r1028797, r1028799 from trunk:
Add a note about LimitRequest* and name-based vhosts as followup on PR#7741
make the name-based vhost note a warning based on offline discussion with Rich
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1028803 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Fri, 29 Oct 2010 14:49:09 +0000 (14:49 +0000)]
Add correct context for LimitRequest* as per bug #7741
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1028781 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 19 Oct 2010 19:29:30 +0000 (19:29 +0000)]
Done and away
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1024371 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Mon, 18 Oct 2010 16:45:27 +0000 (16:45 +0000)]
Belated Copyright bump
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1023896 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Mon, 18 Oct 2010 09:13:55 +0000 (09:13 +0000)]
Fixed copyright year.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1023697 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Mon, 18 Oct 2010 06:42:04 +0000 (06:42 +0000)]
Very minor change required to correctly nmake install the win32 package
from source
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1023663 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 14 Oct 2010 16:36:36 +0000 (16:36 +0000)]
Bump after tag.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1022607 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 14 Oct 2010 16:32:55 +0000 (16:32 +0000)]
Prepare for tag
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1022601 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 14 Oct 2010 16:25:41 +0000 (16:25 +0000)]
Re-./build all for .64 tag
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1022600 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Sat, 9 Oct 2010 10:08:00 +0000 (10:08 +0000)]
zlib 1.1.4/openssl 0.9.7 cannot be sustained, period. bump.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1006128 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 7 Oct 2010 22:29:47 +0000 (22:29 +0000)]
Fix recursive ErrorDocument handling, when r->status isn't HTTP_OK
upon first pass through ap_die().
PR: 36090
Backport: r354118
Submitted by: Chris Darroch
Reviewed by: covener, rjung, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1005656 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 7 Oct 2010 22:24:15 +0000 (22:24 +0000)]
SECURITY: CVE-2010-1452 (cve.mitre.org)
mod_dav: Fix Handling of requests without a path segment.
(mod_cache and mod_session portions don't apply to 2.0.x)
PR: 49246
Backports: r966348
Submitted by: Mark Drayton, trawick
Reviewed by: wrowe, rjung
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1005655 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Wed, 6 Oct 2010 12:04:07 +0000 (12:04 +0000)]
Fix description of proposal (copy&paste error).
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004999 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:35:12 +0000 (10:35 +0000)]
Fixed mod_expires: Expires time shouldn't be in the past.
r1002205 in test framework needs to be reverted now since this is fixed.
Author: rjung, reviewed by: wrowe, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004974 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:30:11 +0000 (10:30 +0000)]
PR 33112 - Fix for query string preservation after content negotiation.
r1002165 in test framework needs to be revertet now since this is fixed.
Author rjung, reviewed by wrowe, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004972 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:24:18 +0000 (10:24 +0000)]
Modified rotatelogs to behave the same as the core log writer.
Author wrowe, reviewed by rjung, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004971 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:18:15 +0000 (10:18 +0000)]
Rename macro to a better name and sync with trunk.
Reviewed by wrowe, rjung.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004969 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Tue, 5 Oct 2010 20:52:18 +0000 (20:52 +0000)]
promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004810 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Tue, 5 Oct 2010 20:49:37 +0000 (20:49 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004809 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 5 Oct 2010 19:39:01 +0000 (19:39 +0000)]
Promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004787 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 5 Oct 2010 19:38:04 +0000 (19:38 +0000)]
Vote, remove comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004785 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 5 Oct 2010 18:01:16 +0000 (18:01 +0000)]
Votes, promote, note intent to tag Thursday
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004740 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:34:35 +0000 (00:34 +0000)]
propose backport.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002915 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:17:12 +0000 (00:17 +0000)]
removed default setting since no longer needed.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002907 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:05:50 +0000 (00:05 +0000)]
enabled building gen_test_char for running on build when cross-compiling;
this does not change code for any platform unless CROSS_COMPILE is defined.
Backport of r795971 - reviewed by trawick, rjung.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002901 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:02:02 +0000 (00:02 +0000)]
promote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002899 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Wed, 29 Sep 2010 15:05:12 +0000 (15:05 +0000)]
Vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002665 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 29 Sep 2010 02:16:10 +0000 (02:16 +0000)]
Added comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002449 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 17:09:44 +0000 (17:09 +0000)]
Vote, comment, propose.
The new proposals fix previous test framework
failures. Those tests are disabled for 2.0 right now.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002266 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 15:59:13 +0000 (15:59 +0000)]
Merge revisions 906039, 906057, 906485, 906491, 908015, 916733, 916817
from trunk resp. 917044 from 2.2.x:
New releases of OpenSSL will only allow secure renegotiation by
default. Add an "SSLInsecureRenegotiation" directive to enable
renegotiation against unpatched clients, to ease transition.
Submitted by: jorton
Backport by: rjung
Reviewed by: pgollucci, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002233 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 15:49:07 +0000 (15:49 +0000)]
Merge r891282 from trunk resp. 896900 from 2.2.x:
Further mitigation for the TLS renegotation attack, CVE-2009-3555:
* modules/ssl/ssl_engine_kernel.c (has_buffered_data): New function.
(ssl_hook_Access): Forcibly disable keepalive for the connection if
there is any buffered data readable from the input filter stack.
* modules/ssl/ssl_engine_io.c (ssl_io_filter_input): Ensure that the
BIO uses blocking operations when invoked outside direct control of
the httpd filter stack.
Thanks to Hartmut Keil <Hartmut.Keil adnovum.ch> for proposing this
technique.
Submitted by: jorton
Backport by: rjung
Reviewed by: pgollucci, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002227 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Mon, 27 Sep 2010 14:42:00 +0000 (14:42 +0000)]
backport trunk r683280
mod_ssl: Use memmove instead of memcpy for overlapping buffers
Submitted by: jorton
Reviewed by: sf, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001762 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:33:22 +0000 (13:33 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001426 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:30:22 +0000 (13:30 +0000)]
backport r791454 from 2.2.x branch:
SECURITY: CVE-2009-1891 (cve.mitre.org)
Fix a potential Denial-of-Service attack against mod_deflate or other
modules, by forcing the server to consume CPU time in compressing a
large file after a client disconnects. [Joe Orton, Ruediger Pluem]
Submitted by: jorton, rpluem
Reviewed by: pgollucci, poirier, rjung
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001425 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:07:15 +0000 (13:07 +0000)]
vote+promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001424 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 26 Sep 2010 10:19:46 +0000 (10:19 +0000)]
Removed a tab and trailing spaces; no code change.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001403 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 26 Sep 2010 09:28:51 +0000 (09:28 +0000)]
prepare NetWare build for creating build helpers to run on build platform;
disabled by default until gen_test_char.c is modified to allow for cross-compile.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001396 13f79535 -47bb-0310-9956-
ffa450edef68
Joe Orton [Sun, 26 Sep 2010 08:48:40 +0000 (08:48 +0000)]
Vote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001392 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Sat, 25 Sep 2010 19:53:46 +0000 (19:53 +0000)]
propose
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001311 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 14 Sep 2010 07:15:29 +0000 (07:15 +0000)]
Vote and correct classification of another accepted patch
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996770
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 14 Sep 2010 02:58:04 +0000 (02:58 +0000)]
Elevate this to a showstopper, 2.0.64 should not occur without, as noted
by trawick.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996743
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Mon, 13 Sep 2010 23:03:47 +0000 (23:03 +0000)]
Promote, demote. Please look at this specific patch if you care that it just hit the 'going nowhere' category
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996719
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 5 Aug 2010 17:41:00 +0000 (17:41 +0000)]
get the CVE-2010-1452 fix in patches/apply_to_xxx into svn
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@982705
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Mon, 26 Jul 2010 10:58:00 +0000 (10:58 +0000)]
Add proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979237
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Mon, 26 Jul 2010 07:42:48 +0000 (07:42 +0000)]
update transformations.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979187
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Mon, 26 Jul 2010 07:40:35 +0000 (07:40 +0000)]
update for sync with English docs.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979186
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 04:04:29 +0000 (04:04 +0000)]
Applied accepted backport 164538.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966953
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 03:49:09 +0000 (03:49 +0000)]
Add backport proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966949
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 00:40:00 +0000 (00:40 +0000)]
Cleaned up NetWare makefiles:
- removed obsolete -prefix compiler switch since already defined global for all files
- removed obsolete include paths
- changed include paths to use internal vars so hat apr/apr-util builds outside source tree
- removed trailing tabs and spaces, other minor cosmetic changes
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966915
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 20 Jul 2010 11:07:01 +0000 (11:07 +0000)]
Replace "back-slash" with "backslash" in docs.
I kept "back slash" when explicitely used in
comparison with "forward slash".
Backport of r965792 from trunk and of r965799
from 2.2.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@965803
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 20 Jul 2010 11:02:16 +0000 (11:02 +0000)]
Fix typo in rewrite docs (slash -> backslash).
Thanks to Denis Howe for the hint.
PR49620.
Backport of r965798 from 2.2.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@965801
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Fri, 14 May 2010 09:12:00 +0000 (09:12 +0000)]
Remove obsolete reference to patch which has already
been committed.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@944165
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 19:18:50 +0000 (19:18 +0000)]
merge r814045 from trunk (2.2.x rev 814847):
CVE-2009-3095: mod_proxy_ftp sanity check authn credentials.
Submitted by: Stefan Fritsch <sf fritsch.de>, Joe Orton
Reviewed by: pgollucci, poirier, rjung, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943980
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 19:16:36 +0000 (19:16 +0000)]
the CVE-2009-3095 fix works for me with 2.0.x
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943977
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 16:06:25 +0000 (16:06 +0000)]
merge r814844 from 2.2.x branch (trunk revs 814652 and 814785):
*) SECURITY: CVE-2009-3094 (cve.mitre.org)
mod_proxy_ftp: NULL pointer dereference on error paths.
[Stefan Fritsch <sf fritsch.de>, Joe Orton]
Reviewed by: pgollucci, poirier, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943925
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 16:00:37 +0000 (16:00 +0000)]
CVE-2009-3094 patch fixes crash for me
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943923
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:47:34 +0000 (13:47 +0000)]
Promote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943882
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:46:21 +0000 (13:46 +0000)]
Vote, comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943880
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:27:03 +0000 (13:27 +0000)]
Merge r833582, r833593, r881222 from trunk:
SECURITY: Partial fix for CVE-2009-3555:
Reject client-initiated renegotiations; this is sufficient to prevent
the attack for any configuration which does not require renegotiation
due to per-directory/per-location access control configuration.
Configuration with per-directory/per-location access control
requirements (such as "SSLVerifyClient require") are still vulnerable
to CVE-2009-3555 with this patch applied (if using OpenSSL != 0.9.8l).
* modules/ssl/ssl_private.h (SSLConnRec): Add reneg_state field.
(ssl_callback_Info): Renamed from ssl_callback_LogTracingState.
* modules/ssl/ssl_engine_init.c (ssl_init_ctx_callbacks): Install
the (renamed) info callback unconditionally.
* modules/ssl/ssl_engine_io.c (ssl_filter_ctx_t): Add config pointer
to SSLConnRec.
(bio_filter_out_write, bio_filter_in_read): Fail with
APR_ECONNABORTED if the reneg state is set to RENEG_ABORT.
* modules/ssl/ssl_engine_kernel.c (log_tracing_state): Factored out
of ssl_callback_LogTracingState.
(ssl_callback_Info): New function.
Submitted by: jorton, rpluem, rjung
Reviewed by: rjung, rpluem, pgollucci
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943879
13f79535 -47bb-0310-9956-
ffa450edef68
Daniel Earl Poirier [Thu, 13 May 2010 11:56:37 +0000 (11:56 +0000)]
Vote to backport some security fixes.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943869
13f79535 -47bb-0310-9956-
ffa450edef68
Philip M. Gollucci [Wed, 12 May 2010 23:31:04 +0000 (23:31 +0000)]
promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943750
13f79535 -47bb-0310-9956-
ffa450edef68
Philip M. Gollucci [Wed, 12 May 2010 23:28:53 +0000 (23:28 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943749
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Wed, 12 May 2010 18:08:31 +0000 (18:08 +0000)]
propose backporting a few security fixes to the 2.0.x branch
I haven't properly reviewed/tested these yet myself, but I'd guess
that some among us may be in a good position to review. (And I
should get to it eventually.)
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943603
13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Mon, 10 May 2010 22:45:57 +0000 (22:45 +0000)]
Line breaks to make example useful.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@942939
13f79535 -47bb-0310-9956-
ffa450edef68
Philip M. Gollucci [Fri, 7 May 2010 20:43:34 +0000 (20:43 +0000)]
- Backports r942209
ix the following:
$> grep -e autoindex_ -e cgi_ httpd.conf
LoadModule autoindex_module libexec/apache22/mod_autoindex.so
LoadModule cgi_module libexec/apache22/mod_cgi.so
fire up the following commands
$> apxs -e -a -n autoindex mod_autoindex.so
[activating module `autoindex' in /usr/local/etc/apache22/httpd.conf]
$> apxs -e -a -n cgi mod_cgi.so
[activating module `cgi' in /usr/local/etc/apache22/httpd.conf]
This will result into the following httpd.conf
$> grep -e autoindex_ -e cgi_ httpd.conf
LoadModule autoindex_module libexec/apache22/mod_autoindex.so
LoadModule cgi_module libexec/apache22/mod_cgi.so
LoadModule autoindex_module libexec/apache22/mod_autoindex.so
LoadModule cgi_module libexec/apache22/mod_cgi.so
As you notice the modules are now loaded twice
Now try to deactivate for the loaded ssl module
$> grep ssl_ httpd.conf
LoadModule ssl_module libexec/apache22/mod_ssl.so
$> apxs -e -A -n ssl mod_ssl.so
[preparing module `ssl' in /usr/local/etc/apache22/httpd.conf]
$> grep ssl_ httpd.conf
LoadModule ssl_module libexec/apache22/mod_ssl.so
#LoadModule ssl_module libexec/apache22/mod_ssl.so
As reported in FreeBSD ports PR: http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/133704
Previously discussed with: wrowe@
This b/c '$lmd' expects the amount of space to be a fixed amount. Use \s+ to make
any valid httpd.conf syntax work (i.e. at least 1 space)
As previously discussed with wrowe, treast this the same way roy treats
mime.types
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@942211
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 16 Mar 2010 15:16:41 +0000 (15:16 +0000)]
Add proposal to backport SSLInsecureRenegotiation
to 2.0.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@923801
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 11 Mar 2010 15:57:26 +0000 (15:57 +0000)]
merge from trunk and 2.2.x:
SECURITY: CVE-2010-0434 (cve.mitre.org)
Ensure each subrequest has a shallow copy of headers_in so that the
parent request headers are not corrupted. Elimiates a problematic
optimization in the case of no request body.
PR: 48359
Submitted by: Jake Scott, William Rowe, Ruediger Pluem
Reviewed by: wrowe, trawick, rpluem
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921910
13f79535 -47bb-0310-9956-
ffa450edef68